The AI Act is a safety code, not a liability regime. Yet the withdrawal of the dedicated directive has made it, by default, the keystone of liability for artificial intelligence, and compliance with the regulation has become the new frontier of insurability.
The European regulation on artificial intelligence, known as the AI Act, formally Regulation (EU) 2024/1689, which entered into force on 1 August 2024, is the first body of law in the world to regulate artificial intelligence in a general manner1. Its architecture rests on a pyramid of risks. At the top, a few uses deemed unacceptable are purely and simply prohibited. Below them, so-called high-risk systems are subject to a set of binding obligations. Lower still, limited-risk systems bear only transparency obligations, and the great mass of minimal-risk uses escapes any specific requirement. The whole regulatory stake concentrates on the intermediate category, that of high risk, which constitutes the core of the apparatus.
The two extremes of the pyramid deserve mention, for they illuminate its logic. At the top, the regulation purely and simply bans a few uses deemed contrary to the Union's values, among them generalized social scoring of citizens, manipulative techniques exploiting people's vulnerabilities, or certain uses of emotion recognition in the workplace and in education. These prohibitions, applicable since February 2025, tolerate no compliance, the use itself being forbidden. At the opposite end, the vast majority of applications, from spam filters to recommendation engines, falls under minimal risk and is subject to no specific obligation. Between these two bounds, the transparency imposed on limited-risk systems, such as conversational agents or artificially generated content, simply aims to ensure that the user knows they are interacting with a machine. This gradation reveals the legislator's intention, to concentrate the constraint where the stake for people's rights is highest.
A system reaches high-risk status by two distinct routes. The first, set out in Annex I, targets artificial intelligence embedded as a safety component in products already regulated by EU law, such as medical devices or machinery. The second, set out in Annex III, targets standalone uses spread across eight sensitive domains, among them biometric identification, critical infrastructure, employment, access to essential services, justice and law enforcement2. For these systems, the regulation imposes an arsenal of obligations covering risk management, data governance, technical documentation, logging, transparency, human oversight, as well as accuracy, robustness and cybersecurity, all validated by a conformity assessment procedure and registration in a European database3.
One must grasp from the outset the exact nature of this text, for it governs the whole analysis that follows. The AI Act is a market-access and product-safety regulation. It says how to lawfully design and deploy an artificial intelligence system, it does not say who pays when that system causes harm. The regulation institutes no right to compensation for victims, and its sanctions, which can reach 35 million euros or 7% of worldwide turnover for prohibited practices, are administrative fines paid to the public authority, not indemnities paid to the injured parties1. The question of civil liability, that is, of the reparation of harm between the author and the victim, falls to other instruments, and it is precisely there that the problem lies.
Before examining this problem, one must measure how directly the insurance sector is concerned. Annex III explicitly ranks among high-risk systems, at its point 5, artificial intelligence intended for risk assessment and pricing in life and health insurance with respect to natural persons2. Any insurer using artificial intelligence to underwrite or price its life or health contracts therefore deploys a high-risk system within the meaning of the regulation, and is subject to the entirety of the corresponding obligations. Property and casualty insurance is not explicitly named and remains a gray zone, but the signal is clear, the legislator has placed the insurer's pricing engine under direct regulatory supervision.
This inclusion places the insurer in a two-faced situation, almost without equivalent. On one side, it is a risk carrier, called upon to cover its clients' exposure to harm caused by their own artificial intelligence systems, and therefore to price a novel risk. On the other, it is itself regulated, its own pricing tools falling under high risk, with the requirements of data governance, non-discrimination and human oversight that this entails. The regulator of artificial intelligence thus regulates the very heart of the insurer's trade, the making of the price. This dual position echoes the debates on actuarial fairness and non-discrimination already tested in insurance, and extends the logic of prudential governance analyzed in relation to Solvency II in this series12.
