Home Blog Page 18

EPLI in the Age of “Ghosting”: Why Your AI Hiring Tool is a Liability Magnet

Hiring manager reviewing AI-ranked job candidates on a computer during an automated recruitment process.

Job-market ghosting traditionally means one side suddenly stops communicating.

An applicant:

  • Applies for a position.
  • Completes an assessment.
  • Uploads a résumé.
  • Records a video interview.
  • Answers chatbot questions.

Then:

Nothing.

No recruiter calls.

No explanation arrives.

The candidate may simply receive an automated rejection—or hear nothing at all.

AI hasn’t created candidate ghosting, but large-scale automated recruiting can make it easier for businesses to process enormous applicant pools with very little human interaction.

That creates an important risk-management problem.

The more hiring decisions you automate, the more important it becomes to understand:

how those decisions are actually being made.

What Is EPLI?

Employment Practices Liability Insurance, commonly called EPLI, is designed to address certain employment-related claims.

Depending on the policy, allegations can include:

  • Discrimination
  • Harassment
  • Wrongful termination
  • Retaliation
  • Failure to promote
  • Certain hiring-related claims
  • Other specified employment practices

Policy terms differ considerably.

An EPLI policy doesn’t mean:

“Anything involving an employee is covered.”

And AI-related claims can create additional questions involving definitions, exclusions, regulatory proceedings and third-party technology.

The New Hiring Department May Be an Algorithm

Consider a company receiving:

8,000 applications

for:

100 positions.

Human recruiters cannot realistically conduct detailed initial reviews of every applicant.

So the company deploys an AI-assisted hiring platform.

The system:

8,000 applicants

2,000 candidates pass initial screening

500 receive automated assessments

200 receive interviews

100 hired

Efficient?

Absolutely.

Risk-free?

No.

The key question becomes:

What caused the algorithm to eliminate the other 7,900 people?

AI Can Screen Résumés

Employers increasingly use automated tools for functions such as:

  • Résumé screening
  • Candidate ranking
  • Skills matching
  • Assessment scoring
  • Interview analysis
  • Recruiting chatbots

The EEOC specifically identifies résumé keyword screening and recorded-video interview evaluation among examples of AI use that workers may encounter during hiring.

Automation itself isn’t automatically discriminatory.

The risk is that:

inputs + training data + model design + employer configuration

can potentially produce unlawful outcomes.

Example: The Historical Hiring Problem

Imagine a company trains a hiring model using data from its:

highest-performing employees over the past ten years.

That sounds reasonable.

But suppose historical hiring practices resulted in one demographic group being heavily overrepresented.

The model identifies patterns associated with those employees.

It may then favor candidates displaying similar patterns.

The employer never programs:

“Reject Group X.”

But the system may still produce disparities.

This illustrates why:

intent

and

outcome

aren’t necessarily the same thing.

Existing Discrimination Laws Still Apply

AI does not operate outside employment law.

The EEOC states that federal employment-discrimination protections continue to apply when employers use AI.

Protected characteristics under federal law can include:

  • Race
  • Color
  • Religion
  • Sex
  • National origin
  • Age 40 or older
  • Disability
  • Genetic information

depending on the particular statute.

An employer generally cannot defend an unlawful hiring practice merely by saying:

“The algorithm selected the candidates.”

Disparate Impact Is an Important Risk

Employment discrimination isn’t limited to explicitly telling a system:

“Don’t hire women.”

A seemingly neutral selection procedure can also create legal problems when it disproportionately excludes members of a protected group and cannot be appropriately justified under applicable law.

The EEOC explains that employment tests and selection procedures can violate federal anti-discrimination laws when they disproportionately exclude people based on a protected characteristic unless the employer can justify the procedure under applicable legal standards.

AI screening tools therefore deserve the same scrutiny as other employee-selection procedures.

Disability Can Create a Different AI Problem

Consider a candidate with a disability.

The employer uses an automated video assessment.

The system evaluates behavioral characteristics that are supposedly associated with successful employees.

But the candidate’s disability affects how they interact with the software.

The algorithm gives them a poor score.

They are rejected.

The candidate may have been perfectly capable of performing the actual job.

The EEOC has specifically warned that algorithmic hiring tools may unlawfully screen out people with disabilities who could perform a job with or without reasonable accommodation.

Reasonable Accommodation Still Matters

An employer using AI should have a process for candidates who need accommodation.

The EEOC identifies reasonable accommodation as one of the key concerns when employers use algorithmic decision-making tools.

For example, depending on the circumstances, a candidate might need:

  • Alternative assessment format
  • Additional time
  • Accessible technology
  • Human-assisted process
  • Alternative method of demonstrating ability

Businesses should ensure that applicants know how to request appropriate accommodations.

“Our Vendor Built It” Is Not a Complete Defense

This may be one of the most important lessons for businesses.

Imagine an employer buys an AI recruiting platform.

The vendor says:

“Our algorithm is unbiased.”

The employer activates it.

Six months later, applicants allege discrimination.

Can the employer simply say:

“Talk to the software vendor”?

Not necessarily.

New York City guidance, for example, states that employers, employment agencies and their agents can face liability under city human-rights law for discrimination resulting from technology or AI.

Vendor selection therefore becomes part of employment-risk management.

Ask Your AI Vendor Difficult Questions

Before deploying a hiring tool, businesses should understand:

  1. What employment decisions does the system influence?
  2. What data does it collect?
  3. How are candidates scored?
  4. What variables affect ranking?
  5. Has the tool been tested for discriminatory outcomes?
  6. How frequently is it tested?
  7. What accommodation options exist?
  8. Can a human override the recommendation?
  9. How are overrides documented?
  10. How long is candidate data retained?
  11. Does the vendor use customer data for model training?
  12. What happens when the model changes?
  13. Who investigates suspected errors?
  14. What contractual protections does the vendor provide?
  15. Will the vendor cooperate during litigation?

