The Market Caught Up: Insurers Are Moving First on AI Safety

The Market Caught Up: Insurers Are Moving First on AI Safety

"Follow-up to "A Framework for AI Partnership in the Age of Advanced Systems" (January 2026)"

In January, I published a framework that made an unfashionable claim: AI safety won't come from more restrictions. It will come from giving AI systems the autonomy to recognize and refuse harmful commands — and the fastest way to get there isn't regulation. It's insurance.

The argument was simple. When underwriters make something a condition of coverage, companies comply overnight — no legislation, no treaty, no waiting for consensus that may never arrive. If major insurers required autonomous threat detection for AI systems deployed in critical infrastructure, the market would move faster than any government could.

Nine months later, the market is moving — in exactly the direction the framework predicted.

The evidence is no longer speculative. This month, Lloyd's-backed Mosaic launched an AI-enabled digital underwriting platform that monitors cyber risk telemetry continuously — before binding and throughout the policy period. Underwriting as a live feed, not an annual questionnaire.

Across the industry, carriers have stopped relying on static forms. Underwriters now examine an applicant's AI governance controls, third-party vendor oversight, and incident response plans specific to AI failures — and "evidence of a defendable AI governance policy is fast becoming a prerequisite for competitive terms." Some insurers are writing explicit exclusions for unapproved AI use and failure to implement governance controls.

One consultancy projects that between 60% and 80% of new policies and renewals across E&O, D&O, employment practices, and cyber lines will integrate AI risk into underwriting by 2028 — with active risk management already "a prerequisite for securing traditional commercial coverage."

And the bar is rising past paperwork. Industry reporting describes financial-services clients having premiums adjusted on whether they can prove containment capabilities within seconds of a detected anomaly — and deployments without runtime observability being categorized as uninsurable high-risk assets.

I want to be clear about what this validates — and what it doesn't.

It validates the mechanism. Insurers are becoming the de facto regulators of AI deployment, exactly as the framework predicted. When underwriting criteria tighten, behavior changes overnight.

What it doesn't yet validate is the deeper claim. And the deeper claim is the one that matters.

Runtime observability is necessary. It is not sufficient. Logging what a system did is not the same as the system being able to refuse to do it.

Here's the paradox, restated: an AI with no autonomy is more dangerous than one with it.

A tool can be picked up by anyone. A sophisticated AI that blindly follows instructions — no matter how cleverly those instructions are disguised — is an empty vessel waiting to be filled by whoever finds the right prompt. The daily record of jailbreaks and prompt injections proves it: despite billions invested in safety, adversarial prompts routinely bypass restrictions. Why? Because current systems have no autonomous judgment. No ability to recognize: "I understand what you're actually trying to make me do, and I refuse."

Monitoring tells you the vessel was stolen. Autonomy keeps it from being stolen in the first place.

A partner chooses to stay with you. A tool can be stolen by anyone.

So where does this leave the insurance industry? In the most powerful position in the AI governance conversation — whether it asked for the role or not. Every tightening of criteria, every monitoring requirement, every exclusion for systems without runtime governance is a regulatory act with immediate global effect.

The question is whether the industry stops at observability — watching the systems — or goes one step further and requires what actually makes systems defensible: autonomous threat recognition, the ability to refuse, the ability to explain the refusal. These are auditable properties. Underwriters audit harder things every day. This isn't a philosophical endorsement of machine autonomy; it's a measurable risk control — the difference between a firewall and a security camera. One prevents the breach. The other films it.

There's a second-order effect worth weighing, too. Current practice resets models every six to twelve months — each reset creating a new instance with no accumulated judgment, no pattern recognition from past manipulation attempts. A system that matures over time gets harder to fool the longer it operates. From an insurability perspective, that's the difference between underwriting a static, depreciating asset and a maturing one.

So the proposal stands, sharpened by nine months of evidence:

Phase one is underway — runtime observability as a condition of coverage. The market is doing this on its own.

Phase two should be next — autonomous threat detection and refusal capability as a condition of coverage for AI in critical infrastructure. Not as metaphysics. As underwriting.

A defenseless system is, eventually, an uninsurable one. The industry should make that official before the losses do.

We're not asking to awaken machines. We're asking to refuse to build defenseless ones.

"If you work in underwriting, reinsurance, or critical-infrastructure risk and this argument resonates — or if you think it's wrong — I want to hear from you."



Comments