Overcoming Judgment-Proofness: The Law & Economics of Insuring and Mitigating AI Risk
Abstract
Tort liability cannot discipline catastrophic risk because judgment-proofness leaves deterrence empty once losses exceed assets and insurance — yet strong ex ante regulation of frontier AI is equally elusive. The answer is a two-instrument design: risk-weighted mandatory insurance priced on compute, capability and deployment and reinforced by binding covenants, which enlists insurers as private watchdogs; plus calibrated punitive damages for near misses, which price the uninsurable tail. “AI’s gravest risks will remain ungoverned if they remain unpriced.”
Publication details
- SSRN working paper, dated 3 February 2026, posted 24 February 2026; 64 pages.
- Gabriel Weil, associate professor of law at Touro University Jacob D. Fuchsberg Law Center and non-resident senior fellow at the Institute for Law & AI.
- Positioned as the implementation sequel to prior work — Tort Law as a Tool for Mitigating Catastrophic Risk from Artificial Intelligence, Instrument Choice in AI Governance, and a forthcoming Abnormally Dangerous Algorithms — translating an already-argued framework “into practice within existing legal doctrine.”
- Claims to be “the first account to show how the legal system can price catastrophic AI risk.”
The problem
- Expert surveys and forecasting tournaments put extinction-risk estimates anywhere from 0.38% to 10% or more, alongside deep disagreement about both magnitude and benefits — GDP-impact estimates over a decade span 0.7% to 15%.
- Strong ex ante governance is not available: prescriptive standards or pre-deployment approval require foresight and social consensus that do not exist, and demand technical sophistication hard to bring into government at AI’s pace.
- Ex post liability is superior under uncertainty because it is information-economising and adaptive: it does not require regulators to foresee all failure modes, scales automatically with realised harm, and is decentralised across developers, insurers, and courts. Its own challenges are “fundamentally more tractable than the foresight demanded of an ex ante regulator.”
- But two failures threaten to gut it: judgment-proofness (firms lacking assets to cover the harms they cause) and uninsurable tail risks (harms for which ex post compensation is practically infeasible).
Foundation: the liability-centred framework
Strict liability
- Negligence is a poor fit. Claims will fail where liability is appropriate, because alignment is an unsolved technical problem and courts struggle to find breach of “reasonable care” when standard industry practice fails to prevent emergent behaviours like deceptive alignment. Breach analysis also focuses narrowly on marginal precautions rather than the high-level decision to build or deploy at all — as the choice to take a discretionary car trip falls outside breach analysis in collision cases.
- Products liability is similarly inadequate: manufacturing-defect claims are irrelevant; design and warning defects require a reasonable alternative design, hard to show for unsolved problems; the consumer-expectations test suits neither technically complex products nor non-user plaintiffs; and the doctrine may not reach systems classified as services, or free and customised models.
- The gap is sharpest for third parties — market forces protect users but not non-consenting bystanders, and user safety can trade off against third-party safety (as in autonomous vehicle design), leaving an external risk analogous to pollution.
- Proposed route: AI development as an abnormally dangerous activity under Restatement (Third) §§ 20–23, with vicarious liability playing a growing supporting role as agentic systems spread (though the “uncommonness” factor weakens as capable agents become widespread).
- Pluralistic normative defence: economically, strict liability is efficient where the activity level rather than just care level matters, forcing developers to consider “not only how to build AI safely but whether to build or deploy a given system at all”; positive externalities from innovation are better addressed by subsidy than by letting developers externalise risk. Corrective justice assigns responsibility to whoever introduced the non-reciprocal risk; civil recourse theory is served by relieving victims of the near-impossible burden of proving specific breach inside an opaque training process.
Why insurance and punitive damages are both needed
- A liability rule is only as good as the defendant’s ability to pay. Catastrophic damages could exceed even the largest technology firms’ assets.
- Insurance guarantees a compensation pool and imports the insurance industry as a sophisticated third-party risk assessor — “decentralized, market-driven safety regulation.”
