AI Insurance Has a Capacity Problem, But Not the One You Think

James Felton Keith, Economist at InclusionScore and Joe Scarlato, EVP at Ampcus Forensics
By: James Felton Keith and Joe Scarlato
Artificial intelligence is rapidly becoming economic infrastructure. Companies are investing heavily in models, compute, data and autonomous systems while giving those systems increasing authority over business decisions and economic activity. As that transition accelerates, the insurance industry faces an uncomfortable question: if trillions of dollars of economic value eventually depend upon artificial intelligence, where will enough insurance capacity come from to protect it?
The question sounds daunting, but it begins with the wrong denominator. Insurance markets do not generally provide capacity equal to the total economic value of everything exposed to a peril. A company worth $100 billion does not ordinarily purchase $100 billion of insurance simply because that is its enterprise value. Instead, insurers determine what can go wrong, how frequently a loss could occur, how severe it could become, what controls reduce that loss, how much the insured will retain and what portion should be transferred.
AI should be approached in much the same way. The relevant question is not how much artificial intelligence is worth in aggregate. It is how much economic value a particular AI system can place at risk, how that value can be lost, and how much of the resulting exposure an organization wants an insurer to assume.
That distinction could determine whether AI develops into a manageable specialty insurance market or becomes an accumulation problem that insurers recognize only after significant losses have occurred.
Also Read: Who Pays When the AI Gets It Wrong? Inside the Race to Insure Artificial Intelligence
From the Value of AI to the Value Exposed by AI
Consider a company using an autonomous procurement agent that influences $50 million of purchasing each year. The insurance exposure is not simply the development cost of the software or the amount the company pays its model provider. An underwriter would need to understand the authority granted to the agent. Can it select vendors, negotiate terms, authorize transactions, commit corporate resources or enter contractual obligations? How large can an individual transaction become before a human must intervene? How quickly can an erroneous decision be reversed?
Two companies could use the same foundation model and represent radically different insurance risks because they have delegated radically different amounts of economic authority to it.
We describe one way of measuring that relationship as Agent Insurable Value, or AIV. AIV is intended to establish the economic value exposed to the decisions and actions of an AI system. It is not simply the replacement cost of the model or the total enterprise value of the company using it. The relevant exposure may instead be the transactions an agent can authorize, the resources it can consume, the operations dependent upon it, or the economic consequences that can arise when it makes the wrong decision.
Establishing that value is only the first step. Underwriters must then determine how it can be lost. We believe at least seven categories of AI exposure are emerging: Autonomous Resource Allocation Risk, Autonomous Economic Decision Risk, Autonomous Operational Failure Risk, Intellectual Property Exposure Risk, Personal Data Exploitation Risk, AI Concentration Risk and Informational Labor Risk.
Those risks should not be treated as if they share the same loss characteristics. An AI system that recursively consumes compute or API resources may generate relatively frequent but bounded financial losses. An autonomous economic decision could produce a larger and more immediate loss by purchasing the wrong inventory or allocating capital incorrectly. Intellectual-property disputes may occur less frequently but produce significant defense costs and damages. Informational labor disputes involving the human contributions from which AI systems derive economic value may emerge over longer periods through litigation, regulation, employment disputes or collective bargaining.
For insurers, the relevant variables remain familiar even if the technology is new: frequency, severity and correlation. It is the third variable that may ultimately create the greatest capital challenge.
AI Creates a New Form of Accumulation Risk
An insurer could provide AI-related coverage to a manufacturer, hospital, bank, retailer and logistics company and reasonably conclude that its portfolio is diversified across industries. But all five companies might depend upon the same foundation model. Hundreds more could rely upon the same cloud infrastructure, model API, semiconductor architecture, critical dataset or agent framework.
The businesses may be unrelated while the underlying technological exposure is not.
Insurance has encountered this problem in other forms. Property insurers map geographic accumulation because thousands of individually acceptable properties can be exposed to the same hurricane or earthquake. Cyber insurers have increasingly had to consider shared software, infrastructure and service providers capable of producing simultaneous losses across otherwise unrelated insureds.
AI potentially creates another form of accumulation. A common model failure, infrastructure outage or other shared dependency could affect organizations across industries and geographies at the same time. What appears to be a diversified book when measured by conventional industry classifications could therefore contain a hidden technological concentration.
AI’s equivalent of geographic catastrophe accumulation may be technological dependency accumulation.
This changes the capacity question. Suppose companies eventually place trillions of dollars of economic activity under some degree of AI influence. That does not mean insurers need trillions of dollars of AI capacity. The relevant progression runs from total AI investment to identifiable AI assets, then to the economic value actually exposed, then to plausible losses after controls, and finally to the portion of those losses that organizations choose to transfer.
An enterprise may retain an initial layer of risk itself. A primary insurer may assume the next layer. Excess insurers can participate above that. Reinsurers can protect carriers against severity and portfolio accumulation. If sufficiently credible exposure and loss data eventually develop, alternative capital may also become capable of participating in appropriate tail risks.
Also Read: Who Pays When the AI Gets It Wrong? Inside the Race to Insure Artificial Intelligence
The amount of capital required is therefore a function of the loss distribution and its correlation, not the total economic value of artificial intelligence.
There are useful precedents. Cyber insurance developed despite limited historical loss information. Early underwriters bounded their exposures, restricted appetite and limits, accumulated claims experience and progressively refined policy language and pricing. Catastrophe markets developed sophisticated accumulation models precisely because insurers learned that individually acceptable risks could collectively produce unacceptable losses. Other specialty markets have expanded as standardized diligence made unfamiliar exposures easier to evaluate repeatedly.
