AI

The Insurability Frontier of AI Risk

Mapping 55 AI threat classes across 26 insurance products to identify where coverage exists, where exposure is ambiguous, and where exclusions leave gaps.

Published May 2026

Share:

Research details

Context

Most organisations assume their existing insurance responds when AI causes a loss. It might, or it might not, depending on whether AI directly caused the harm or simply played a role. This study maps 55 AI threat classes across 26 insurance products to show where coverage is clear, where it is ambiguous, where it is excluded, and where traditional insurance cannot yet reach.

Key takeaways

  1. AI risk does not sit in a single policy. The study found clear coverage, ambiguous exposure, active exclusions, and risks that traditional insurance cannot yet cover spread across cyber, technology E&O, D&O, crime, employment, media, and other lines. An organisation's AI risk posture depends on the interaction between multiple policies, not any one product.
  2. Ambiguous AI exposure is the most dangerous category. When AI plays a role in a loss but is not the direct legal cause, existing policies may or may not respond. Neither the insurer nor the insured may know until a claim is filed. Cyber, technology E&O, and D&O policies are particularly exposed to this ambiguity.
  3. Public descriptions of AI coverage are not coverage. Marketing language, product summaries, and even policy endorsement titles do not determine the outcome of a claim. The applicable wording, sub-limits, exclusions, and factual circumstances must be assessed together. That process requires both technical understanding and insurance expertise.

Contributors

  • Alex LeungVulcan
  • Rex ZhangOneInfinity
  • Ervin LingOneInfinity
  • Kentaroh ToyodaVulcan
  • SiewMei LohVulcan

Interested in working together?

Our team is expanding research across Web3, Cybersecurity, and AI.