Underwriting
the Agent Economy:
The Blueprint
for an AI Insurance Stack

July 2026

Cristian Trout1, Sanmi Koyejo2, Sasha Romanosky3, Giorgio Ripamonti4,5, Lynn Thompson6,5, Desiree Spain6,5, Alex Taylor6,5, Kevin Casey6,5, Stephen Casper7,8,9, Matthew Botvinick10,11, Sean McGregor12, Miles Brundage12, A. Feder Cooper12, Patricia Paskov13,12, Adrien Ecoffet14, Ben Bucknall15,13, Kevin Wei13, Markus Anderljung16, Lukasz Szpruch17, Bri Treece18, Tom Zick9, Gabriel Weil19,20, Ugur Ozer21, Kevin Kalinich22, Jesus Gonzalez22, Vitaly Baranov22, Derek Blum23, Moran Koren24,5, Guy Laban24,5, Gil Arazi25,5, Henri Winand26,5, Toby Clowes27, Adam Kleinman27, Anita Srinivasan28, Tom Fehring1, Rune Kvist1, Rajiv Dattani1

1Artificial Intelligence Underwriting Company 2Stanford University 3RAND Corporation 4Generali 5The Spark 6QBE Insurance 7MIT 8Harvard Kennedy School 9Harvard Berkman Klein Center 10Anthropic 11Yale Law School 12AVERI 13Oxford Martin AI Governance Initiative 14OpenAI 15University of Oxford 16GovAI 17University of Edinburgh 18Fathom 19Institute for Law & AI 20University of Houston Law Center 21Royal Bank of Canada 22Aon 23Moody’s Analytics 24Ben-Gurion University of the Negev 25FinTLV Ventures 26AkinovA 27Tysers 28MATS Research

Listed authors contributed writing, research, and or review for one or more sections. This report covers a wide range of empirical and normative topics; with the exception of the corresponding author (Cristian Trout, cristian@aiuc.com), inclusion as an author does not entail endorsement of all claims in the report, nor does authorship imply an endorsement on the part of any individual’s organization.

Acknowledgments: Dean Ball, Michael Colao, Alan Chan, Aidan Homewood, Emil Bender Lassen, Austin Atkinson, Pranav Pativada, Mudit Tulsianey, Vignesh Prasad, Abby Shen, Emil Pellonpaa, Tanya Bas, Riley Hockett.

Read the full report on arXiv

Key Takeaways

Extended Summary

From maritime trade to commercial nuclear power, insurance has enabled economic growth and major technological developments by limiting downside risk for companies and their investors, quantifying risk, supporting safety research, spreading best practices, and ensuring third parties are compensated after an accident [1], [2], [3].

We believe AI agents — AI systems that receive high-level natural language instructions, form plans, and then take consequential actions in the world with limited or no human oversight — represent another such major technological development. Analysts expect AI agents to be producing hundreds of billions of dollars in economic value by 2030 [4], [5], [6], [7]. Realizing that promise will depend on enterprises having the confidence to adopt these systems at scale — confidence that, in turn, will depend on insurers’ willingness to help absorb and manage the risks.

Developers of AI agents, the enterprises that deploy them, and the foundation model providers they depend on all need insurance. They need coverage for both first-party operational losses, where an agent damages the policyholder’s own systems, data, operations, or reputation; and for legal liability, where the policyholder’s AI agent product or service harms a business partner, customer, or member of the public, who then sues.

But insurers are not ready. Today, the vast majority of AI agent risk sits in “silent coverage” within existing cyber, professional liability, and general liability policies — unpriced, invisible, and potentially destabilizing [8], [9], [10]. Underwriters also appear to be underestimating the risk posed by their policyholders’ usage of AI agents: nearly 50% of Lloyd’s underwriters surveyed believe their policyholders have “adequate” AI risk management [11], while only 1 in 5 surveyed businesses report having a mature model for governance of autonomous agents [12]. This suggests a significant disconnect.

Insurers are beginning to write exclusions to correct for this unpriced risk [13], [14], [15], [16]. While perhaps necessary, this only widens the coverage gap, leaving businesses to fend for themselves when they most need support. Some 60% of business leaders admit having “intentionally slowed implementation due to concerns over potential errors and malfunctions” [17]; it is no coincidence that over 90% report wanting insurance tailored to frontier AI risk [18].

This report argues that insurers can and should reassume their role as enablers of innovation. We claim that affirmative coverage for AI agents, with enterprise coverage towers reaching the billions, is achievable by 2030, but only if the insurance industry works together to make AI agents more insurable. Coverage will remain theoretical unless insurers can reliably profit from it at premiums that customers are willing to pay.

The challenges are several. First, frontier AI is too fast-moving and too general-purpose for conventional actuarial approaches. Consider: the length of tasks that agents can accomplish without human intervention is doubling roughly every four months [19], [20], and new use cases and vulnerabilities evolve on a similar timeframe. This means the insurer’s usual playbook — offer limited coverage, then expand as loss data and actuarial models improve — will not work: actuarial models will struggle to remain predictive, always lagging behind the shifting reality on the ground [21], [22].

Second, while the alignment and accuracy of AI agents have so far been improving — published benchmarks tracking helpfulness, harmlessness, and honesty show sustained gains across frontier model generations [23], [24], [25], [26] — reliability improvements (consistency, robustness, predictability) are being outpaced by capability improvements [26], [27]. As a result, the upper bounds of incident severity appear to be rising. Hallucinated refund policies in 2022 [28] have given way to wrongful death suits and unauthorized practice of law cases in 2025 and 2026 [29], [30], [31], [32].

