The insurance industry faces a choice it hasn’t fully recognized yet: adapt existing products to cover AI risk, or define an entirely new class of business.
Key takeaways
- “Silent AI” is the new silent cyber, and it may be harder to contain: Policies written before widespread AI adoption neither explicitly cover nor exclude AI-related harm. That ambiguity is already creating dangerous gaps, and because AI-driven harm spans multiple lines of business simultaneously, the exposure is broader than silent cyber ever was.
- The AI liability market is likely to develop faster than cyber did: Cyber took 15 to 20 years to reach $15 billion in capacity. AI adoption is moving at a fundamentally different speed; ChatGPT reached 100 million users in weeks, not years. Deloitte projects $4.7 billion in AI liability premium within four years. The window for early positioning is shorter than the cyber precedent suggests.
- The deployer liability framework is already being set by the courts: Organizations are accountable for what their AI systems do, regardless of whether they built the underlying technology themselves. Assuming vendor liability is a business model built on a legal fiction.
- Agentic AI in insurance introduces a category of risk that didn’t exist two years ago: When an AI system has autonomous authority to take actions, approve payments, make decisions, interact with customers, and then operates outside its intended parameters, the resulting exposure has no clean home in existing policy structures. That gap is growing faster than the industry is moving to address it.
- Deployers face aggregated exposure across multiple lines at once: Using AI for customer advice or operational decision-making simultaneously creates new risk in E&O, D&O, product liability, and general liability. That aggregation has not been priced into traditional underwriting, which means organizations may be carrying far more exposure than their current coverage reflects.
- The market structure is still being defined, and that’s the opportunity: Whether AI liability lands in standalone policies, buyback endorsements, or affirmative coverage added to existing lines will be answered in the next 18 months. The players who move now to understand the risk deeply — as Coalition did in cyber — are the ones who will shape the market rather than respond to it.
AI liability in insurance isn’t an extension of cyber, E&O, or product liability. It’s a risk class that doesn’t map cleanly to any of them. And the industry is only beginning to reckon with what that means.
We’re already seeing the answer. Over 2,000 state regulatory filings and policy exclusions related to AI have been filed by insurance companies in recent months. They’re not yet active in policies, but they’re ready to deploy. This is a market waking up to something that became clear to me over the past year of analysis, namely that AI liability represents a structural shift in how risk manifests, not just an incremental expansion of existing coverage.
Why AI risk doesn’t fit existing products
The problem is that AI systems generate a type of harm that doesn’t map cleanly to past insurance structures. When an AI model hallucinates, discriminates, causes financial loss, or infringes on intellectual property, which policy covers that? Is it cyber? E&O? Product liability?
We’ve analyzed the wording of numerous policies at Gallagher, and the gray areas are significant. Some policies might cover AI-related harm. Others might not. Still others might provide partial coverage that leaves dangerous gaps.
This is why we now talk about “silent AI”, a direct parallel to “silent cyber” in the early 2000s.
The phrase means coverage that exists in policies but isn’t explicitly identified, priced, or managed. With cyber, the question was, “Does property insurance cover damage caused by computer systems?” Nobody had considered whether to exclude, or include it explicitly because it was new. The same is true now with AI. Companies are deploying AI across their operations, and nobody has explicitly addressed what happens when that AI causes loss.
However, the critical difference from cyber is that silent cyber was about physical or performance damage caused by computer systems. Silent AI is about a broader category of decision-driven harm across multiple lines of business simultaneously.
The agentic AI in insurance problem is different, and more urgent
Spelling out this distinction is more important at this moment because we’re not just talking about AI outputs anymore. We’re talking about agentic AI in insurance, systems that make autonomous decisions and take independent actions within a business.
Here’s a concrete example. An insurance company deploys an agentic claims handler with authority to approve payments up to $5,000. This is legitimate use of the technology and critical to keeping costs manageable in claims handling. Many companies are already doing this. But what happens if that agent goes rogue, starts approving $10,000 payments, or begins operating outside its intended parameters? That’s an insurable risk that didn’t exist two years ago.
There are now companies monitoring agent behavior. They’re analyzing logs to see how these systems interact with clients and with each other, scoring the likelihood they’ll drift from their intended role. An adjacent industry is already emerging around this, much like cybersecurity firms emerged in the late 1990s to help enterprises understand computer risk.
The liability question courts are already answering
Every deployer of AI should be concerned that the legal liability is shifting. And the insurance industry hasn’t caught up.
