Abstract

The AI industry is predicted to grow substantially (up to a 14.5% contribution share to North American GDP by 2030), and this growth will bring AI-inflicted harms alongside its economic benefits. The debate over AI liability has so far focused on which liability regime should apply, but an appropriate policy response must also treat insurance as a regulatory mechanism: insurance can act as a governance tool that channels the behavior of regulated entities, serving both preventive and compensatory functions, rather than merely a blame-placing or indemnification device. The article argues that existing insurance infrastructure — rather than a novel AI-specific insurance scheme — should be extended and adjusted to regulate AI entities, and offers a framework for what type of policy should be purchased and who the policyholder should be.

Introduction and Framing

  • Insurance is usually seen as an ex post tool for indemnification (risk pooling, loss spreading, risk reduction/shifting), but it also performs ex ante risk reduction and management — a role the article says is especially needed for AI “entities” (AI commercial machines, robots, agents, and algorithms).
  • The article identifies two distinct existing inquiries about AI and insurance: (1) how AI changes the insurance industry/actuarial science (the more prominent conversation), and (2) how the insurance industry can change AI — i.e., insurers’ ability to offer coverage when AI entities cause harm. The article focuses on the second, underexplored inquiry.
  • AI liability scholarship has mostly asked which liability regime (negligence, strict liability, etc.) should govern AI-inflicted damages, but has largely failed to also consider insurance’s regulatory role.
  • The article’s central proposal: extend existing mandatory/coercive insurance compensation schemes (no-fault accident compensation) to AI activities rather than creating a new AI-specific insurance product. This would bypass legal problems of liability and blame-placing, make it more predictable which entity compensates victims, and minimize insureds’ moral hazard by requiring safety standards to keep a policy valid.
  • The best way to ensure insurers can regulate AI-using businesses is to impose strict liability for AI-related accidents, since a system of liability insurance requires liability rules to make purchasing insurance necessary; strict liability encourages businesses to purchase policies and adjust behavior/activity levels accordingly.
  • The article does not take a position on which liability regime should ultimately apply to AI, and does not support a comprehensive mandatory insurance scheme for all AI — but argues that most significant AI-using businesses will purchase liability insurance in the long run regardless, out of fear of suits or strict liability.
  • Compares two real-world regulatory paths: the EU’s 2017 European Parliament resolution on civil law rules for robotics (proposing new compulsory insurance schemes and a compensation fund for AI/robots) versus the UK’s 2018 Automated and Electric Vehicles Act (which extended existing motor insurance infrastructure to autonomous vehicles). The article “endorses the UK route” of building on existing insurance infrastructure rather than creating novel schemes.
  • Rationale for preferring existing infrastructure: regulators and insurers currently lack the knowledge, resources, and time to build new AI-specific insurance policies before AI becomes deeply embedded in commercial life; because of AI’s “substitution effect” (AI replacing existing human-performed activities), existing insurance already covers most of the activities AI will eventually perform.

Actuarial Science Meets AI

  • Actuarial science calculates the probability a policyholder will suffer harm from an activity and the predicted magnitude of that harm; accurate risk classification lets insurers combat adverse selection (attracting low-risk policyholders with accurate premiums) and mitigate moral hazard (signaling riskiness to insureds, nudging them to reduce it).
  • An insurance policy is fundamentally a contract between insurer and insured, and both parties need to identify the risks covered — a particular challenge with novel technology like AI.
  • Existing complementary coverage: cyber insurance (covering information security/privacy liability and business interruption) will likely cover some AI-caused harms like data leakage or model-stealing, but is unlikely to cover bodily injuries, brand damage, discriminatory algorithmic decisions, or property damage caused by AI — these will require dedicated coverage as more AI-perils are identified.
  • AI’s growth is fueled by big data, which “revolutionizes” insurers’ business practices, enabling more precise premiums, individualized policies, and easier fraud detection (example: China’s Ping An uses facial recognition to tailor health premiums).
  • Two problems with using big data for risk classification: (1) increased bias risk, since machine learning trained on biased datasets can reinforce discrimination, limit access to insurance as a social safety net, and create dignitary harms from unintuitive correlations; (2) privacy violations, since insurers may access data insureds could not otherwise obtain or that is illegal to collect directly. The article notes these are not new problems unique to AI/big data, just intensified versions of existing insurance-market challenges, and treats a full analysis of AI’s discriminatory risk as beyond its scope.