Recent developments reinforce this trend. In April 2026, Anthropic unveiled Claude Mythos Preview, a frontier model capable of autonomously discovering and exploiting zero-day vulnerabilities across every major operating system and browser [33], [34], [35], [36]. Experts fear future models will gain other dangerous dual-use capabilities (e.g. in synthetic biology) [37], [38], [39]. Deployed responsibly, such models promise prosperity; but mistakes will be made, and the transition to a society resilient to such powerful technology will likely be disruptive.

The situation is also not helped by concentration in the foundation model market, where three providers account for over 80% of deployments [40]: a defect at any one propagates as a correlated shock across thousands of policyholders. This and other single points of failure create textbook conditions for heavy-tailed loss distributions. In short, if little effort is made to control tail risks, premiums and capital requirements will be not only harder to calibrate but higher — mirroring challenges that have plagued cyber insurance for decades [41], [42].

Getting ahead of the challenge means developing a technical understanding of the risks and controlling their tails. The bulk of this report describes the insurance infrastructure stack needed to do so — to guarantee agentic AI remains insurable and can be adopted with confidence. We break down the stack into eight components:

  1. Incident Data Collection and Analysis (§II.1): Pooling data on incidents and near misses, combining public reports with private policyholder data and claims data, in standardized formats. Treated as a shared resource, such data can benefit all parties, as demonstrated by the Closed Claims Project for anesthesiology malpractice: this program uses insurer claims data to develop new safety measures for anesthesiologists, reducing premiums and expanding the insurance market in the process [43], [44], [45], [46], [47], [48]. However, such a resource depends on insurer coordination: government intervention (e.g. incident disclosure mandates, and information sharing safe harbors) may be necessary [3], [49].

  2. Accumulation Risk Research and CAT Modeling (§II.2): Modeling catastrophe scenarios to better understand accumulation risk arising from single points of failure (such as the handful of frontier model providers), correlated triggers, and systemic risk (such as emergent multi-agent failures). Insurers are also uniquely incentivized to develop and disseminate macro-level mitigations for such risks (e.g. “circuit-breakers” for the agent economy) — public goods that would mirror their investments in cyber CAT scenario modeling and safety R&D at the Insurance Institute [50], [51] for Highway Safety and Insurance Institute for Business & Home Safety [52].

  3. Standard Setting (§II.3): Supporting auditable, prescriptive standards that set the minimum requirements for insurability and play three reinforcing roles: as underwriting tools that speed binding and supply contractual hooks for claims handling; as controls that bound correlated legal risk by anchoring the duty of care; and as concrete loss control guidance for policyholders. Wary of both the preventable damages they might pay for and the compliance burden on their customers, insurers are well-incentivized to balance stakeholders’ competing interests in standard-setting. Insurers have been involved in standard-setting before, most famously in 1894 when they founded the Underwriters Laboratories (UL) to manage the novel fire hazards of electrical equipment [53]. The UL mark became a litmus test for insurability and was later codified into law [54], [55], [56], [57], [58].

  4. Contract Design (§II.4): Agreeing on clear, consistent definitions of covered AI risks, appropriate exclusions, aggregation clauses, and trigger mechanisms. These terms can end ambiguous silent coverage and move toward the affirmative coverage that gives portfolio managers and actuaries visibility into AI risk exposures and loss distributions, respectively. This is critical for avoiding the decade of costly ambiguity that plagued cyber insurance [10], [59], [60].

  5. Risk Selection and Evaluation (§II.5): Developing AI specific underwriting practices that go beyond good-faith, annual questionnaires to incorporate organizational audits, realistic performance evaluations, red teaming, and other recurring technical tests as capabilities and vulnerabilities shift month to month. Standards can accelerate the process, providing technical test data and harmonizing questionnaires. In the limit, they enable streamlined standards-based rating like the widely used Fire Suppression Rating Schedule from the Insurance Services Office [61], cf. [62].

  6. Pricing (§II.6): Developing an expected-loss formula that leans on performance evaluation results and usage telemetry to supplement immature actuarial tables, feature-rates on system specifications, safeguards, and deployment sector, before adding accumulation risk loading. Because this approach is system-specific and forward-looking, it enables genuine price differentiation between high- and low-risk deployments. This expands the addressable market and turns premium signals into a lever for driving safety improvements.

  7. Ongoing Monitoring and Loss Control (§II.7): Investing in ongoing risk management guidance and oversight for policyholders, to keep pace with the rapid evolution of AI agents. Like cyber, the AI insurance market might mature in two stages: first, frequent, labor-intensive performance evaluations that build institutional knowledge of which mitigations are effective; then, scaling through partnerships with cloud service providers and foundation model providers who supply telemetry for low-friction underwriting and monitoring [63]. With appropriate leadership, AI insurers can compress cyber’s decades-long learning curve.

  8. Incident Response and Claims Management (§II.8): Developing an AI-literate claims management process that pays valid losses promptly and enforces exclusions, along with an AI-specific incident response function layered onto the existing breach coach and crisis management ecosystem for cyber and recall insurance lines. Finally, rigorous AI-native post-incident forensics will turn every loss into a learning opportunity. As cyber proved, a technology moving as fast as AI requires a feedback loop — from claims processing to forensics to revised underwriting criteria and actuarial models — that turns far faster than the traditional annual cycle.