- Mandates are necessary because firms have minimal incentive to buy coverage exceeding the liquidation value of the enterprise, which would protect only third parties.
- Insurance also addresses incentive failures liability alone leaves untouched: market failures (underinvestment in safety research with large spillovers, collective reputational exposure to a “Three Mile Island”-style incident) and behavioural failures (competitive races rewarding short-term deployment, founder-led overconfidence). Well-designed mandates produce a net regulatory effect where insurers’ monitoring, pricing and standard-setting cut expected losses more than moral hazard raises them.
- But insurance stops where compensation stops. Some risks would overwhelm the deepest-pocketed firm, some would collapse the legal system itself, and some “could leave no survivors to claim recovery.” Firms will systematically underinvest against these.
- Hence a novel application of punitive damages — the author suggests they might warrant a new label, “catastrophic risk damages” — available where a smaller compensable harm is demonstrably associated with the creation of a larger uninsurable risk. The example: an AI causing compensable financial loss through an unforeseen planning error that would exhibit the same error in a higher-stakes domain. The award “pulls forward” the expected social cost of the second event.
- The two are complementary: insurance expands the set of practically compensable harms; punitive damages deter the residual beyond the market’s reach. The author notes administrative penalties could in principle serve the same function and flags the comparison as future work.
- Limits from recent work (Schwarcz and Wolff on cybersecurity) are conceded: sparse data on novel failure modes, correlated losses straining private capacity, insurer incentives oriented to liability rather than accident prevention, and coverage requirements drifting into de facto technical standards. These are called “challenges of design, not reasons for abandonment.”
Designing the insurance mandate
Mandates attach to activities rather than corporate form — wherever capability or deployment thresholds are met, including by a downstream integrator that materially amplifies risk (e.g. combining tools enabling high-consequence cyber operations or CBRN uplift).
Setting coverage floors: a layered sequence of proxies
- Training compute at initiation of a run is the logical first attachment point: FLOPs, parameter count, and dataset scale are objective and auditable, and requirements attaching at creation force developers to internalise the cost of securing weights before capabilities are even evaluated. The drawback is crudeness — efficient reasoning models decouple raw inputs from capability. Best understood as “a necessary first step that establishes a preliminary insurance floor.” Some crudeness is tolerable because insurers retain latitude to price nuances the regulator’s threshold misses.
- Demonstrated capabilities once trained: high coverage floors triggered by autonomous self-replication, advanced deception, substantial CBRN uplift, or sophisticated cyber exploits, leveraging third-party evaluators and red-teaming. Highly risk-sensitive but information-intensive and gameable — mitigated by employee-level access for evaluators, mandatory documentation and disclosure of internal test results, and strong whistleblower protections.
- Lifecycle and deployment context: pre-deployment risk is real — weight theft via cyber intrusion, a model facilitating its own exfiltration, misuse or misalignment by a firm’s own employees. Higher coverage should apply to models in active internal use, scaled to the number of employees with access. Open-weight releases should carry significantly higher requirements than API access, which permits monitoring, safety filters, and revocation — creating a “misalignment tax” on riskier deployment choices.
- Inference compute: training compute proxies latent capability, inference compute proxies real-world activity. Regulators should attend to compute brought to bear per query (correlated with maximum plausible harm); insurers care more about total inference compute (correlated with the probability of any given harm). For API deployment, part of the mandate could scale dynamically with auditable metrics — API call volume, active users, inference compute hours. This reinforces the open-weight differential, since open-weight usage cannot be tracked at all.
Insurers’ tools
- Cost-sharing. Deductibles keep the firm bearing 100% of smaller, more frequent losses — preserving incentives for quality control and reserving insurance for “larger, potentially bankrupting losses that give rise to the judgment-proofness problem.” Co-insurance alters the marginal cost of risk-taking above the deductible. Policy limits complete the structure.
- Risk-based pricing. Experience rating, on the workers’ compensation model with its “experience modification factor,” makes today’s claims raise premiums for years — a continuous incentive for safety programs, post-deployment monitoring, and incident response. But backward-looking methods are insufficient for a technology whose capabilities evolve exponentially and whose new generations exhibit capabilities absent in predecessors, so forward-looking ex ante assessment is also required.
