AI Liability Insurance Buyer's Guide
Underwritten Part 1 of 2 Essay

The Questions Before the Policy · Part 1 of 2

Why Underwriters Price the Company

With almost no loss history to price against, AI underwriters price the company instead of the risk, and the renewal questionnaire is where that judgment is made.

Written by

Joel R. Singh

Section

Underwritten

The Empty Table


Two loss-experience tables side by side. The house and auto table shows an unbroken record of losses from 1960 to 2025. The artificial intelligence table is blank for every period before 2020 and carries only two short entries after it.
The same table, drawn twice. An underwriter pricing house or auto reads a century of losses; one pricing artificial intelligence reads almost nothing. Schematic: the bars show where a loss record exists, not plotted claim volumes. Diagram by iSinghLabs.

An underwriter pricing a risk is, at heart, a person reading a table. The table records how often a given thing has gone wrong in the past, and by how much, across enough cases that the pattern stops being a story and becomes a rate. A century of house fires produces a rate. A hundred years of automobile collisions produces a rate. From that rate the underwriter derives a premium, and the whole apparatus of modern insurance rests on the assumption that the future will resemble the past closely enough for the table to keep working.

When an underwriter is asked to price artificial intelligence, they reach for that table out of long habit, and their hand closes on almost nothing. Large-scale deployment of these systems is only a few years old, the harms are still surfacing, and many of them surface slowly, hidden inside decisions that looked perfectly reasonable at the moment they were made. The table an AI underwriter would most like to consult has barely begun to fill.

This is not a small inconvenience to be worked around with a wider confidence interval. It cuts to the foundation of how a price gets made, because the machinery of pricing was built to extrapolate from a record, and here the record does not yet exist. An underwriter faced with this vacuum has only two honest options:

  • They can decline to write the risk at all, as much of the market did at first and still does.
  • Or they can find some available signal that stands in for the missing loss data and lets them form a judgment about the risk they can actually see.

The whole subject of this essay is that second option, and what it now demands of any business that wants to be insured.

They price the company instead

The substitute the market has settled on is not a substitute for the risk itself, which cannot be conjured out of thin data. It is a substitute for the record. When an underwriter cannot price the AI, they price the company that operates it. They look for evidence that the organization understands what it has deployed, that it watches the system in operation, that it has thought in advance about how the system fails and what it will do when it does.

Where a mature line of insurance asks the risk to speak for itself through a hundred years of claims, an emerging line asks the operator to speak for the risk through the discipline of how it is governed. The governance becomes the proxy, standing in for the loss history that has not yet accumulated. This is the shift that reorganizes everything a buyer needs to do, and it is worth being precise about why it happened, because a buyer who mistakes it for a passing demand will prepare for the wrong thing.

When an underwriter cannot price the AI, they price the company that operates it.The underwriting proxy

Two applicants, one measurable difference

Consider the plainest version of the underwriter's problem. Two companies apply for the same AI liability coverage on the same day. Both deploy a large language model in a customer-facing role with real financial stakes attached to its answers.

One of them can produce, on request, a current inventory of every model it runs and what each one touches, a written record of where a human reviews the machine's output before it reaches a customer, the results of testing the system for bias and for the ways an adversary might push it off the rails, and a plan for what happens in the first hour after something goes wrong.

The other company can produce a slide deck and a feeling of confidence. To an underwriter with no loss table to fall back on, these two applicants are not close. The difference between them is the only difference the underwriter can actually measure, and so it becomes the difference that sets the terms, or that decides whether terms are offered at all.

None of this is a courtesy the market extends to well-organized firms. It is a necessity the market has backed into because the alternative is to price blind, and because it is a necessity it hardens quickly into a requirement. The soft language of best practice becomes the hard language of a condition on the policy, and the documentation a thoughtful company might have kept anyway becomes the documentation it must keep in order to buy coverage at any price it can stomach. The rest of this series is about what that documentation is, why each piece answers a specific fear the underwriter carries, and how a buyer builds the file before the questions arrive rather than after.

