Insurers Split Over AI Coverage As Misinformation And Deepfakes Drive Most Reported Harms
Businesses are rapidly embedding artificial intelligence into customer service, hiring, fraud detection and autonomous systems, but insurance coverage for any resulting harms remains fragmented and inconsistent, according to RAND.
The report, from RAND’s Institute for Civil Justice and Feinberg Center for Catastrophic Risk Management and Compensation, examined the AI Incident Database, a George Washington University database of AI lawsuits, enacted state laws and insurance filings submitted through the industry’s electronic rate and form filing system. Of 713 generative AI incidents tracked since ChatGPT’s November 2022 launch, 599, or 84%, involved misinformation or deepfakes, RAND found. An additional 47% of incidents fell into categories including hallucinations and factual errors (30%), harmful content (13%) and agentic or autonomous failures (12%), with some incidents spanning multiple categories.
Litigation tells a different story. Of 249 U.S. generative AI lawsuits reviewed, 150, or 60%, centered on intellectual property or training-data disputes against AI developers rather than harms from model outputs, RAND found. Privacy and surveillance claims, fraud and deception cases, and product liability suits, including wrongful-death claims tied to companion chatbots, made up smaller but growing shares.
Separately, most of the 189 enacted state AI laws RAND examined target harmful synthetic content: 33 states have passed 62 laws addressing nonconsensual intimate images and child sexual abuse material.
Carriers Diverge On Exclusions, Coverage And Silence
Insurers are not treating AI as a single peril or a stand-alone line, RAND found, because the same model can generate very different forms of loss depending on how it is trained, deployed and used.
Some major carriers are moving to exclude AI losses broadly. Verisk/ISO developed exclusionary language in January 2026 for bodily injury, property damage and personal and advertising injury caused by generative AI, and its standardized forms appear in more than 80% of U.S. property and casualty policies, according to the report.
Berkley revised its directors and officers, errors and omissions, and fiduciary liability policies to exclude claims tied to nearly any use, deployment or development of AI, including a company’s own statements about its AI capabilities, the report said.
RAND said filing data show exclusion activity surging beginning in summer 2025, concentrated in commercial umbrella and commercial general liability policies.
Other carriers are moving toward affirmative coverage. Munich RE, AXA XL and Coalition have expanded policies to address hallucinations, bias, privacy infringement and AI-enabled fraud, while new entrants including Testudo, Armilla and the Artificial Intelligence Underwriting Company offer stand-alone AI liability products, some with limits up to $50 million, according to RAND.
Most carriers, however, are doing neither, leaving policies silent on whether AI-related losses are covered. RAND said this silence does not necessarily create ambiguity for policyholders in every case, but coverage still depends on policy language, the theory of liability and how exclusions and definitions not drafted with AI in mind ultimately apply.
Accumulation Risk And A Widening Protection Gap
RAND identified five mechanisms that could produce correlated, large-scale losses across insurers:
- Universal attacks exploiting the same vulnerability across many AI systems.
- Common dependency on shared models or infrastructure, including hyperscalers Amazon Web Services, Microsoft Azure and Google Cloud.
- AI acting as a “force multiplier” for cyberattacks.
- Legal or regulatory shocks that suddenly expose many firms to liability at once.
- Subtle, prolonged degradation of model performance.
RAND said the size of the AI protection gap, the difference between economic losses and insured losses, and the extent of insurer accumulation exposure are linked: broader affirmative coverage shrinks the protection gap but raises insurer exposure, while broader exclusions do the reverse. Silent coverage, the report said, obscures both metrics, making it difficult for policyholders, insurers and regulators to determine what is actually insured.
RAND recommended that state insurance regulators and the National Association of Insurance Commissioners develop a standardized AI Coverage Notice, that industry stakeholders build a common taxonomy for tracking AI incidents and claims, and that insurers and reinsurers conduct and disclose AI accumulation scenario analysis.
Obtain the full report here. &

