Wednesday, 23 September 2026 PDT | 01:46 PM
The 1 News Alt Logo Text Smart News for Global Indians

Emmanuèle Lutfalla and Louis Fer discuss the emerging insurance risks posed by artificial intelligence, in Global Relay Intelligence & Practice

AI News September 23, 2026 11:00 PM
Emmanuèle Lutfalla and Louis Fer discuss the emerging insurance risks posed by artificial intelligence, in Global Relay Intelligence & Practice

Artificial intelligence may be creating an insurance problem that will only become fully visible after the first major catastrophe. To date, the debate has largely focused on familiar risks: hallucinations, data breaches, intellectual property infringement, discrimination and cybersecurity failures. But the development that may matter most to insurers and reinsurers is the transition from passive AI tools to autonomous systems capable of performing tasks, making decisions and initiating actions with limited human intervention. An employee can make a mistake. A defective AI system deployed across thousands of businesses may make the same mistake simultaneously. The claims are already emerging. The more difficult question is whether the market understands the extent to which it may already be exposed to a single, systemic AI event.

I. From individual claims to systemic accumulation

Insurance markets are familiar with accumulation risk. AI may introduce a particularly difficult form of it. Modern businesses increasingly rely on a small number of technology providers, cloud infrastructures and underlying AI models. Enterprise spending on frontier AI grew over 300 per cent in 2025, and the same technology may now be embedded in the operations of banks, law firms, manufacturers, healthcare providers and insurers themselves.

A defect in a widely used model, a faulty update or a coordinated attack could affect thousands of businesses simultaneously, triggering claims across cyber, professional indemnity, directors' and officers', general liability and other policies, from the same root cause. Chubb has already recognised the danger, excluding losses hitting many policyholders simultaneously from certain AI-related covers. Exposure that appears limited when assessed policy by policy may become substantial when hundreds of insureds depend on the same technology.

II. How AI risk is currently covered: the "silent AI" question

Most conventional policies were not drafted with autonomous AI in mind. Yet AI-related losses may well fall within their scope: professional indemnity where AI contributes to negligent advice, cyber where an AI system is compromised, D&O where directors are accused of inadequate AI governance, general liability where an autonomous system causes damage to a third party.

This is what the market describes as "silent AI": exposure under policies that neither expressly cover nor expressly exclude AI-related risks. A study published in 2026, co-authored with researchers from Anthropic and OpenAI, estimated that more than 90 per cent of insurers' aggregate AI liability exposure sits within this category, never identified, disclosed or priced.

The parallel with "silent cyber" is worth recalling. That earlier uncertainty led insurers to clarify their wordings, introduce exclusions and develop standalone products. AI may follow a similar trajectory, but the range of potential losses is considerably wider, touching nearly every line of business rather than a single product category. In France, the question is already arising in coverage disputes: does a professional indemnity policy respond when the "professional act" was performed by an AI system the insured deployed? As of January 2026, ISO introduced generative AI exclusion endorsements for US commercial general liability policies, and European carriers are following with their own endorsements and sublimits. But the transition remains fragmented and slow. Insurers carry accumulations they have not measured, and when the first major AI loss crystallises, the coverage disputes will be fought over wordings that were never designed for the risk.

III. Familiar legal questions, unfamiliar technology

AI does not necessarily create entirely new legal questions. It places traditional principles of insurance law under new pressure. When an AI system provides incorrect information to a customer who suffers financial loss, what is the relevant cause? The defective model? The professional service? The customer's reliance? A failure of oversight? The answer may determine which policy responds, if any. Exclusions designed to address cyber incidents, intentional conduct or defective products may not capture the risks created by autonomous decision-making.

This uncertainty is compounded at the European level. The AI Liability Directive, intended to harmonise civil liability rules across Member States, was withdrawn by the Commission in 2025. What remains is the AI Act (a compliance instrument, not a liability regime) and the revised Product Liability Directive, which Member States need not transpose until December 2026. National courts are left to apply existing civil liability doctrines to a technology those doctrines were never designed to address. For reinsurers seeking coherent pricing, the resulting fragmentation is deeply problematic.

IV. The lesson of 9/11: when private markets reach their limits

The comparison between AI and terrorism is obviously imperfect, but it remains instructive.

The 11 September attacks resulted in approximately $47 billion in insured losses in 2019 dollars across property, business interruption, aviation, workers' compensation and liability. Insurers sharply reduced their exposure. In the United States, this led to the Terrorism Risk Insurance Act (TRIA). In France, GAREAT provided the equivalent mechanism. TRIA has been reauthorised four times and remains in force through 2027, because the private market still cannot absorb the tail risk of large-scale terrorism on its own.

AI presents a similar challenge. Unlike a natural catastrophe, an AI failure would not be geographically limited. A defect affecting a widely used model could simultaneously affect insureds in Paris, London, New York and Singapore. An insurer may know that it has written a professional indemnity policy for a law firm or a cyber policy for a financial institution. It may not know which AI models those insureds rely upon. The first major AI catastrophe could therefore reveal correlations that were invisible when the risks were originally underwritten.

The priority for insurers and reinsurers is therefore visibility. They need to understand not only whether their insureds use AI, but which technologies are deployed, how those technologies operate and where common dependencies exist across their portfolios. Policy wording will be equally important. The alternative is to leave the scope of AI coverage to be determined after the first major loss. Only when such an event occurs will the true capacity of private insurance markets be tested.