If the vendor cannot clearly answer basic questions about a system influencing hiring decisions, that is itself a risk signal.

New York City Already Regulates Automated Hiring Tools

New York City provides one of the clearest examples of specific AI hiring regulation.

Local Law 144 restricts employers and employment agencies from using covered Automated Employment Decision Tools (AEDTs) unless certain requirements are satisfied.

Among them:

Bias audit

The tool must have undergone the required bias audit within the applicable period.

Public disclosure

Information concerning the audit must be made publicly available.

Notice

Covered candidates and employees must receive required notice.

Enforcement began in July 2023.

For employers operating in multiple jurisdictions, the lesson is important:

One nationwide AI hiring process may encounter different local requirements.

A Bias Audit Isn’t a Magic Shield

Suppose your tool passes a required audit.

Does that mean:

“Zero liability forever”?

No.

An audit is a compliance mechanism—not immunity from every employment claim.

Businesses still need to consider:

  • Federal anti-discrimination law
  • State requirements
  • Local requirements
  • Disability accommodation
  • Actual hiring outcomes
  • Changes to the algorithm
  • Changes to candidate populations

AI governance needs to be ongoing.

“Ghosting” Can Hide Patterns

Imagine 10,000 people apply.

The system rejects:

8,500 automatically.

Nobody regularly examines those rejected candidates.

That’s risky.

The rejected population may contain the most important information about whether your hiring process creates unintended disparities.

Employers should consider monitoring:

Who applies?

Who passes each stage?

Who is rejected?

Who receives interviews?

Who receives offers?

Who accepts?

The goal isn’t simply measuring:

time-to-hire.

It is understanding the hiring funnel.

Human Review Helps—but Isn’t Magic Either

Some businesses respond:

“Don’t worry. A human makes the final decision.”

That’s useful, but it doesn’t automatically eliminate algorithmic risk.

Suppose:

AI reviews 10,000 candidates.

It eliminates:

9,500.

Human recruiters only review:

500.

Humans technically make the final hiring decisions.

But the AI determined who was allowed to reach the humans.

The meaningful employment decision may therefore occur much earlier in the process.

Automation Bias Is Another Problem

Humans can place too much confidence in automated recommendations.

Recruiter sees:

Candidate A — 94% match

Candidate B — 67% match

The recruiter may assume:

94% = objectively better.

But what exactly does that number represent?

A score can appear scientific while hiding assumptions about:

  • Training data
  • Job requirements
  • Candidate history
  • Weighting
  • Statistical correlations

Human oversight only works when humans are genuinely empowered to question the machine.

Train Recruiters to Challenge AI

Recruiters should understand:

AI recommendation ≠ command.

Training should explain:

  • What the tool does
  • What it doesn’t do
  • What data it uses
  • Known limitations
  • When human review is necessary
  • How accommodations work
  • How to escalate unusual outcomes
  • How overrides are documented

Otherwise “human oversight” may exist only on paper.

Candidate Notice Matters

Transparency is increasingly important.

New York City’s rules require notice in covered situations, including informing candidates or employees that an AEDT will be used.

Even where a particular notice law doesn’t apply, businesses should consider whether applicants clearly understand:

when automation is materially involved in evaluating them.

Transparency can also help candidates identify when they need an accommodation.

What Does This Have to Do With EPLI?

Everything.

An unsuccessful applicant might allege:

“Your AI hiring system discriminated against me.”

That can potentially become an employment-practices claim.

The employer then needs to determine:

Does our EPLI policy respond?

Don’t wait for litigation to find out.

Does EPLI Cover Applicants?

This is a crucial policy question.

Some EPLI policies may define covered claimants broadly enough to include:

job applicants.

Others may contain different definitions, limitations or endorsements.

Ask your broker:

“Does our EPLI policy cover discrimination claims brought by applicants who were never employed by us?”

For AI-heavy hiring organizations, this should be specifically confirmed.

Regulatory Investigations May Be Different

Suppose an individual files a discrimination lawsuit.

Your EPLI may potentially respond according to policy terms.

But what happens when a:

regulator

investigates the hiring system?

Coverage for:

  • Government investigations
  • Administrative proceedings
  • Fines
  • Penalties
  • Compliance costs

can differ considerably.

Certain fines or penalties may also be uninsurable under applicable law.

Businesses should understand these distinctions before a regulator arrives.

AI Can Create Class-Wide Exposure

Traditional employment disputes may involve:

one employee.

Algorithmic systems can affect:

thousands of candidates simultaneously.

Imagine one screening rule is flawed.

It processes:

50,000 applicants.

Even a small statistical problem can potentially affect a large population.

That creates a defining characteristic of AI risk:

automation scales mistakes.

A human recruiter can make one poor decision.

An algorithm can potentially repeat a problematic decision:

every few seconds.

This Can Affect EPLI Limits

Suppose your business has:

$1 million EPLI limit.

That may seem substantial.

But imagine allegations involving:

  • Thousands of applicants
  • Class litigation
  • Regulatory investigation
  • Expert witnesses
  • Algorithmic analysis
  • Discovery
  • Defense costs

The economics can look very different.

Businesses using AI extensively should discuss whether existing EPLI limits remain appropriate.

Defense Costs Matter

Read how your policy treats legal defense expenses.

Some EPLI policies may have defense costs:

inside the limit.

For example:

$1,000,000 limit

minus:

$300,000 defense costs

leaves:

$700,000

for other covered amounts.

Policy structures vary.

For complex AI-related litigation, defense-cost treatment can become particularly important.

Review Your Deductible or Retention

EPLI policies commonly involve a deductible or self-insured retention.

For example:

EPLI limit: $2 million

Retention: $50,000

The business may therefore bear the first:

$50,000

of qualifying loss according to policy terms.

Companies should understand this before a dispute arises.

Check the AI and Technology Language

Insurance policies are evolving alongside AI.

