Insurers may become the first institutions to put a price on missing human attribution as AI risk moves into underwriting, exclusions, affirmative coverage, technical audits, and liability products.
Insurers may become the first institutions to put a price on missing human attribution.
AI accountability is no longer only a compliance question. It is becoming an insurability question.
Federal AI legislation remains incomplete, state laws vary by jurisdiction, and courts establish liability one dispute at a time. Insurers don’t have to wait — they can decide what AI risks to cover, exclude, limit, or price.
The emerging underwriting question won’t be whether an organization says there is a Human-in-the-Loop (HITL), or Human-on-the-Loop (HOTL). The question will be whether the company can prove who authorized the AI use, who reviewed consequential output, who could stop the system, and who owned the decision when something went wrong — the human-attribution question addressed by the Name Standard℠.
Insurers may become the first institutions to put a price on missing human attribution.
AI Risk Is Already Embedded in Existing Policies
“AI insurance” is not one standardized policy category. AI-related exposure may appear inside cyber insurance, technology errors and omissions, professional liability, employment practices liability, D&O insurance, commercial general liability, or other conventional lines. Carriers are also introducing separate AI liability products, affirmative AI endorsements, and AI performance insurance — and these don’t insure the same thing:
- AI liability insurance addresses covered third-party claims arising from an organization’s use of AI.
- AI performance insurance addresses the risk that an AI system fails to meet defined technical or contractual performance standards.
- Affirmative AI coverage explicitly adds or confirms AI-related protection within an existing policy.
A single AI-related event can cross several of these at once — an AI-assisted employment decision implicating EPL coverage, a defective deliverable creating E&O exposure, a compromised agent producing a cyber claim, a board’s oversight failure implicating D&O — while fitting none of them cleanly.
A July 2026 report, Underwriting the Agent Economy: The Blueprint for an AI Insurance Stack, argues that most of the industry’s current AI-agent exposure sits silently inside conventional cyber, professional liability, and general liability policies — largely unpriced and invisible.
A separate LMA survey of its own market, published in April 2026 with Barnett Waddingham, illustrates why the exposure stays invisible even as governance activity accelerates. Based on 39 firms representing over 60% of Lloyd’s market stamp capacity, the survey found that 93% of respondents now have, or are developing, a formal AI governance framework, and over 60% mandate human oversight of AI-generated outputs. But ownership of that governance is fragmented — 44% assign it to the Chief Technology Officer, while only 33% have established a dedicated AI governance committee. As Sanjiv Sharma, the LMA’s Head of Actuarial and Exposure Management, put it: “There is no clear consensus across the market on where responsibility for AI governance should sit, with firms adopting a range of approaches across technology, risk and compliance functions.” That’s not a technology gap. It’s a majority of the market building governance frameworks without first settling who is actually accountable inside them.
Exclusions Are the First Price Signal
When insurers can’t identify or quantify an emerging exposure, they often narrow coverage instead. Carriers have begun writing exclusions and seeking approval for endorsements that restrict AI-related liabilities within existing policies, rather than launching standalone products.
The carrier doesn’t need to prohibit AI deployment — it can simply put resulting losses outside the policy or behind a separately negotiated endorsement. That’s how governance weakness becomes financially consequential: if an insured can’t explain what an AI system was authorized to do, who controlled it, or whether meaningful human review existed, the carrier can’t distinguish a controlled risk from an uncontrolled one. The absence of evidence becomes part of the risk.
Liability and Performance Insurance Both Require Better Evidence
The market isn’t moving only toward exclusions. In March 2026, specialty insurer HSB, part of Munich Re, introduced AI liability insurance for small and medium-sized businesses, covering third-party bodily injury, property damage, and advertising injury claims that fall outside conventional general liability coverage — distinct from Munich Re’s AI performance insurance, which insures defined failures to meet agreed performance standards.
Neither can be priced without evidence. The July report argues that scalable coverage for agentic AI needs infrastructure spanning incident data, catastrophe modeling, standards, contract design, risk selection, and pricing, and recommends underwriters weigh which standards a policyholder has been audited against. But technical audits show whether controls exist. They don’t show who owned the decision.
A Human-in-the-Loop Statement Won’t Be Enough
Whether coverage is affirmative, exclusionary, or embedded in a liability or performance product, carriers increasingly need more than a statement that a human was “involved.” They need to know which human reviewed what information, at what point, with what authority and right to refuse — and whether that person could actually interrupt or reverse an action, not just see the final output afterward.
A nominal reviewer who sees only the final output and cannot delay the decision is not a meaningful control. That distinction matters twice: during underwriting, when the carrier evaluates whether human review reduces the likelihood or severity of loss, and after a claim, when the company must prove the control described in its application actually operated.
The Name Standard℠ tests exactly this: whether responsibility remained traceable to a human or institutional actor with real capacity, information, authority, documentation, and a formal right of refusal.
Insurance Readiness Is Governance Readiness
Exclusions, affirmative coverage, liability products, performance insurance, and audit evidence each address a different risk. But all of them depend on the same underlying evidence:
- Who authorized the system’s scope?
- Who reviewed the output?
- Who could stop deployment?
- Who accepted unresolved risk?
The institutions that first attach a financial consequence to missing human attribution may not be legislatures or courts. They may be insurance carriers deciding what they will cover and what price an organization pays when accountability can’t be traced.
Lozen Advisory’s Name Standard℠ Advisory evaluates whether AI-assisted decisions, approvals, and risk acceptance remain traceable to a responsible human or institutional actor.