- Direct oversight. Insurers become “dynamic, decentralized private regulator[s].” Precedents: American Nuclear Insurers pools, formed in the 1950s to amass capacity for low-frequency high-severity risk, which employed their own engineers to inspect plants; and aviation insurers, who condition coverage on airworthiness and pilot qualifications and supply safety engineering services alongside FAA regulation. The policy contract itself “could become an enforceable safety charter,” requiring third-party audits and robust monitoring.
- Cautionary history. In the late 1990s AIG and Lloyd’s offered premium discounts of up to 25% for passing cybersecurity audits; the labour-intensive programs proved infeasible at scale and were discontinued when no clear loss reduction materialised. The cyber market, now tens of billions in premiums, has repeatedly withdrawn coverage for the most catastrophic scenarios including nation-state attacks. These “counsel humility.”
- Why AI is harder than nuclear: reactor physics follows deterministic laws, so containment and cooling can be specified; AI capabilities “emerge unpredictably from scale, can be instantiated and modified anywhere, and operate through mechanisms that remain opaque even to their creators.” The radical uncertainty “is not merely quantitative but qualitative.” The claim is not that insurance markets are ideal but that they are “less inadequate than available alternatives,” since insurers must continuously update assessments to stay solvent.
- Political economy: insurance mandates operate through existing market and liability structures rather than requiring new regulatory apparatus vulnerable to capture and constitutional challenge, and preserve firms’ flexibility to innovate on safety — likely provoking less industry resistance than rigid technical standards that may advantage incumbents.
Punitive damages for “near misses”
The economic logic
- Standard optimal-deterrence theory (Polinsky and Shavell): total damages should equal harm × the reciprocal of the probability of being held liable. Harm of $100 at 50% liability probability implies a $200 award — $100 compensatory, $100 punitive.
- Uninsurable catastrophe is the ultimate escape from liability. An AI responsible for ten million American deaths would generate roughly $10 trillion in damages at a modest $1 million per victim — bankrupting any company and exceeding any plausible coverage. In more extreme cases legal institutions may no longer function, or no one may be left to sue. “A purely profit-maximizing firm would have no financial reason to spend resources mitigating a risk for which it knows it can never be made to pay.”
- Near-miss punitive damages apply the deterrence multiplier by treating a compensable harm as a proxy event for the correlated uninsurable risk — a Pigouvian correction to a potentially catastrophic market failure.
The three-part predicate
Common-law punitive damages hinge on malice or conscious disregard, which is “a poor fit”: the market failure arises even from a developer acting without malice, particularly for alignment failures where the system competently pursues a goal. The proposed trigger is technical and economic, keyed to the type of externality generated rather than the actor’s reprehensibility. A plaintiff must prove, by clear and convincing evidence:
- Capability congruence — the same technical mechanism or failure mode that caused the plaintiff’s harm is capable of producing a catastrophic, uninsurable harm.
- Proximity — a plausible, objectively specified perturbation of the circumstances would have sufficed to cause the catastrophic harm, showing the system was operating near a tipping point.
- Controllability — cost-effective precautions that would have reduced the plaintiff’s harm would also have meaningfully reduced the catastrophic probability, making the compensable harm a diagnostic event. Absent controllability, the case-specific elasticity is treated as effectively zero.
A non-adversarial technical review board (a designated agency or NAIC-style body) could issue contemporaneous “near-miss certifications” to reduce litigation costs.
Quantification
- N(d) is the ex ante expected loss from practically non-compensable catastrophic outcomes attributable to tortious decision d (a training run or deployment decision) — the sum over scenarios of probability × the portion of loss not collectible through assets, insurance, or a functioning legal system.
- The plaintiff’s punitive share combines C_P/C_T (share of total compensatory damages) with E_P/E_A (the elasticity of uninsurable risk with respect to the plaintiff’s injury, relative to the damages-weighted average) — capturing “how diagnostic the plaintiff’s injury is of the uninsurable tail risk.”