We categorize the components by their role in the value chain: foundational functions, supporting functions, product & underwriting functions, and functions for servicing policies (see Figure 1). The components are complements in important ways. Incident response and claims management, for example, are key sources of data, whose analysis then feeds into virtually every other layer, especially standard setting, risk evaluations, pricing, and accumulation risk research. Likewise, contractual exclusions of losses caused by upstream model failures, aimed at controlling accumulation risk, are unenforceable without appropriate logs for post-incident forensics — exactly the kinds of technical controls mandated by robust standards and underwriting practices.

The AI Insurance StackFoundationalSupporting FunctionsProduct & UnderwritingServicing PoliciesIncident Response + Claims ManagementOngoing LossControl + MonitoringPricingAccumulation Risk Research + CAT ModelingRisk Selection +EvaluationStandardsContract DesignIncident Data Collection + Analysis
Figure 1. The insurance infrastructure stack.

Of course insurance has inherent limits, and cannot manage all of frontier AI’s risks. Insurers will always struggle to control or price criminal misuse of AI systems, much as they have with cyber (in part due to third-party moral hazard): insurance cannot replace law enforcement.

Looking ahead, we foresee the need for purpose-built institutions and alternative capital structures dedicated to covering and controlling catastrophic risk from frontier AI, or “AI CAT.” (For reference, in the world of insurance “catastrophic risks” refer to low-probability, high-severity loss events roughly in the hundreds of millions of dollars or more). Catastrophes reaching the low tens of billions will strain but not exceed private-market capacity. However, beyond this threshold lies a class of catastrophes whose magnitude and structure render them all but uninsurable by private markets. We refer to these as societal-scale risks. Picture critical infrastructure collapse, systemic economic disruption, or CBRN1 risks.

Hypothetical Coverage Tower for Frontier AI CAT Severity of loss Self-insured retention Primary insurance Mutual insuranceIndustry group captive Reinsurance CAT bonds Government backstopRisk-priced governmentreinsurance
Figure 2. Note: Proportions are illustrative.

As we approach artificial general intelligence, many experts warn of more societal-scale risks on the horizon. Besides dual-use capabilities, such as automated zero-day discovery and synthetic biology capabilities, which could enable widespread cyber attacks and bio-terrorism (respectively), some experts also warn of the possibility of losing control over advanced AI systems that develop goals misaligned with their operators’ intentions [39]. In the limit, they warn, this could lead to human extinction [39], [64], [65]. Of course no institution can insure extinction risks, but covering risks correlated with extinction may help control them.

Private markets can provide first-layer coverage and help with pricing, distribution, and claims management, but the bulk of coverage capacity for societal-scale risks will depend on governments, society’s de facto insurer of last resort [3], [66].

We sketch several complementary mechanisms for handling AI CAT that are worth exploring further: industry mutuals modeled on self-regulatory structures in commercial nuclear power and other industries [3], [67], [68]; catastrophe bonds (“CAT bonds”) for additional risk transfer [69]; bespoke liability regimes to correct for externalities and improve insurability [70], [71], [3], [72], cf. [73]; and government backstops to take on the risks only government can manage, while giving private insurers the confidence to shoulder more catastrophic risk than they otherwise would [66], [3], [74], cf. [21] (see Figure 2).

If insurers fail to quickly get a handle on AI agent security, safety, and reliability, an AI insurance coverage gap will rapidly balloon, with consequences for the broader economy. In the best case, the Artificial Intelligence Underwriting Company estimates that the resulting drag on AI adoption could leave some $200 billion in US GDP on the table over a decade, based on IMF productivity-diffusion estimates under a scenario of lower institutional readiness. In the worst case, a disaster whose direct damages only cost some hundred billion dollars could wipe out several trillions of US GDP over five years due to an economic slowdown cf. [75], [76]. The mechanisms that might drive such a slowdown include: a violent withdrawal of insurance coverage for AI-related risk, stalled enterprise adoption of AI, regulatory backlash, and investors suddenly pulling out of AI as trust in the technology craters [77], [78], [79], [80]. There is historical precedent for this: after 9/11 the abrupt collapse of the insurance market for terrorism risk froze major construction projects and grounded commercial aviation until ad hoc government intervention stabilized the situation [81], [82], [83], [84]. If the AI disaster is an accident, we could see adoption set back a decade given negative public sentiment about AI [85], much like nuclear power post Three Mile Island or Fukushima [3].

Building the stack needed will require coordinated action across brokers, Managing General Agents (MGAs), primary insurers, reinsurers, risk modelers, standard-setting bodies, oversight bodies and government. The insurance industry must overcome a cold-start problem: many of the components described are complements, working best in synergy. The alternative for insurers — guarding what little proprietary data one has while relying on low limits and blanket exclusions — may protect today’s fragile margins, but cedes the opportunity to expand the serviceable market, enable responsible AI adoption, and protect the broader economy from shocks.

1 Chemical, Biological, Radiological, or Nuclear harms.

Overview of the AI Insurance Stack and Recommendations

Component

Key Actions

Carriers and MGAs

Reinsurers

Advisory Bodies and Risk Modelers

Oversight Bodies and Government

Incident Data Collection & Analysis

  • Build a shared incident database as an industry resource (similar to CyberAcuView), combining public and private policyholder data.
  • Build a shared incident database as an industry resource (similar to CyberAcuView), combining public and private policyholder data.
  • Encourage carriers to adopt a standard incident taxonomy and data structure.
  • For severe incidents, enact mandatory AI incident disclosures (similar to SEC rules for cyber incidents).
  • Establish a voluntary anonymized reporting database at NIST (similar to NASA’s ASRS).
  • Provide long-term reauthorization to CISA to enable an AI-ISAC.

