Article — Position paper · ○ Open access

From System Delivered to Risk Allocated

Why AI-specific insurance covers only fragments of the business case, and why the residual economic risk stays on the client's balance sheet.

Jérôme Vetillard · · Twingital Institute · 10 pages · 6 min read
🇫🇷 Lire en français ↓ Download PDF

Deploying software once meant handing over an artifact: a program, a database, a data flow. Deploying an AI means handing over a decision-making capability, and that single shift reconfigures governance, liability, insurance and financing at once. A market for AI-specific insurance now exists and is growing, and it is tempting to read it as the instrument that finally transfers the profitability risk of a deployment to a third party. It is not, and the reason is not the market’s immaturity. The reason is that the residual economic result of a deployment is not the kind of object an insurer can price. This note states that reason and holds to it.

Three units that never align

The whole difficulty compresses into a single sentence: the vendor delivers a system, the business expects an outcome, the insurer covers a peril. Three units, and nothing guarantees that an object expressed in one of them is expressible in the other two. A hallucination is a mechanism, not a claim. The claim, if it ever comes into being, is the legally established loss of a third party who relied on it, and the defense cost is what a policy agrees to indemnify. To treat the hallucination as the claim is the founding error of the ambient discourse, because it collapses six distinct levels (peril, exposure, damage, risk, trigger, object of cover) into one. The market can cover a defined AI failure. It cannot convert every economic disappointment into an indemnifiable loss.

Why the economic result is not a peril

The objects the market knows how to handle, third-party harm, a security incident, an intellectual-property breach, a deviation from a performance threshold, are bounded events or states. The net economic result of a deployment is not one of them. It is a causal aggregate endogenous to the client, in which technical performance, organizational adoption, real usage, supervision cost, change management, management quality and external shocks all intervene at once. Four properties make it refractory to classical indemnity. Causality is diffuse: a technically compliant system can still miss its ROI, and a mediocre model can produce ROI through a reorganization or a price rise. Control belongs largely to the insured, which installs a moral hazard of a different scale than a technical threshold. Measurement is counterfactual: indemnifying a shortfall means comparing the observed world to a world without failure, a counterfactual rarely observable. Volatility is partly external. An object with these four properties does not wait to be better reconstructed. It waits, at best, to be decomposed.

What the market actually covers

Read at the level of proof at which they present themselves, the public offerings confirm the shift. Armilla, a Lloyd’s coverholder, raised its standalone facility to twenty-five million dollars in early 2026, with a trigger set on performance judged below initial expectations, not on the collapse of the business case. Munich Re’s aiSure has built guarantees around defined and measurable indicators since 2018, the trigger being the crossing of a performance threshold, the analysis bearing on the model. Testudo forbids any hasty generalization: its standalone third-party liability policy prices on litigation and exposure data, without an extended technical audit of the system. The reality is graded, not uniform. The more the trigger depends on the model’s own behavior, the more central its technical characterization becomes; the more it depends on generic legal liability, the more underwriting leans on exposure proxies. One word, “insurance”, conflates instruments that do not cover the same object: indemnity requires a demonstrated loss and a causal link, a performance guarantee requires a threshold and a measurement method, a parametric cover requires an index and accepts a basis risk, a service-level agreement often caps compensation far below the actual damage. Insuring the proxy is not insuring the outcome.

Reconstructibility opens a market, not a guarantee

To attribute a loss, one must reconstruct it, and the delivery model shows its hole here: the evidentiary chain is fragmented among the vendor, the client and the integrator, and the contractual structure charges no one with assembling it for the insurer. Reconstructibility, the work of turning a contextual, tacit, distributed deployment into persistent proof interrogable by a financial third party, reduces one part of the information asymmetry, the distributed part and the non-observable part. It does not touch the strategically withheld part, and it may even produce more data without making them credible. Its value is wider than insurance. By making an opaque risk observable, attributable and boundable, it turns that risk into a negotiable financial object, which is the condition not only of a policy but of refinancing, reinsurance, rating and securitization. That is precisely why its absence is costly: the delivery contract that does not fund its production leaves the risk on the balance sheet of whoever lacks the means to transfer it. It does not, for all that, make the business case insurable, and it removes neither the moral hazard nor the diffuse causality.

The norm that has not yet been written

Actuarial tractability is not the higher gate. A risk can be actuarially treatable and normatively indeterminate, and then the insurer does not know what it is promising to indemnify. Two properties make the AI-applicable norm resist. Its requirements are orthogonal: explicability and human oversight pull against data minimization, the right to explanation pulls against the trade secret covering the model, the MDR’s demand for a stable clinical evidence base collides with an AI Act that presupposes systems which keep learning. When two requirements are orthogonal, compliance is not a state one reaches but an arbitration one renders, and the peril “non-compliance” is under-defined by construction. The second property follows: a large part of the operative rule will be forged by the courts, not written by the legislator. The underwriter prices the written rule and pays against the enforceable one, forged after the loss. A single landmark ruling can reclassify an entire portfolio built on the same orthogonal arbitration, a normative correlation that no reconstructibility of the system detects, because it lives in the legal layer, not the model layer. The regulatory fines and defense costs that appear with such assurance in the product descriptions are, on this reading, less a covered peril than a bet on the pace and direction of a case law barely begun.

What it does to the break-even

The tempting claim is that insurance reduces the variance of the break-even. It asserts more than the mechanism allows. A bounded, deductible-bearing, selective cover does not reduce global variance and may even raise certain financial volatilities. The exact proposition is more modest: it adds a certain cost to every scenario and may reduce the severity of some extreme scenarios that would delay or prevent the break-even. Even a covered claim leaves a deductible, a sub-limit, a settlement delay, a causation dispute. The premium belongs to transfer, not to governance, and keeping the two apart reveals the paradox that concerns the business case: the very infrastructure that makes risk transferable can defer the break-even it was meant to secure, once the cost of transfer plus the governance it requires grows faster than the risk it removes. A policy is then sometimes bought not for its actuarial expectation but as a contractual entry ticket to markets that demand it.

Validity domain

This note reasons on public product descriptions, not on contractual wordings, which are not accessible; what is described as a trigger is a public positioning, not an enforceable clause. It describes a young market and predicts neither its size nor the sustainability of its premiums. The thesis is falsifiable. It would weaken if indemnity guarantees durably covered a global economic result without reducing it to bounded events, thresholds or indices, or if ordinary deployment deliverables regularly produced an evidence base simultaneously maintained, causally relevant and reusable across several carriers. It predicts the opposite. As long as the three units do not align, and as long as no one is contractually charged with drawing the map that says who controls, who answers and who pays, the loss always finds someone to bear it. Simply not always the one who caused it.

[Series: The Hidden Costs of Deploying AI. The complete argument, with its six-term vocabulary and its footnoted carriers, is in the document below.]

Read the document