Skip to main content

Insurers will exclude AI before they cover it, and the specialists that fill the gap will be valued as insurers, at around twice the premium they write. Cyber insurance went the same way. Five lessons from its first twenty years, and what they suggest for AI liability insurance.

By Nuno Afonso, Start Ventures


In June 2017 a piece of malware called NotPetya spread out of a Ukrainian accounting package and into companies around the world. It disrupted Merck’s operations worldwide, and the company claimed roughly $1.4 billion under its property insurance.

The insurers refused to pay. The policy had been written with physical damage in mind and said nothing about cyberattacks either way, so the insurers relied on the war exclusion, arguing that NotPetya had been attributed to Russia and aimed at Ukraine. Merck sued. New Jersey courts ruled against the insurers twice, and the last of them settled in January 2024, almost seven years after the attack.

The policies had been drafted before anyone imagined an attack like NotPetya. The market called that gap “silent cyber”: exposure sitting inside a policy that neither covered it nor excluded it, until a loss forced a court to decide what the words meant. AI liability is in the same position now, and the market has started calling it “silent AI”.

Silent AI

Companies now use AI to decide who gets a loan or a job interview, and to tell customers what they are owed. When one of those decisions goes wrong, the company is left with insurance policies drafted before it deployed the model. Aon mapped around 300 AI-related lawsuits and found more than nine in ten sitting in exactly this grey zone.

Courts are deciding liability faster than insurers are rewriting their policies. A Canadian tribunal held Air Canada liable for what its chatbot told a passenger about a bereavement fare. In June 2026 a US federal judge let most of the discrimination claims against Workday’s AI screening tools go forward. The month before, two German courts reached the same conclusion by different routes. The Higher Regional Court of Hamm ruled that a clinic’s chatbot is not a third party, so the medical titles it invented counted as the clinic’s own false statements, and said that careful configuration doesn’t remove the risk of hallucination. The Munich Regional Court treated Google’s AI Overviews as Google’s own speech.

Courts are converging on holding the company that deploys an AI system responsible for its output. Whether an insurer pays when that happens is, for most policies, undecided.

Dot chart of about 300 AI-related lawsuits mapped by Aon in 2026: more than 90% fall under policies that neither cover nor exclude AI (silent AI), fewer than 10% under policies that address AI explicitly
More than nine in ten of the ~300 AI lawsuits Aon mapped in 2026 hit policies that say nothing about AI. Source: Aon.

1. AI exclusions arrive before AI cover

After NotPetya, insurers moved first to spell out what they would not cover. In July 2019 Lloyd’s told its market that from 1 January 2020 every first-party property policy had to state explicitly whether cyber losses were covered, and later phases extended the rule to other lines. Many insurers responded by writing cyber exclusions into their property and liability policies.

Excluding is the cheaper choice for an insurer. It takes a paragraph at renewal. Covering a new risk means estimating losses with no history to go on, holding capital against them, filing new wording and getting reinsurers to back it.

AI exclusions are arriving in the same order. ISO, which writes the standard forms most US insurers use, introduced a generative-AI exclusion for general liability in January 2026. About one in ten employment practices policies already carries an AI exclusion, according to a Burns & Wilcox broker quoted in Insurance Business.

We expect exclusions to spread through directors’ and officers’, professional and employment liability over the next two to three years, until a regulator or a large market requires the kind of clarity Lloyd’s required for cyber. That creates demand. A risk manager who was only uneasy about AI now has a document from their own insurer saying the exposure isn’t covered.

2. Standalone AI insurance grows in the space exclusions leave

Cyber cover started as endorsements added to general liability and property policies. The standalone line grew once insurers began excluding cyber from those policies and the risk needed a policy of its own. Specialists such as Coalition and At-Bay built their books in that space.

AI liability cover is at that first step. CFC added explicit AI wording to seven of its existing products in June 2026, and Counterpart and Munich Re’s HSB have done something similar for smaller businesses. Only the insurer that owns the underlying policy can endorse it, so a new specialist is always selling a standalone policy of some kind.

A layer that sits on top of a company’s existing insurance and pays out where those policies are silent or exclude AI is a standalone contract with its own limit, yet the buyer sees it as closing a gap in a programme they review at every renewal. A fully separate AI policy needs its own budget line, which few companies have yet; cyber had none at first and gained one as exclusions spread. The specialists we want to back sell the easy-to-buy version now and can grow into a full AI line as exclusions push more of the risk out of traditional policies.

