Note: This is a research note supplementing the book Unscarcity, now available for purchase. These notes expand on concepts from the main text. Start here or get the book.
The Uninsured Frontier: Who Underwrites an AI Catastrophe?
On October 5, 2026, all 51 members of the New York City Council sat for one hearing, a format they almost never use, to question four companies under oath: OpenAI, Anthropic, Google and Meta. Speaker Julie Menin had written to the chief executives. She got policy staff: Morgan Dwyer, OpenAI’s head of policy development and operations; Logan Graham, a researcher at Anthropic; Shane Cahill, Meta’s director for privacy and AI legislation; and Alice Friend for Google. A fifth company had been subpoenaed and did not come. “SpaceXAI, however, is not here at all in direct violation of the subpoena that we issued last week,” Menin said.
She asked four questions. What are the odds of a catastrophe? Dwyer: “I don’t know. I also don’t think it matters whether it’s 1% or 10% or a 20% chance that something catastrophic will go wrong.” Friend said there was “not yet a rigorous scientific method for assigning a probability.” Do you carry insurance against a catastrophic failure? Dwyer and Cahill said they did not know and would follow up; nobody said yes. Would you accept legal liability if your system caused serious harm or death? Only Friend answered directly: “if it’s illegal without AI, it’s still illegal with AI.” Would you halt a model that failed a safety test? Each witness described a review process. None said yes. “I think a simple yes or no would instill more confidence in the public on a matter as serious as this,” Menin said. She called the answer on the odds “flippant at best.”
Five days earlier, the heads of the same companies had stood with the President and signed a White House accord, the Joint Commitment on Frontier Responsibilities. The signatures were Dario Amodei’s, Sundar Pichai’s, Mark Zuckerberg’s, OpenAI president Greg Brockman’s, Nvidia’s Jensen Huang’s and Elon Musk’s. The text commits each company to internal controls, an independent external auditor and a board-level committee that reads the audits. It carries no penalty for breaking it, and it says it “may make sense” to turn the commitments into law at some later date. “I think I’m seeing tremendous self-policing,” Trump said. “And they understand that they have to self-police.”
Dwyer is half right. Nobody can put a defensible number on the probability of an AI catastrophe today, and Menin’s demand for one will not be met this year. But the industries that learned to live with unknowable catastrophic risks never settled the probability question first. They settled a different question: who posts the money, how much, and before what? That question has an answer in every one of them. It is the only one of Menin’s four that a hearing can actually force.
The insurance market already answered
The witnesses did not know whether their companies were insured. Their insurers know. On January 1, 2026, the Insurance Services Office’s generative-AI exclusion endorsements took effect for commercial general liability policies. The broadest, CG 40 47, strikes AI-related bodily injury, property damage and personal and advertising injury from coverage outright. More than 60 property and casualty groups have filed to adopt the forms. By April 23, The Information reported, state insurance commissioners had approved more than 80 percent of carrier requests to exclude AI damages from corporate policies. W.R. Berkley went further and proposed excluding “any actual or alleged use” of AI from its directors-and-officers, errors-and-omissions and fiduciary lines.
That is the bottom of the stack, the coverage an ordinary company buys. At the top, where the model makers sit, the picture is thinner. In October 2025 the Financial Times reported that OpenAI had secured up to $300 million of emerging-risk cover through the broker Aon, against lawsuits already measured in billions, and had discussed setting up a captive insurer funded from its own investors’ money. Aon’s head of cyber risk, Kevin Kalinich, said the sector simply lacks “enough capacity for (model) providers.” Anthropic paid its $1.5 billion copyright settlement from its balance sheet. Cumulative U.S. lawsuits involving generative AI grew 978 percent between 2021 and 2025, according to Testudo Global data cited by the Center for Strategic and International Studies.
The Cloud Security Alliance’s September 30 research note explains why carriers are filing exclusions rather than writing policies. Underwriters test a new peril against four classical criteria: predictable frequency, boundable severity, independence across policyholders, and the absence of severe information asymmetry. Generative AI strains or fails all four. The note’s sharper point is that this is not ordinary risk, where losses are large but a distribution exists. It is Knightian uncertainty, where there is no loss history from which to compute any actuarially defensible rate at all. CSIS’s Gregory Allen, writing three weeks earlier, drew the consequence: insurance has become “the most important de facto regulator of U.S. AI deployment,” not through any rulemaking but through thousands of individual decisions to decline.