AI insurance may require elements of all of these approaches. The opportunity is that insurers can begin building the measurement architecture while the market is still developing rather than waiting for a catastrophic loss to reveal where the concentrations were hiding.
Connecting AI Controls to Insurance Capital
The development of an AI insurance market will require more than identifying which companies use artificial intelligence. Underwriters need to understand what individual systems actually do and how changes in their controls change their potential losses.
Return to the procurement agent. Suppose the system initially has authority to transact with any vendor for amounts up to $5 million without human approval. An assessment identifies that authority as a significant source of potential severity. The company responds by limiting the agent to approved vendors, reducing autonomous transaction authority to $100,000, requiring human authorization above that threshold and implementing anomaly detection capable of stopping unusual transactions.
The company has not simply improved its compliance posture. Its loss exposure has changed.
An effective AI assurance methodology should be able to demonstrate that change quantitatively. Better controls should reduce modeled exposure. Reduced exposure should eventually affect underwriting appetite, retentions, attachment points, limits and pricing. This creates an economic connection between governance and risk transfer: governance changes risk, risk changes capital requirements, and the cost and availability of capital create incentives for better governance.
The same principle applies at the portfolio level. An underwriter evaluating one company may need to know which model providers, cloud platforms and critical AI vendors it depends upon. A carrier managing hundreds of such policies needs to know how much aggregate exposure sits behind each dependency. A reinsurer needs to understand the tail of that distribution and whether one event could trigger claims across multiple cedants.
This is why the initial challenge in AI insurance is as much a measurement problem as a policy-form problem. Before insurers can confidently determine how much capacity to deploy, they need a consistent way to inventory AI systems, quantify their economic authority, identify their loss pathways, validate their controls and map their shared technological dependencies.
Why State Insurance Regulators Should Pay Attention Now
Technological accumulation also means AI insurance cannot ultimately be viewed solely as a company-by-company underwriting issue. At sufficient scale, it becomes a question of insurer solvency and potentially systemic insurance risk.
Insurance regulators already monitor the relationship between exposure and capital. They examine catastrophe concentrations, reinsurance structures, risk-based capital and other conditions capable of impairing an insurer’s financial position. AI may eventually require an analogous capability because conventional measures of diversification may fail to reveal shared technological dependencies.
A carrier could appear diversified across hundreds of policyholders, industries and states while unknowingly accumulating substantial exposure to the same model provider, cloud platform or agent architecture. If a common failure affected those insureds simultaneously, individually reasonable underwriting decisions could aggregate into an unexpectedly large portfolio event.
The regulatory challenge is therefore broader than determining whether an insurer should be permitted to market a product as “AI insurance.” State insurance commissioners, working through existing regulatory and NAIC structures, should begin considering what information would be necessary to understand material AI concentrations across insurer portfolios.
That does not require regulators to prescribe an AI underwriting model today. Doing so before sufficient evidence exists could freeze assumptions into regulation before the market understands the risk. A better near-term objective is to develop a common language for identifying material AI exposures and dependencies, while allowing carriers, brokers, reinsurers and assurance providers to test competing methods of quantification.
The questions change depending upon where one sits in the insurance system. An enterprise needs to know how much economic value its AI systems can affect. An underwriter needs to determine which loss scenarios are fortuitous and transferable. A carrier must understand how much correlated exposure is accumulating across its book. A reinsurer must decide how much tail risk it can absorb. Regulators must eventually determine whether those accumulated exposures could threaten carrier solvency.
Those are different questions, but they depend upon compatible information.
Capacity Will Follow Measurement
None of this requires pretending that insurers can already predict AI losses with actuarial precision. They cannot. Emerging insurance markets rarely begin with the amount of historical data available in mature property and casualty lines.
What the industry can do now is establish a repeatable methodology for identifying AI systems, quantifying their economic authority, documenting controls, constructing plausible loss scenarios and recording technological dependencies. Each properly structured assessment then becomes another observation about the relationship between AI agency and economic loss.
Across dozens of organizations, those observations begin producing useful underwriting data. Across hundreds, insurers can start testing assumptions about frequency and severity. Across thousands, carriers and reinsurers can begin identifying concentrations that remain invisible when every account is considered independently. Claims experience can then refine those assumptions further.
This is how the apparent trillion-dollar AI capacity problem becomes considerably more manageable. The progression is not from trillions of dollars of AI investment directly to trillions of dollars of insurance. It is from AI investment to measurable economic exposure, from exposure to plausible loss, from plausible loss to control-adjusted risk, and from that risk to the portion retained, insured and reinsured.
The first generation of AI insurers will undoubtedly get some assumptions wrong. Cyber insurers did. Catastrophe models continue to evolve. The advantage will belong to the insurers, brokers, reinsurers and regulators capable of identifying those errors quickly and improving the measurement system as experience develops.
The first major breakthrough in AI insurance therefore may not be a new policy form. It may be the creation of a credible denominator for AI exposure and a way of seeing the dependencies connecting those exposures across the insurance system.
Capacity follows confidence. Confidence follows measurement.
And in AI insurance, better measurement may be what allows a new specialty market to grow without allowing a new form of systemic risk to grow unnoticed alongside it.
The writers are James Felton Keith, Economist at InclusionScore and Joe Scarlato, EVP at Ampcus Forensics.
Editorial Disclaimer:This is a contributed article. The views and opinions expressed are those of the author(s) and do not necessarily reflect the position of The Insurance Reporter, which does not endorse or take responsibility for the accuracy of claims made herein. Readers should conduct their own due diligence before making any financial or insurance-related decisions.

1 thought on “AI Insurance Has a Capacity Problem, But Not the One You Think”