Silent Exposure, Broken Data: AI Liability Arrives as Insurance Scrambles to Catch Up
WTW's latest research confirms what many in the market have suspected: AI liability is no longer theoretical, coverage language hasn't kept pace with actual exposure, and the data infrastructure most insurers are building on may not be fit for what's coming.
38 of 100 — cautious. Coverage language for AI liability is still catching up to actual exposure, and the underlying data infrastructure many insurers depend on isn't built for what's coming. Expect this gap to surface at claim time rather than underwriting time.
When the Incident Surge Hits the Policy Language: WTW Warns of Silent AI Exposure Across Lines
A new report from WTW’s Willis Research Network is one of the more comprehensive treatments of AI liability the industry has seen, and its central warning is hard to dismiss. AI-related incidents rose approximately 50 percent year over year from 2022 to 2024, with 2025 incident totals exceeding 2024’s full-year count before the year ended. The report does not frame AI as a standalone peril. It frames it as a risk amplifier sitting inside existing lines, and draws an explicit comparison to how silent cyber exposure evolved before 2019, when ambiguous policy language produced unintended coverage once claims and litigation forced interpretation. WTW calls this the “silent AI” problem, noting that AI-related losses can sit embedded across multiple lines and many insureds simultaneously, invisible until a claim forces interpretation.
The report maps AI risk into four overlapping categories: performance risk, misuse risk, governance risk, and systemic risk. Of these, systemic risk draws the starkest concern. Shared dependencies on a small number of models, vendors, or infrastructure providers could trigger losses across thousands of insureds and multiple lines simultaneously, undermining the diversification assumptions that underpin reinsurance. That accumulation dynamic is not well-modeled anywhere in the market yet.
The liability pathway analysis breaks down by claim type. Physical harm claims from AI in autonomous vehicles, industrial systems, or medical devices are largely being routed through traditional negligence and product liability frameworks. Financial harm claims are more contested, with attribution disputes surfacing across model developers, data providers, system integrators, and end users, landing across tech E&O, professional indemnity, and D&O simultaneously.
The report also includes findings from a joint study with Rutgers Business School that evaluated eight leading large language models across six governance dimensions. No system tested met the researchers’ threshold for adequate data protection, with privacy gaps widespread across consumer-tier offerings and governance scores varying significantly based on whether formal third-party audit processes were in place. The non-deterministic behavior finding is particularly relevant for regulated use cases: identical prompts can produce different outputs across runs, complicating validation in underwriting and claims contexts. For risk managers, the takeaway is straightforward. Organizations accumulating AI exposure across multiple lines, often without explicit policy language to address it, are sitting on a liability position that may not be visible until litigation clarifies the coverage question.
— R&I Editorial Team at Risk & Insurance
URL: https://riskandinsurance.com/ai-risk-is-here-and-insurers-are-learning-to-write-the-rules/
Policy Language Is the Battleground: D&O and E&O Carriers Work to Define What They’re Actually Insuring
If the WTW report establishes the scope of the problem, this Risk & Insurance feature examines how carriers are trying to respond to it in real time. The picture is one of genuine market complexity, with carriers moving at different speeds, using different definitional frameworks, and arriving at different conclusions about where AI risk fits within their existing product architecture.
The definitional challenge is foundational. Munich Re and HSB have moved toward broad affirmative coverage, defining AI as any statistical model that produces an output or takes an autonomous action, a definition intended to capture machine learning, generative AI, and agentic systems under a single framework. That approach reflects a deliberate effort to avoid the silent exposure problem by making coverage intent explicit. Other carriers are taking a coordination approach, rationalizing terms across GL, D&O, cyber, and crime to ensure that AI-related losses don’t fall into gaps between policies or produce overlapping triggers.
The E&O distinction between AI-enabled services and AI product development is emerging as a core underwriting question. Carriers are increasingly treating AI embedded in professional services as a service error rather than a product failure, meaning hallucinations and model inaccuracies delivered as part of a fee-based service can be addressed under existing professional services language. That framing holds until AI systems move from tool to autonomous decision-maker, where the agentic AI problem introduces liability dynamics that existing language wasn’t built to handle.
