Artificial intelligence is no longer a futuristic talking point. It is already in the tools that screen résumés, write customer-service replies, spot fraud, and even carry on late-night conversations that can feel startlingly human. But here is the uncomfortable question that has insurers scratching their heads: if an AI system messes up, who pays? According to a new RAND Corporation research report, the insurance industry is anything but united on the answer. Carriers are split into three camps: some are excluding AI-related losses from coverage, some are affirmatively covering them, and many are simply staying quiet. That patchwork approach leaves businesses in a strange limbo, where a policyholder may not know whether it is protected until after a loss occurs. RAND’s report, produced by the Institute for Civil Justice and the Feinberg Center for Catastrophic Risk Management and Compensation, is one of the first serious attempts to map this messy landscape systematically. It draws on a wide range of evidence, including the AI Incident Database, a George Washington University database of AI lawsuits, enacted state laws, and insurance filings submitted through the industry’s electronic rate and form filing system. The result is a snapshot of a moment when technology is sprinting far ahead of the legal and actuarial frameworks designed to manage its risks. The report does not just count policies; it tries to understand what the silence means. It finds that the same AI model can cause very different losses depending on how it is trained, deployed, and used. Insurers are not treating AI as a single peril or a stand-alone line, because AI shapeshifts across many types of claims. For business owners, the takeaway is sobering: AI risk is not a monolith, and the insurance market is still trying to figure out what exactly it is looking at.
To see why the divide is so deep, consider what the data show. RAND tracked 713 generative AI incidents since ChatGPT’s November 2022 launch. The overwhelming majority—84 percent, or 599 incidents—involved misinformation or deepfakes. But that is not the whole story. Another 47 percent of incidents fell into overlapping categories: hallucinations and factual errors made up 30 percent, harmful content 13 percent, and agentic or autonomous failures 12 percent. In other words, AI systems are failing in many different ways, and often at the same time. A deepfake video might also be defamatory and trigger a privacy claim. A chatbot hallucination might cause a customer to take harmful action. These are not clean, separate categories; they are tangled knots. Then look at the courts. RAND reviewed 249 U.S. generative AI lawsuits and found the legal battlefield looks very different from the incident data. The biggest share—60 percent—were intellectual property or training-data disputes against AI developers, not claims by end users who were harmed by model outputs. Think of authors and artists suing over copyrighted material scraped into training datasets. But other claims are growing: privacy and surveillance cases, fraud and deception suits, and product liability claims, including wrongful-death lawsuits tied to companion chatbots. It is a reminder that AI liability is not just about what the technology does, but about who built it, who deployed it, and what they promised about it. Around the same time, state legislatures have focused on one particularly graphic corner of AI harm. RAND found that most of the 189 enacted state AI laws it examined target harmful synthetic content; 33 states have passed 62 laws addressing nonconsensual intimate images and child sexual abuse material. So while the federal government has mostly watched from the sidelines, states are moving on the issues that generate the most public outrage. The overall picture: incidents are broad, lawsuits are concentrated on intellectual property for now, and lawmakers are prioritizing the most visceral harms rather than broader civil liability.
So how are insurers responding? Not uniformly. Some of the biggest players are heading for the exits. Verisk/ISO, whose standardized forms are embedded in more than 80 percent of U.S. property and casualty policies, has developed exclusionary language for bodily injury, property damage, and personal and advertising injury caused by generative AI. That is not a niche move; it is a sweeping declaration that standard commercial policies will not cover AI-caused harms. Berkley has gone even further in some ways, revising its directors and officers, errors and omissions, and fiduciary liability policies to exclude claims tied to nearly any use, deployment, or development of AI—including a company’s own statements about its AI capabilities. RAND’s filing data show this exclusionary activity has surged since summer 2025, particularly in commercial umbrella and general liability lines. The message from these carriers is clear: they do not feel they can price a risk that can fail in so many unpredictable ways. On the other side, a smaller but notable group is leaning in. Munich Re, AXA XL, and Coalition have expanded their policies to address hallucinations, bias, privacy infringement, and AI-enabled fraud. New entrants like Testudo, Armilla, and the Artificial Intelligence Underwriting Company are offering stand-alone AI liability products, some with limits up to $50 million. These insurers see an opportunity: if you can underwrite AI risk well, you can capture a growing market and differentiate yourself in a world where most policies say nothing about AI. The stand-alone approach also lets insurers charge premiums that better reflect the actual exposure, rather than trying to bolt AI coverage onto policy lines that were designed for older, more predictable risks.