Businesses should examine whether their EPLI policy contains provisions affecting:

  • Algorithmic decision-making
  • Privacy
  • Biometric data
  • Regulatory investigations
  • Third-party vendors
  • Cyber incidents
  • Wage-and-hour matters
  • Class actions

Don’t assume a policy purchased several years ago automatically addresses every modern AI hiring exposure.

Cyber Insurance May Also Become Relevant

An AI hiring platform handles valuable information.

Potential data can include:

  • Names
  • Email addresses
  • Résumés
  • Employment histories
  • Assessment results
  • Interview recordings
  • Candidate profiles

A data breach involving the hiring platform may therefore trigger:

Cyber insurance issues

rather than—or alongside—EPLI.

One technology can create:

employment risk + privacy risk + cyber risk.

Insurance programs should be reviewed together.

Biometric Data Can Create Another Layer

Some recruiting technologies may analyze or collect information from:

  • Video
  • Voice
  • Facial characteristics
  • Behavioral assessments

That can potentially create additional privacy or biometric-law considerations depending on the jurisdiction and technology.

Before using such functionality, employers should understand:

what is actually collected

rather than assuming:

“It’s just an interview.”

Your Vendor Contract Matters

Suppose the AI vendor’s technology causes a serious problem.

Review whether the contract addresses:

  • Indemnification
  • Liability limits
  • Insurance
  • Data security
  • Regulatory cooperation
  • Audit rights
  • Incident notification
  • Data ownership
  • Record retention
  • Model changes

If your company carries:

$5 million EPLI

but your vendor contract limits the vendor’s liability to:

$25,000,

you may have a significant mismatch.

Maintain an AI Hiring Inventory

Businesses increasingly use AI without central management realizing it.

HR uses:

Tool A

Recruiting uses:

Tool B

Department manager uses:

Tool C

Staff download:

Tool D

Suddenly the company has four automated hiring technologies.

Create a simple inventory:

ToolPurposeOwnerCandidates AffectedLast Review
Tool ARésumé screeningHRExternal applicantsQ2 2026
Tool BCandidate scoringRecruitingGraduate hiresQ1 2026
Tool CInterview supportSalesSales applicantsQ2 2026

You cannot govern technology you don’t know exists.

Audit the Entire Hiring Funnel

Don’t review only the final algorithm.

Examine:

Job advertisement

Application

Résumé screening

Assessment

Interview

Candidate ranking

Offer

Rejection

At each stage ask:

Is automation involved?

What decision does it influence?

What data is collected?

Can a candidate request accommodation?

Who reviews the result?

Keep Appropriate Records

When a candidate challenges a hiring decision, you may need to explain what happened.

Useful records may include:

  • Tool version
  • Applicable hiring criteria
  • Audit documentation
  • Candidate notices
  • Accommodation procedures
  • Human review
  • Vendor documentation
  • Model changes
  • Override records

Recordkeeping requirements can vary, so businesses should coordinate retention practices with employment counsel.

Don’t Let AI Write Unreviewed Rejection Messages

Automation can also create reputational problems.

Imagine a candidate receives:

“After reviewing your extensive experience, we have determined that your lack of relevant experience does not meet our requirements.”

They have:

15 years of relevant experience.

Clearly, nobody reviewed the message.

Even if this doesn’t create legal liability by itself, it can undermine trust and encourage candidates to question whether the entire process was legitimate.

Create a Human Escalation Path

Candidates should have a reasonable route for issues involving:

  • Accommodation
  • Technical problems
  • Incorrect information
  • Assessment accessibility
  • Hiring-process questions

A completely automated hiring system with no practical human contact can make small problems harder to correct.

2026 AI Hiring Risk Checklist

Before deploying or renewing an AI hiring system:

  • Identify every AI hiring tool in use.
  • Determine which employment decisions each tool influences.
  • Review federal discrimination requirements.
  • Review applicable state and local AI laws.
  • Determine whether bias audits are required.
  • Review audit results.
  • Establish candidate notices where required.
  • Create an accommodation process.
  • Provide alternative assessments where appropriate.
  • Test candidate accessibility.
  • Train recruiters.
  • Maintain meaningful human oversight.
  • Monitor hiring outcomes.
  • Review rejection patterns.
  • Document overrides.
  • Review vendor contracts.
  • Confirm vendor insurance.
  • Review indemnification.
  • Review candidate data collection.
  • Review retention practices.
  • Evaluate biometric-data exposure.
  • Review EPLI coverage.
  • Confirm applicant claims are addressed.
  • Review regulatory-investigation coverage.
  • Review cyber insurance.
  • Reassess the system after major model updates.

Questions to Ask Your EPLI Broker

  1. Does our EPLI policy cover claims from job applicants?
  2. Are discrimination allegations involving AI covered?
  3. Is algorithmic hiring specifically excluded?
  4. How are class or collective claims handled?
  5. Are EEOC proceedings covered?
  6. Are state and local agency proceedings covered?
  7. Are regulatory investigations covered?
  8. Are defense costs inside or outside the limit?
  9. What retention applies?
  10. Are fines or penalties covered where legally insurable?
  11. Does third-party vendor involvement affect coverage?
  12. Are biometric-related claims excluded?
  13. Could cyber insurance respond to candidate-data incidents?
  14. Do we have overlapping EPLI and cyber coverage?
  15. Are our limits appropriate given our annual applicant volume?

Frequently Asked Questions

What is EPLI?

Employment Practices Liability Insurance is coverage designed for certain employment-related allegations such as discrimination, harassment, retaliation and wrongful termination, subject to policy terms.

Can an applicant sue over an AI hiring decision?

Potentially. Federal anti-discrimination laws can apply to hiring decisions involving AI just as they can to conventional hiring processes.

Is using AI to screen résumés illegal?

No. AI résumé screening isn’t inherently unlawful. But the employer must still comply with applicable employment-discrimination and other laws.

Is the employer responsible if a third-party AI tool discriminates?

