Specialty Insurance Products: Market Trends, Challenges and Technology
Surplus lines grew 10.4% in 2025 while filings outran premium in 2026. What specialty products ask of a PAS, and five tests to run before you buy one.
Insurers spent two years writing AI out of standard policies and building a new market to replace it. Here is what Armilla, Munich Re, AIUC and Testudo sell.
In February 2024 a British Columbia tribunal ordered Air Canada to pay a passenger CA$812. The airline’s website chatbot had told Jake Moffatt he could book a flight and claim a bereavement discount retroactively. He could not. Air Canada argued that the chatbot was, in effect, responsible for its own answers. The tribunal did not accept that: the bot was part of the airline’s website, so the airline owned what it said.
The money was trivial. The principle was not.
Moffatt v. Air Canada settled cheaply what every business now has to answer at scale: if your AI gets it wrong, you pay.
And that was a chatbot answering a question. The systems going into production in 2026 do things: issue refunds, place orders, move money, change records, ship code, decide inside workflows nobody reads end to end.
Insurers worked this out before most of their customers did, and moved in two directions at once: writing AI out of the policies businesses already hold, and building a market to sell the cover back.
The clearest signal came from Verisk, whose ISO policy forms sit underneath much of the world’s property and casualty business. It filed a family of generative AI exclusion endorsements that carriers could start attaching to commercial general liability renewals from 1 January 2026, and the ISO forms are not the only place the door is closing:
The Verisk endorsements are optional forms. Plenty of carriers have chosen to attach them.
Technology errors and omissions, the line closest to the risk, is no safety net either. It was written for deterministic software and human-delivered services, and where AI is addressed it is often addressed by sublimit.
Armilla has pointed to general technology policies carrying a $25,000 sublimit for AI-related liabilities inside cover that otherwise runs to $5m.
Even the model developers feel it. OpenAI has reportedly arranged roughly $300m of cover for emerging AI risks through the broker Aon, against litigation claiming multiples of that figure.
When insurers will not comfortably cover the companies building the technology, the message to everyone deploying it is not subtle.
Insurers price from loss history, and there isn’t one. The losses that do exist correlate unpleasantly: if a widely used foundation model degrades or gets jailbroken, thousands of policyholders can have a bad day at once. Hard to model, easy to exclude.
Worth checking from the other side. A liability or E&O portfolio written before any of this may already cover AI losses without pricing for them, and leaving it there is a decision, not a default.
Excluding the risk leaves a gap businesses want filled. Deloitte’s Center for Financial Services expects AI-specific insurance premiums to grow at roughly 80% a year and reach about $4.8bn globally by 2032. Testudo, one of the new specialist underwriters, says generative AI litigation is up 137% year over year.
Armilla is a managing general agent and Lloyd’s coverholder built for AI risk. With Chaucer and other Lloyd’s underwriters it launched a standalone AI liability policy in spring 2025 that says out loud what standard policies now exclude: hallucinations, model drift, inaccurate outputs, data leakage, claims tied to defamation, confidentiality breaches and regulatory violations. Limits reach $25m per organisation.
The trigger is the interesting part. Rather than waiting purely for a lawsuit, Armilla underwrites the model’s expected performance and responds when it degrades from that baseline. Chief executive Karthik Ramakrishnan describes it plainly.
“We assess the AI model, get comfortable with its probability of degradation, and then compensate if the models degrade.”
Karthik Ramakrishnan, chief executive, Armilla
A chatbot that was right 95% of the time at bind and drops to 85% is a covered event, not a support ticket.
Armilla has noted that a policy of this shape could have responded to the Air Canada loss.
It is not a blank cheque. Tom Graham of Chaucer put the underwriting stance simply: “We will be selective, like any other insurance company.”
Testudo works the same seam from a standing start, launching as an MGA in January 2026 to write generative AI liability for vendors and deployers: third-party claims from AI outputs including hallucinations and model drift, plus legal costs and damages. By March 2026 the programme had expanded to $9.25m per insured, with Apollo, Atrium and QBE behind it. Peta Kilian, senior innovation underwriter at QBE, framed the appeal for capacity as the tooling rather than the wording: helping clients with “AI risk scoring and reporting tools”.