But the largest group is doing neither. Most carriers leave their policies silent on AI-related losses. That silence is not necessarily a legal disaster; policyholders can still argue that an AI-caused loss falls under existing coverage for, say, negligence or advertising injury. But the uncertainty is real. Coverage depends on the specific policy language, the legal theory of liability, and how old exclusions and definitions—drafted long before ChatGPT—apply to a technology that did not exist when the forms were written. RAND says this silence does not automatically make policies ambiguous, but it makes it incredibly hard for anyone to know what is covered until a claim is denied or litigated. More troubling, perhaps, is what silence does to the industry’s ability to understand systemic risk. RAND identified five mechanisms that could create correlated, large-scale losses across many insurers simultaneously. First, a universal attack could exploit the same vulnerability in many AI systems at once. Second, common dependencies on shared models or infrastructure—including hyperscalers like Amazon Web Services, Microsoft Azure, and Google Cloud—mean a single point of failure could cascade across the economy. Third, AI can act as a force multiplier for cyberattacks, enabling attackers to launch broader or faster campaigns. Fourth, a legal or regulatory shock could suddenly expose thousands of firms to liability at the same time, such as a court ruling that training on public data violates copyright. Fifth, subtle, prolonged degradation of model performance could quietly erode decision-making across industries, producing losses that only show up in hindsight. These are not the kind of risks that fit neatly into a single policy period, and they are exactly the kind of risks that keep reinsurers up at night.
That brings us to what RAND calls the AI protection gap—the difference between economic losses caused by AI and the losses that are actually insured. The report makes a pointed observation: the size of that gap and the extent of insurer accumulation exposure are two sides of the same coin. If insurers broadly affirmatively cover AI-related losses, the protection gap shrinks because more losses are insured. But that also increases insurers’ exposure to the correlated, system-wide risks described above. If insurers broadly exclude AI losses, they shield themselves from catastrophic accumulation, but the protection gap widens, leaving businesses and victims to bear the costs. And when policies are silent, both metrics are invisible. Nobody—not policyholders, not insurers, not regulators—knows what is actually covered. It is a recipe for unpleasant surprises on both sides. To address this, RAND makes three practical recommendations. First, it urges state insurance regulators and the National Association of Insurance Commissioners to develop a standardized AI Coverage Notice. Think of it like a nutrition label for AI insurance: a clear disclosure that tells buyers whether a policy covers AI-caused losses, excludes them, or says nothing. Second, it calls on industry stakeholders to build a common taxonomy for tracking AI incidents and claims. Without a shared vocabulary, it is impossible to compare data across insurers or learn from past losses in any systematic way. Third, it asks insurers and reinsurers to conduct and disclose AI accumulation scenario analysis—essentially stress tests that ask what would happen if a major AI catastrophe occurred. If an insurer cannot answer that question, it probably should not be selling the coverage in the first place.
At its heart, this report is a warning against complacency. Insurers are making high-stakes decisions in a fog. Some are retreating, some are charging ahead, and most are hoping the problem will resolve itself. But AI is not going to wait. It is already in the workplace, in the courtroom, and in the news. The businesses adopting AI deserve better than a policy that may or may not cover them when things go wrong. The insurers that resist clear answers are not protecting themselves; they are just deferring the conflict to the claims department. And the regulators who let silence persist are leaving citizens and companies exposed to a new kind of systemic risk. RAND’s report does not pretend to have a perfect answer—it is an early map of a shifting landscape. But its recommendations point toward something that should not be controversial: transparency. A standardized notice, a common taxonomy, and honest scenario analysis will not solve every AI liability question. They would, however, let businesses know where they stand, let insurers price risk with clearer eyes, and let regulators spot dangerous concentrations of exposure before they blow up. In a world where an AI can convincingly imitate a political leader, give bad medical advice, or make decisions that harm real people, the least we can ask of the insurance industry is to speak clearly about what it will and will not cover. That clarity is not just an actuarial nicety; it is a critical piece of social protection for the age of artificial intelligence.