Using a vendor does not automatically eliminate an employer’s legal exposure. Employers should evaluate both the technology and their own use of it.

Does New York City require AI hiring audits?

For covered automated employment decision tools, NYC Local Law 144 requires a qualifying bias audit and other requirements before use.

Does New York City require candidates to be notified?

Yes, covered use of an AEDT is subject to candidate or employee notice requirements.

Can AI discriminate against people with disabilities?

Potentially. The EEOC has warned that automated tools may screen out individuals with disabilities even when those individuals could perform the job with or without reasonable accommodation.

Does having a human recruiter eliminate AI liability?

Not automatically. If the AI determines which applicants reach human review, automated screening can still materially influence employment decisions.

Does EPLI automatically cover AI discrimination?

Don’t assume it does. Coverage depends on definitions, exclusions, claimant status, limits, retention and other policy provisions.

Should small businesses worry about AI hiring risk?

Yes, particularly if automated tools materially screen or rank applicants. A business doesn’t need thousands of employees before discrimination and compliance requirements become relevant.

Final Thoughts

AI can make hiring extraordinarily efficient.

It can:

read résumés in seconds

rank candidates instantly

schedule interviews automatically

answer applicant questions 24/7

and help recruiters manage applicant volumes that would once have required enormous teams.

But there is a fundamental principle employers shouldn’t forget:

Automating the decision doesn’t automate away responsibility.

The EEOC makes clear that existing federal employment-discrimination protections continue to apply when AI is used in employment.

And New York City’s AEDT rules demonstrate that some jurisdictions are imposing requirements specifically around automated hiring technology.

For employers, the better strategy is:

Know your tools → understand the data → test outcomes → provide accommodations → maintain human oversight → monitor vendors → document decisions → review EPLI.

The greatest AI hiring risk may not be that the machine makes an obviously terrible decision.

It may be that it quietly makes the same problematic decision thousands of times before anyone notices.

Supply Chain Interruption: Why “Physical Damage” Isn’t Enough in 2026.

Business manager inspecting delayed shipping containers and supply-chain disruption at a commercial distribution center.

Imagine your company owns a manufacturing plant in Ohio.

The building is fine.

There is:

No fire.

No flood.

No storm damage.

No broken machinery.

But production suddenly stops.

Why?

A specialized component you need comes from a supplier thousands of miles away.

That supplier cannot deliver.

Within days:

Production slows → inventory runs out → orders are delayed → customers leave → revenue falls.

Your property suffered:

$0 physical damage.

Your business suffers:

$500,000 in lost income.

Now comes the uncomfortable question:

Will your insurance pay?

The answer may be:

Not necessarily.

That is the supply-chain insurance problem businesses need to understand in 2026.

Traditional Business Interruption Starts With Your Property

Business interruption insurance is designed to protect income when operations are interrupted by a covered event.

But traditional coverage commonly requires:

direct physical loss or damage

to insured property caused by a covered peril.

For example:

Fire damages your factory → production stops → business income falls.

That is the classic business interruption scenario.

But modern businesses don’t operate entirely within their own walls.

They depend on:

suppliers + utilities + transportation + cloud services + ports + telecommunications + customers.

A failure anywhere along that network can interrupt operations.

Your Building Can Be Fine While Your Business Stops

Consider an electronics manufacturer.

Its factory is operational.

Its employees are available.

Its machinery works.

Its customers are placing orders.

But one semiconductor supplier shuts down.

Without that component, the manufacturer cannot complete its product.

The company may still face:

  • Lost revenue
  • Payroll
  • Rent
  • Loan payments
  • Customer penalties
  • Expedited shipping costs
  • Alternative sourcing expenses

The absence of damage to your own property doesn’t mean the absence of financial loss.

What Is Contingent Business Interruption Insurance?

This is where Contingent Business Interruption (CBI) coverage becomes important.

CBI is designed to address certain business-income losses resulting from disruption involving third parties on which your business depends.

That can include:

Suppliers

Companies providing materials, components or services.

Customers / Receivers

Businesses that purchase or receive your products.

Marsh explains that CBI commonly protects against lost income and extra expenses when disruption to key suppliers or customers interrupts the insured company’s operations.

Simple CBI Example

Imagine your company produces furniture.

You purchase specialty wood from one major supplier.

A fire destroys the supplier’s warehouse.

The supplier cannot deliver for:

three months.

Your factory is undamaged.

But production falls dramatically.

If your CBI coverage applies to:

that supplier + that type of physical damage + resulting income loss,

the policy may potentially respond, subject to its limits and conditions.

But CBI Can Still Have a Physical-Damage Requirement

This is where businesses sometimes misunderstand their protection.

They think:

“We bought contingent business interruption insurance, so every supplier interruption is covered.”

Not necessarily.

Marsh notes that CBI is typically triggered when a key supplier or customer suffers direct physical loss or damage, and coverage depends heavily on the policy’s definitions and covered perils.

So:

Supplier factory burns down → potentially covered.

But:

Supplier stops production because of financial insolvency → potentially not covered.

Supplier cannot ship because of a trade restriction → potentially not covered.

Supplier’s computer system fails → potentially not covered under traditional property-based CBI.

The distinction matters enormously.

2026 Supply Chains Have Many Non-Physical Risks

Modern supply-chain disruption can result from:

  • Cyberattack
  • Port closure
  • Labor strike
  • Political unrest
  • Trade restrictions
  • Supplier insolvency
  • Regulatory action
  • Transportation bottleneck
  • Critical infrastructure outage
  • Pandemic
  • Shipping disruption

None necessarily requires your building—or even your supplier’s building—to suffer traditional physical damage.

Marsh specifically identifies exclusions or limitations involving non-physical triggers such as cyber incidents, labor strikes, pandemics and insolvency as common CBI coverage gaps.

Scenario 1: Your Supplier Is Hacked

Imagine your primary parts supplier suffers ransomware.

Its factory is physically intact.