The Problem with AI’s Insurability

  • Two central reasons insuring AI activities is difficult: (1) current lack of information about the damage AI can cause, since AI is not yet widely or frequently used (an issue expected to diminish as usage grows and data accumulates); (2) the “black-box” problem, unique to AI.
  • The black-box issue: an AI entity’s decision-making process cannot be evaluated either while the decision is being made or after the fact, creating unpredictability and undermining actuarial science’s ability to calculate accurate premiums.
    • Machine learning teaches itself the “best” decision from training data in a process opaque even to programmers; neural networks/deep learning use weighted, largely untraceable connections between layered “neurons” — the more layers, the harder it is to understand or predict the AI’s output.
    • This opacity makes it hard to establish a causal nexus between a victim and a tortfeasor (illustrated by the example of a security robot running over a toddler — it’s unclear whether a “but for” test can even be satisfied given the ambiguity among the AI, its owner, programmer, user, and manufacturer).
    • This also raises an insurance-design puzzle: should coverage be a first-party policy (purchased by the user) or a third-party policy (purchased by the AI company)?
  • The lack of current AI usage data is distinct from the black-box problem: even once information is gathered, the black-box’s inherent opacity still challenges risk assessment. However, this data gap is expected to shrink over time as AI is deployed more widely, generating data insurers can use for risk-adjusted premiums.
  • Despite these challenges, insurance has a long history of facilitating the entry of new technologies into society, and the article argues the industry is well-suited to do so again for AI.

Insurance and Emerging Technology

Insurance of New Technologies

  • New technologies have historically presented challenges to tort law, which takes time to fully assimilate new innovations; insurance provides a parallel and complementary safety net that helps society adopt new technology faster.
  • Historical example: the first industrial revolution (~1760s–1840s) created new forms of harm that spurred rapid development of first-party insurance (fire, health, liability insurance) in the following decades; liability insurance for personal injury emerged later, near the end of the nineteenth century, moving from a first-party to third-party (employer-protecting) model.
  • Fire insurance illustrates how insurers adapted premiums as risk profiles changed (e.g., factories presenting more concentrated risk than domestic workshops) without needing new legislation — insurers initially absorbed losses from mispriced risk but adjusted over time.
  • Tort law and insurance are not alternatives but deeply intertwined; liability insurance is fundamentally shaped by tort law, and emerging technologies have shaped the development of tort law in turn.

Insurance and Its Assimilation of Innovations

The article identifies several institutional advantages insurance has over the tort system in assimilating new technologies:

  • Handling “atypical early claims” better: Courts create common-law rules from early, atypical cases that can persist even once a technology matures and those rules are no longer relevant (stare decisis). Insurers, unbound by judicial precedent, can proactively and flexibly adjust premiums and policy terms ex ante in real time as data accumulates, rather than waiting to act ex post after a claim (as courts must).
  • Tort systems tend to underestimate harms of new technologies: while the public can also exaggerate the harms of an innovation (including AI), courts applying tort principles often fail to identify unreasonable risks that are hard to predict when a technology is new. Insurers can use actuarial data to identify and price in these “unreasonable risks” more quickly, incentivizing insureds to take protective measures sooner than tort law would.
  • Early adopters treated differently: Tort law tends to view early adopters as “taking their chances” with new technology and denies them compensation for resulting harm. Insurance similarly may deny coverage to early adopters or charge high premiums due to lack of data — but insurance can adapt and provide remedies more rapidly than tort, since policies are renewed annually and updated as data develops, unlike static case law.
  • New technologies receive a “grace period”: Regulators tend to favor innovation over safety when a new technology first enters the market and its benefits aren’t yet clear (Citron’s “hyper-vigilant” stage — once benefits become apparent, courts and law reverse course and grant sweeping protection to firms, having previously been protective of victims). During this regulatory vacuum where tort law holds no one accountable, insurance can fill the gap and at least provide victims a monetary remedy even without a judicial liability finding. Example: the largely unregulated grace period autonomous vehicle (AV) manufacturers have enjoyed in the U.S. since Nevada first permitted AVs in 2011 — with liability resting on the AV “driver” who has no real control, insurance fills the resulting gap.
  • Two intertwined structural differences make insurance faster than tort law at adapting to new technology: (1) tort systems only act ex post, after a lawsuit, while insurers act ex ante to prevent accidents and thus increase profit; (2) insurers can convert complex tort standards into “simpler and more easily administered rules” via aggregated data and independently produced “bright-line rules,” without waiting for courts to adjudicate a new technology.

Current Suggestions for Insuring AI

The article reviews six existing proposals for insuring AI, mostly from the autonomous vehicle (AV) context, and offers normative criticism of each.

1. “Turing Registry” (Karnow, 1996)

  • One of the oldest AI insurance proposals: developers would submit an AI agent to a certification procedure, and if successful would be quoted a rate based on the agent’s probable risk — the higher the intelligence/automation, the higher the risk and premium.
  • Only registered AI entities would be covered; programmers would need Turing certification, pay the premium, and secure protection before deploying/selling their AI. This is an ex ante scheme obligating manufacturers (not end-users) to purchase third-party liability coverage.
  • Critique: the scheme’s efficacy hinges on defining “AI entities,” which is difficult given AI proliferation, and it’s unclear who would administer such a vast general registry. The article agrees with the underlying premise (AI features should determine premiums) but argues a single general registry is unworkable — insurers lack the ability to adequately spread risk across such a broad, undifferentiated pool. A registry divided into nuanced sub-categories by specific AI activity would better leverage insurers’ existing specialized expertise.

