On September 16, 2026, the US think tank RAND published a research report, "The Insurability of Artificial Intelligence," arguing that corporate AI use and insurance coverage are drifting out of alignment. Some products now cover AI-related losses, while other insurers are excluding AI from existing policies or simply not saying whether it is covered. For companies adopting AI, holding insurance does not by itself mean they are protected against AI failures. A look at actual products shows that the role of insurance changes greatly depending on which AI behavior is measured and whose losses are covered.
Uncertainty when a policy does not mention AI
RAND's report, by Sasha Romanosky and Celine Robinson, examines AI-related incidents and lawsuits in the US, along with enacted state laws and filings in the licensed insurance market. It belongs to a research report series that undergoes RAND's peer review. Insurers' approaches fall into three groups: those that explicitly cover AI-related losses, those that exclude them through exclusion clauses, and those that say nothing in the contract.
When a policy is silent, coverage may still be possible. But the actual outcome depends on the policy wording, the nature of the loss, existing exclusions, and other factors. The report cautions against equating this state with confirmed coverage.
The survey also needs to be read with care. On page 20 of the report, a footnote explains that the classification of the remaining insurers as not specifying coverage includes inferences drawn from the filing analysis. It is not a study that examined every contract and measured the share of uninsured companies. The AI coverage notice that RAND proposes, which would make clear for each line of insurance whether AI is covered, excluded, or unmentioned, is likewise a proposal and should be distinguished from a system already in force.
Even in AI insurance, underperformance and liability are separate problems
On February 26, 2026, Mosaic Insurance announced it would offer "Mosaic x aiSure" in partnership with Munich Re. It targets companies that develop and sell AI, and covers financial losses that arise when a model fails to meet predefined performance levels. HSB, part of Munich Re, by contrast, describes a product covering liability for bodily injury, property damage, and similar harms tied to AI use.
Extracting the coverage targets and decision criteria from the two companies' public descriptions gives the following.
| Item compared | Mosaic x aiSure | HSB AI Liability Insurance |
|---|---|---|
| Focus of product description | Performance risk of AI developers and sellers | Liability of companies that use AI, among others |
| Losses presented as covered | Financial losses from failure to meet defined AI performance | Bodily injury, property damage, and personal and advertising injury |
| Basis for decisions | Clearly defined performance standards and measurable data | Third-party claims related to AI use and contract terms |
| Relationship to existing insurance | Complements cyber insurance and technology errors-and-omissions insurance | Addresses gaps that can arise from AI exclusions in commercial general liability insurance |
Sources: Mosaic announcement and HSB product description. This is a comparison of public descriptions checked on September 19, 2026, not a comparison of full policy wording or premiums. Whether a loss is covered depends on the individual contract's terms, exclusions, and the region where it is offered.
Mosaic builds its coverage around losses from failing to meet defined AI performance, while HSB builds its around liability to third parties arising from AI use.
This difference bears directly on what a company calls an "AI failure." A model's answer accuracy falling below an agreed level is one problem; a customer seeking damages after relying on that answer is another, and the facts to be established differ. Both may arise from the same incident, but choosing a product that handles one does not automatically cover the other.
Mosaic describes a mechanism close to parametric insurance, using measurable performance data to drive payout decisions. It says this reduces the burden of investigating every path of loss from scratch and leads to faster claims handling. Under this approach, the work of turning "expected performance" into something measurable before deployment becomes tied to the insurance terms.
HSB gives examples such as an AI cleaning robot colliding with a customer or generated content facing a copyright infringement claim. These are explanations of anticipated claims, not published records of actual payouts. Even if performance evaluation results are good, how third-party harm is handled needs to be checked separately.
Dependence on shared models, and losses that can overlap
Another RAND report, on supply chains and AI insurance and published on September 2, points out that hidden dependencies form between companies. Even separate firms may suffer simultaneous losses from a common failure if they rely on the same model provider, cloud service, or logistics software. In insurance terms this is accumulation risk: a common cause producing overlapping losses across multiple contracts.
Consider, for example, several logistics companies using the same AI service. Even if each has different warehouses and customers, an error in the shared decision-making function could disrupt operations in separate locations. This is a hypothetical example to explain the mechanism, but from an insurer's perspective, having different policyholders does not by itself mean the risk has been diversified.
The report combines a literature review and a survey of incidents and lawsuits with stakeholder interviews and scenario analysis. It does not measure actual future claims payments. It advises operating companies to identify where AI is used, put human oversight and monitoring in place, and actually test fallback procedures.
From the adopter's side, this adds a new item to model comparisons: how far operations can continue when something fails. Can humans take over decisions? Would an outage of a shared service halt multiple processes at once? Even with equally accurate AI, the path from failure to loss varies with the authority delegated and how the AI is built into operations.
Before insurance, can you explain how the AI is run?
In its explanation of technical review for AI insurance, Munich Re says it conducts technical due diligence, meaning detailed pre-underwriting investigation, on AI that it insures under performance guarantees. The problem is that a seller's claim of "high accuracy" is not enough for an insurer to define the risk it is taking on.
There are also moves to combine certification with insurance for AI agents. AIUC's product description outlines a flow in which an AI company obtains AIUC-1 certification and buys insurance to cover cases where an agent's failure harms customers. Obtaining certification and entering an insurance contract are separate steps.
The AIUC-1 certification process is structured around defining the target agent and its operating conditions, then certifying it after technical testing and a third-party audit. Certification is valid for one year, with retesting every quarter. Test targets include prompt injection, in which external instructions can change the agent's behavior, as well as data leakage and unsafe tool calls. Passing the tests is not a guarantee that no accident will occur.
What follows from this is that documents explaining how AI is operated can be useful in both procurement and insurance. For a customer-service AI, for instance, one would distinguish between an AI that merely explains refund procedures in text and one that has the authority to actually send money. If money transfers are delegated, it would also be necessary to explain how that authority is tested and who stops the system when problems arise. This lets people examine concrete paths to loss, rather than being told only that "AI is used."
RAND's US-centered diagnosis cannot be used to directly judge the scope of coverage in Japanese insurance contracts. Still, the questions remain: separate underperformance from harm to third parties, and check actual authority and dependencies against contract terms. If companies can concretely match the tasks they delegate to the losses insurance will bear, they can build into the cost of adopting AI the portion they would have to absorb themselves when something fails.