The underwriting proxy, in one line. When a risk has no loss history, the underwriter cannot price the risk, so they price the operator's control over it. Governance evidence is the instrument they read in place of the missing table.

The Renewal Questionnaire Is the Real Exam


Flight controllers at their consoles in NASA Mission Control during Apollo 16, monitoring a system in operation
Mission Control during Apollo 16, 1972. Nearly every question on the renewal form is a version of the same one: who is watching the system, and what do they do in the first hour when it goes wrong. NASA, no known copyright restrictions.

The document where all of this becomes concrete is the application, and then, year after year, the renewal questionnaire. It arrives looking like paperwork, and it is easy to treat it as paperwork, a set of boxes to fill on the way to a quote. That treatment is a mistake. The questionnaire is the exam, and the whole grade rides on it, because in the absence of a loss table the questionnaire is very nearly the only instrument the underwriter has for forming a view of the risk. Every question in it is a probe for a specific piece of the governance record, and every answer either produces the document behind it or reveals that the document does not exist. The buyer who understands this reads the questionnaire not as a form to complete but as a checklist of artifacts to have built, ideally long before the form ever arrives.

What the specialty AI underwriters ask has converged, across a still-young market, on a recognizable core. Each question is a probe for one document, and each document answers one fear.

Seven rows mapping each question the AI insurance questionnaire asks to the governance artifact that answers it and the underwriting fear behind it: model inventory, human-oversight map, test and red-team results, incident response plan, data lineage record, AI use policy, and third-party AI review. A band beneath shows all seven mapped to a recognized framework: NIST AI RMF, ISO/IEC 42001, or the EU AI Act.
The questionnaire, read as a checklist of artifacts. Every question is a probe for one document, and every document answers one fear the underwriter carries. The framework beneath them is what turns seven local habits into a standard someone else already trusts. Diagram by iSinghLabs.

Above all, increasingly, they want to see the whole apparatus mapped onto a recognized framework, so that the governance reads as an implementation of a standard the underwriter already trusts.


Beyond what the carriers say about themselves

The public evidence for this no longer rests on what carriers say about themselves. The Geneva Association, an insurance research body with no cover to sell, finds that insurers are tightening underwriting standards by scrutinising an insured's AI systems and governance practices, a process it compares to a technical audit, before granting coverage at all.[1] The safeguards it describes are the same ones the questionnaire probes for: human oversight, bias checks, contingency plans, model audits, third-party certification, and reporting obligations written into the policy terms.[1]

Carriers writing the cover say it in plainer commercial language. Armilla, which writes affirmative AI coverage, states that providers seeking cover must maintain documented AI governance policies with at least annual compliance testing, and warrant alignment with recognized frameworks including the NIST AI Risk Management Framework and the EU AI Act.[2]

At least one carrier now treats a formal management-system certification as a direct underwriting input. Armilla incorporates the signal from an ISO/IEC 42001 certification alongside its own technical evaluation, and says the result can be a clearer path to insurability and the potential for preferential terms.[3] Whether that hardens into market-wide practice is still open. As recently as mid-2025, no insurer was known to price the certification at all.[4]

Applications have been declined where governance and monitoring were too thin to support risk transfer, which tells you the questionnaire is not a formality with a foregone conclusion.[5]

The specialist carriers built for this risk underwrite the operator's discipline because the operator's discipline is what they can see. Lloyd's describes the first managing general agent and coverholder dedicated solely to AI liability as underwriting its exposures through independent model evaluation and regulatory-grade audits.[6] The Lloyd's Market Association puts the underwriter's central question in almost the same terms a buyer should expect on the form: whether the system decides what real-world actions to take, and whether it does so supporting a human decision-maker or replacing one without supervision.[7]

[1] The Geneva Association, Gen AI Risks for Businesses  ·  [2] Armilla AI, AI Insurance Becomes a Procurement Requirement  ·  [3] Armilla AI, From ISO/IEC 42001 Certification to Insurable AI  ·  [4] Deploy Securely, AI governance and cyber insurance  ·  [5] Armilla AI, From Paper Policies to Real Oversight  ·  [6] Lloyd's of London, Lloyd's Lab  ·  [7] Lloyd's Market Association

What the market now asks in writing

Documented AI governance with at least annual compliance testing, warranted alignment to recognized frameworks, and, increasingly, an ISO/IEC 42001 certification treated as a direct underwriting input that opens pathways to insurability and preferential terms. Applications have been declined outright for insufficient governance.