Munich Re’s aiSure turns the model itself into the rated object. It runs technical due diligence on the AI, quantifies how likely and how severe underperformance would be, and prices off that assessment. The cover indemnifies consequential financial loss: lost revenue, business interruption costs, legal damages.
Claims settle on measurable performance data rather than conventional loss adjustment, which makes it behave much more like parametric insurance than a liability policy. It is model-agnostic, so generative systems sit alongside classical machine learning. Munich Re has also put the product in other people’s hands, partnering with Mosaic to reach AI vendors.
A third group treats the audit as the product and the policy as what comes after.
The Artificial Intelligence Underwriting Company (AIUC) launched in July 2025 with a $15m seed round led by Nat Friedman’s NFDG, alongside Emergence Capital and Terrain. Its AIUC-1 standard is pitched as SOC 2 for AI agents: a security and risk framework covering the technical, legal and operational safeguards enterprise buyers ask about. Vendors certify to get through procurement, then buy insurance that protects their customers if the agent fails.
The certificate opens the door. The policy is what makes the promise credible.
Klaimee, out of Y Combinator’s spring 2026 batch, raised $5.5m in July 2026 for autonomous agents specifically. Every agent submitted goes through automated pre-bind testing: adversarial attacks, penetration testing, behavioural analysis, permission validation, operational stress testing. Out of it come an insurability score, a remediation report and an insurance-backed performance warranty. The company’s argument for existing is that tech E&O and cyber were “designed around deterministic software, data breaches and services delivered by humans”, which is not what an autonomous agent is.
Those four designs serve AI vendors and large deployers. HSB, the specialty insurer inside Munich Re Group, went after the long tail. On 18 March 2026 it launched AI Liability Insurance for small and mid-sized businesses, covering defence, settlement and judgment costs for third-party claims of bodily injury, property damage, or personal and advertising injury arising from the business’s own AI use.
The examples HSB gives are deliberately mundane: an AI-controlled HVAC system that creates a slip hazard, a chatbot that generates faulty appliance installation instructions, AI-written marketing copy that draws a copyright or defamation claim.
HSB’s own survey of 1,000 businesses with 1 to 500 employees found 74% already using AI and 91% planning to.
“All types of businesses are using AI to do things more quickly and efficiently. At the same time, the AI transformation brings new legal and financial exposures.”
Timothy Zeilman, Global Head of Product Ownership, HSB
The distribution choice matters as much as the wording. HSB does not sell direct: the coverage attaches to the business policies of its carrier partners, a faster route to a million small businesses than building a brand. Embedded insurance has distributed cover this way for years, and the mechanics of embedded insurance do not change because the risk is now a model.
| Design | What triggers a payout | How it is underwritten | Who buys it |
|---|---|---|---|
| Affirmative AI liability | Third-party claim, or measured performance degradation | Model assessment plus conventional liability underwriting | Enterprises deploying AI, AI vendors |
| Performance guarantee | A measured drop below the agreed performance level | Technical due diligence on the model, premium set by that assessment | AI vendors and their customers |
| Certify then insure | Agent failure covered by the warranty | Pre-bind testing against a published standard | AI vendors selling into enterprise procurement |
| SME add-on | Third-party claim arising from the business’s AI use | Rated with the underlying business policy | Small and mid-sized businesses, through their carrier |
| Specialist MGA | Third-party claim from AI outputs | Delegated authority, AI risk scoring | Vendors and deployers wanting standalone limits |
The rating inputs are all the same kind of thing: eval results, red-team findings, permission scopes, observed accuracy. Not headcount and industry code. Underwriting here is a technical test rather than a questionnaire, and several of these products pay when a measured number crosses a threshold, closer to parametric cover than to liability.
Certification is a revenue line and a sales tool, not an internal step: buyers want the certificate as much as the cover. Distribution sits next to the thing insured, on a carrier’s paper or a vendor’s enterprise sales cycle. Nobody is waiting for someone to search for AI insurance.
Data keeps flowing after bind. Audit logs, telemetry and model version changes are policy conditions, because a model underwritten in March is a different risk in September, and an upgrade can undo the assessment the price came from. Notification belongs in the wording, the re-test in the workflow.
