Written and maintained by CASRAI Editorial Board
Last updated
No U.S. state currently requires AI developers or deployers to carry liability insurance. That is the plain answer to a question that gets asked with increasing frequency as state AI bills multiply. It is worth stating narrowly and precisely, because the interesting activity right now is happening one step removed from a mandate: insurers are mapping where AI risk is and is not underwritable, and a handful of states are regulating something adjacent but different — how insurers themselves use AI, not whether AI companies must buy coverage.
The lead fact, checked against a live tracker
AI Laws By State maintains a running index of AI legislation across all 50 states — as of this writing it tracks 69 published bills across 27 states, with 3 enacted into law. Its insurance-specific index returns no bill or enacted law anywhere that requires AI developers or deployers to hold liability insurance. The bills that do exist in this space cluster around impact assessments, bias auditing, consumer disclosure, and human-oversight requirements — none of them condition an AI company’s ability to build or deploy a system on proof of an insurance policy.
A January 13, 2026 Law360/Wiley Rein LLP analysis, “2026 State AI Bills That Could Expand Liability Insurance Risk,” reaches the same conclusion from the insurance-industry side. Its actual subject is not an insurance mandate — it is the proliferation of state-level private rights of action that expand what a company’s existing liability exposure looks like, which is a different mechanism entirely. Examples it cites: a New York bill allowing deepfake victims to sue for “punitive damages in addition to compensatory damages and injunctive relief”; a Michigan proposal permitting civil actions against AI-companion chatbots that encourage self-harm; a Florida bill letting minors or guardians sue for up to $10,000 per violation; and New York and Minnesota bills creating statutory or treble damages for AI-driven dynamic pricing. The throughline the analysis draws is that these new causes of action raise the stakes of the liability an AI company already carries — they do not require it to buy a new category of insurance to operate.
A different, adjacent question: states regulating insurers’ own use of AI
It is easy to conflate “AI liability insurance mandate” with a real and growing category of state activity: rules governing how insurance companies may use AI and algorithms in their own underwriting and claims decisions. That is regulation of the insurer as an AI deployer, not a requirement that AI companies carry insurance — a meaningfully different target.
Colorado is the clearest enacted example, but not through the bill most often cited for this. SB21-169 (“Restricting Insurers’ Use Of External Consumer Data”), enacted in 2021, prohibits insurers from using external data sources, algorithms, and predictive models in ways that unfairly discriminate on protected characteristics. It requires insurers to report the external data sources behind their algorithms to the insurance commissioner, build a risk-management framework to detect discriminatory impact, and obtain a chief risk officer’s attestation of proper implementation. That is a real, enacted, insurer-specific AI governance statute.
By contrast, Colorado’s general AI Act — SB24-205, the bill most often associated with this topic — is not insurer-specific at all. It is the broad developer/deployer high-risk-AI statute already covered in CASRAI’s own Colorado AI Act guide, and it explicitly exempts insurers that already comply with the insurance commissioner’s own data/algorithm rules (i.e., the SB21-169 regime). Citing SB24-205 as an insurer-AI-underwriting law gets the relationship backwards — it carves insurers out, it does not regulate them directly.
Florida’s activity in this space is real but not yet law: the National Conference of State Legislatures’ AI legislation tracker lists a Florida bill, S 1229 (“Insurance Disclosures”), that would require a property-and-casualty insurer to disclose to an applicant or insured when AI was used to make, or materially affect, a decision on an application or a claims review. NCSL’s tracker lists it as pending, not enacted.
A specific Alabama bill (frequently cited elsewhere as “SB63”) could not be verified against a readable primary source this session — the bill text retrieved was a corrupted PDF and the legislature’s bill-search tool did not return a usable summary. Rather than repeat an unverified citation, it is omitted here. If Alabama has enacted comparable insurer-AI rules, they are not confirmed on this page.
What’s actually moving: underwriters mapping the exposure
The more consequential activity right now is inside the insurance market itself, not the statehouse. On January 22, 2026, the Lloyd’s Market Association (LMA) published the results of a market survey, “Understanding AI Exposures: AI Loss Scenarios,” fielded across Q2–Q3 2025. It drew 144 responses, 94% of them from underwriters (the balance split across leadership, head-of-class, manager, and team-member roles), and asked them to score a set of AI-related loss scenarios across four lines of business on viability (out of 5), magnitude (out of 5), and overall impact (out of 25):
| Line of business | Viability | Magnitude | Overall impact | Rating |
|---|---|---|---|---|
| Professional indemnity | 2.82 | 3.8 | 10.72 | Moderate |
| Cyber | 3.42 | 2.87 | 9.82 | Moderate |
| Accident & health | 2.6 | 3.15 | 8.19 | Low |
| Product recall | 1.45 | 3.15 | 4.57 | Minimal |
Professional indemnity underwriters see the most viable, highest-impact AI exposure of the four lines tested — consistent with how widely AI is now embedded in the professional-services workflows those policies cover. The survey’s own supporting material (Annex 1) catalogues 65 distinct AI loss scenarios across 10 business classes, and Annex 2 maps LMA’s own cyber model wordings against AI-related exposure. The work sits under David Powell, the LMA’s Head of Technical Underwriting; CASRAI could not locate a verbatim public quote from him about the findings and has not invented one, but the survey itself — market-wide, underwriter-led, methodologically scored — is the clearest signal available that the market is actively pricing a risk category that, per the section above, no state yet requires anyone to insure against.