On the D&O side, AI washing is the exposure that practitioners are watching most closely. Carriers and practitioners are drawing parallels to pharmaceutical companies that overstated COVID response capabilities and subsequently faced securities litigation, with companies now promoting AI-driven revenue projections that may not be grounded in tested performance. Board-level disclosure is a growing compliance obligation, with 72 percent of public companies having disclosed AI risks in their 2025 10-K filings. The 28 percent that have not are sitting in the highest-risk position as regulatory scrutiny and plaintiff litigation capacity both increase. Underwriters are now asking detailed questions about data sourcing, privacy controls, and human-in-the-loop protocols during renewals, with governance transparency becoming a material underwriting factor.
— Elisa Ludwig at Risk and Insurance
URL: [could not verify — please add manually]
AI Can’t Scale on Broken Foundations: Why Insurance’s Data Problem Is the Real Transformation
The operational diagnosis is familiar but the stakes are now higher. Insurance organizations have operated for decades with fragmented systems, siloed business units, inconsistent data formats, and legacy infrastructures. AI requires something fundamentally different: trusted, connected, high-quality data ecosystems capable of supporting real-time analytics and intelligent automation at scale. The report’s framing is direct: AI is not creating new data problems in insurance. It is exposing existing ones.
The underwriting implications are concrete. Predictive models, automated enrichment, and risk selection tools all require seamless access to structured, interoperable datasets across policy and claims systems. Without connected data environments, AI workflows become fragmented and manual, and automation initiatives cannot scale efficiently across the enterprise. For carriers expanding partnerships with insurtechs or deploying API-driven operating models, fragmented legacy environments create integration friction that compounds at every connection point.
The governance angle connects directly to the liability discussion running through this week’s other coverage. Insurance organizations must be able to explain how AI-driven decisions are made, what data influenced those outcomes, and whether systems remain compliant and defensible. Governance is becoming a foundational requirement for scaling AI responsibly, not simply a compliance exercise. For carriers facing regulatory scrutiny on underwriting models and risk managers being asked to document AI controls that could survive an independent audit, the readiness gap identified in this report is not abstract. Organizations that cannot explain their AI outputs to a regulator or a plaintiff’s attorney are facing the same exposure from a different direction.
— Carrier Management Team at Carrier Management
URL: https://www.carriermanagement.com/news/2026/06/03/288586.htm
This Week’s TL;DR
The clearest signal from this week’s coverage is that AI liability in insurance has stopped being a forward-looking concern and started generating present-tense exposure. WTW’s Willis Research Network documented a roughly 50 percent year-over-year rise in AI-related incidents from 2022 to 2024, with 2025 totals outpacing the prior full year before it closed. The more structurally significant finding is that most of this exposure is accumulating silently inside existing GL, professional indemnity, cyber, EPLI, and D&O policies, in policy language that was never written to address AI. WTW draws the comparison to silent cyber before 2019 explicitly, and the parallel is uncomfortable: that ambiguity resolved in costly ways for carriers once litigation forced interpretation.
The underwriting community is responding, but unevenly. Some carriers, notably Munich Re and HSB, have moved toward affirmative AI coverage with dedicated pricing frameworks and systemic accumulation monitoring. Others are still rationalizing legacy terms and conditions, trying to close gaps before claims do it for them. On the D&O side, AI washing is emerging as the nearest-term litigation risk, with practitioners drawing direct lines to how COVID-era pharmaceutical overpromising generated securities class actions. Board-level AI disclosure is no longer optional for public companies, and underwriters are beginning to treat governance transparency as a material factor at renewal.
Underneath all of it is a data infrastructure problem that neither liability frameworks nor policy language can solve on their own. The operational case is plain: AI is not creating new data problems in insurance. It is exposing ones that already existed. Fragmented systems, siloed architectures, and inconsistent metadata are creating a ceiling on what AI can actually deliver, and on how defensibly carriers can explain the decisions their models are making to regulators and courts.
Taken together, this week’s coverage describes an industry caught between the competitive pressure to deploy AI and the governance, legal, and infrastructure readiness required to do it safely. For risk managers, brokers, and underwriters, the practical question is no longer whether to engage with AI, but whether the controls, the data foundations, and the policy language are keeping pace with the exposure being accumulated along the way.