Read those two documents next to the hearing transcript and the honest answer to Menin’s second question is already on file with fifty state regulators. The market’s price for the catastrophic tail of a frontier model is currently “no.” And a risk nobody will underwrite has not disappeared. It has been assigned, by default, to the public.
Five industries that refused to accept “we don’t know”
The United States has faced this exact configuration before: a technology judged too valuable to stop, a worst case too uncertain to price, and insurers heading for the exit. Five times, Congress answered with the same instrument.
Nuclear reactors, 1957. The Price-Anderson Act requires every licensed plant site to carry the maximum liability insurance the market will sell, currently $500 million. Above that sits a second layer the industry funds itself: after any incident, every power reactor in the country is assessed a “retrospective premium,” capped at about $158 million each. With 95 reactors covered, the two layers provide roughly $15.5 billion per incident, about $16.3 billion with the permitted surcharge. Operators must waive most legal defenses after a severe release. Congress passed this in 1957, eighteen years before the first serious probabilistic risk assessment of a reactor existed, and in 2024 extended it to December 31, 2065. One detail matters for today: because Price-Anderson covers nuclear damage, every property and liability policy in the United States excludes nuclear accidents, which is precisely the move insurers are now making for AI. The nuclear exclusion came with a sixteen-billion-dollar pool behind it. The AI exclusions come with nothing.
Oil tankers, 1990. After the Exxon Valdez, the Oil Pollution Act required any vessel over 300 gross tons to obtain a Coast Guard Certificate of Financial Responsibility proving it can pay up to its statutory liability limit for a spill, and it created the Oil Spill Liability Trust Fund, financed by an excise tax on each barrel of oil, to pay what the responsible party cannot. No certificate, no U.S. port. The rule did not wait for anyone to agree on how likely the next grounding was.
Rockets, 1988. Under the Commercial Space Launch Act, the FAA computes a maximum probable loss for every licensed launch, and the operator must show funds equal to it before flying, up to $500 million for third-party claims. The government indemnifies the next tier, $1.5 billion in 1988 dollars adjusted for inflation, a figure the GAO put at about $2.7 billion in 2012, and the operator is liable above that. SpaceX has never launched a rocket without posting that bond. Its AI arm skipped a subpoena about whether it holds anything comparable.
Terrorism, 2002. The September 11 attacks produced roughly $60 billion in insured losses in today’s dollars. Reinsurers pulled terrorism cover almost overnight, insurers filed exclusions, and by early 2002 most state regulators had approved them. Real-estate lending nearly stopped, because no bank would lend against a building that could not be insured. Fourteen months after the attacks Congress passed the Terrorism Risk Insurance Act: insurers must make terrorism coverage available, and the federal government shares losses above an annual threshold ($58.7 billion for 2026). It has been renewed four times, both chambers passed a further extension to 2034 this September, and in 24 years no certified act of terrorism has ever triggered a payout. Its value was never the payout. It was the market it kept open.
Vaccines, 1986. A wave of lawsuits over the DPT vaccine drove most manufacturers out of the market and the last major one threatened to follow. The National Childhood Vaccine Injury Act created a no-fault compensation program funded by a 75-cent excise tax on every dose of a covered vaccine, per disease prevented, so a measles-mumps-rubella shot pays $2.25. The manufacturers stayed. The injured got paid without proving fault. The tax made the risk a line item instead of an argument.
Strip away the industries and the design is identical each time. A mandatory, pre-funded, publicly visible answer to “who pays.” A first layer the operator buys. A second layer the industry carries collectively, so that each firm’s recklessness lands on its competitors’ invoice. A government layer at the top for the truly correlated tail. And a condition precedent: no certificate, no license, no launch, no port. Not one of these regimes required anyone to agree on the probability first.
What a bond does that a pledge cannot
The White House accord asks for internal controls, an auditor and a board committee. A financial-responsibility regime asks for something the accord structurally cannot produce.