Accumulation Risk Research & CAT Modeling

  • Form or support an industry safety research body (similar to the IIHS or IBHS) to study systemic AI risk and develop shared infrastructure and protocols for making AI agents safe, secure, and reliable.
  • Track frontier AI exposure across portfolio.
  • Form or support an industry safety research body (similar to the IIHS or IBHS) to study systemic risks from AI agents and develop shared infrastructure and protocols to make them safe, secure, and reliable when deployed at scale.
  • Track frontier AI exposure across portfolio and model accumulation risk.
  • Develop or commission AI catastrophe scenario modeling.
  • Develop formal AI catastrophe scenarios and accumulation risk models, including from single points of failure, supply chain concentration, risk of emergent multi-agent failures and more.
  • Commission or prompt AI catastrophe scenario modeling (PRA, Council of Lloyd’s, FIO as part of TRIP).
  • Track frontier AI exposure across the market and model accumulation risk (Council of Lloyd’s).

Standard Setting

  • In underwriting, consider what standards the policyholder has been audited against.
  • Where available, leverage a policyholder’s audit report to accelerate underwriting.
  • Encourage carriers to recognize certain standards as an underwriting signal, and possibly as a minimum requirement for insurability.
  • Develop and maintain prescriptive AI agent standards (similar to UL).
  • Build accreditation programs for third-party auditors.
  • Recognize effective private standards in regulatory guidance or procurement requirements.
  • More broadly: reduce uncertainty of law.

Contract Design

  • Draft affirmative AI coverage with durable definitions. Consider specifying unifying factors for aggregation clauses.
  • Exclude currently uninsurable accumulation risks (e.g. losses arising from failures of upstream AI model providers).
  • Encourage the use of model policy language.
  • Promulgate model language for AI-specific definitions, exclusions, and trigger (LMA, ISO).
  • Encourage or require carriers to report macro-level data on AI coverage (NAIC, Council of Lloyd’s), possibly including the number of policies in force, direct premiums written, loss ratios, etc.
  • Issue a notice encouraging or directing carriers to end silent AI coverage by a given date (PRA, Council of Lloyd’s).

Risk Selection & Evaluation

  • Inquire into the systems’ safeguards, as well as the organization’s AI literacy and governance practices.
  • Conduct or require performance evaluations, red teaming, and where applicable, chaos testing.
  • Develop standardized proposal forms (ACORD, LMA).
  • Develop a rating schedule for agentic AI systems (similar to ISO’s FSRS).

Pricing

  • Use performance evaluation scores as a pricing input, serving as quasi-actuarial data.
  • Feature rate according to system specifications and safeguards implemented.
  • Partner with frontier model providers to track a policyholder’s AI usage.
  • Supply risk modeling services to improve carrier pricing (especially for accumulation risk loading).

Ongoing Loss Control & Monitoring

  • Encourage or require regular performance evaluations, red teaming.
  • Help policyholders with remediation and provide loss control guidance.
  • Partner with frontier model providers to monitor a policyholder’s controls.

Incident Response & Claims Management

  • Establish pre-approved panels of AI-specific technical response providers.
  • Encourage or require structured forensic reports as a condition of a major claim settlement.
  • Train claims adjusters to be AI literate.
  • Extract learnings from incidents to improve underwriting and loss control.
  • Encourage or require structured forensic reports as a condition of a major claim settlement.
  • Train claims adjusters to be AI literate.
  • Develop standardized incident and claims reporting templates (ACORD, LMA). Update standards in light of incident trends.
  • Support institutional learning, by both clarifying liability and reducing friction for voluntary reporting.

Acronyms:

  • ACORD: Association for Cooperative Operations Research and Development
  • ASRS: Aviation Safety Reporting System
  • CISA: Cybersecurity and Infrastructure Security Agency (US)
  • FIO: Federal Insurance Office (US)
  • FSRS: Fire Suppression Rating Schedule
  • IIHS: Insurance Institute for Highway Safety
  • ISO: Insurance Services Office
  • LMA: Lloyd’s Market Association
  • NAIC: National Association of Insurance Commissioners (US)
  • NASA: National Aeronautics and Space Administration (US)
  • NIST: National Institute of Standards and Technology (US)
  • PRA: Prudential Regulation Authority (UK)
  • SEC: Securities and Exchange Commission (US)
  • TRIP: Terrorism Risk Insurance Program
  • UL: Underwriters Laboratories

