AI Liability Insurance Buyer's Guide
Underwritten In brief: the short version

The Questions Before the Policy, Part 1: Why Underwriters Price the Company, in brief

The short version of The Questions Before the Policy, Part 1: Why Underwriters Price the Company. Three minutes, same sources.

Written by

Joel R. Singh

Section

Underwritten

Published

2026-09-07

Picture two companies applying for AI liability insurance on the same day. AI liability insurance pays out if your AI system costs a customer real money. It works like general liability insurance, but for AI. Both companies use a chatbot to answer customer questions. Both have real money riding on what that chatbot says.

One company can show a list of every AI system it runs. It can show proof that a person checks the chatbot's answers before customers see them. It has records of testing the system for bias and security holes. It has a written plan for the first hour after something goes wrong.

The other company has a slide deck and a good feeling about its technology.

To the underwriter, this is not close. The underwriter is the person at the insurer who decides whether to offer coverage, and at what price. The company with the paper trail gets better terms, or gets covered at all. The one without it can be turned down outright.[5]

Why the paperwork matters this much


Why does the paperwork matter this much? Insurers usually set prices using loss history. Loss history is the record of what has gone wrong in the past, and how often. A century of car crashes tells an auto insurer roughly what a policy should cost. Wide use of AI is only a few years old. AI failures often surface slowly, buried inside decisions that looked fine at the time. The record an AI underwriter wants barely exists yet.

So insurers price the company instead of the risk. They look for proof that you understand what you have deployed. They want to see that you watch it while it runs. They want a plan for when it breaks. Governance, the rules and records that show how you control your AI systems, becomes the stand-in for the missing loss data.

Two loss-experience tables side by side. The house and auto table shows an unbroken record of losses from 1960 to 2025. The artificial intelligence table is blank for every period before 2020 and carries only two short entries after it.
The same table, drawn twice. An underwriter pricing house or auto reads a century of losses; one pricing artificial intelligence reads almost nothing. Schematic: the bars show where a loss record exists, not plotted claim volumes. Diagram by iSinghLabs.

The renewal questionnaire is the exam


Flight controllers at their consoles in NASA Mission Control during Apollo 16, monitoring a system in operation
Mission Control during Apollo 16, 1972. Nearly every question on the renewal form is a version of the same one: who is watching the system, and what do they do in the first hour when it goes wrong. NASA, no known copyright restrictions.

The form you fill out to apply for coverage, and again each year to renew it, is where this becomes real. It looks like paperwork. It works like an exam. Every question asks for one document: a list of your AI systems, proof of human review, test results for bias and security, an incident plan, and often, proof that you follow a recognized standard.

Insurance researchers and carriers say this openly. The Geneva Association, an independent research group, finds that insurers are tightening standards. They check an applicant's AI systems and governance closely, more like a technical audit than a form.[1] Armilla, a carrier that writes this coverage, requires written governance policies with yearly testing. It requires a match to recognized standards.[2] Some carriers now treat a certification such as ISO/IEC 42001, an international standard for managing AI risk, as a factor in the price. It can open the door to coverage or better terms.[3] That practice is still new. As of mid-2025, no insurer was known to price it at all.[4]

There is a second reason to build the file early. What you write on an insurance application carries legal weight. It is not marketing copy. Say you claim a control you do not actually have, and a claim later depends on exactly that control. The insurer can point to the gap and deny the claim, at the worst possible moment. The safer path is to build the thing the question asks about, well before you have to answer it.

Seven rows mapping each question the AI insurance questionnaire asks to the governance artifact that answers it and the underwriting fear behind it: model inventory, human-oversight map, test and red-team results, incident response plan, data lineage record, AI use policy, and third-party AI review. A band beneath shows all seven mapped to a recognized framework: NIST AI RMF, ISO/IEC 42001, or the EU AI Act.
The questionnaire, read as a checklist of artifacts. Every question is a probe for one document, and every document answers one fear the underwriter carries. The framework beneath them is what turns seven local habits into a standard someone else already trusts. Diagram by iSinghLabs.

What to do this week


  • List every AI system your business uses, and what each one touches.
  • Confirm a person reviews AI output before it reaches a customer. Write that down.
  • Schedule a test of your AI for bias and security weaknesses.
  • Draft a one-page plan for the first hour after something goes wrong.
  • Look into a recognized standard, such as the NIST AI Risk Management Framework or ISO/IEC 42001.

Handle this before the renewal form shows up, not after. The questionnaire only asks the questions. The governance file is the answer you show up with.

Works Cited


  1. 1The Geneva Association, Gen AI Risks for Businesses: Exploring the Role for Insurance (2 October 2025) https://www.genevaassociation.org/publication/digital-ai-transformation/gen-ai-risks-businesses-exploring-role-insurance-0
  2. 2Armilla AI, Covering AI: AI Insurance Becomes a Procurement Requirement (15 May 2026) https://www.armilla.ai/resources/covering-ai-ai-insurance-becomes-a-procurement-requirement
  3. 3Armilla AI, From ISO/IEC 42001 Certification to Insurable AI (17 December 2025) https://www.armilla.ai/resources/from-iso-iec-42001-certification-to-insurable-ai
  4. 4Joseph Breen, How effective AI governance can improve cyber insurance coverage , Deploy Securely (15 June 2025) https://blog.stackaware.com/p/cyber-insurance-ai-governance-iso-42001-nist-rmf
  5. 5Armilla AI, From Paper Policies to Real Oversight: How AI Governance Is Becoming Insurable (14 January 2026) https://www.armilla.ai/resources/from-paper-policies-to-real-oversight-how-ai-governance-is-becoming-insurable
  6. 6Lloyd's of London, Lloyd's Lab Accelerator alumni: Armilla AI https://www.lloyds.com/insights/lloyds-lab/programmes-and-initiatives/lloyds-lab-accelerator/alumni/armilla-ai
  7. 7David Powell, Head of Technical Underwriting, Understanding artificial intelligence risk in insurance products: the challenges , Lloyd's Market Association (13 April 2025) https://lmalloyds.com/understanding-artificial-intelligence-risk-in-insurance-products-the-challenges/
HOME