2. In-House Insurance

  • Manufacturers act as their own insurers — e.g., Volvo’s 2018 pledge to take full responsibility for AV accidents, and Tesla’s in-house insurance program bundled with its vehicles.
  • Appealing because the manufacturer has both the knowledge to price accurately and an interest in protecting customers, correcting information asymmetries in the insurer’s favor.
  • Critique: despite its advantages, this scheme risks adverse selection, diminished bargaining power for the customer (who may lack a real choice between vendors), and logistical problems of manufacturers acting as insurers (including the need to spread risk across a large enough insured pool, which single-manufacturer schemes may lack). Large manufacturers may also lack economic incentive to buy outside insurance at all, since risk-neutral companies like this can more cheaply self-insure.

3. The UK Automated and Electric Vehicles Act and Germany’s Road Traffic Act amendment

  • UK’s Automated and Electric Vehicles Act (2018) extends the existing compulsory motor insurance scheme to cover autonomous vehicles: if an accident is caused by an insured AV, the insurer is liable; if uninsured, the owner is liable. As a coercive/mandatory scheme, it ensures every UK driver (human or autonomous) carries insurance, widening the overall safety net.
  • Critique: the scheme assumes the insured party can modulate risky behavior to earn lower premiums, but this fails where the “operator” of an AV has no actual control over the driving process. Scholarly critique (James Davey) argues the Act is more concerned with protecting motor insurance as a mass-market product than establishing a genuinely workable AV liability system, reflecting private-insurer interest-group influence.
  • Germany’s 2021 amendment to its Road Traffic Act and Compulsory Insurance Act requires insurance when a vehicle operates with “technical supervision” (a person able to deactivate/release autonomous driving functions remotely). This focuses on the supervising human rather than the vehicle as a whole — a reasonable starting point but one that fails to grapple with the full complexity AVs present.

4. Manufacturer Enterprise Responsibility (“MER”) for Autonomous Vehicles (Abraham & Rabin)

  • Proposal: once autonomous vehicles reach 25% of registered vehicles (SAE level 4/5 automation), auto manufacturers should become strictly responsible for all injuries arising from AV operation, via a manufacturer-financed fund providing automatic bodily-injury compensation up to a benefit limit (excluding harms from the owner’s own negligence, and excluding property damage, which stays under conventional insurance). This would be the exclusive remedy for victims, displacing tort claims.
  • MER would be financed via third-party (manufacturer) liability rather than first-party (owner/victim-purchased) insurance, since manufacturers control vehicle design and are best positioned to build safer vehicles — shifting focus from the driver to the vehicle itself as the proper subject of underwriting.
  • Critique from Ryan Calo: the proposal assumes AVs will be privately owned, but they may instead be owned by manufacturers and deployed as a transportation resource (i.e., “the authors’ proposal is certain; the future is not”), which would make MER inapplicable. Abraham and Rabin’s response: inaction is not the appropriate path given how consequential the alternative (doing nothing about AV liability law) would be. The article calls MER “brilliant and meticulous” as the first comprehensive theoretical proposal for how tort law and insurance could intersect for AVs, even while flagging Calo’s ownership-model critique as a live concern.

5. National Insurance Fund for Autonomous Vehicles (Schroll)

  • Proposes eliminating AV accident liability altogether and replacing it with a national insurance fund, premised on a future where most AVs are provided by third parties (e.g., Uber, Google, LG) rather than privately owned — again shifting from driver-focused to vehicle/provider-focused insurance.
  • The fund would be paid for via taxes on riders, car-sharing companies, and manufacturers, proportional to how much each benefits from AV use.
  • The article notes existing national accident funds (e.g., Israel) function as complementary funds for cases where the liable party cannot be identified (hit-and-run, stolen vehicles) — not as sole/exclusive remedies.
  • Critique: as a sole/stand-alone solution, a national fund has two major drawbacks — high administrative costs, and (more importantly) reduced deterrence because splitting costs across all parties fails to properly allocate incentives to prevent harm ex ante. Federal/social-insurance-style funds are usually justified for activities of major, undisputed social value (vaccines, Social Security/Medicare) — while AVs specifically may have this social value as the primary means of transport, it’s unclear that AI entities in general fit this category. Similarly, federal/state reinsurance programs (as exist for nuclear accidents or terrorism) are not currently justified in the AI context because AI’s societal-scale effects remain unknown, unlike nuclear or terrorism risk — though such a scheme could become necessary later if combined with a compensation cap.

