Insurers are deeply divided over how to handle losses involving artificial intelligence, with some moving to exclude coverage, others offering affirmative protection, and most remaining silent, according to a new report from the RAND Corporation. The report, produced by RAND’s Institute for Civil Justice and the Feinberg Center for Catastrophic Risk Management and Compensation, says businesses are embedding AI into customer service, hiring, fraud detection, and autonomous systems so quickly that insurance practices have not caught up. Coverage for resulting harms is fragmented and inconsistent, the report concludes. RAND examined the AI Incident Database, a George Washington University database of AI lawsuits, enacted state laws, and insurance filings submitted through the industry’s electronic rate and form filing system. It found that of 713 generative AI incidents tracked since ChatGPT’s November 2022 launch, 599, or 84%, involved misinformation or deepfakes. An additional 47% of incidents fell into overlapping categories: hallucinations and factual errors made up 30%, harmful content 13%, and agentic or autonomous failures 12%. Because some incidents involved multiple categories, the percentages do not sum to 100. The findings illustrate the range of AI-related harms that could generate claims, from false statements that damage reputations to allegedly defective model outputs that cause physical or financial harm. RAND also notes that the same AI system can produce very different losses depending on context, which complicates underwriting, claims handling, and coverage litigation. The report stresses that insurers are not treating AI as a single peril or a stand-alone line; rather, coverage decisions are being made line by line, policy by policy, and carrier by carrier. That fragmented approach leaves policyholders with substantial uncertainty at a moment when AI adoption is accelerating across nearly every sector of the economy.

Litigation arising from generative AI tells a different story from the incident data, according to RAND. Of the 249 U.S. generative AI lawsuits the researchers reviewed, 150, or 60%, centered on intellectual property or training-data disputes against AI developers, rather than on harms caused by model outputs. This suggests that early legal exposure is heavily concentrated upstream, in the way AI systems are built and trained, rather than downstream, in how their outputs are used by customers and third parties. Privacy and surveillance claims, fraud and deception cases, and product liability suits, including wrongful-death claims tied to companion chatbots, made up smaller but growing shares of the litigation. These categories may expand as AI systems become more autonomous and as chatbots and embodied AI tools interact more directly with people. The report notes that the coming wave of cases could shift from developers to deploying businesses if the focus moves from training-data controversies to the actual consequences of AI-generated content and decisions. Separately, RAND found that most of the 189 enacted state AI laws it examined target harmful synthetic content. Thirty-three states have passed 62 laws addressing nonconsensual intimate images and child sexual abuse material. This state legislative activity is significant because it creates new statutory duties and potential liabilities for technology companies, employers, and platform operators, and those liabilities may not be covered by existing commercial insurance forms that were drafted before generative AI was widely deployed. The combination of litigation and legislative change means insurers, policyholders, and courts are confronting AI-related claims without a settled body of legal precedent or a standard set of policy terms.

Carriers are diverging sharply in how they respond to these pressures, according to RAND. Some major insurers are moving to exclude AI losses broadly. Verisk/ISO developed exclusionary language in January 2026 for bodily injury, property damage, and personal and advertising injury caused by generative AI. Because ISO standardized forms appear in more than 80% of U.S. property and casualty policies, this exclusion language has the potential to shape the market broadly communicated across many carriers and lines. Berkley went further in the management liability space, revising its directors and officers, errors and omissions, and fiduciary liability policies to exclude claims tied to nearly any use, deployment, or development of AI, including a company’s own statements about its AI capabilities. That kind of broad exclusion reaches not only injuries caused by model outputs but also corporate representations, board oversight, and disclosure obligations related to AI. RAND’s review of filing data shows that exclusion activity surged beginning in summer 2025, with the increase concentrated in commercial umbrella and commercial general liability policies. The concentration in umbrella and excess lines suggests that insurers are particularly worried about catastrophic tail exposures, where a single AI-related event could generate losses far exceeding primary limits. For policyholders, the emergence of broad AI exclusions means that standard commercial policies may no longer respond to a growing class of risks unless affirmative coverage is purchased separately. The report warns that this could widen the protection gap, especially for small and medium-sized businesses that cannot negotiate manuscript provisions or afford stand-alone specialty policies.

