RAND Read The Filings. Most Carriers Are Silent On AI Losses, And That Is The Problem.

Estimated reading time: 11 minutes

Mind the AI insurance coverage gaps. A vendor report says carriers are confused about AI. A RAND Corporation report says carriers are diverging, and names the consequences of each path.

Sasha Romanosky and Celine Robinson spent the better part of 2026 reading actual SERFF filings, AI incident databases, federal lawsuit records, and enacted state laws. The result is The Insurability of Artificial Intelligence, published on 16 September and aimed directly at insurers, reinsurers, brokers, MGAs, and the NAIC.

RAND frames the problem as a mismatch: enterprise AI adoption is moving fast, and the market for insuring what goes wrong is fragmented. The work was conducted jointly within RAND’s Institute for Civil Justice and its Feinberg Center for Catastrophic Risk Management and Compensation, which is a useful signal about how RAND is classifying this risk.

Their central finding is not that AI risk is hard to price, though it is. It is that most of the market has chosen not to declare a position, and that silence creates consequences distinct from either covering or excluding the risk.

Three Carriers Walk Into An AI Claim

The market has sorted into three groups. RAND identified the excluding carriers directly from admitted-market filings, and infers the silent group by elimination, noting that no standalone AI policies had been filed in the admitted market at the time of writing. The same carrier may sit in different groups across different lines.

The first group excludes:

Verisk and ISO introduced optional exclusion endorsements effective January 2026, described publicly the previous October, covering bodily injury, property damage, and personal and advertising injury caused by generative AI. ISO’s standardized forms appear in more than 80% of US property and casualty policies generally, though RAND notes it has no data on how many carriers have actually adopted these particular exclusions. Berkley filed a specialty lines exclusion covering every aspect of AI: use, development, deployment, content generation, vendor relationships, internal policies, employee training, external statements about AI, and compliance with AI regulation. An executive who overstates the company’s AI capabilities and later faces securities litigation would find the claim excluded. An executive who fails to disclose AI use adequately would find it excluded. The scope is not narrow.

The second group covers:

Munich Re insures first- and third-party losses for AI deployers and developers, across model underperformance, hallucination, bias, privacy, IP violation, and harmful content. AXA XL introduced an endorsement in late 2024 aimed at firms developing their own AI applications, covering training-data poisoning, training-data usage-rights infringement, and EU AI Act violations. Coalition added an affirmative endorsement in March 2024 addressing AI-related failures of computer system security and fraudulent transfer instructions, including deepfakes, which is narrower than blanket cover for faulty AI outputs. A cluster of specialist entrants, including Armilla and AIUC, offer standalone AI policies.

The third group:

This is the largest, and it has said nothing. Their policies neither affirm nor exclude. A policyholder whose claim would otherwise fall within the insuring agreement may reasonably expect coverage. Whether they get it depends on policy language written before anyone thought about this, the theory of liability, and how existing exclusions interact with losses the drafters never anticipated.

RAND’s characterization of that third position is the sharpest line in the report: silence preserves the possibility of coverage and increases the likelihood of dispute.

What The Litigation Actually Looks Like

The coverage debate has focused on harm caused by AI. The litigation has gone somewhere different.

In the Database of AI Litigation that RAND examined, 150 of 249 generative AI lawsuits, or 60%, relate to alleged intellectual property violations or improper training by developers rather than to the use, misuse, or outputs of models. The claims are copyright and IP actions against developers, not negligence or product liability claims against deployers. The training data suits are where the courts are, including the Anthropic settlement over the use of pirated books in training. Thomson Reuters v. Ross Intelligence is often cited alongside them, though the judge in that case expressly noted it involved non-generative AI, which limits how far it reads across.

The insurance framing assumes someone was harmed by an AI output. Most of the actual litigation is about how models were built.

The incident data runs the other way. In the AI Incident Database that RAND examined, 599 of 713 public generative AI incidents, or 84%, relate to misinformation and deepfakes: false, deceptive, or manipulative content, and AI-generated or altered media impersonating real people. RAND cautions that incident confirmation across these repositories remains incomplete. That is where documented harm is happening. It is not where most lawsuits are filed.

RAND names six root causes across incident and litigation data:
  1. Model error.
  2. Security vulnerabilities.
  3. Information and copyright violations.
  4. Civil and personal rights violations.
  5. Fraud and deception from malicious use.
  6. Bad governance from management misconduct.

That last category should be familiar. Cybersecurity disclosure failures have produced enforcement for years, including the SEC’s 2021 settlement with Pearson over misleading breach disclosures and inadequate disclosure controls. The AI version is a company that exaggerates its AI capabilities and later faces securities litigation. What is new is that the broad AI exclusions some carriers have filed would bar coverage for exactly those claims.

Five Ways AI Accumulation Risk Differs From Cyber

CyberCube named six AI event families earlier this month. RAND names five accumulation mechanisms and one of them does not appear in vendor reports.

  1. Universal attacks exploit the same vulnerability across many AI systems simultaneously. The analogy to cyber is direct: the same software flaw exposes many companies at once.
  2. Common model dependency concentrates exposure in the companies supplying the infrastructure, the foundation models, and the cloud providers. A failure in one propagates to every customer using it.
  3. AI as force multiplier amplifies existing cyberattacks rather than creating new categories. This is the established mechanism: AI-enhanced phishing, automated vulnerability discovery, faster exploit development.
  4. Legal shock is a ruling or enforcement action that makes previously widespread AI practice actionable across many companies at once. The latency is the problem. A practice widespread today, found unlawful in three years, could activate claims across many historical policy years simultaneously under occurrence-based coverage.
  5. Subtle corruption or degradation is the one nobody else names. A model drifts gradually, or develops sycophantic, deceptive, or misleading tendencies, in ways that do not trigger a visible event. First- and third-party claims emerge slowly across many insureds, many lines, and many carriers. No single triggering event. No obvious moment at which the accumulation becomes visible. RAND acknowledges this mechanism is speculative and calls for further research. That it appears in a RAND report at all indicates someone with a background in catastrophic risk took it seriously enough to name it.