What your answers bind you to

There is a further reason to build the file well ahead of the deadline, and it has to do with what insurance law does with the answers you give. An insurance application is not a marketing document, and the statements a buyer makes on it are relied upon by the insurer in deciding whether and how to cover the risk.

A confident overstatement of controls that do not actually exist is a misrepresentation on the record that an insurer may later invoke, at the worst possible moment, when the claim it would have to pay is precisely the kind the overstated control was supposed to prevent. The questionnaire rewards a company that answers truthfully and completely, and it punishes, sometimes catastrophically and after the fact, a company that answers the way it wishes the truth were.

The only safe way to answer well is to have built the thing the question asks about, which is why the work of becoming insurable is done in advance and in earnest, not in the two weeks before renewal.

The questionnaire is the exam, and in a market with no loss table, it is very nearly the only instrument the underwriter has.The underwriting proxy

Where this leads next

If governance is the proxy, the file is the exam paper. Part 2 is the file itself.

The questionnaire probes for a recognizable set of documents, and they have converged on roughly nine. Part 2 walks through each one, what fear it answers, and the frameworks that turn a company's private habits into evidence an underwriter can price.

Continue with Part 2, The Underwriter's File. For the shape of the AI insurance market itself, read the companion essay Who Insures the Machine.

Works Cited

Every factual claim in this part is sourced below, with primary sources preferred. The numbers match the citation after each paragraph. Descriptions of the present-day AI underwriting market draw on published statements from carriers and specialty insurers writing this risk today.

  1. 1The Geneva Association, Gen AI Risks for Businesses: Exploring the Role for Insurance (2 October 2025). Authors Ruo Jia, Martin Eling and Tianyang Wang. The same research team set out these findings for practitioners in The Actuary Magazine (Society of Actuaries, October 2025); that article is the same body of work in another outlet, not a second independent confirmation.
  2. 2Armilla AI, Covering AI: AI Insurance Becomes a Procurement Requirement (15 May 2026). A carrier describing its own contract language. Cited as first-hand evidence of what one insurer requires, not as a survey of the market.
  3. 3Armilla AI, From ISO/IEC 42001 Certification to Insurable AI (17 December 2025). Describes Armilla's own underwriting, in partnership with A-LIGN.
  4. 4Joseph Breen, How effective AI governance can improve cyber insurance coverage, Deploy Securely (15 June 2025). States that no insurer was then known to offer terms tied to ISO 42001 or the NIST AI RMF. Predates source 3, so it marks the position before that offering existed rather than contradicting it.
  5. 5Armilla AI, From Paper Policies to Real Oversight: How AI Governance Is Becoming Insurable (14 January 2026).
  6. 6Lloyd's of London, Lloyd's Lab Accelerator alumni: Armilla AI. Lloyd's describes Armilla as the first managing general agent and Lloyd's coverholder dedicated solely to AI liability insurance, underwriting through independent model evaluation and regulatory-grade audits.
  7. 7David Powell, Head of Technical Underwriting, Understanding artificial intelligence risk in insurance products: the challenges, Lloyd's Market Association (13 April 2025). The LMA also notes that underwriters do not yet know as much about AI systems as they might wish to, which is part of why the questionnaire carries so much weight.
Informational only. This essay is analytical commentary on insurance underwriting practices and governance frameworks and is not insurance advice, legal advice, or a recommendation of any policy, standard, or carrier. Framework citations and carrier statements reflect publicly available documents and market reporting; underwriting requirements change frequently and vary by carrier and jurisdiction. Research and writing by Joel R. Singh for iSinghLabs Inc.
HOME