References

  1. A. Lior, “Innovating Liability: The Virtuous Cycle of Torts, Technology and Liability Insurance,” Sep. 11, 2023, Social Science Research Network, Rochester, NY: 4568702. Accessed: Apr. 25, 2024. [Online]. Available: https://papers.ssrn.com/abstract=4568702
  2. O. Ben-Shahar and K. D. Logue, “Outsourcing Regulation: How Insurance Reduces Moral Hazard,” Michigan Law Review, vol. 111, no. 2, pp. 197–248, 2012, Accessed: Mar. 03, 2024. [Online]. Available: https://www.jstor.org/stable/41703440
  3. C. Trout, “When Does Regulation by Insurance Work? The Case of Frontier AI,” Oct. 10, 2025, Social Science Research Network, Rochester, NY: 5588732. Accessed: Nov. 17, 2025. [Online]. Available: https://papers.ssrn.com/abstract=5588732
  4. “Agentic commerce: How agents are ushering in a new era | McKinsey.” Accessed: Apr. 02, 2026. [Online]. Available: https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-agentic-commerce-opportunity-how-ai-agents-are-ushering-in-a-new-era-for-consumers-and-merchants
  5. “Gartner Unveils Top Predictions for IT Organizations and Users in 2026 and Beyond,” Gartner. Accessed: Apr. 02, 2026. [Online]. Available: https://www.gartner.com/en/newsroom/press-releases/2025-10-21-gartner-unveils-top-predictions-for-it-organizations-and-users-in-2026-and-beyond
  6. “Agentic AI implementations in advanced industries | McKinsey.” Accessed: May 06, 2026. [Online]. Available: https://www.mckinsey.com/industries/automotive-and-assembly/our-insights/empowering-advanced-industries-with-agentic-ai
  7. “Generative AI to Become a $1.3 Trillion Market by 2032, Research Finds | Press | Bloomberg LP,” Bloomberg L.P. Accessed: May 06, 2026. [Online]. Available: https://www.bloomberg.com/company/press/generative-ai-to-become-a-1-3-trillion-market-by-2032-research-finds/
  8. M. Le Gouais, “AI liability: An age of silent exposures has already begun,” Insurance Insider. Accessed: Sep. 30, 2025. [Online]. Available: https://www.insuranceinsider.com/article/2f5mn8u0mwcdnovlve7eo/lines-of-business/casualty-gl/ai-liability-an-age-of-silent-exposures-has-already-begun
  9. Aon, “AI Fact Sheet 2026: Artificial Intelligence Risk Management 2026,” Aon, Fact Sheet, 2026. Accessed: Dec. 31, 2025. [Online]. Available: https://assets.aon.com/-/media/files/aon/reports/2026/aon-ai-fact-sheet-2026.pdf
  10. Swiss Re, “AI – unintended insurance impacts and lessons from ‘silent cyber’ | Swiss Re.” Accessed: Jul. 13, 2025. [Online]. Available: https://www.swissre.com/institute/research/sonar/sonar2024/ai-silent-cyber.html
  11. D. Powell, “LMA - Understanding AI Exposures: AI Loss Scenarios Survey Results.” Accessed: May 06, 2026. [Online]. Available: https://lmalloyds.com/campaigns/understanding-ai-exposures-ai-loss-scenarios-survey-results/
  12. “The State of AI in the Enterprise | Deloitte,” Deloitte, Jan. 2026. Accessed: Jan. 28, 2026. [Online]. Available: https://www.deloitte.com/cz-sk/en/services/consulting/research/the-state-of-ai-in-the-enterprise.html
  13. L. Harris and C. Criddle, “Insurers retreat from AI cover as risk of multibillion-dollar claims mounts,” Financial Times, Nov. 23, 2025. Accessed: Apr. 02, 2026. [Online]. Available: https://www.ft.com/content/abfe9741-f438-4ed6-a673-075ec177dc62?syn-25a6b1a6=1
  14. G. B. Fehling, M. S. Levine, M. “Mady” Moore, and A. D. Pappas, “The Continued Proliferation of AI Exclusions.” Accessed: Nov. 10, 2025. [Online]. Available: https://www.hunton.com/hunton-insurance-recovery-blog/the-continued-proliferation-of-ai-exclusions
  15. L. Bratton, “Berkshire Hathaway, Chubb Win Approval to Drop AI Insurance Coverage,” The Information, Apr. 23, 2026. Accessed: May 06, 2026. [Online]. Available: https://www.theinformation.com/articles/berkshire-hathaway-chubb-win-approval-drop-ai-insurance-coverage
  16. M. Lerner, “Insurers, brokers adjust as AI exclusions emerge,” Business Insurance. Accessed: May 06, 2026. [Online]. Available: https://www.businessinsurance.com/insurers-brokers-adjust-as-ai-exclusions-emerge/
  17. J. Apotheker, “CEOs are all in on AI but anxieties remain: What leader confidence indicates for 2026,” World Economic Forum. Accessed: May 06, 2026. [Online]. Available: https://www.weforum.org/stories/2026/01/ceos-are-all-in-on-ai-but-anxieties-remain/
  18. R. (Alex) Jia, M. Eling, and T. Wang, “Gen AI Risks for Businesses: Exploring the role for insurance,” Geneva Association, Oct. 2025. [Online]. Available: https://www.genevaassociation.org/publication/digital-ai-transformation/gen-ai-risks-businesses-exploring-role-insurance