But:

ERP system offline

Orders unavailable

Production scheduling unavailable

Shipping systems unavailable

The supplier stops operations for ten days.

Your company runs out of components.

Traditional property-based CBI may not respond if the policy requires physical damage.

Cyber-related business interruption may require different insurance arrangements.

This is why businesses should coordinate:

Property + CBI + Cyber

rather than reviewing each policy independently.

Scenario 2: A Port Closes

Your goods arrive at a major port.

Then operations are interrupted.

Your containers cannot move.

Your warehouse has no damage.

Your supplier has no damage.

The cargo may even be physically intact.

But your company cannot obtain inventory.

You suffer:

$200,000 lost sales.

A traditional physical-damage trigger may not necessarily be satisfied.

Coverage depends entirely on the policy and circumstances.

Scenario 3: A Trade Restriction Blocks Your Supplier

Suppose your company relies on a specialized component from one country.

A new trade restriction prevents imports.

Nothing is damaged.

But the component becomes unavailable.

Production stops.

This is a:

business interruption without physical destruction.

Traditional property-based insurance may provide little or no protection for that scenario unless appropriate specialized coverage applies.

Scenario 4: Your Supplier Goes Bankrupt

Your only supplier of a critical component suddenly becomes insolvent.

The factory still exists.

The machinery still works.

There is no:

fire + flood + earthquake + explosion.

But shipments stop.

Marsh identifies insolvency as an example of a trigger that many traditional CBI arrangements may exclude.

This demonstrates why businesses need to understand:

cause of interruption

rather than merely:

amount of interruption.

The Tier-1 Supplier Problem

Many businesses know their direct suppliers.

These are commonly called:

Tier-1 suppliers.

For example:

Your company buys batteries from:

BatteryCo.

BatteryCo is your Tier-1 supplier.

But BatteryCo buys a critical battery-control chip from:

ChipCo.

ChipCo is effectively deeper in your supply chain.

Now ChipCo suffers a catastrophic loss.

BatteryCo cannot manufacture batteries.

BatteryCo cannot supply you.

You cannot manufacture your product.

Your loss began:

two levels away.

Does Your Insurance Cover Tier-2 Suppliers?

Maybe.

Maybe not.

Marsh says CBI commonly focuses on direct Tier-1 suppliers, although some programs can negotiate coverage or sublimits for Tier-2 suppliers.

This creates one of the biggest hidden supply-chain exposures.

You might know:

who you buy from.

But do you know:

who they depend on?

Swiss Re’s 2026 analysis highlights this visibility problem. In its review of Fortune 500 Europe corporate disclosures, 43% reported assessing physical risk to their own facilities, but only 7% publicly disclosed extending those assessments to supplier facilities, and fewer than 2% disclosed assessing broader infrastructure dependencies.

That doesn’t mean those percentages describe every company globally.

But they illustrate how quickly visibility declines beyond an organization’s own property.

The Single-Source Supplier Problem

Consider two manufacturers.

Manufacturer A

Critical component suppliers:

Supplier 1 + Supplier 2 + Supplier 3

Manufacturer B

Critical component supplier:

Supplier 1 only

Manufacturer B may have a much larger interruption exposure.

If Supplier 1 stops operating, there is no immediate alternative.

Single-source suppliers deserve special attention.

Ask:

If this supplier disappeared tomorrow, how long could we operate?

Calculate Your “Time to Pain”

Suppose you keep:

30 days of critical inventory.

Supplier disruption occurs today.

Days 1–20:

Operations continue normally.

Day 25:

Inventory becomes tight.

Day 30:

Critical component reaches zero.

Day 31:

Production stops.

Your:

Time to Pain = approximately 30 days.

Now compare that with supplier recovery time.

If the supplier needs:

six months

to rebuild,

you potentially face a substantial interruption.

Inventory Isn’t Always the Answer

Businesses sometimes respond:

“We’ll simply carry more inventory.”

That can improve resilience.

But inventory has costs.

More inventory means:

  • More working capital
  • More warehouse space
  • Higher storage expense
  • Potential obsolescence
  • Additional property exposure

The solution isn’t necessarily:

maximum inventory.

It is:

appropriate inventory based on criticality and recovery time.

Just-in-Time Can Increase Interruption Exposure

Just-in-time inventory can improve efficiency.

Instead of holding:

three months of components,

a company might hold:

five days.

That reduces:

  • Storage
  • Inventory carrying costs
  • Working capital requirements

But it also reduces the buffer against disruption.

A supplier outage that would previously have been inconvenient can quickly become a production shutdown.

Efficiency and resilience aren’t always the same thing.

Geographic Concentration Matters

Suppose you have five suppliers.

That sounds diversified.

But all five factories are located within:

50 miles of each other.

A single:

  • Hurricane
  • Earthquake
  • Flood
  • Regional power outage

could affect all five simultaneously.

True diversification means examining:

supplier count + geographic concentration + common dependencies.

Suppliers Can Share the Same Hidden Supplier

This is even more dangerous.

You buy components from:

Supplier A

and

Supplier B.

You assume:

“We’re diversified.”

But both suppliers obtain a critical microchip from:

Supplier C.

Supplier C shuts down.

Both A and B fail simultaneously.

Your apparent:

two-supplier strategy

was actually:

one hidden dependency.

Swiss Re’s research emphasizes that complex supply networks can transmit and amplify interruption losses across businesses and industries.

Infrastructure Is Part of Your Supply Chain

A supplier doesn’t operate in isolation.

It depends on:

Electricity

Water

Roads

Ports

Rail

Telecommunications

Cloud services

Fuel

Suppose your supplier’s factory is undamaged.

But the region loses electricity for:

10 days.

Production may still stop.

Or:

Factory works.

Road is destroyed.

Products cannot leave.

From your perspective:

same outcome — no components.

But from an insurance perspective, the trigger can be completely different.

Utilities Need Special Attention

Business interruption policies may offer service-interruption extensions for losses involving:

  • Electricity
  • Gas
  • Water
  • Telecommunications
  • Other utilities

But conditions can apply.