The challenge the five mechanisms share is RAND’s own framing:

AI losses may be correlated even when they do not appear identical at the claim level. Traditional line-by-line exposure management may understate the problem.

Erin Kenneally, an AI risk expert and licensed attorney who founded the advisory firm Elchemy, named exactly that failure mode a year ago. Writing for Cyber Insurance News in September 2025, she argued that AI’s black-box behavior and the immature understanding of causal dependencies in AI systems render conventional risk management and actuarial techniques obsolete. (Kenneally also appeared on the Cyber Insurance News Podcast to discuss the issue; get that here.)

Kenneally is listed in the RAND report’s acknowledgments as a reviewer, and her 2021 work appears in the citations. Her argument is now embedded in a report aimed at the NAIC.

This publication interviewed her on the podcast in October 2025 and ran that essay the month before, ahead of RAND engaging her. The same expert, the same argument, arrived at through two independent channels.

Get The Cyber Insurance News Upload
Subscribe to our weekly newsletter!

What Underwriting AI Actually Requires

The underwriting chapter is the most useful for practitioners and the most uncomfortable for anyone who sells AI risk assessments.

RAND reviews four methods. Historical claims, the most useful input, barely exist yet for AI, and what exists is changing too fast to establish actuarial stability. Incident data provides broader coverage, but months or years may pass between an alleged wrong and any formal disposition. Quantitative model evaluation, testing LLMs across accuracy, calibration, robustness, fairness, bias, toxicity, and efficiency, works well when tasks can be reduced to measurable benchmarks with defensible ground truth, and poorly for open-ended tasks like employment decisions or strategic advice. Qualitative governance assessments rely heavily on self-reported information and judgment.

The conclusion is exact: these tools are individually limited and collectively immature. Carriers cannot yet reliably estimate AI loss frequency or severity.

That sits directly against the six monitoring proposals this publication has tracked since March, from Sophos and Spektrum through Silent Push to CyberCube. Each proposes observable signals as an underwriting input. RAND’s analysis of what underwriting actually requires does not discount those signals. It contextualizes them: useful inputs into an immature and collectively insufficient toolkit, not substitutes for loss experience that does not yet exist.

Three Things RAND Wants The NAIC To Do

The recommendations are practical, and the first one is overdue.

  1. An AI Coverage Notice. State regulators and the NAIC, with carrier and broker support, should develop a standardized notice enabling carriers to declare, per line, whether AI losses are affirmatively covered, excluded, or left silent. It need not require common treatment. It requires transparency. Two firms using similar AI systems may face entirely different loss outcomes depending on their specific policy language. The notice would resolve at least some of the ambiguity.
  2. A common incident taxonomy. Without standardized reporting for attrition and accumulation loss, the data that would let carriers price AI risk more accurately will not accumulate. Incident data should remain private. The taxonomy should be common. RAND notes that making this workable requires focusing only on material AI use, a fixed scenario set, and annual aggregate reporting with ad hoc updates for major dependency or legal changes.
  3. Accumulation scenario analysis. Insurers and reinsurers should run dependency-aware scenarios focused on shared model dependency, infrastructure failure, and regulatory shock. This is what reinsurers already do for natural catastrophe. It is not yet standard practice for AI.
See also  AI Identity Risk Surges in 2026 as Executives Admit Low Preparedness

The report ends on a note that deserves repetition. Insurers, regulators and policyholders that clarify coverage, improve incident reporting and monitor accumulation will also shape practical standards for what counts as insurable and therefore acceptable AI use. This is how insurance industry standards have historically worked: what carriers will cover and on what terms has defined, in practice, what organizations do about risk.

AI may be the first case where that shaping needs to happen before the loss data arrives rather than after.

FAQ – AI Insurance Coverage Gaps

Are AI losses covered by cyber insurance?

It depends on the carrier and the policy. RAND found three responses in the market: carriers filing broad exclusions, carriers offering affirmative coverage through endorsements or standalone products, and the majority remaining silent, neither covering nor excluding. Silence preserves the possibility of coverage but increases the likelihood of dispute.

What does RAND mean by silent AI coverage?

Policies that neither expressly affirm nor exclude AI-related losses. A claim may be covered if it falls within the existing insuring agreement, but that depends on policy language written before AI was considered, the theory of liability, and how other exclusions interact with AI-related harm. RAND calls silent coverage the most problematic position because it obscures both the protection gap and accumulation exposure.

What are the five AI accumulation mechanisms RAND identifies?

Universal attacks exploiting the same vulnerability across many AI systems; common model dependency on shared infrastructure or foundation models; AI as a force multiplier for existing cyberattacks; legal shock from a ruling making widespread practice suddenly actionable across many firms; and subtle corruption or degradation of model performance producing correlated claims without a visible triggering event.

What does RAND recommend for the NAIC?

Three things. An AI Coverage Notice enabling carriers to declare, per line, whether losses are covered, excluded or silent. A common incident taxonomy for attritional and accumulation loss reporting. And accumulation scenario analysis focused on shared model dependency, infrastructure failure and regulatory shock.

What does most AI litigation actually look like?

Intellectual property disputes over training data rather than harm caused by outputs. In the litigation database RAND examined, 150 of 249 generative AI lawsuits relate to IP or alleged improper training. The insurance debate centers on harm from AI use. Most of the actual litigation centers on how models were built.

Leave a Comment

×