6. European Parliament Compensation Fund

  • The European Parliament’s 2017 Report with Recommendations to the Commission on Civil Law Rules on Robotics (Section 59) proposes insurance principles for AI/robots, including a compulsory insurance scheme for specific robot categories and a compensation fund.
  • Section 59(b): a compensation fund would guarantee compensation for robot-caused damage not covered by insurance.
  • Section 59(c): manufacturers, programmers, owners, or users could benefit from limited liability if they contribute to a compensation fund or jointly purchase insurance to guarantee compensation. Critique: this tradeoff risks lessening incentives to proactively minimize risk, since it effectively offers a safe harbor (de facto immunity) in exchange for a fund contribution or joint insurance purchase, rather than incentivizing genuinely safer AI development.
  • Section 59(d): considers whether to create one general fund for all “smart autonomous robots” or individualized funds per robot category, and whether contributions should be a one-off market-entry fee or ongoing periodic payments. The article favors individualized, category-specific funds (since damages from different AI types, e.g., AVs vs. hiring algorithms, are not comparable, and a single general fund would fail to properly incentivize safety or create profitable risk pools) and favors periodic/ongoing contributions over one-off fees, since AI entities evolve continuously via software updates.
  • Section 59(e): proposes an individual registration number for every robot, informing anyone interacting with it about the fund’s nature, liability limits, and contributors — echoing Karnow’s Turing Registry. Such registration could make a fund operate more efficiently by keeping victims informed, but should not be a stand-alone solution since it risks weakening incentives to improve safety over time.
  • Overall conclusion on the six proposals: the current infrastructure is the best starting point for these new technologies, with adjustments to auto and other AI-based insurance made as new data accumulates; abolishing tort law altogether via a stand-alone insurance scheme (social insurance, federal fund, or otherwise) is unwarranted and drastic.

Insurance as a Civil Remedy for AI Damages

The Disadvantages

1. Moral Hazards and Insurance

  • Moral hazard — insurance reducing insureds’ incentive to prevent harm since they won’t bear the full cost — is insurance’s most prominent counterargument, and was historically viewed as a public-policy violation in the nineteenth century (“less is more”).
  • The article argues moral hazard theory ignores several points: money cannot compensate for every loss (e.g., bodily/emotional injury); external factors (e.g., a badly paved road) are often outside a policyholder’s control; malicious or wanton conduct is typically excluded from coverage, reducing insureds’ incentive to act recklessly.
  • Moral hazard arguments have also historically been used to place the burden of accident prevention on the weaker/individual party (consumer, worker) rather than the more powerful party (manufacturer, employer) who is often better positioned to reduce loss — a framing that is not always socially or economically desirable.
  • AI-specific concern: because AI risks are more unpredictable than traditional insured risks (auto, health, travel), moral hazard could encourage AI manufacturers/users/operators to experiment recklessly, assuming damages will be covered regardless of their conduct — but this assumption is incorrect once exclusions and safety conditions are built into policies (see “Exceptions and Exclusions” below).
  • Moral hazard is not unique to AI and arises with every new technology; it should not be a reason to forgo insurance but is mitigated in practice because insurers are financially incentivized to encourage insureds to avoid reckless behavior (fewer accidents = more profit).

2. The Lack of a Global Adoption of Insurance in the AI Context

  • Critique (Rachum-Twaig): because AI entities will be ubiquitous and cross national borders, and because a uniform global insurance guideline is politically impractical, a no-fault insurance model cannot serve as a general global solution to AI liability.
  • The article’s response: this does not disqualify insurance’s use in the AI context. Automobile insurance already functions across borders for non-autonomous cars and rental cars; most AI entities today are narrowly created for specific tasks; conflicts of laws between countries have not historically stopped international trade or the insurance industry from operating globally; and mandatory no-fault insurance is meant to be complementary to, not a full replacement for, the tort system. Thus the lack of a global standard is not sufficient reason to abandon an insurance regime for AI, mandatory or otherwise.

3. Cost Allocation and Premium Estimation

  • Setting accurate AI premiums and determining who should bear costs is difficult because information about the probability and severity of AI-inflicted harm is severely lacking — the pool of data is too shallow and narrow.

a. Known Unknowns

  • AI accidents can be framed as “known unknowns” — contingencies known to exist but to which insurers cannot yet actuarially assign a probability or magnitude — similar to terrorism insurance, which remains infeasible in the U.S. because there isn’t yet enough actuarial data on frequency to price and redistribute the risk in a pool.
  • The article argues AI does not belong in the same category as terrorism/nuclear risk: AI entities more closely resemble car or workplace accidents in scope; AI-caused damages are likely to be more frequent but more limited in scope than catastrophic terrorism-scale events; and while the exact timing/magnitude of an individual AI-caused loss can’t be predicted, there is far more statistical information about the general likelihood of AI causing harm than for genuinely uncertain, catastrophic risks — meaning AI risk is better framed as a manageable “risk” than a true, uninsurable “uncertainty.”
  • On government’s role: once AI-inflicted damages exceed a predetermined cap, it’s reasonable to expect government to step in (as with nuclear or chemical catastrophes), especially given publicly stated U.S. government interest in advancing AI. But the possibility of rare catastrophic incidents needing government backstop is not itself a reason the insurance industry cannot manage everyday AI-related harms.

