What happened
CSIS's Gregory C. Allen argues that insurance has become the de facto most important regulator of U.S. AI deployment — and that its current trajectory is producing an outcome 'neither carriers nor policymakers nor AI developers would have chosen deliberately.' The paper cites reporting that state insurance commissioners had quietly approved more than 80 percent of carrier requests to exclude AI-related damages from corporate insurance policies, effectively making uninsurable AI activity commercially prohibitive for many U.S. businesses. Allen proposes four federal policy interventions designed to convert insurance from a brake on AI adoption into a 'virtuous-cycle accelerator,' building on six key judgments about how AI liability exclusions are reshaping enterprise risk-taking. The paper is grounded in industry filings, the Geneva Association's prior AI-insurance analysis, and Lockton Re's February 2026 white paper on the same dynamic.
Why it matters
For any enterprise deploying AI at scale, the paper reframes insurance exclusions — not just legislation — as the binding constraint on what AI activity a company can practically undertake; boards and CISOs should map their own coverage gaps against the exclusion trend before assuming AI-related incidents are insurable.
Action needed
Have the CFO/General Counsel audit current corporate insurance policies for AI-related exclusion clauses and brief the board on residual uninsured AI liability exposure.