It makes someone else believe the risk assessment. The accord’s auditor is paid by the lab and reports to the lab’s board. An underwriter who writes a ten-billion-dollar layer has its own capital on the line. It will ask for the evaluation results, the incident logs, the shutdown procedure, and it will price what it sees. If the answer to “how likely is a catastrophe” is genuinely unknown, the premium says so, in a number the lab’s chief financial officer has to sign. That is the discipline Menin was reaching for when she compared the witnesses to a drugmaker unable to confirm its product is safe.
It makes “we don’t know” expensive. Under Price-Anderson, a meltdown at one utility bills every other utility in the country. Mutualized liability turns an industry into a watchdog of its own weakest member. In AI, it would make SpaceXAI’s empty chair the other four companies’ problem, which is a far more reliable enforcement mechanism than a council’s contempt motion.
It builds a stop that does not depend on the operator’s judgment. Menin’s lead bill requires a human able to shut a deployed system down and a third-party validator to certify it, at $25,000 per violation. A certificate regime gets the same effect by another route: when an insurer cancels cover, the fleet is grounded, the tanker stays out, the reactor idles. Nobody at the company has to decide to halt. The absence of a bond halts it.
It puts the number where the public can see it. Posted capital is a disclosure. On September 15, Treasury Secretary Scott Bessent told the House Financial Services Committee that what the government “shouldn’t do on safety is to give these labs a liability exemption, which is what they are asking for,” and that “the best way to guarantee safety is that the creators are liable for what they build and generate.” Anthropic intends to list in November at a valuation near $2 trillion. Its prospectus will be the first document in which a frontier lab’s insurance, or the lack of it, is written down for the Securities and Exchange Commission.
The hard parts
None of this is simple to transplant, and the places where it is hard are instructive.
Correlation. A reactor accident is local. A flaw in one model is deployed in millions of places at once, which is the “independence across policyholders” criterion failing on purpose. That is an argument against retail AI policies, and for exactly the pooled-and-backstopped structure that nuclear and terrorism use. Individual carriers cannot carry a correlated tail. A pool plus a sovereign layer can.
Defining the event. Each regime names its trigger: an “extraordinary nuclear occurrence,” a “discharge,” a “certified act of terrorism,” and in each case someone outside the industry does the certifying. AI has no agreed definition of a reportable incident, and today the labs write their own. New York’s amended RAISE Act, effective January 1, 2027, requires frontier developers to disclose incidents within 72 hours to a new office inside the Department of Financial Services, the state’s insurance regulator, which is not a coincidence. Who investigates the event is the subject of its own note.
The cap. Every liability limit is a subsidy to the industry it limits; the Congressional Research Service records that critique of Price-Anderson in its first paragraph. Bessent’s warning about a liability exemption is the same worry in modern dress. The answer in the precedents is that the cap sits only above a mandatory pool large enough to hurt, and that the premiums are retrospective, so every firm’s conduct moves every other firm’s bill. A cap with no pool beneath it is an exemption with better branding. The labs have asked for the exemption. Nobody has yet offered them the pool.
Moral hazard. A government backstop that is never used can look like a free guarantee. TRIA has never paid; Price-Anderson’s pool has never been breached. The discipline comes from the lower layers, which are priced, posted and renewed, and from the condition precedent. A backstop without a certificate in front of it is just a promise of bailout.
The Unscarcity read
The book’s governance rules apply here with unusual precision.
Power Must Decay. A company that holds civilization-scale leverage while carrying no priced, posted capital against its own failure has not shouldered a risk. It has exported one. Capital at risk is the oldest decay mechanism there is: you lose it when you fail, and the amount you must post rises with the damage you can do. The witnesses in New York could not say whether their companies had posted anything. Under a financial-responsibility regime the question answers itself, in public, every renewal period.
Truth Must Be Seen. An insurer’s refusal to price a risk is the most honest information in this entire debate, and it is currently buried in exclusion filings at fifty state insurance departments. A bond makes the same information legible: the size of the pool, the premium, the trigger, the certifier. The hearing produced “I don’t know” four times. A certificate regime produces a number, and a name attached to it.
The liability gap note argued that a professional license sells accountability, not knowledge: the point of a doctor’s signature is that someone stands behind the advice. Insurance is the receipt for that promise. A frontier lab that cannot name its underwriter is selling a license with no one behind it. And the book’s picture of AI as a referee, auditable and bounded, assumes that a referee who makes a catastrophic call can be made to pay for it. A referee no one can bill is not a referee. It is a sovereign.