Accumulation is the exposure nobody has a table for yet. If four hundred of your insureds run on the same foundation model, one bad release is a single loss event wearing four hundred hats. Model family has to be an exposure dimension from day one, which means AI reporting that can answer questions about concentration and loss ratio.
Every one of those decisions cuts against a legacy policy administration system. Rating engines in most cores are built around a stable set of factors keyed to industry classification, revenue and headcount: an AI liability product wants an insurability score, an accuracy baseline, a model identifier and a permission scope, plus a new factor next quarter when the market works out what actually predicts loss.
Claims modules assume a loss event and an adjuster, where a performance trigger has to open, evaluate and pay from a measured data feed. Meanwhile the capacity partner behind you still wants clean, conventional bordereaux every month, in the format their actuaries already use.
Product change cycles of three to six months are normal in this industry. They are fatal in a market where a competitor launched in January, expanded capacity in March and doubled its limits by summer.
Take a coverholder offering an agent performance warranty to companies selling AI customer-service agents. The vendor buys it; the vendor’s enterprise customers are the ones it reassures. Cover pays when measured resolution accuracy falls more than ten points below the level certified at bind, and when a third party brings a claim over an agent’s output. Illustrative, not a live account, but the shape is realistic.
Weeks one and two go on writing the product as a plain-English brief and building it in the AI Product Builder, which turns the brief into a change-set of coverages, limits, rating structure, underwriting rules and workflow, shown as a before-and-after diff and applied transactionally with a version history. Rating starts simple, on certified accuracy band, agent permission scope and annual interaction volume, in editable rating tables with effective dating.
A worked version of that build, screen by screen, is in the tutorial on creating an AI insurance agent product.
Week three wires the certification partner’s test output in over the API, straight-through rules take the clean scores, and the rest go to the underwriting workbench with the evidence attached, where document generation builds the certificate and policy pack.
Week four publishes quote and bind as a branded form and as an embedded API the vendor drops into its own contracting flow. Week five connects the monitoring webhook, so workflow automation opens a claim when the accuracy feed breaches the threshold, applies reserves and routes approvals, with two people signing off before payment. Week six agrees bordereaux templates with capacity and puts the first binder out.
Six weeks is not a stretch when nothing in that list requires a code release. It is out of reach when every step is a change request.
That gap is the argument for configuring products rather than developing them, and why the interesting activity here is coming from MGAs and coverholders rather than large carriers.
No platform decides for you what counts as failure. “The AI made a mistake” is not a trigger. “Measured accuracy on the agreed test set falls below X for Y consecutive days” is. Pricing, claims and every later argument with a policyholder rest on that sentence.
Regulation is arriving on the same schedule. A majority of US states have adopted the NAIC model bulletin on insurers’ use of AI or guidance close to it, and the EU AI Act is phasing in. Both govern how you use AI as well as what you cover, so tenant isolation, role-based access and an audit trail of who changed what have to be real rather than documented.
None of that is exotic technology. Either products, rules, rating and workflow are configuration your own team owns, in your environment or on managed cloud, or they are code someone else has to release. That is what Openkoda is, on published flat pricing with no percentage of your premium, and easier to see in a demo than to read about.
Two years ago insuring AI agents was a conference topic. Today there are affirmative liability policies at Lloyd’s with $25m limits, parametric performance guarantees from the world’s largest reinsurer, certification standards with insurance attached and an SME add-on riding carrier paper, while the policies that quietly covered some of this close off form by form.
Nobody has the right wording yet, so the teams that win will not be the ones with the best wording at launch. They will be the ones who can rewrite the wording, the rating and the triggers four times in two years without a migration project each time.

Surplus lines grew 10.4% in 2025 while filings outran premium in 2026. What specialty products ask of a PAS, and five tests to run before you buy one.

Six of the best policy management software systems for 2026, split by what they actually do: insurance policy administration, or internal policy governance.

What to actually test in a mutual insurer's policy, claims, billing, portal and reporting systems, and which platforms are worth a shortlist.
Book a live, personalized demo with our product team - tell us your use case and see the platform work with your data. No commitment.