The AI Act was never designed to function alone. The European legislator had conceived it as the first piece of a pair, the second being a specific directive on liability for artificial intelligence, proposed as early as September 2022. Where the regulation set out safety obligations upstream, this directive was to organize compensation downstream, by easing the burden of proof that falls on the victim of harm caused by an artificial intelligence, in particular through a rebuttable presumption of causality and a right of access to the evidence held by the developer4. The idea was to offset the technical opacity of these systems, which makes it almost impossible for a layperson to demonstrate the link between an algorithmic failure and their harm.
This second component will not see the light of day. In February 2025, in its annual work program, the European Commission withdrew its proposal for a directive on artificial intelligence liability, citing the absence of any foreseeable agreement and the priority given to simplification and competitiveness, in the wake of the concerns expressed by the Draghi report4. The consequence is direct. In the absence of European harmonization, fault-based liability for artificial intelligence falls back on national civil liability laws, each with its own rules, and the burden of proving the harm, the breach, the causal link and the fault rests once again, for the most part, on the victim. The pairing imagined by the legislator is thus broken, leaving a maximalist and harmonized safety regime resting on a fragmented liability landscape.
The withdrawal of the dedicated directive does not leave the victim without recourse, for another instrument has met the opposite fate. The revised directive on liability for defective products, Directive (EU) 2024/2853, adopted in October 2024 and which member states must transpose before 9 December 2026, thoroughly modernizes a framework inherited from 19855. Its decisive novelty is now to include software and artificial intelligence systems explicitly within the notion of product, and to treat the providers of such systems as manufacturers. Harm caused by a defective artificial intelligence therefore falls under strict liability, where the victim does not have to demonstrate the manufacturer's negligence, but only the defect of the product, the harm suffered and the causal link between the two.
To take account of the opacity of complex systems, the revised directive introduces presumptions of defectiveness or causality in cases where proof would be excessively difficult, as well as an obligation for the manufacturer to disclose the relevant evidence when the victim makes their claim plausible5. It also takes into account the fact that software evolves after being placed on the market, through updates or learning. Its scope nonetheless remains strictly delimited. It covers personal injury, property damage and the destruction of data, but it excludes purely economic loss, non-material damage and, above all, infringements of fundamental rights such as algorithmic discrimination. These blind spots, considerable in view of the risks specific to artificial intelligence, fall back on national laws, accentuating fragmentation.
For the insurer, this legal landscape creates an exposure that existing contracts had not anticipated. The losses specific to artificial intelligence, whether the hallucinations of a language model, algorithmic bias or the drift of a model over time, often escape the scope of classical policies, designed for a world where error was human. The phenomenon is massive, litigation linked to generative artificial intelligence having risen by 978% in the United States between 2021 and 2025 according to joint work by Gallagher Re and the Massachusetts Institute of Technology6. The associated loss experience presents a formidable profile, of low frequency but very high severity, with a risk of accumulation when a single model failure propagates to thousands of users simultaneously, a configuration already encountered in this series in relation to systemic incidents10.
This profile poses a formidable capacity problem. A failure affecting a widely distributed model, for example a foundation system used by thousands of companies, could trigger a wave of correlated losses that classical pooling could not absorb, in the image of cyber accumulation. Reinsurers therefore approach this risk with caution, aware that the absence of history forbids a robust actuarial pricing and imposes a largely qualitative approach, founded on the assessment of the model's governance and quality rather than on a statistical distribution of losses11. This indeterminacy brings the risk of artificial intelligence closer to climate and cyber risks, where the lock of insurability is not the existence of the danger but the impossibility of measuring its distribution tail.
The insurance market reacts according to a pattern that readers of this series will recognize, the one that marked silent cyber. In a first phase, AI risk lodges implicitly in policies that have not priced it, a non-affirmative exposure that insurers now seek to clarify. Providers of model clauses circulated in 2026 standardized exclusions allowing generative artificial intelligence to be carved out of civil and professional liability coverage, and several major insurers have begun to exclude this risk explicitly7. In a second phase, dedicated affirmative coverage emerges. The Lloyd's market saw the birth, as early as April 2025, of a first AI liability policy coupled with continuous validation of the model, followed by comparable products covering up to several tens of millions of dollars, while established insurers adjust their coverage through endorsements8. The shift from silent to affirmative, already observed for cyber, thus structures the nascent market of artificial intelligence insurance.