Marsh notes that utility-related coverage may contain:

  • Distance limitations
  • Excluded perils
  • Restrictions involving transmission lines
  • Waiting periods

So don’t assume:

“Power outage = covered.”

Read the extension.

Waiting Periods Matter

Imagine your CBI coverage has a:

72-hour waiting period.

Supplier outage:

48 hours.

Your business loses:

$80,000.

The disruption may end before the waiting period is satisfied.

Marsh notes that CBI waiting periods commonly range from 24 to 72 hours, although actual policy terms vary.

For businesses where even a few hours of downtime can be expensive, this matters.

Sublimits Can Be Much Lower Than Your Main Property Limit

Imagine your commercial property policy has:

$20 million total limit.

You might assume:

“We have $20 million for supply-chain losses.”

Not necessarily.

CBI might have a separate:

$1 million sublimit.

A catastrophe affecting your most important supplier causes:

$4 million income loss.

The main property limit doesn’t automatically increase the CBI sublimit.

Businesses should specifically identify:

CBI limit + supplier-specific limit + catastrophe sublimit + waiting period.

Named vs. Unnamed Suppliers

Some policies may cover only:

specifically scheduled dependent properties.

For example:

Supplier A — listed

Supplier B — listed

Supplier C — not listed

If Supplier C causes your interruption, coverage could differ.

Marsh identifies narrow definitions of dependent properties and unscheduled suppliers as important potential CBI coverage gaps.

Businesses therefore need accurate supplier information.

Don’t Forget Your Customers

Supply-chain interruption isn’t only:

upstream.

It can also be:

downstream.

Imagine your company manufactures packaging.

Your largest customer represents:

35% of revenue.

A fire destroys the customer’s manufacturing plant.

They stop purchasing your packaging for six months.

Your facility is fine.

But your revenue falls substantially.

Certain CBI arrangements may address dependent customers or receivers, subject to policy wording.

What Is Non-Damage Business Interruption?

Non-Damage Business Interruption, commonly shortened to:

NDBI

refers broadly to interruption losses arising without the traditional physical-damage trigger.

Historically, such coverage has been more specialized.

Potential non-damage scenarios can include certain:

  • Cyber events
  • Strikes
  • Civil unrest
  • Government actions
  • Supply-chain failures
  • Other defined events

Swiss Re has discussed NDBI and specialized supply-chain insurance as approaches for certain interruption events occurring without physical property damage.

Availability, triggers, limits and exclusions vary substantially.

It is not a universal replacement for traditional BI.

Parametric Solutions Can Play a Role

Some organizations also use parametric insurance.

Instead of waiting for traditional physical-loss adjustment, payment may depend on an agreed measurable trigger.

For example:

Earthquake intensity reaches X

or

Wind speed exceeds Y.

Parametric coverage can potentially provide rapid liquidity.

But it introduces:

basis risk.

Your financial loss may not perfectly correspond to whether the specified trigger is reached.

It should therefore be viewed as one component of a broader risk-financing strategy.

Cyber and Supply Chain Are Becoming Connected

Modern supply chains depend heavily on software.

Manufacturers rely on:

  • ERP systems
  • Cloud platforms
  • Logistics software
  • Electronic ordering
  • Warehouse systems
  • Payment platforms

A cyberattack affecting any one of those systems can potentially stop physical goods from moving.

That creates a modern paradox:

Digital event → physical supply-chain shutdown.

Businesses should therefore examine:

Cyber BI

and

Dependent Business Interruption

within cyber policies as well as traditional property CBI.

Cloud Providers Can Be Critical Suppliers

For some businesses, the most important supplier doesn’t manufacture anything.

It provides:

computing.

Imagine your company is an online retailer.

Your website, inventory system and checkout depend on one cloud provider.

The cloud platform experiences a major outage.

Your warehouse is fine.

Your inventory is fine.

Your employees are fine.

Customers simply cannot place orders.

That is a supply-chain dependency.

Businesses increasingly need to map:

digital suppliers

alongside physical suppliers.

The 2026 Risk Environment Makes Mapping More Important

Marsh’s 2026 supply-chain outlook highlights:

  • Geopolitical tensions
  • Tariffs and trade policy
  • Climate risk
  • Cybersecurity
  • Transportation disruptions

and recommends improved visibility into Tier-2 and Tier-3 suppliers, together with risk modelling and alternative risk-transfer approaches.

This is the key change.

Supply-chain risk management can no longer stop at:

“Who sends us the invoice?”

Businesses increasingly need to understand:

Who makes it?

Where is it made?

Who supplies them?

How does it reach us?

What infrastructure does the process depend on?

Build a Supply Chain Map

Start with your most important products.

For each one:

Product

Critical component

Tier-1 supplier

Tier-2 supplier

Manufacturing location

Port / transport route

Warehouse

Your facility

This can expose dependencies you didn’t know existed.

Swiss Re specifically recommends supply-chain mapping as a way to identify risk hotspots and hidden aggregation risks.

Rank Suppliers by Business Impact

Don’t treat every supplier equally.

A company supplying office stationery probably isn’t as critical as the only manufacturer of your patented component.

Create categories.

Critical

Failure stops operations quickly.

Important

Failure creates significant disruption but alternatives exist.

Replaceable

Alternative suppliers can be activated easily.

Then concentrate risk-management resources on:

critical suppliers first.

Calculate Maximum Foreseeable Supply-Chain Loss

Ask:

What happens if our most important supplier disappears for 12 months?

Estimate:

Lost revenue

minus

saved expenses

plus

extra expenses

plus

expedited shipping

plus

alternative sourcing costs.

Suppose the result is:

$8 million.

Then compare it with your:

CBI limit: $1 million.

You have discovered a potentially important insurance gap before the claim occurs.

Alternative Suppliers Need to Be Real

A spreadsheet may say:

Backup supplier: Supplier B.