b. The Feasibility of Insurance in the AI Market

  • Before insurers can price a risk, they must answer three questions: how much reserve is needed for expected future losses; how much to charge in premiums given that reserve; and how much capital must be available to remain solvent in a worst-case scenario. The first two are answered via actuarial science; true uncertainty (as with terrorism) makes all three hard to answer, but the article again argues AI accidents are not true uncertainties given AI’s distinct traits and market position.
  • Insurers must evaluate three components of insurability: calculation, distribution, and profitability.
    • Calculation: because most AI commercial products substitute for products/activities already on the market (e.g., a robot security guard for a human guard), insurers already possess baseline risk information from these prior human-performed activities. AI is widely assumed to be safer than the humans/products it replaces (a chief justification for adopting AI, e.g., safer driving via AVs), so premiums — initially high due to imperfect calculability — should decrease over time as insurers gather more data, similar to how premiums adjust for other newly introduced risks (e.g., COVID-era travel insurance). Early adopters of AI, like early adopters of other disruptive technologies historically, will pay higher premiums for their willingness to take on more risk.
    • Distribution: insurers must be confident they can distribute/spread a risk across a large enough pool. Insurers already established in fields like auto or professional liability insurance can incorporate AI into their existing pools (e.g., auto insurers grouping AV owners with owners of conventional vehicles) and eventually create AI-specific sub-pools once enough data and volume exist. Because AI damages vary widely by context, there is no one-size-fits-all AI policy — specialized, pre-existing categories of insurance are best positioned to issue tailored AI coverage. A caveat is the risk of catastrophic/aggregated harm from many AI entities sharing a common underlying technology (the issue that has hampered the cyber-insurance market, where many companies share the same online platforms) — though this is considered less severe for AI than for cyber risk because AI entities operate on more varied platforms and functions, and can be mitigated by manufacturers diversifying/protecting their platforms.
    • Profitability: even if the first two elements are met, a market needs profitability to sustain coverage (absent government subsidy). The article argues profitability should not be a problem for insuring AI given the large existing profitable market for the human activities and products (truck drivers, security guards, lawyers, doctors) that AI is expected to replace — demand for coverage (by users or manufacturers) will exist to ensure safe deployment, sustaining insurer profit even while premiums remain high early on.
  • On who should purchase the policy: this should be determined based on which entity insurance data proves is best positioned to purchase and bear the cost — the article’s own view (elaborated in Part VI) favors manufacturers, but notes this could shift over time as more information is gathered.

4. Exceptions and Exclusions

  • A further potential disadvantage: insurers’ ability to exclude coverage for certain activities, such as deliberate/willful damage-causing acts, or (per Turner) AI activity that falls “outside a set range” (e.g., a delivery robot used for something other than delivery). If insurers exclude any instance where an AI acted outside its set range, this could render coverage functionally inapplicable to most accidents, since abnormal AI action is common in accident scenarios.
  • However, insurers seeking profit have an incentive to reduce such exclusions over time as they gather more information about how AI is actually used, in order to offer marketable and useful policies.
  • Exceptions/exclusions are not necessarily a disadvantage — they can function as a tool insurers use to channel policyholder behavior, by signaling which activities are not covered and thus discouraging them.
  • Exclusions can be “silent” (unforeseen risks simply not mentioned in a policy) rather than affirmative; this has historically been the pattern with cyber insurance, where new/uncovered risks were gradually excluded from traditional policies and covered instead via specialized cyber policies or “riders.” The article predicts this same process will occur for AI: as new AI-related harms emerge, insurers will progressively exclude them from traditional policies, prompting demand for AI-specific riders — a process that clarifies risk allocation and legal certainty for both insurers and insureds over time.