From this interlacing a major practical consequence emerges for the insurer. Since compliance with the AI Act tends to become the standard of care on which liability will depend, it also becomes the natural criterion of underwriting. Respect for the regulation's obligations, documented risk management, traceability, human oversight, data quality, tends thus to impose itself not as a mere pricing factor but as a precondition of coverage, in the image of what the NIS2 directive produced for cyber7. The insurer outsources to the regulator part of its selection work, relying on an enforceable legal benchmark to distinguish underwritable risks from those that are not. Regulatory compliance and the insurance guarantee find themselves, once again, entangled.
This articulation leaves a clear boundary between what is transferred and what is not. As with the NIS2 sanctions, the administrative fines of the AI Act are, by a public-policy principle in many jurisdictions, largely uninsurable, for insuring a sanction would neutralize its deterrent effect. What remains insurable is civil liability, that is, the reparation of harm caused to third parties, whose contours nonetheless remain uncertain and non-uniform for want of harmonization. To this substantive uncertainty is added a timetable uncertainty, the political agreement of 7 May 2026 on a digital omnibus having postponed the application of the high-risk obligations of Annex III to December 2027 and those of Annex I to August 2028, and opened the possibility of disapplying the regulation's requirements where sectoral rules already cover the same ground9. This delay buys time, it does not resolve the underlying asymmetry.
A public-policy question is moreover beginning to emerge from this imbalance, that of whether the liability insurance of artificial intelligence designers should be made mandatory, in the image of what exists for motor or medical liability. Proponents see in it a means of guaranteeing the effective compensation of victims faced with sometimes insolvent actors, and of disciplining the market through the insurance requirement. Opponents fear that such an obligation would hold back innovation and entrench the position of the large players able to bear its cost. No jurisdiction has for now taken this step, but the mere fact that the debate is opening confirms that insurance is called upon to play a central role in the liability architecture that the withdrawal of the dedicated directive has left incomplete, whether it acts through the market or through legal constraint.
At the close of this analysis, the AI Act appears in a paradoxical light. Conceived as a safety code devoid of any compensation mechanism, it has become, through the withdrawal of the instrument that was to complete it, the keystone of the liability regime for artificial intelligence. Its obligations define the diligence expected, the Product Liability Directive draws from it the notion of defect, national laws draw from it the notion of fault, and insurance makes it the condition of coverage. The real question of the coming years is therefore not whether liability for artificial intelligence exists, it already does, but how to price an exposure whose substance is set by a harmonized safety code while its sanction remains entrusted to fragmented national courts. As long as this asymmetry persists, between a unified safety and a shattered liability, the insurance of artificial intelligence will remain a discipline of uncertainty, where compliance with the regulation constitutes the only stable foundation, and the new frontier of insurability, the one on which will be decided the sharing between what the market will be able to bear and what the community will have to take on.
NIS2 does not mention insurance even once, and it does not directly regulate insurers. Yet by raising the cybersecurity baseline of fifteen to twenty thousand French entities and by making executives personally liable, this directive profoundly reshapes the risk that insurers underwrite.
Solvency II rests on two postulates inherited from classical actuarial science, the ability to diversify weakly correlated risks and the ability to estimate their distribution from historical data. Cyber risk contradicts both.
The Insurance-Linked Securities market represents a quiet revolution in global finance: for the first time, catastrophe risk migrates off insurer balance sheets into the portfolios of pension funds and institutional investors.
A mid-sized company receives a letter from its largest client, a clause demanding proof of NIS2 compliance within ninety days, or the contract ends. Its director has never heard of NIS2. And they are wrong not to worry.
A leader makes a decision, a merger, a launch, a restructuring. It fails, the shareholders lose money and sue them, personally. Their house, their savings are on the line. And yet they sleep soundly, because an insurance exists that covers them against the consequences of their own judgment.