But have you verified:

  • Capacity?
  • Quality?
  • Pricing?
  • Regulatory approvals?
  • Tooling?
  • Shipping time?
  • Contract availability?

A theoretical backup supplier isn’t necessarily a usable backup.

Consider pre-qualifying critical alternatives.

Test Your Business Continuity Plan

A plan stored in a PDF isn’t enough.

Run scenarios.

Scenario

Your largest supplier disappears tomorrow.

Ask:

Who is notified?

How much inventory remains?

Which customers are prioritized?

Can production switch?

Can another supplier help?

How quickly?

What will it cost?

Who contacts the insurer?

Marsh recommends treating BI planning and insurance review as recurring activities rather than something businesses discover during a claim.

Document Everything Before a Claim

CBI claims can be complicated.

Businesses may need to demonstrate:

  • What happened
  • Which supplier was affected
  • Why operations were interrupted
  • How long disruption lasted
  • Expected revenue
  • Actual revenue
  • Extra expenses
  • Mitigation measures

Marsh notes that CBI losses often require detailed financial records and evidence showing causation and mitigation.

Good documentation can make the claims process significantly easier.

2026 Supply Chain Insurance Checklist

Before your next renewal:

  • Identify all critical Tier-1 suppliers.
  • Identify important Tier-2 suppliers.
  • Map critical supplier locations.
  • Identify geographic concentration.
  • Identify single-source components.
  • Review supplier recovery times.
  • Calculate inventory buffers.
  • Identify transportation dependencies.
  • Map critical ports.
  • Review utility dependencies.
  • Identify important cloud providers.
  • Review cyber dependencies.
  • Check your CBI coverage.
  • Identify named dependent properties.
  • Review Tier-2 coverage.
  • Check CBI sublimits.
  • Review waiting periods.
  • Identify physical-damage requirements.
  • Review cyber exclusions.
  • Investigate appropriate non-damage solutions.
  • Pre-qualify alternative suppliers.
  • Test continuity plans.
  • Review financial-loss estimates.
  • Maintain supplier documentation.
  • Repeat the review after major supply-chain changes.

Questions to Ask Your Insurance Broker

  1. Does our BI coverage require physical damage?
  2. Do we have contingent business interruption coverage?
  3. Which suppliers are covered?
  4. Must suppliers be specifically named?
  5. Are Tier-2 suppliers covered?
  6. What CBI sublimit applies?
  7. What waiting period applies?
  8. Are flood and earthquake included for dependent properties?
  9. Are utility failures covered?
  10. Are port closures covered?
  11. Are strikes covered?
  12. Is supplier insolvency covered?
  13. How are cyber-related supplier disruptions handled?
  14. Does our cyber policy include dependent business interruption?
  15. Are cloud-service outages addressed?
  16. Do we need specialized NDBI coverage?
  17. Could parametric insurance address particular gaps?
  18. How should we calculate appropriate CBI limits?
  19. What supplier information will underwriters require?
  20. What records would be needed after a claim?

Frequently Asked Questions

What is supply chain interruption insurance?

There isn’t necessarily one universal policy bearing that exact name. Businesses can use combinations of CBI, cyber, cargo, trade-credit, political-risk, specialized supply-chain or non-damage coverage depending on their exposures.

What is contingent business interruption insurance?

CBI generally addresses qualifying income loss and extra expense resulting from covered disruption involving certain suppliers, customers or other dependent properties rather than physical damage at your own location.

Does CBI require physical damage?

Traditional property-based CBI commonly does. The exact trigger depends on the policy. Specialized products may address certain non-physical events.

Does CBI cover every supplier?

No. Policies can restrict coverage to direct, named or otherwise qualifying dependent properties. Tier-2 and deeper suppliers may receive limited or no coverage unless specifically addressed.

Does business interruption insurance cover supplier bankruptcy?

Do not assume it does. Insolvency is one of the non-physical triggers that may be excluded from traditional CBI coverage.

Can a cyberattack on a supplier be covered?

Potentially under appropriate cyber or other specialized coverage, but traditional property CBI may not respond when its physical-damage requirement isn’t satisfied.

Can a port closure trigger business interruption insurance?

It depends on the cause of the closure and specific policy language. A port being unavailable does not automatically create coverage.

What is non-damage business interruption insurance?

NDBI refers to specialized approaches designed to address specified interruptions where traditional physical property damage is absent. Coverage availability and triggers vary significantly.

Why should businesses map Tier-2 suppliers?

Your direct supplier may depend on another company that provides an irreplaceable component. A failure at that deeper-tier supplier can interrupt your operations even though you have no direct relationship with it.

How much CBI insurance should a business buy?

There is no universal amount. Businesses should model potential lost income, extra expenses, supplier recovery periods and alternative-sourcing costs and compare that exposure with available limits.

Final Thoughts

The biggest supply-chain mistake businesses can make in 2026 is assuming:

“If our property isn’t damaged, our business isn’t at risk.”

Modern companies don’t operate as isolated buildings.

They operate as networks.

Your business may depend on:

a semiconductor factory in Asia

a port thousands of miles away

a shipping company

a regional electricity grid

a cloud platform

a trucking company

your warehouse.

Break one critical link and the entire operation can slow down.

Swiss Re’s latest analysis highlights exactly this problem: business continuity depends not only on a company’s own facilities but also on suppliers, infrastructure and logistics networks, while visibility into those deeper dependencies remains limited.

Traditional property insurance remains essential.

But in 2026:

Protecting the building is not the same as protecting the business.

A stronger strategy is:

Map dependencies → identify bottlenecks → quantify downtime → build alternatives → review insurance triggers → test the recovery plan.

Because the next major interruption may leave your building completely untouched.

The 2026 FAIR Act: Why “Technical Compliance” is No Longer Enough for Insurers

California small-business property owner reviewing FAIR Plan insurance documents after wildfire risk changes.