The case for standalone is weaker for AI than it was for cyber. Cyber losses were often first-party, such as ransomware and business interruption, and had no natural home in a property or liability policy. Most AI losses are liability to other people and fit reasonably well inside professional, employment and directors’ and officers’ cover, which is CFC’s argument for keeping AI inside existing products. If incumbents write AI into their policies faster than exclusions spread, the standalone line stays small, so the pace of new exclusions against new affirmative cover is the number we are watching.

3. AI underwriting moves from questionnaires to evidence

The cyber insurers that grew fastest stopped relying on questionnaires. They scanned a prospect’s systems from the outside before quoting and kept scanning through the policy year. Coalition built its model around this, and when Travelers bought Corvus in 2023 it cited that capability.

Most AI underwriting still runs on forms and self-reported governance, and the specialists haven’t agreed on a method. Some test the model itself. Some price from litigation and incident data without auditing the customer. Others look at what the AI is allowed to do: whether it can move money or only draft an email, and whether a person approves its decisions. AIUC has gone furthest with that approach and has published a standard audited by accredited third parties.

We expect the winners to underwrite what the AI is permitted to do, rather than how the model scores in testing or how often similar companies have been sued. A well-tested model can still cause a large loss if it has been allowed to approve payments without anyone checking, and litigation data describes the market as a whole while permissions describe the deployment being quoted. We also expect standards checked by independent auditors to count for more with buyers and reinsurers than scorecards produced by the insurer selling the policy.

4. The first bad year decides which AI insurers survive

For cyber insurance, the first bad year was 2020. Ransomware claims surged, and the loss ratio on standalone US cyber insurance (the share of premium paid out in claims) rose to 73%, against an average of 42% over the previous five years. The average paid claim more than doubled, and insurers raised rates sharply.

AI’s first bad year will probably come from correlation. Thousands of companies build on a handful of foundation models, so one model failure, or one ruling applied across an industry, could trigger claims on many policies at once, however many sectors the book spans.

Most specialist AI insurers are managing general agents, or MGAs. An MGA designs, prices and sells the policies, but a licensed insurer lends it the right to write them and a panel of reinsurers pays most of the claims. Both relationships usually renew every year, and both partners get a quarterly report on every policy and claim. They can cut the MGA’s limits or walk away after a bad year, and also when they spot business written outside the agreed rules, pricing they no longer trust or a senior underwriter leaving. Sometimes they leave a whole class of business at once. One industry analysis calls losing a sole capacity provider “an existential crisis”, since an MGA without capacity has nothing to sell. AI makes these calls harder to get right. Ransomware claims arrived within weeks, while lawsuits take years, so an AI book written in 2026 can look clean in 2027 and go bad in 2029.

Timeline of liability cases against one-year insurance renewals: the Air Canada chatbot case took one renewal to reach a ruling (chat Nov 2022, ruling Feb 2024); the Workday AI hiring case has run through three renewals and is still open (filed Feb 2023); Merck's NotPetya cyber claim took six renewals to settle (attack Jun 2017, settled Jan 2024)
AI liability claims outlast the policy year: Air Canada took one renewal to reach a ruling, Workday is three renewals in and still open, and Merck’s NotPetya claim took six. Sources: Moffatt v. Air Canada, 2024 BCCRT 149; Mobley v. Workday, N.D. Cal. 3:23-cv-00770; Insurance Journal.

Correlation in an AI insurance book can be priced, though. What an AI is allowed to do sets how large one failure can get, and the model it runs on sets how many failures can happen together. Fifty customers whose agents approve payments unreviewed, all on the same model, are one large bet. Spread them across models, or put a person in front of each decision, and the bet shrinks. Cyber insurers handle the equivalent by tracking which cloud providers their customers depend on and capping exposure to each. AI underwriters can cap exposure per model provider, most tightly for the deployments with the most authority, and charge less for controls such as human approval above a set amount. Policy wording can also put a ceiling on a systemic event, much as Lloyd’s did for cyber when it required exclusions for state-backed cyberattacks.

Correlation in an AI insurance book: 50 policies on one foundation model with no human review produce 50 large claims from one model failure; the same 50 spread across four models with human sign-off on big decisions produce 12 claims, most of them capped
One model failure: 50 large claims when every customer runs on the same model unchecked, 12 mostly capped claims when the book is spread across four models with human sign-off. Illustrative book of 50 policies.

The survivors will be the MGAs that priced for correlation early and kept more than one capacity provider, and investors should note that this test comes before any exit. Corvus was bought about six years after it was founded and At-Bay about nine, and both had to get through 2020 first. An AI insurer founded in 2026 will probably face its test around the end of the decade, and a buyer will wait to see it passed. A fund backing one at seed should expect a long hold and keep reserves for at least one more round.