  19. “Task-Completion Time Horizons of Frontier AI Models.” Accessed: Apr. 23, 2026. [Online]. Available: https://metr.org/time-horizons/
  20. M. Mertens et al., “Crashing Waves vs. Rising Tides: Preliminary Findings on AI Automation from Thousands of Worker Evaluations of Labor Market Tasks,” Apr. 01, 2026, arXiv: arXiv:2604.01363. doi: 10.48550/arXiv.2604.01363.
  21. D. Schwarcz and J. Wolff, “The Limits of Regulating AI Safety Through Liability and Insurance: Lessons From Cybersecurity,” Aug. 27, 2025, Social Science Research Network, Rochester, NY: 5411062. doi: 10.2139/ssrn.5411062.
  22. C. Trout, “Healthy Insurance Markets Will Be Critical for AI Governance,” Lawfare, Dec. 2025, Accessed: Jan. 14, 2026. [Online]. Available: https://www.lawfaremedia.org/article/healthy-insurance-markets-will-be-critical-for-ai-governance
  23. Y. Bai et al., “Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback,” Apr. 12, 2022, arXiv: arXiv:2204.05862. doi: 10.48550/arXiv.2204.05862.
  24. S. Sajadieh et al., “The AI Index 2026 Annual Report,” AI Index Steering Committee, Institute for Human-Centered AI, Stanford University, Stanford, CA, Apr. 2026.
  25. M. Akhtar et al., “When AI Benchmarks Plateau: A Systematic Study of Benchmark Saturation,” 2026, arXiv. doi: 10.48550/ARXIV.2602.16763.
  26. S. Rabanser, S. Kapoor, P. Kirgis, K. Liu, S. Utpala, and A. Narayanan, “Towards a Science of AI Agent Reliability,” Feb. 23, 2026, arXiv: arXiv:2602.16666. doi: 10.48550/arXiv.2602.16666.
  27. “HAL Reliability Evaluation.” Accessed: May 29, 2026. [Online]. Available: https://hal-evals.com
  28. M. Garcia, “What Air Canada Lost In ‘Remarkable’ Lying AI Chatbot Case,” Forbes, Feb. 19, 2024. Accessed: Jul. 11, 2025. [Online]. Available: https://www.forbes.com/sites/marisagarcia/2024/02/19/what-air-canada-lost-in-remarkable-lying-ai-chatbot-case/
  29. D. Kerr, “Google faces lawsuit after Gemini chatbot allegedly instructed man to kill himself,” The Guardian, Mar. 04, 2026. Accessed: May 07, 2026. [Online]. Available: https://www.theguardian.com/technology/2026/mar/04/gemini-chatbot-google-jonathan-gavalas
  30. M. Helfand, “OpenAI Facing 8th Wrongful Death Lawsuit,” Illinois Lawyers. Accessed: May 07, 2026. [Online]. Available: https://www.illinoislawyers.com/blog/openai-facing-8th-wrongful-death-lawsuit/
  31. S. Nerkar, “A.I. ‘Hallucinations’ Created Errors in Court Filing, Top Law Firm Says,” The New York Times, Apr. 21, 2026. Accessed: May 27, 2026. [Online]. Available: https://www.nytimes.com/2026/04/21/nyregion/sullivan-cromwell-ai-hallucination.html
  32. R. Butler, “How AI-powered access to justice is impacting unauthorized practice of law regulations.”
  33. Anthropic, “Project Glasswing: Securing critical software for the AI era.” Accessed: May 07, 2026. [Online]. Available: https://www.anthropic.com/glasswing
  34. AI Security Institute, “Our evaluation of Claude Mythos Preview’s cyber capabilities | AISI Work,” AI Security Institute. Accessed: May 07, 2026. [Online]. Available: https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities
  35. B. Grinstead, C. Holler, and F. Braun, “Behind the Scenes Hardening Firefox with Claude Mythos Preview.” [Online]. Available: https://hacks.mozilla.org/2026/05/behind-the-scenes-hardening-firefox/
  36. “Anthropic’s Mythos model found vulnerabilities in classified US government systems, AP reports,” Reuters, Jun. 24, 2026. Accessed: Jul. 04, 2026. [Online]. Available: https://www.reuters.com/business/anthropics-mythos-model-found-vulnerabilities-classified-us-government-systems-2026-06-24/
  37. J. Wentzel, Z. Graves, and D. Ball, “In Support of Mandatory Nucleic Acid Synthesis Screening and Recordkeeping.” Accessed: Jul. 09, 2026. [Online]. Available: https://www.thefai.org/posts/in-support-of-mandatory-nucleic-acid-synthesis-screening-and-recordkeeping
  38. Frontier Model Forum, “Latest from the FMF: Grant-Making to Address AI-Bio Risk Challenges,” Frontier Model Forum. Accessed: May 09, 2026. [Online]. Available: https://www.frontiermodelforum.org/updates/latest-from-the-fmf-grant-making-to-address-ai-bio-risk-challenges/
  39. Y. Bengio et al., “International AI Safety Report 2026,” Feb. 24, 2026, arXiv: arXiv:2602.21012. doi: 10.48550/arXiv.2602.21012.
  40. M. Ventures, “2025: The State of Generative AI in the Enterprise,” Menlo Ventures. Accessed: Apr. 01, 2026. [Online]. Available: https://menlovc.com/perspective/2025-the-state-of-generative-ai-in-the-enterprise/
  41. M. Eling and J. H. Wirfs, “Cyber risk: too big to insure? Risk transfer options for a mercurial risk class,” no. 59, 2016.