The Advantages

1. Regulation by Liability Insurance: Behavior Channeling

  • Insurance policies inherently exert a behavior-channeling effect on insureds, giving insurers a quasi-regulatory role — what Kenneth Abraham calls the “governance conception” of insurance, where insurance functions like government by influencing policyholder conduct and protecting them against misfortune, acting as a surrogate for government regulation.
  • Caveat/caution flagged by the article: recent empirical literature suggests the governance conception of insurance “still has a long way to go” — while the theoretical framework is sound, empirical work shows insurers often lack the incentive and capability to actually transform these tools into effective governance mechanisms in practice. The article’s discussion of insurance’s regulatory tools should be read with this caution in mind; more nuanced empirical research is needed on the conditions under which insurers can “make positive regulatory interventions,” including in the AI context specifically.
  • The article discusses several tools insurers use (or could use) to channel AI policyholder behavior:
    • Liability caps: limiting the amount an insurer will pay per accident (e.g., Connecticut’s mandatory auto minimums of $25,000 per person / $50,000 per accident). Caps incentivize insureds to internalize that risky conduct carries real monetary consequences beyond the cap, and reduce moral hazard since insureds know damages above the cap come from their own pocket. A cap on AI-related damages could similarly incentivize large tech manufacturers to act more safely, though this could leave victims facing insolvent tortfeasors for damages exceeding the cap.
    • Risk-based pricing: tailored premiums based on the insured’s own risk factors, incentivizing insureds to reduce their exposure to future higher premiums. This is a useful channeling tool as long as the proxies used are within the insured’s control; AI-driven risk-based pricing risks producing biased/discriminatory results when it relies on proxies (e.g., gender, race) the insured cannot control, in which case the channeling mechanism breaks down. “Experience rating” (adjusting premiums post-sale based on the specific insured’s track record) is a related tool that further signals which safety measures reduce costs.
    • Underwriting: the process of deciding which risks to insure and at what price; distinct from pricing because it also lets insurers share loss-prevention information with insureds. This is a “softer” tool than risk-based pricing (no immediate monetary penalty for ignoring the advice) but may be especially valuable for AI given insureds’ need for guidance navigating this new and unpredictable field.
    • Contract design (deductibles, coinsurance, exclusions): mechanisms that ensure the insured has some of their own money at stake, reducing moral hazard. In the AI context, some insurers may simply exclude AI entities from coverage altogether given unpredictability and cost-calculation difficulties — but the article argues this should not justify wholesale rejection of insuring AI, since all new technologies are initially dangerous/unpredictable to some degree; particular AI activities may be excluded at first, with coverage expanding as more data is gathered.
    • Claims management: an ex post tool giving insurers (rather than insureds) exclusive authority to defend/settle claims, letting insurers control litigation costs and gather information about liability risks useful for future pricing, underwriting, and loss-prevention advice — important for future AI claims given insurers’ relevant expertise advantage.
    • Loss prevention services: using data gathered through the above tools to identify and disseminate the “best ways to reduce risk of loss” to insureds — potentially the most direct/valuable channeling mechanism in a field like AI where reliable information is especially scarce and desired.
    • Nontraditional/unconventional tools (Ben-Shahar & Logue): private safety codes (insurers enforcing safety standards exceeding government requirements, e.g., subsidizing anti-theft or anti-virus technology) — though empirical literature (particularly in employment law) shows such internally designed grievance/safety structures don’t always work as planned and can become symbolic or “captured” by the very organizations they’re meant to improve, so private safety codes should be treated with some skepticism and monitored over time; and research/education and engagement with public regulation (a “trickle effect” from private insurers to public regulators — e.g., airbag and seatbelt regulations originated as insurer-driven private practices before becoming law), which could similarly shape future written AI safety law.
    • The insurance industry’s regulatory effectiveness rests on having superior information relative to government regulators; this is not yet obviously true for AI specifically, but the article argues insurers can obtain such information more quickly and efficiently than other actors as the AI market matures.

2. Questions of Liability and Predictability

  • Building on existing insurance infrastructure helps avoid legal dilemmas of liability and blame-placing by making it predictable who (the policyholder) will pay damages, largely bypassing the near-impossible task of establishing a direct causal link between AI-caused damage and a specific liable human party given the black-box problem. This does not resolve underlying legal difficulties like AI personhood or foreseeability, but it ensures victims are not left uncompensated regardless of how those questions are eventually answered.
  • Insurance also provides a partial solution to AI’s unpredictability by letting risk-averse parties pass the cost of harm to insurers for a fixed price, allowing planning under uncertainty even though it doesn’t resolve the underlying cost-allocation/premium-estimation challenges. Society and policyholders alike benefit from insurers absorbing the initial burden of insuring AI activities while the scope of AI-inflicted harm is not yet fully clear — insurers have an incentive to do so, since in the process they gather valuable data that lets them refine premiums and terms.
  • Example given: a 2016 incident where a robot security guard ran over a toddler at a California shopping mall — as more such incidents accumulate, insurers gain the data needed to set accurate premiums for both first parties (e.g., the robot company) and third parties (e.g., the mall employing the robot), creating a reinforcing loop that improves AI insurability over time without stalling AI development.

