Why Liability and Insurance Won’t Save AI: Lessons From Cyber Insurance
Core claim
Imposing legal liability on AI developers — a popular policy proposal — will not meaningfully improve AI safety, because liability insurers will be unable to price coverage based on genuine risk assessment and will instead rely on crude proxies like firm size and industry sector, sending no signal that rewards safety investment. Standfirst: “Holding AI developers responsible for any harm their systems cause may not be the most effective path to promoting AI safety.”
Context
- The piece opens with California’s 2024 SB 1047, which would have imposed liability on some AI companies for model-related harms; Governor Newsom vetoed it, but proponents argued liability was “the best way to force AI companies to make their machine learning models safer.”
- The authors say this view is widespread among policymakers, but argue the history of the cyber insurance market offers cautionary lessons about how well liability actually works in practice.
The core argument
- Liability insurers covering AI harms will end up basing premiums on “crude measures such as firm size and industry sector” rather than on a firm’s actual safety practices.
- This keeps insurers solvent but fails to create any economic incentive for real safety improvements, because refined, risk-based pricing is extremely difficult in AI: historical loss data is limited and rapidly outdated, and assessing an individual firm’s AI safety requires specialized expertise most insurers lack.
Precedent: how cyber insurance developed
- Cyber insurance traces to 2002, when California’s SB 1386 data-breach notification law created new legal liability exposure, prompting companies to seek coverage. The market subsequently expanded to cover data breaches, denial-of-service attacks, ransomware, and regulatory investigations.
- Insurers asked companies to complete questionnaires about their security practices and sometimes required specific controls (e.g., multi-factor authentication), but struggled to verify proper implementation or to identify which controls actually mattered.
- A 2012 Department of Homeland Security roundtable hoped cyber insurance would push companies toward security best practices via premium incentives, the way fire insurance encouraged smoke-detector installation — “it didn’t happen.” Despite market growth, the industry never identified best practices or offered meaningful discounts for adopting them, leaving an industry that helps firms cover incident costs and avoid liability but does “little to actually strengthen their cybersecurity.”
Three challenges that stopped cyber insurers from improving security
- Data limitations — cyber incidents often go unreported outside legally mandated cases (like breaches), and sophisticated adversaries adapt their tactics in response to defenses, making historical data unreliable for prediction. The 2019–2020 ransomware spike caught insurers by surprise, driving steep premium increases and exposing how little they understood actual risk.
- Assessment complexity — complex systems with many software and hardware components make vulnerabilities extraordinarily hard to identify. Rather than in-depth technical assessment, insurers rely on questionnaires (e.g., about encryption or multi-factor authentication) that cannot capture implementation nuance — a company might encrypt data poorly or forget to enable multi-factor authentication on legacy accounts. Most insurers end up pricing coverage based on revenue and industry sector rather than tying it to security practices, which negates any incentive effect.
- Catastrophic risk concentration — insurers normally diversify across geography and sector to limit correlated losses, but cybersecurity risk defies this because most companies rely on the same handful of operating systems and cloud providers; a single vulnerability in Windows or AWS can hit huge numbers of policyholders simultaneously. Insurers have repeatedly sought a federal catastrophic cyber-risk backstop, and many now exclude certain risks (state-sponsored attacks, critical-infrastructure attacks) from coverage.
AI insurance would face the same three problems
- Data scarcity — very little data exists on actual AI harms; what is available comes from voluntary public reports, presumably a small fraction of real incidents since companies have reason to hide failures, and is “nonrepresentative” because it mostly captures harms too visible to conceal — limiting what can be concluded about prevention.
- Assessment complexity — evaluating AI system safety and security is “even harder and more technologically complex” than cybersecurity assessment. A cited 2025 Accenture survey found only 20 percent of companies confident in securing generative AI against cyber risk; a cited 2025 IBM study found 13 percent of companies had experienced an AI model or application breach, with 97 percent lacking access controls on those systems. Even AI developers themselves — the piece cites OpenAI’s Sam Altman — acknowledge they cannot guarantee full safety against serious threats.
- Concentration risk — AI is a highly concentrated industry in which a small number of large companies provide the foundation models most organizations rely on, so a vulnerability in a widely used model could rapidly affect a large share of an insurer’s customer base.
Where AI risk differs from cyber risk
- AI harms can arise from accidental malfunction as well as deliberate attack, whereas cybersecurity incidents are almost always intentional; in principle this could make AI risk easier to model, but the pace of AI development makes that unlikely except in narrowly defined domains. Narrow “performance guarantee” insurance products already exist but address only a limited slice of AI safety risk.
- AI risk is also more dispersed across different insurance lines than cyber risk, which may make it harder for insurers to build focused AI expertise.
Conclusions and recommendations
- The authors conclude that “AI liability and the resulting insurance market are extremely unlikely to produce meaningful results” for AI safety, and argue that ex ante regulation is “the only viable path to changing how companies safeguard their AI models,” while acknowledging that regulation will face similar difficulties.
- They recommend regulators “start experimenting with regulations that require companies to report on AI harms and to perform audits and tests early on, rather than waiting for the insurance industry to handle this problem.”
- As a cautionary parallel, they note it took roughly two decades from California’s SB 1386 (2002) to the 2022 Cyber Incident Reporting for Critical Infrastructure Act, and warn it would be “wise to begin that process for AI now, rather than wasting another decade hoping that insurance will save us.”
About the authors
- Daniel Schwarcz and Josephine Wolff are the authors; published as an article/opinion piece in Lawfare.