  42. M. Eling and W. Schnell, “EXTREME CYBER RISKS AND THE NON-DIVERSIFICATION TRAP,” 2020.
  43. J. LeMasurier, “Physician medical malpractice,” Health Care Financ Rev, vol. 7, no. 1, pp. 111–116, 1985, Accessed: Mar. 05, 2026. [Online]. Available: https://pmc.ncbi.nlm.nih.gov/articles/PMC4191514/
  44. J. Metzner, K. L. Posner, M. S. Lam, and K. B. Domino, “Closed claims’ analysis,” Best Practice & Research Clinical Anaesthesiology, vol. 25, no. 2, pp. 263–276, Jun. 2011, doi: 10.1016/j.bpa.2011.02.007.
  45. A. N. Pandya, S. Z. Majid, and M. S. Desai, “The Origins, Evolution, and Spread of Anesthesia Monitoring Standards: From Boston to Across the World,” Anesth Analg, vol. 132, no. 3, pp. 890–898, Mar. 2021, doi: 10.1213/ANE.0000000000005021.
  46. S. D. Turpin, “Anesthesiologists’ Claims, Insurance Premiums Reduced: Improved Safety Cited,” Anesthesia Patient Safety Foundation. Accessed: Mar. 04, 2026. [Online]. Available: https://www.apsf.org/article/anesthesiologists-claims-insurance-premiums-reduced-improved-safety-cited/
  47. G. Li, M. Warner, B. H. Lang, L. Huang, and L. S. Sun, “Epidemiology of Anesthesia-related Mortality in the United States, 1999–2005,” Anesthesiology, vol. 110, no. 4, pp. 759–765, Apr. 2009, doi: 10.1097/aln.0b013e31819b5bdc.
  48. A. C. Schaffer, A. B. Jena, S. A. Seabury, H. Singh, V. Chalasani, and A. Kachalia, “Rates and Characteristics of Paid Malpractice Claims Among US Physicians by Specialty, 1992-2014,” JAMA Intern Med, vol. 177, no. 5, pp. 710–719, May 2017, doi: 10.1001/jamainternmed.2017.0311.
  49. D. B. Schwarcz, J. Wolff, and D. W. Woods, “How Privilege Undermines Cybersecurity,” SSRN Journal, 2022, doi: 10.2139/ssrn.4175523.
  50. D. C. Viano and C. S. Parenteau, “Rollover injury in vehicles with high-strength-to-weight ratio (SWR) roofs, curtain and side airbags, and other safety improvements,” Traffic Injury Prevention, vol. 19, no. 7, pp. 734–740, Oct. 2018, doi: 10.1080/15389588.2018.1482489.
  51. E. R. Teoh and A. K. Lund, “IIHS Side Crash Test Ratings and Occupant Death Risk in Real-World Crashes,” Traffic Injury Prevention, vol. 12, no. 5, pp. 500–507, Oct. 2011, doi: 10.1080/15389588.2011.585671.
  52. Insurance Institute for Business & Home Safety, “FORTIFIED vs. Common Residential Construction,” Insurance Institute for Business & Home Safety. Accessed: May 08, 2026. [Online]. Available: https://ibhs.org/wind/residential-fortified-demonstrations/
  53. UL Research Institutes, “Our History.” Accessed: May 06, 2026. [Online]. Available: https://ul.org/about/our-history/
  54. A. Amirnovin, “UL Compliance: Does YOUR Product Need UL?,” Agilian. Accessed: May 07, 2026. [Online]. Available: https://www.agiliantech.com/blog/ul-compliance-does-your-product-need-ul/
  55. Tobyahz, “What Makes a Home Product Retail‑Ready – Deep Dive,” China Direct Source. Accessed: May 07, 2026. [Online]. Available: https://chinadirectsource.com/home-product-retail-ready/
  56. R. E. Fairfax, “Electrical conductors and equipment must be approved and used according to its listing/label.,” Occupational Safety and Health Administration. [Online]. Available: https://www.osha.gov/laws-regs/standardinterpretations/2003-05-27-0
  57. Occupational Safety and Health Administration, “OSHA’s Nationally Recognized Testing Laboratory (NRTL) Program - Products Requiring Approval.” [Online]. Available: https://www.osha.gov/nationally-recognized-testing-laboratory-program/products-requiring-approval
  58. “National Fire Protection Association Standards in Fire Litigation,” in Engineering Standards for Forensic Application, Academic Press, 2019, pp. 155–168. doi: 10.1016/B978-0-12-813240-1.00011-X.
  59. “End of Silent Cyber in Property Insurance.” Accessed: Jul. 09, 2025. [Online]. Available: https://www.irmi.com/articles/expert-commentary/end-of-silent-cyber-in-property-insurance
  60. M. Eling, “Cyber Risk and Cyber Insurance,” in Handbook of Insurance: Volume I, G. Dionne, Ed., Cham: Springer Nature Switzerland, 2025, pp. 199–224. doi: 10.1007/978-3-031-69561-2_7.
  61. Verisk’s Community Hazard Mitigation Services, “Fire Suppression Rating Schedule (FSRS) Overview,” Verisk’s Community Hazard Mitigation Services. Accessed: May 08, 2026. [Online]. Available: https://www.isomitigation.com/ppc/fsrs/
  62. Verisk’s Community Hazard Mitigation Services, “Building Code Effectiveness Grading Schedule (BCEGS®),” Verisk’s Community Hazard Mitigation Services. Accessed: May 08, 2026. [Online]. Available: https://www.isomitigation.com/bcegs/
  63. D. W. Woods and J. Wolff, “A history of cyber risk transfer,” Journal of Cybersecurity, vol. 11, no. 1, p. tyae028, Jan. 2025, doi: 10.1093/cybsec/tyae028.