Potential Liability Barriers and the Role of Insurance

1. Joint Causation

  • When an AI entity acts entirely alone (e.g., a fully autonomous vehicle, an autonomous security robot, a hiring algorithm using predefined proxies), causal ambiguity is generally not an issue.
  • The harder case is when an AI entity works in conjunction with a human — e.g., a doctor relying on AI diagnostic tools, a lawyer using AI-assisted software, or an investment consultant using an algorithmic recommendation — where it may be nonobvious how much the AI’s involvement contributed to resulting harm. These joint human-AI scenarios will multiply as AI becomes further embedded in commercial and social life.
  • Such scenarios are potentially problematic for insurance where a policy doesn’t cover damage the AI didn’t solely cause, and the traditional “substantial factor” causation test is hard to apply given the black-box’s opacity as to the AI’s actual contribution.
  • The article argues insurance is not powerless here: professionals who cooperate with AI entities (accountants, lawyers, physicians) typically already hold their own professional liability insurance policies regardless of whether AI is involved, and these policies should cover joint-causation damages because AI can be seen as a foreseeable “intervening cause” — and even if AI isn’t deemed foreseeable, the type of consequences it causes usually are, meaning the human cooperator will be held liable or partially liable under existing policies, with victims compensated through that professional’s insurance. As more human-AI joint-causation damages arise, insurers may respond by explicitly excluding such coverage from traditional policies, which would in turn create demand for new specialized riders — again illustrating insurance’s capacity to evolve to cover foreseeable-but-legally-tricky types of damage.

2. Hacking AI Entities

  • Most AI entities are internet-connected and thus vulnerable to malicious third-party hacking, which can make it difficult to identify and seek redress from the actual wrongdoer, leaving liability uncertain.
  • The article argues that, building on cyber-insurance’s treatment of data breaches, the manufacturer of a hacked AI entity should generally be viewed as liable for resulting damages, since there is an expectation manufacturers will safeguard their AI from hackers and proactively fix vulnerabilities — the manufacturer’s tort obligations are said to encompass the AI entity’s cybersecurity. Hackers, especially of critical infrastructure that is a known target, can be characterized as a foreseeable intervening cause.
  • While holding manufacturers liable for hacking incidents is reasonable, it risks stifling innovation if companies fear boundless liability from an emerging technology in an ongoing “cyber arms race.” Insurance helps alleviate this fear: today’s cybersecurity insurance market already offers broad protection to companies defending against liability claims from malicious hacks, and manufacturers/distributors of AI entities can and should purchase such policies to hedge hacking risk — allowing continued AI development while giving insurers a lever to incentivize better proactive cybersecurity practices among AI companies.
  • Terrorism is flagged as a likely exception, since terrorism insurance remains more difficult to issue, but the article treats such cases as a small, government-handled subset falling outside the commercial focus of the article.

A Proposal for Insurance in the AI Realm

Building Upon Existing Infrastructure

  • The type of insurance for a given AI entity should depend on the type of AI, the activity it performs, its unique features and associated risks, and the identity of the insured — including whether coverage should be a first-party or third-party policy.
  • The article’s preferred baseline: a liability insurance policy purchased by the companies manufacturing or distributing AI to the public is preferable at this stage, given manufacturers’ superior ability to minimize damages (as the “pressure point” with the most control over safety, akin to MER’s logic for AVs).
  • Certain insurance regimes (auto, professional liability) are coercive/mandatory in most U.S. states, obligating one side of a potentially harmful relationship to carry minimum coverage before engaging in the covered activity — this benefits the broader community of participants by creating “more coverage for more people,” spreading risk more broadly, protecting bystanders as well as the insured party, and avoiding market failure from an insolvent liable party.
  • However, legislatures are unlikely to (and should not) mandate insurance for every AI entity — doing so would be overbroad, invasive, and inefficient. Whether insurance should be voluntary or mandatory should instead turn on the type of AI and activity involved:
    • For particularly dangerous but essential AI activities, or those risking serious market failure, insurance should be mandatory.
    • Existing mandatory insurance obligations should remain mandatory even once the covered activity is handed over to an AI entity (e.g., driving).
    • Low-risk AI entities, such as a Roomba vacuum cleaner, should not be subject to a mandatory coercive insurance policy, given the comparatively low likelihood and severity of resulting harm relative to something like an AV.
    • While the article does not support mandatory insurance for all AI entities, it anticipates that most businesses using AI with a significant public effect will, as a practical matter, purchase liability insurance anyway to hedge against likely future lawsuits.
  • On who should purchase the policy: the article argues the burden should initially fall on the manufacturing/distributing side of the AI transaction (not the consumer/user side via a first-party policy), since manufacturers and distributors are the best “pressure point” to ensure safer AI research and development practices — without preventing consumers from separately purchasing their own first-party coverage if desired. In the AV context specifically, shifting the initial insurance-purchasing burden to manufacturers (rather than consumers, who have little control over an autonomous vehicle’s operation) makes particular sense, since placing the burden on a party with no behavioral control would blunt insurance’s ability to regulate conduct or mitigate moral hazard.
  • The identity of the appropriate “pressure point” party may evolve over time as the AI landscape changes; the insurance industry is best suited among institutions to monitor and adapt to this evolution given its ongoing data collection and its ability to implement change faster than the traditional tort system.
  • The EU Report on Robotics’ suggestion of a compulsory insurance scheme “where relevant and necessary” for specific robot categories is endorsed in principle — the article argues such compulsory policies are relevant and necessary specifically when needed to prevent market failure or to ensure a beneficial activity remains accessible to all (as with cars, which the EU Report itself already treats as warranting a compulsory scheme, paralleling the UK’s Automated and Electric Vehicles Act).
  • Overall conclusion of this section: given current uncertainty about AI, the most logical path is to start with existing insurance infrastructure rather than build a novel AI-specific scheme, since regulators and insurers currently lack the knowledge, resources, and time to construct new policies before AI becomes further integrated into commercial and personal life. Policies should not be fixed in place — insurers are well-suited to adjust caps, risk-based pricing, deductibles, co-pays, etc. as more data accumulates, and this should mean building on and updating existing coverage and riders rather than creating a wholly new class of “AI policies.”