5. Specialist AI insurers take the middle of the market, and incumbents buy them

As cyber matured, the specialists held their position. Several legacy writers shed more than half their cyber books while digital-first entrants grew at triple digits. In May 2026 Allianz handed its whole standalone cyber business to Coalition, saying cyber risk demands a dynamic, tech-forward approach.

Incumbents kept the large, complex accounts, where high limits and bespoke wording matter more than technology, and most of the successful specialists were eventually bought by incumbents. Travelers paid around $435 million for Corvus. In August 2026 Munich Re agreed to buy At-Bay for $575 million, on about $278 million of premium, or roughly twice what it wrote.

We expect AI to follow the same pattern: specialists win the technical middle of the market, incumbents keep the largest accounts, and the strongest specialists get acquired. That should shape how these companies are built and funded. An MGA keeps a commission, usually in the mid-teens as a percentage of premium, and when it is sold it’s valued as an insurance business, at around twice premium. A plan that depends on a software multiple is unlikely to hold up.

Cyber insurance exits: Travelers bought Corvus in November 2023 for about $435M on $200M+ of premium, and Munich Re agreed to buy At-Bay in August 2026 for $575M on $278M of 2025 gross written premium, both roughly 2x premium, after the 2020 loss spike when cyber loss ratios rose from 42% to 73%
Corvus and At-Bay both sold for about twice their written premium, after surviving cyber’s 2020 loss spike. Sources: Travelers, Munich Re, Fitch via Insurance Journal.

Where the cyber comparison breaks

Cyber moved slowly. Standalone cyber policies go back to the late 1990s, and Lloyd’s only forced clarity in 2020. With AI, incumbents are writing affirmative cover in the same years the specialists are launching, so specialists will have much less time before serious competition arrives.

AI law is also being written as we go. Because AI losses are mostly liability to other people, the legal rules matter more than they did for cyber, and those rules shifted in two German courts and a US federal court within a few weeks of each other in May and June 2026. A risk is harder to price while its legal definition keeps moving.

An AI deployment also changes during the policy year in a way most insured risks don’t. The vendor releases a new model version, the agent gets access to another system, or a tool built for drafting emails starts approving refunds. A contract priced once a year fits that poorly, and we expect the products that last to collect evidence throughout the year.

What we look for in AI insurance startups

We think AI liability will become a real insurance line, and that it will grow the way cyber did rather than the way software does. Four things decide whether a company in it lasts, and they’re what we look at first.

Distribution that lets you say no

A book only tells you something once it’s big and varied enough that one bad claim, or one flaw in a model many customers share, can’t sink the year. Capacity providers stay with books like that.

Broad distribution also buys choice. An MGA that sees plenty of submissions can turn most of them down. So when we ask how many brokers have sent a founder more than one customer, what we want to know is whether the company picks its customers or takes whoever shows up.

Turning business down goes against the startup habit of growing as fast as possible. We want founders who already know that in insurance, premium written for its own sake tends to come back as losses.

Underwriting built on evidence

We want to see a company price what the AI it covers is allowed to do, and check that against something other than the customer’s own questionnaire. It should also know which model providers its book depends on, and cap how much it holds on each.

Independent standards, and controls that stop one defect from turning into many claims, should show up in the price.

A capacity panel that will stay

The MGA doesn’t pay the claims. The carriers and reinsurers behind it do, and they can leave at renewal. So we look at who they are, how many there are, how they’re rated, how long they’ve committed for and on what terms they can walk away.

We’d rather see several well-rated reinsurers who have signed up for the class, with commission tied to results, than one famous name on a one-year deal.

Profit in the book, then in the company

The book has to make money first, with premium that covers claims and leaves a margin. An MGA whose commission rises and falls with its loss ratio has a direct reason to keep it there.

The company matters too, for a different reason: this is a long game, and a company that keeps needing new rounds will be pushed to show the growth venture investors usually want to see, and that is the kind of growth that damages an insurance book. One that can pay its own way from commission doesn’t have to make that choice. So we pay close attention to how soon, and how believably, a founder can get there.

How they get there matters as much. Losing money while hiring underwriters, an actuary and claims staff is normal. Cutting those people to reach breakeven sooner is a bad trade, because they’re the ones keeping the book profitable.

If you’re building in AI risk or insurance and this is already how you think about it, we’d like to hear from you.


Nuno Afonso is an investor at Start Ventures, an early-stage fund backing B2B fintech and insurtech companies.