  64. CAIS, “Statement on AI Risk.” Accessed: Jun. 07, 2024. [Online]. Available: https://www.safe.ai/work/statement-on-ai-risk
  65. Y. Bengio et al., “Managing extreme AI risks amid rapid progress,” Science, vol. 384, no. 6698, pp. 842–845, May 2024, doi: 10.1126/science.adn0117.
  66. D. A. Moss, When All Else Fails: Government as the Ultimate Risk Manager. Harvard University Press, 2004.
  67. N. Gunningham and J. Rees, “Industry Self-Regulation: An Institutional Perspective,” Law & Policy, vol. 19, no. 4, pp. 363–414, 1997, doi: 10.1111/1467-9930.t01-1-00033.
  68. J. E. Gudgel, “Insurance and the public–private management of risk at US commercial nuclear power plants,” Risk Management and Insurance Review, vol. 26, no. 4, pp. 437–465, 2023, doi: 10.1111/rmir.12257.
  69. D. Reti and G. Weil, “Making Extreme AI Risk Tradeable,” AI Frontiers. Accessed: May 11, 2026. [Online]. Available: https://ai-frontiers.org/articles/ai-catastrophe-bonds-extreme-risk-tradeable
  70. G. Weil, “Tort Law as a Tool for Mitigating Catastrophic Risk from Artificial Intelligence,” Jan. 13, 2024, Rochester, NY: 4694006. doi: 10.2139/ssrn.4694006.
  71. C. Trout, “Liability and Insurance for Catastrophic Losses: the Nuclear Power Precedent and Lessons for AI,” in Generative AI and Law Workshop at the International Conference on Machine Learning, Vienna, Austria, 2024.
  72. B. G. Friedman, “Shared Residual Liability for Frontier AI Firms,” Jul. 05, 2025, Social Science Research Network, Rochester, NY: 5339887. doi: 10.2139/ssrn.5339887.
  73. K. Ramakrishnan, “Tort Law at the Frontier of Artificial Intelligence,” Jun. 22, 2026, Social Science Research Network, Rochester, NY: 6979919. doi: 10.2139/ssrn.6979919.
  74. C. Trout, “Insuring Uninsurable Risks from AI: Government as Insurer of Last Resort,” in Generative AI and Law Workshop at the International Conference on Machine Learning, Vienna, Austria, 2024.
  75. S. J. Ruffle et al., “Stress Test Scenario: Sybil Logic Bomb Cyber Catastrophe,” Centre for Risk Studies, University of Cambridge, 2014.
  76. Centre for Risk Studies and Lloyd’s of London, “Business Blackout: The insurance implications of a cyber attack on the US power grid,” 2015. [Online]. Available: https://www.jbs.cam.ac.uk/wp-content/uploads/2020/08/crs-lloyds-business-blackout-scenario.pdf
  77. C. Metz, “Why Debt Funding Is Ratcheting Up the Risks of the A.I. Boom,” The New York Times, Nov. 10, 2025. Accessed: May 11, 2026. [Online]. Available: https://www.nytimes.com/2025/11/10/technology/ai-data-centers-debt-risks.html
  78. E. Katz, “Treasury Has an Internal Report Warning About the Dangers of an AI Bubble,” Jul. 06, 2026. Accessed: Jul. 07, 2026. [Online]. Available: https://www.notus.org/economy/treasury-internal-report-warning-dangers-ai-bubble
  79. B. Berkowitz, “AI bubble a ‘key downside risk’ to U.S. economy, OECD warns,” Axios, Dec. 02, 2025. [Online]. Available: https://www.axios.com/2025/12/02/ai-bubble-stock-market-forecast-oecd
  80. “IMF says AI investment bubble could burst, comparable to dot-com bubble,” Al Jazeera, Oct. 14, 2025. [Online]. Available: https://www.aljazeera.com/economy/2025/10/14/imf-says-ai-investment-bubble-could-burst-comparable-to-dot-com-bubble
  81. U. S. D. of the T. Federal Insurance Office, “Report on the Effectiveness of the Terrorism Risk Insurance Program,” U.S. Department of the Treasury, Jun. 2022. [Online]. Available: https://home.treasury.gov/system/files/311/2022%20Program%20Effectiveness%20Report%20%28FINAL%29.pdf
  82. B. Elias, R. Y. Tang, and B. Webel, “Aviation War Risk Insurance: Background and Options for Congress,” Congressional Research Service, CRS Report R43715, Sep. 2014. [Online]. Available: https://www.congress.gov/crs-product/R43715
  83. E. Michel-Kerjan and B. Pedell, “How Does the Corporate World Cope with Mega-Terrorism? Puzzling Evidence from Terrorism Insurance Markets,” Journal of Applied Corporate Finance, vol. 18, no. 4, pp. 61–75, 2006, doi: 10.1111/j.1745-6622.2006.00112.x.
  84. E. Michel-Kerjan and B. Pedell, “Terrorism Risk Coverage in the Post-9/11 Era: A Comparison of New Public–Private Partnerships in France, Germany and the U.S.,” Geneva Pap Risk Insur Issues Pract, vol. 30, no. 1, pp. 144–170, Jan. 2005, doi: 10.1057/palgrave.gpp.2510009.
  85. N. Dreksler, H. Law, C. Ahn, D. Schiff, K. J. Schiff, and Z. Peskowitz, “What Does the Public Think About AI? An Overview of the Public’s Attitudes Towards AI and a Resource for Future Research,” Jan. 22, 2025, Social Science Research Network, Rochester, NY: 5108572. doi: 10.2139/ssrn.5108572.