New York’s proposed price is small: $25,000 per unvalidated deployment, with a quarter of any recovery paid to whoever reports it and half if they bring the case themselves. The nuclear industry carries sixteen billion dollars against a single incident. But the council did something the White House accord did not: it put a number, however modest, on the shrug.
What to watch
- The follow-up. OpenAI and Meta said they would come back with an answer on insurance. Whether that answer is public, and whether it names an amount, is the first test of whether the hearing produced anything.
- Anthropic’s prospectus. A November listing means risk factors, litigation reserves and coverage written for the SEC, the first time a frontier lab’s financial responsibility is documented rather than asserted.
- The validator and bounty bills. If New York enacts third-party validation with a human shutdown requirement, the validators will need professional liability cover of their own, and the insurers who write it will become the first independent assessors of frontier systems.
- The empty chair. SpaceXAI’s subpoena can be enforced through the state courts. A company that posts a maximum-probable-loss bond before every rocket launch will have to explain why its AI unit posts nothing.
- A backstop proposal. CSIS has already sketched a Price-Anderson-style layered reinsurance mechanism for correlated AI losses, together with a NIST incident database to supply the loss data insurers lack. Watch whether any legislator picks it up, and whether the labs, who are asking for an exemption, accept a pool as its price.
Related Articles
- The Liability Gap: What a License Really Sells - accountability is the product; insurance is its receipt
- Who Investigates the Machine? An NTSB for AI Agents - who gets to define the reportable event
- Frontier AI Emergency Governance Protocols - a warning without infrastructure is theater
- Accountability Laundering: When the AI Takes the Blame - why “the model did it” cannot be the end of the invoice
- A Black Box for AI Agents - the log an underwriter would ask to see
- Human-in-the-Loop: Where AI Agents Must Stop - the shutdown Menin’s bill requires
- IPOs, Shareholder Primacy and Abundance - what a listing forces a lab to write down
- Foundational Principles - Power Must Decay and Truth Must Be Seen
Sources
- Anthropic, OpenAI, Google, Meta execs testify at NYC Council AI hearing - CNBC (October 5, 2026)
- AI giants give few clear answers to key safety questions at NYC Council hearing - amNY (October 5, 2026)
- OpenAI, Anthropic, Google and Meta face 10 proposed NYC AI bills - PPC Land (October 2026)
- New York City Council to hold major hearing on artificial intelligence risks - NYC Council press release (September 16, 2026)
- Speaker Menin issues rare subpoena to Elon Musk’s SpaceXAI - NYC Council press release (September 28, 2026)
- Trump says top tech firms have signed accord to self-police AI development - NPR via WLRN (September 30, 2026)
- Trump accord calls for tech firms to self-police their own frontier AI - Cointelegraph (September 30, 2026)
- The Insurance Industry’s Retreat from AI Threatens to Slow Innovation and Adoption - CSIS, Gregory C. Allen (September 4, 2026)
- The AI Insurability Gap: Why Insurers Can’t Price What They Can’t See - Cloud Security Alliance (September 30, 2026)
- OpenAI, Anthropic eye using investor funds to settle AI copyright lawsuits, FT reports - Insurance Journal (October 8, 2025)
- Treasury’s Scott Bessent says no liability exemptions for AI labs - FedScoop (September 15, 2026)
- Price-Anderson Act: Nuclear Power Industry Liability Limits and Compensation to the Public - Congressional Research Service IF10821 (February 28, 2025)
- Financial Responsibility for commercial space launch and reentry - FAA Office of Commercial Space Transportation
- Commercial Space Launches: FAA Should Update How It Assesses Federal Liability Risk - GAO-12-899 (2012)
- What is a COFR? Certificates of Financial Responsibility under OPA 90 - Falvey Insurance Group
- How 9/11 rewired American insurance - Insurance Business (September 9, 2026)
- Senate passes seven-year extension of the Terrorism Risk Insurance Program - Insurance Journal (September 29, 2026)
- About the National Vaccine Injury Compensation Program - HRSA
- NY overhauls transparency and governance requirements for frontier AI developers - Davis Wright Tremaine (April 2026)
- Anthropic targets November for IPO, pushing back from October - Crypto Briefing (September 19, 2026)