Other carriers are moving in the opposite direction, affirmatively covering AI-related losses. Munich Re, AXA XL, and Coalition have expanded policies to address hallucinations, bias, privacy infringement, and AI-enabled fraud, according to RAND. These affirmative coverage developments are notable because they recognize that AI risks are not entirely new but require specific policy language to remove ambiguity. In addition, new entrants including Testudo, Armilla, and the Artificial Intelligence Underwriting Company have launched stand-alone AI liability products, some with limits up to $50 million. These specialty products are designed for businesses that need express coverage for AI-related claims, particularly in areas such as intellectual property, defamation, discrimination, and autonomous system failures. The emergence of a dedicated AI insurance market suggests there is demand for clarity and capacity beyond what traditional policies provide. Most carriers, however, have done neither: they have not added explicit AI exclusions, nor have they added affirmative coverage, leaving their policies silent on whether AI-related losses are covered. RAND says this silence does not necessarily create ambiguity for policyholders in every case, but coverage still depends heavily on policy language, the theory of liability, and how exclusions and definitions not drafted with AI in mind ultimately apply. Courts may be asked to decide whether standard terms such as “occurrence,” “personal and advertising injury,” “property damage,” or “error or omission” capture AI-caused harm. The report cautions that policyholders should not assume silence means coverage, nor should they assume an exclusion applies. The result is a market in which businesses may think they are insured when they are not, or may purchase unnecessary coverage for risks already covered.

RAND also warns of accumulation risk, the possibility that a single event or common cause could produce correlated, large-scale losses across many insurers and policyholders at once. The report identifies five mechanisms that could trigger such losses. First, a universal attack exploiting the same vulnerability across many AI systems could affect thousands of organizations simultaneously. Second, common dependency on shared models or infrastructure, including hyperscalers such as Amazon Web Services, Microsoft Azure, and Google Cloud, means a failure or disruption at one provider could cascade across the entire economy. Third, AI can act as a force multiplier for cyberattacks, enabling threat actors to automate attacks, evade defenses, and scale intrusions far faster than traditional methods. Fourth, a legal or regulatory shock could suddenly expose many firms to liability at once, for example if a court adopts a broad theory of liability or a new statute creates retroactive obligations for AI deployment. Fifth, subtle but prolonged degradation of model performance could gradually erode the quality of automated decisions, producing widespread but slow-building losses that insurers and policyholders may not recognize until they have accumulated significantly. These mechanisms are particularly challenging for insurers because they are not easily diversified away. If many insureds rely on the same underlying AI systems, infrastructure, and data pipelines, a single root cause can produce claims across many unrelated policyholders in different lines of business. RAND says the size of the AI protection gap, the difference between economic losses and insured losses, and the extent of insurer accumulation exposure are directly linked. Broader affirmative coverage shrinks the protection gap but raises insurer exposure to accumulation. Broader exclusions do the reverse, reducing insurer exposure but leaving more economic loss uninsured. Silent coverage obscures both metrics, making it difficult for policyholders, insurers, and regulators to determine what is actually covered and where the true vulnerabilities lie.

To address these problems, RAND recommends that state insurance regulators and the National Association of Insurance Commissioners develop a standardized AI Coverage Notice. Such a notice would require or encourage insurers to disclose clearly whether their policies cover, exclude, or remain silent on AI-related lossesasi, and would give businesses a baseline for comparing coverage across carriers. RAND also calls on industry stakeholders to build a common taxonomy for tracking AI incidents and claims, which would allow regulators, insurers, reinsurers, and policyholders to measure losses consistently and identify emerging risk patterns. Finally, the report recommends that insurers and reinsurers conduct and disclose AI accumulation scenario analysis, modeling how different types of AI failures, cyberattacks, legal shocks, or infrastructure outages could affect their portfolios. Greater transparency around accumulation exposure would help the market price AI risk more accurately and avoid a repeat of past failures to recognize correlated risks until after they materialize. The report’s findings point to a pivotal moment for the insurance industry. Artificial intelligence offers enormous benefits, but it also introduces new, hard-to-predict liabilities that do not fit neatly into existing coverage architecture. Insurers must decide whether to underwrite AI-related risk explicitly, exclude it completely, or leave it ambiguous. According to RAND, silence is not a neutral option. It simply shifts the burden of uncertainty onto policyholders and courts, making the protection gap harder to measure and the potential for systemic insurer losses harder to manage. The full report is available from RAND.

Share.
Leave A Reply

Exit mobile version