A court case involving Air Canada two years ago made this clear. The airline was sued by a passenger who received what turned out to be incorrect booking advice in a conversation with Air Canada’s AI-powered chatbot. Even though Air Canada didn’t build the chatbot itself, they licensed it from a vendor. A small claims Canadian court held them liable for what the chatbot said because the chatbot was on their website.
Yet many companies still assume vendors are liable. They’re building business models on that assumption. And they’re wrong. The courts are consistently reinforcing the message that deployers are accountable for AI-enabled outcomes regardless of vendor involvement.
This is a behavior-shaping moment. Either companies will move quickly to understand their exposure and obtain appropriate coverage, or they’ll learn about this liability mismatch the expensive way.
The timeline is accelerating beyond cyber
Cyber took 15-20 years for the insurance market to reach $15 billion in capacity. I don’t think AI will take as long to reach that point.
Consider adoption speed. The internet took a long time to reach 100 million users. ChatGPT got there in weeks. AI adoption is exponentially faster and broader than cyber was at its inception. Nearly 5,000 mentions of AI appeared in S&P 500 earnings calls last quarter—more than earnings itself. AI is now foundational to companies’ operations, no longer an emerging technology.
Deloitte projects the AI liability market will reach $4.7 billion in premium within four years. That’s not a trivial space. And it will draw players from across the insurance ecosystem. Examples include MGAs like Testudo Global and Armiller AI who specialize in AI liability; traditional reinsurers like Munich Re, who was the first major player to enter the market; and startups who, as Coalition did in cyber, will become significant players by understanding the risk deeply and intentionally seek to corner the market early.
That market structure is still being defined. Do companies need standalone AI liability policies? Do they need buyback endorsements to cover gaps in existing policies? Will affirmative coverage be added to existing lines with additional pricing? These questions will be answered in the next 18 months.
What deployers need to understand now
If you’re using AI in your business, and if you’re running a modern insurance operation, you need to understand two things.
First, if you’re advising customers based on AI output, or using AI models for decision-making, you’re creating new risk in E&O, D&O, product liability, and general liability coverage. Often simultaneously. That’s aggregation risk that traditional underwriting hasn’t priced for.
Second, if you’re deploying agentic AI systems, you’re creating both first-party and third-party liability exposure. You’re accountable for what those systems do.
The insurance industry is well-positioned to address these issues. We have the skill sets. We have partnerships with experts outside insurance who understand AI risk at a depth most enterprises don’t. But that positioning only matters if we move fast and clearly educate our clients about what they’re actually signing up for when they deploy AI.
Frequently asked questions
Q: What is AI liability insurance?
A: AI liability insurance is coverage for harm caused by artificial intelligence systems, including hallucinations, discrimination, financial loss, and intellectual property infringement. Unlike cyber or E&O, AI liability doesn’t map cleanly to existing insurance products because AI-driven harm can span multiple lines of business simultaneously.
Q: What is “silent AI” in insurance?
A: Silent AI refers to AI-related coverage that exists in policies but isn’t explicitly identified, priced, or managed. It’s a direct parallel to “silent cyber” from the early 2000s. Policies written before widespread AI adoption neither explicitly cover nor exclude AI-related harm, creating dangerous gaps.
Q: How is agentic AI in insurance different from other AI risk?
A: Agentic AI in insurance introduces autonomous systems that make decisions and take independent actions, such as approving claims payments. When these systems operate outside their intended parameters, the resulting exposure has no clean home in existing policy structures. This is a category of risk that didn’t exist two years ago.
Q: Who is liable when an AI system causes harm — the deployer or the vendor?
A: Courts are consistently ruling that deployers are accountable for AI-enabled outcomes regardless of vendor involvement. In a Canadian court case, Air Canada was held liable for incorrect advice from a chatbot it licensed from a vendor, not built itself. Assuming vendor liability is a business model built on a legal fiction.
Q: How fast will the AI liability insurance market grow?
A: Deloitte projects the AI liability market will reach $4.7 billion in premium within four years. Cyber took 15 to 20 years to reach $15 billion in capacity, but AI adoption is moving exponentially faster. ChatGPT reached 100 million users in weeks, not years.
Q: Who is Freddie Scarratt?
A: Freddie Scarratt is Global Deputy Head of InsurTech at Gallagher Re, where he develops reinsurance solutions for emerging risk classes including AI liability. He co-chairs the AI Reinsurance Risk Initiative and is an ACII-qualified professional with expertise in AI risk governance, MGA innovation, cyber and technology E&O, and treaty structuring.
Speak with a carrier operations expert about building your AI strategy and governance foundation.