Nobody Wants to Insure Your AI Disaster: The Coverage Gap Nobody Planned For
The insurance industry has looked at AI risk and, by and large, decided it would rather not be involved. That creates a quietly serious problem for every boardroom that has signed off on deploying AI without fully working out who picks up the tab when things go sideways.
A new report from RAND Corporation lays out the tension plainly. AI is already causing real harm — hallucinated outputs, deepfakes, privacy breaches, intellectual property disputes, discriminatory decisions — and companies are getting sued over them. Yet existing insurance products were never designed with any of this in mind, and the industry is reacting accordingly.
Insurer W. R. Berkley has gone so far as to carve out explicit exclusions across its D&O, E&O, and fiduciary liability products, removing coverage for anything touching on 'the use, deployment, or development of Artificial Intelligence.' The CEO framed it as needing to properly understand a risk before pricing it. Which is a reasonable position, actually. It just leaves a lot of corporate customers in a difficult spot.
More significantly, Verisk/ISO, whose standardised policy language underpins over 80 percent of US property and casualty insurance, introduced optional exclusion clauses in January 2026. Carriers can now formally exclude bodily injury, property damage, and other harms arising from generative AI. Many are taking that option.
RAND points to the AI Incident Database to illustrate what's actually going wrong out there. It currently catalogues 713 incidents across more than 6,000 reports. Misinformation and manipulation lead the count at 586 incidents, followed by deepfakes at 346, hallucinations at 215, harmful content at 92, and agentic failures at 84. Privacy breaches, bias, copyright violations and wrongful attribution make up the rest. Several incidents straddle multiple categories, which is part of why the numbers don't add up neatly.
Beyond the incidents themselves, there are roughly 250 US lawsuits with an AI angle, covering everything from copyright and fraud to negligence, discrimination, and surveillance. On top of that, dozens of state-level laws are already on the books covering AI-generated abuse material, deepfake political ads, automated decision-making systems, and similar territory. Any one of these could catch a company off guard.
Despite all of this, businesses keep shipping AI products and integrating AI into workflows. The market hasn't paused. The uncertainty around insurance coverage apparently hasn't slowed adoption much, even as the fiduciary logic for caution grows stronger.
RAND's recommendations are sensible, if unglamorous. It wants a common taxonomy so incidents and claims can actually be tracked consistently across the industry. It also wants state regulators to require clear AI Coverage Notices so policyholders know exactly what their policies do and do not protect them from. Right now, too many companies probably assume they're covered when they aren't.
The think tank believes AI insurance will eventually mature into a standard product rather than a specialist niche. The risks, in theory, can be modelled and priced. But that requires data, time, and an industry willing to sit with uncertainty long enough to build proper actuarial frameworks. None of that happens quickly.
In the meantime, the gap between AI ambition and AI accountability continues to widen. Companies are taking on liability they may not fully understand, and the people who normally price that liability are busy writing exclusion clauses.