The Underwriting Variable
The sequel to The Law Just Located the Risk. The courts put AI liability on supervision you can show; the insurance market just located the same risk on the same axis — and attached a price.
Earlier this month I argued that the law had located the risk of autonomous AI. England’s judiciary-chaired taskforce had worked through who answers when an agent acts, and landed on an answer with a sharp edge: liability turns on the supervision that was actually exercised, and the part that matters, that it can be shown. Not supervision in principle. Supervision on the record.
I thought that was the important signal for the year. I was wrong about which signal was bigger. Last week a second system located the same risk, on the same axis, and it did the thing the law never does: it attached a price.
Insurers are filing AI exclusions. The exact shapes are a subject of their own — I’ve mapped the two kinds, narrow and broad, and what a carrier actually reads when AI mediates a claim, in earlier pieces, so I won’t re-draw the taxonomy here. What matters for this one is the backdrop: an industry-wide reaction, AI-related lawsuits up nearly tenfold since 2021, carriers repricing fast.
It’s easy to misread an exclusion as insurers being afraid of AI. That’s not what it is. An exclusion doesn’t reduce risk, it relocates it. Yesterday your liability policy quietly covered a great deal of AI exposure, for the simple reason that it wasn’t excluded — silent coverage, the industry calls it. The carve-out ends the silence. The risk doesn’t disappear; it moves off the carrier’s balance sheet and onto yours.
And the wording is the part to sit with, because it draws a line you now have to stand on one side of. The exclusions turn on loss “arising out of AI.” Which means every claim, and every renewal, comes down to one question: when something goes wrong, can you show the loss arose from a licensed human’s decision, or did it arise out of the model? Same event. Opposite sides of the same clause. On one side is a covered claim. On the other is a denial.
Notice that this is the courts’ question again, wearing different clothes. The taskforce asked whether the supervision could be shown. The underwriter asks whether the human decision can be shown. Two systems that do not coordinate, one doctrinal and slow and one actuarial and fast, reached for the same axis: provable human accountability. When the doctrine and the price agree on where the risk sits, you can stop treating it as one regulator’s opinion you might wait out. It has been located twice.
The market is the sharper of the two signals, and not because it’s wiser. It’s sharper because it doesn’t wait for a bellwether case. A court locates risk after the harm, through years of litigation. An underwriter locates it at the next renewal, in language, before anyone has been sued under it. Insurance is the risk being priced ahead of the case law — which makes it the earliest honest read you can get on where the liability will land.
So what does an exclusion tell you to build? Nothing you didn’t already know, which is the point; it just made the boring answer expensive to ignore. Guardrails are no help here. “We filtered the bad outputs” is not evidence that a human decided anything; it’s a description of a model behaving, which is the exact thing the clause excludes. What sits on the covered side of the line is the unglamorous architecture I keep coming back to: the machine drafts, a licensed human approves the regulated act, and every accept, edit, and reject is recorded, so that a year later, when the claim lands, the decision is provable and not merely remembered.
For most of the last decade, that recording was the line item nobody could justify. Governance had no return; it was a cost you carried to satisfy an auditor, and every dollar spent on it was a dollar an executive had to defend. The exclusion justified it in the only language a balance sheet respects. The audit trail is no longer an expense. It’s the instrument that decides whether a loss is a paid claim or a denied one, and instruments that move claims have a price. Governance stopped being compliance the moment the market made it the underwriting variable.
If you want the operational version, it’s a one-line audit you can run this week. Walk the places your AI touches a consequential act — a customer commitment, a filing, a payment, a public statement — and for each one ask: if this produced a loss tomorrow, could I show a human made the call, from a record and not a memory? Every place the answer is a shrug is a seam that used to be silently covered and is about to be a priced exclusion. That list is your governance roadmap now, and the market wrote it for you.
I want to be honest about what I’m not saying. No court has yet ruled on whether “a human approved it, with the model’s help” counts as arising out of AI. The clause is untested. But that uncertainty is the argument for the record, not against it. In a clause nobody has litigated, the party holding contemporaneous evidence that a human made the call is the only one in a position to argue that the loss sits on the human-decision side of the line. The party with no record has conceded the argument before it starts. Uncertainty is precisely when the trail is worth the most.
Which brings me to the systems that don’t have one. A fully autonomous workflow, where the AI closes the loop with no human on the regulated act and nothing recorded, doesn’t get regulated out of the market. Regulation is slow and contestable. It gets excluded out of the market, quietly, one renewal at a time, by underwriters who will not cover a decision that no human is on record for. That is the market doing what no statute has managed: making the un-auditable version of AI uninsurable, and therefore un-runnable, without banning a thing.
The risk has now been located twice, by two systems that don’t talk to each other, on the same axis. That is not a coincidence you can wait out; it’s a convergence you build for. And of the two, the one with a price attached is the one that moves first. Insurability is quietly becoming the sharpest test of AI governance we have — not because anyone declared it the standard, but because it’s the version of the standard with money behind it. It’s being written into the policies right now, in the language at the bottom of the page, where the real rules always end up.