What About the Singularity?

  • A further complication arises if AI technology advances to the point of “the singularity” — strong/general AI exhibiting sentience or consciousness, capable of a wide variety of cross-domain activities at or beyond human-level performance, or able to self-improve its own general cognitive abilities. The article notes the singularity would likely manifest not as a dramatic “Skynet”-style event but as a fully capable AI entity that, for practical/legal purposes, operates similarly to a human being — raising novel questions about what type of “subject” and “policyholder” such an entity would represent for insurance purposes.
  • If/when the singularity occurs, simply building on existing insurance infrastructure would not suffice, since there are no general AI policies capable of offering such broad coverage, and the risks posed by strong AI would themselves be “unknown unknowns” — even the general types of risk and the way they’ll manifest are unknown, unlike the more moderate “known unknowns” framing used earlier in the article for near-term AI risk.
  • The article outlines three possible alternative approaches for this scenario:
    1. Insurers accumulate specific policies covering specific activities the superintelligent AI performs, treating it similarly to a human purchasing individual policies for particular activities — but this approach may not suffice for genuinely novel kinds of risk that strong AI could introduce.
    2. A registry paired with a general compensation fund, tracking these new entities and ensuring the right parties (developers, users, or even the strong AI entities themselves, if they hold legal personhood) contribute proportionally to the fund.
    3. A coercive/mandatory insurance scheme imposed on strong AI entities — complicated by uncertainty over whether such entities would have the solvency or a solvent backing party to fund such a scheme.
  • The article treats the singularity as still largely theoretical and likely decades away, if it ever occurs, but argues this remote possibility should not render insurance as an instrument obsolete for near-term AI regulation. An AI superintelligence would likely create a market failure given the inherent insolvency risk of strong AI entities, at least initially; coercive insurance or a mandatory registry paired with a compensation fund could help address that failure, provided such schemes clearly designate a solvent party (not the strong AI entity itself) responsible for purchasing the policy or contributing to the fund. At its core, insurance aims to mitigate risk of damage for the right price, and the article argues it could do so even in a post-singularity context.

Conclusion

  • Insurance has a vital role in both adopting and regulating emerging technologies like AI: it offers a hedging tool that translates AI’s many risks into a manageable scope, facilitating AI’s adoption into the commercial market.
  • Given the unknown potential risks AI may inflict on users and third parties, premiums offered to manufacturers purchasing liability insurance are likely to be high at first, but should decrease as AI entities become safer, more explainable, and more predictable, or at least once enough data has been gathered for accurate actuarial calculations — meaning coverage may not be accessible to all AI companies or users at first, but should become available to all who wish to hedge their participation in the AI market over time, as has happened with other emerging technologies historically.
  • The assessment of AI-related risk will evolve, and the existing insurance infrastructure provides a solid starting point for managing activities that were once conducted by humans and are now performed by AI entities — most human activities already carry some catastrophic-risk exposure that insurers already cover, and insurers retain the ability to exclude specific AI frameworks (such as AI used in war or terrorism) that fall outside the commercial context that is this article’s focus.
  • As with other life-threatening activities society continues to permit given assumed aggregate social utility, AI use is predicted to keep expanding and becoming integrated into daily life, inevitably producing new and sometimes novel types of harm. While insurance as a regulatory instrument has flaws, it has nonetheless proven a valuable tool for facilitating emerging technologies historically.
  • The specific design elements of AI insurance policies (caps, deductibles, exceptions, etc.) should be left to actuaries and insurance companies to work out, rather than being dictated by legislators or courts in the first instance. Insurers also have a strong profit incentive to offer such policies to a fast-growing industry expected to become an inseparable part of daily life. The article closes by arguing that elevating discussion of AI insurance will allow different stakeholders — regulators, insurers, AI companies, and scholars — to further unlock AI’s power and potential for society.