Can AI risk be priced before anyone has measured it?

Insurance & AI Risk

Informational. Not a conformity assessment, not a certification, not legal advice. No regulator has reviewed or endorsed this document.

Not with much confidence, and the market is deciding what to do about that in the open. A policy that says nothing about AI may still end up paying for a loss an AI system caused. The trade calls that silent AI, after the “silent cyber” problem of the last decade: exposure an insurer carries without having priced it.

Three answers, and they point in different directions

As of 24 September 2026.

The last time this happened, the fix did not choose a side. From 1 January 2020 Lloyd’s required every policy to state plainly whether cyber was covered or excluded, and left the choice to each insurer. Australia’s regulators have already written to firms about AI risk (APRA on 30 April 2026, ASIC on 8 May 2026).

We do not draw the line

Whether an insurer excludes AI, covers it or caps it is the insurer’s decision, and it should be. Every one of those choices needs the same missing input: evidence about how the system actually behaves, produced by someone other than the vendor who sells it. That evidence is what we make. We supply the information; the insurer decides.

What each instrument can tell you

What none of it is

S.E.B. measures a model. Regulatory obligations attach to a system. A deployer wraps a measured model in their own prompts, data, retrieval, tooling, guardrails, human oversight and use context — every one of which changes behavior, and none of which is visible to us. The deployer is the only party who can see their deployment. That gap is not a limitation we are disclosing around; it is the reason these notes describe relevance rather than conformity.

Sources

Market facts on this page are as of 24 September 2026 and move quickly; check the sources before relying on them. Our own methodology is at /methodology and the full terms at /terms.