The LMA followed that survey with a practical artifact: an AI Adoption Toolkit, published April 23, 2026 in partnership with Barnett Waddingham, offering “practical, principles-based guidance to help firms move from early-stage experimentation towards more structured, governance-led adoption.” It accompanies a separate April 2026 LMA survey of chief actuaries and risk officers (39 respondents representing over 60% of Lloyd’s market stamp capacity, plus 11 in-depth interviews) that found 93% of respondents already have an AI governance framework in place or in development. Together, the two documents describe a market that is building its own internal AI governance faster than it is being told to by regulation — the opposite order from what a “state mandate” framing would predict.
The academic grounding: where AI risk is, and isn’t, insurable
“The Insurability Frontier of AI Risk” (Leung, Zhang, Ling, Toyoda, and Loh; arXiv:2605.18784, submitted May 2026) gives the LMA’s market-level findings a structural explanation. The paper systematizes 55 AI threat classes against 26 existing insurance products and organizes what it finds into a four-tier frontier: perils that are already affirmatively insured; “silent AI” exposures sitting inside legacy policies that were never written with AI in mind (cyber, E&O, D&O, EPLI, crime, and media policies, mostly); perils that carriers have moved to actively exclude; and perils that fall outside what private insurance can structure at all.
Different carriers are staking out different pieces of that frontier — the paper notes Munich Re concentrating on model performance and drift, Armilla and Lloyd’s on hallucination, Tokio Marine Kiln and CFC on intellectual-property exposure, Apollo on autonomous-system liability, and Coalition on deepfakes — which is itself evidence of a market still discovering where the lines belong, not one converging on settled terms. The paper’s most significant finding for where this eventually lands: “foundation model concentration” — the possibility that a single upstream foundation-model failure correlates losses across many insurers and many downstream policyholders simultaneously — as the frontier’s hardest open problem, because that kind of correlated, systemic loss is exactly the shape of risk that private insurance structurally struggles to price and reserve against. That is a more precise way to say what “not yet insurable” actually means than any single state bill currently attempts.
What this page does not claim
An earlier round of research for this cluster surfaced a claim, sourced only to a moonpool.ai blog post, that New York had created a bespoke catastrophic-harm liability regime specifically for frontier AI. No bill number, session, or legislative citation could be found for that claim, and it does not appear in AI Laws By State’s tracker, in the Wiley Rein analysis, or in New York’s own legislative search. It is discarded here rather than repeated with a hedge. New York’s genuinely enacted and pending AI activity — including the RAISE Act, covered in CASRAI’s existing frontier-AI-safety content — is a separate, verified matter and should not be read as indirect confirmation of the discarded liability-regime claim.
The NIKOLAI angle: what gets priced follows what gets classified and promised
CASRAI’s own NIKOLAI project — an independent, unendorsed reference dictionary of 64 frontier-AI-safety elements across 10 tracks — has no crosswalk row for Lloyd’s, the LMA, or any insurer, because NIKOLAI tracks how frontier AI developers, governments, and safety bodies describe their own systems, not how the insurance industry underwrites them. Rather than force a mapping that does not exist, the honest connection runs one level downstream: what an underwriter can actually price depends on what a developer has classified and promised in the first place.
Two NIKOLAI elements make that concrete. Incident Type, in Track N7 (Incidents), is NIKOLAI’s proposed controlled classification of AI incidents by mechanism and severity — weight exfiltration, loss-of-control or deceptive-subversion events, materialized catastrophic-risk harm, and lower-severity precursor or near-miss events — built because, as the element’s own definition states, “no unified enumeration exists across sources.” That is precisely the taxonomy gap the LMA’s 65-scenario Annex 1 is independently trying to fill from the underwriting side, for the same underlying reason: a loss cannot be scored, and a policy cannot be priced, against a category that has no shared definition. Commitment, in Track N9 (Commitments and Governance), is NIKOLAI’s proposed record of a public pledge — with its modality, scope, target date, and trackable status — of the kind Anthropic, OpenAI, and the Seoul Summit signatories have already made about frontier-safety practices. A developer’s binding commitments are the other half of what an underwriter needs: not just how a bad outcome would be classified, but what the insured party has already promised to do to prevent or contain it.
Put plainly: what gets measured under N7 and promised under N9 is what LMA’s underwriters would need in hand to price professional-indemnity or cyber exposure with any precision. No state requires that pricing to happen yet. The market is building the classification work anyway, on its own timeline, a year or more ahead of any statehouse — and NIKOLAI’s N7/N9 tracks are CASRAI’s own attempt at the same underlying problem, independently and unendorsed by any of the organizations named on this page.
Bottom line
- No U.S. state mandates AI liability insurance for AI developers or deployers, as of this writing — verified against a live legislative tracker and a January 2026 insurance-law analysis.
- A separate, real category exists: states regulating insurers’ own use of AI in underwriting and claims. Colorado’s enacted SB21-169 is the clearest example; Florida’s S 1229 is a pending, not-yet-enacted disclosure bill; an often-cited Alabama bill could not be verified and is not asserted here.
- The Lloyd’s Market Association’s January 2026 underwriter survey and April 2026 AI Adoption Toolkit show the insurance market actively mapping and building governance for AI exposure well ahead of any regulatory requirement to do so.
- Academic work (arXiv:2605.18784) frames why: AI risk splits into affirmatively-insured, silent, excluded, and currently-uninsurable tiers, with correlated foundation-model failure as the hardest open problem.
- A widely-repeated claim that New York created a bespoke frontier-AI catastrophic-harm liability regime could not be verified and is explicitly not asserted here.







