What happened
RAND examined AI incidents, U.S. lawsuits, enacted state laws, and admitted-market insurance filings to assess how insurers are responding to AI-related losses. Key finding: 84% of public generative AI incidents relate to misinformation and deepfakes, while 60% of U.S. litigation for generative AI harms concerns IP violations or improper training rather than model use/misuse. The report identifies five mechanisms through which AI could generate accumulation losses spanning technology E&O, cyber, D&O, and commercial property lines, and finds carriers responding unevenly — some offering affirmative coverage, others filing broad exclusions, and most remaining silent, leaving coverage untested and open to dispute. RAND recommends state regulators develop an AI coverage notice and that insurers/reinsurers analyze AI aggregation scenarios around shared model dependency and infrastructure failure.
Why it matters
CFOs, general counsel, and risk officers need to know that most enterprise AI exposure is currently uninsured or ambiguously covered — a board-level gap given AI's rapid embedding into operations.
Action needed
Audit current insurance policies for AI-related silence or exclusions across all applicable lines, and engage brokers on affirmative AI coverage options.