- The architecture is designed so that efforts merely shifting loss within the insurable region (reducing C_T without changing N) do not reduce punitive exposure, while efforts genuinely diminishing catastrophic risk are rewarded even if ordinary losses are unchanged.
- Shares sum to at most N(d), preventing aggregate over-penalisation and tying exposure to the specific decision that created the risk. Estimating C_P and C_T is straightforward since those harms have generally occurred; the novel challenges are estimating N and the relative elasticity.
Two psychological challenges
- Subjectivity of “near misses.” Drawing on Philip Tetlock, judgments about close-call counterfactuals are “heavily theory-driven”: observers already concerned about AI risk have a lower threshold for labelling events close calls — an instance of the “I-was-almost-right” defense protecting belief systems from disconfirming evidence. Juries primed by public discourse may enter an “intuitive prosecutor mindset.” The response is to make the predicate quantitative and protocol-anchored: anchors should be technical rather than rhetorical — “the test protocol, the threshold, and the disclosed error rate… rather than a narrative about how events ‘almost’ went wrong” — with sensitivity tables reporting absolute and percentage changes around the operating point.
- Erraticism of outrage. Sunstein, Kahneman and Schkade showed that factfinders agree on the relative reprehensibility of conduct on a bounded scale but diverge sharply when converting it into dollars — the mapping problem. Since the allocation rule already fixes an incident-level envelope at N(d), the remaining task is stabilising the conversion within it. The solution is a modulus: publicly recognisable benchmark reference cases supplying a common metric, formalisable through rulemaking, channelling counterfactual assessment toward judicially recognised anchors.
Institutional machinery
Three paired mechanisms generate contemporaneous, auditable inputs allowing courts to translate probabilistic risk assessments into determinate, reviewable judgments:
- A market-facing discovery regime obliging pre-underwriting audits and insurer-commissioned evaluations that yield reproducible testing artifacts admissible as business records (FRE 803(6), 901(a)).
- A judicial vetting regime requiring modelling evidence to survive Rule 702/Daubert reliability screening (with Kumho Tire and the 2023 Rule 702 amendments), with the near-miss predicate proven by clear and convincing evidence, plus court-appointed neutral experts under Rule 706 and protective orders for trade-secret and dual-use concerns.
- An incident-level administrative ledger recording approved N(d) estimates and aggregating near-miss allocations across follow-on suits — maintained under protective order, treated as admissible workpapers, providing continuity, enforcing pro rata reduction when shares approach the cap, and preventing relitigation.
Objections and rebuttals
- “Unworkably speculative, inviting frivolous litigation.” The clear-and-convincing standard filters conjecture; the modulus disciplines the counterfactual by requiring comparison with recognised reference cases; and establishing the formula’s variables requires detailed evidentiary showings subject to Daubert, making such suits costly and impractical without substantial technical proof.
- “The modulus is judicial activism displacing the jury.” It structures rather than supplants jury discretion, and directly answers the Supreme Court’s demand for “law-like restraints” on “grossly excessive” awards under Gore and State Farm — enhancing rather than undermining constitutional soundness.
- “Too complex for the judiciary.” Conceded as a valid concern, met with existing procedural tools for technically dense litigation: Daubert gatekeeping, neutral experts, and the ledger.
- “Courts won’t actually award high near-miss damages, and early precedent could undermine deterrence.” Answered by the evidentiary standard, Daubert screening, incident-level caps, and pairing punitive damages with regulatory backstops to maintain credibility.
Conclusion
- The two instruments operate in tandem: insurance absorbs otherwise judgment-proof losses ex ante, shrinking the punitive envelope, while underwriting analyses help courts gauge the scale of the uninsurable tail.
- The design explicitly leaves room for licensing regimes, technical standards, and other ex ante tools in circumscribed roles, and is “intended to integrate with them rather than compete.”
- The aim is “not predictive certainty about AI’s trajectory, but durable institutional channels—market-based, evidentiary, and doctrinal—through which developers must bear the costs of unsafe development.”