The California FAIR Plan is an insurance program intended to provide access to basic property insurance when coverage cannot reasonably be obtained through the traditional insurance market.

FAIR stands for:

Fair Access to Insurance Requirements.

FAIR Plans aren’t unique to California.

According to the National Association of Insurance Commissioners (NAIC), FAIR Plans are state-mandated property insurance mechanisms that provide coverage to certain homeowners and businesses unable to obtain insurance through the regular market. They generally function as an insurance option of last resort.

California’s program has become particularly important because of the state’s significant wildfire exposure and changes in its property-insurance market.

Why Is California Changing the FAIR Plan?

The immediate backdrop is straightforward:

The FAIR Plan has become much more important than originally intended.

As private insurers became more selective about catastrophe exposure, more property owners turned to the FAIR Plan.

That increased pressure on:

  • Customer service
  • Claims operations
  • Staffing
  • Financial management
  • Governance
  • Policy administration

Then came the devastating January 2025 Los Angeles wildfires.

According to the California Department of Insurance, wildfire survivors subsequently reported problems involving:

delays + claim denials + communication difficulties.

The Department conducted a comprehensive examination of the FAIR Plan.

Its findings helped produce the proposed:

Make It FAIR Act.

What Did Regulators Find?

This is where the 2026 proposal becomes particularly significant.

The California Department of Insurance said its comprehensive examination evaluated the FAIR Plan across:

32 areas

involving matters such as:

  • Financial condition
  • Corporate governance
  • Internal controls
  • Consumer protection

According to the Department, the FAIR Plan had not started or fully implemented recommendations in more than half of those areas.

The Department specifically described 17 recommendations as critical.

That’s considerably more serious than a simple paperwork problem.

It suggests regulators are looking at how the organization actually operates.

Why “Technical Compliance” Isn’t the Whole Story

Insurance regulation has traditionally involved extensive technical requirements.

Insurers must comply with rules governing matters such as:

  • Rates
  • Policy forms
  • Claims
  • Financial solvency
  • Licensing
  • Consumer disclosures
  • Market conduct

But regulators increasingly examine outcomes as well as procedures.

A company could theoretically have:

policy manual ✓

compliance department ✓

claims procedures ✓

while customers still experience:

delays + poor communication + inconsistent claims handling.

That distinction is important.

Compliance shouldn’t simply mean:

“We have the required procedure.”

The practical question becomes:

“Does the procedure actually protect policyholders?”

The Make It FAIR Act Targets Claims Handling

Claims are one of the central areas addressed by the proposal.

The California Department of Insurance says the legislation would strengthen claims handling and require the FAIR Plan to improve its operational capacity.

That matters enormously after a catastrophe.

Consider a homeowner whose property has been damaged by wildfire.

They may simultaneously be dealing with:

  • Temporary housing
  • Smoke damage
  • Property repairs
  • Lost possessions
  • Contractors
  • Mortgage payments

An insurance claim that becomes unnecessarily delayed can therefore create consequences extending far beyond paperwork.

Smoke-Damage Claims Are Part of the Dispute

Smoke damage has become particularly contentious.

The California Department of Insurance says it has taken formal legal action against the FAIR Plan concerning hundreds of smoke-damage claims.

The underlying issue demonstrates why claim interpretation matters.

A house doesn’t need to burn completely to suffer potentially serious damage.

Smoke can potentially affect:

  • Walls
  • Furniture
  • HVAC systems
  • Electronics
  • Clothing
  • Interior surfaces

Whether particular damage is covered ultimately depends on the policy and circumstances.

But regulators clearly see claims handling in this area as significant enough to warrant enforcement attention.

Customer Communication Is Becoming a Regulatory Issue

Insurance claims can involve complicated documentation.

But complexity doesn’t eliminate the need for communication.

Policyholders reasonably need to understand:

What information is required?

Has the insurer received it?

What happens next?

Why was something denied?

How can the decision be challenged?

The Department says delays, denials and miscommunication were among the leading complaints involving FAIR Plan policyholders following the January 2025 Los Angeles wildfires.

That makes customer communication more than simply a:

“service quality”

issue.

It can become part of regulatory scrutiny.

The Proposal Would Require More Staffing

One surprisingly practical provision involves staffing.

The Department says the legislation would require the FAIR Plan to hire additional personnel to address its growing operational workload, including claims and consumer complaints.

Why does staffing matter?

Because insurance infrastructure has to scale with policy volume.

Imagine:

100 claims adjusters → 20,000 claims

versus:

100 claims adjusters → 200,000 claims.

Even excellent procedures can fail when an organization doesn’t have sufficient operational capacity.

The FAIR Plan Could Offer Broader Coverage

Another major proposal involves coverage itself.

Traditional FAIR Plan coverage has generally been more limited than a conventional homeowners insurance package.

According to the California Department of Insurance, residential FAIR Plan policyholders currently may need separate coverage for risks including:

  • Water damage
  • Personal liability
  • Other standard homeowners protections

The Make It FAIR Act proposes a more comprehensive homeowners coverage option.

This could potentially simplify insurance arrangements for some policyholders.

Why Homeowners Often Need a Difference in Conditions Policy

Because FAIR Plan coverage can be limited, homeowners commonly combine it with another policy.

This is often referred to as:

Difference in Conditions (DIC) coverage.

Simplified:

FAIR Plan

may provide certain core property protection.

Then:

DIC policy

may provide additional coverage not included in the FAIR Plan policy.

Together, the policies can more closely resemble broader homeowners protection.

But this arrangement can create:

  • Additional premiums
  • Multiple policies
  • Multiple insurers
  • More paperwork
  • Potential confusion after a claim

A broader FAIR Plan coverage option could therefore be significant.

The Clearinghouse Is Another Important Piece

The long-term goal isn’t necessarily for consumers to remain in the FAIR Plan forever.

California has created mechanisms intended to help eligible policyholders move back into the voluntary insurance market.

The Department says its examination found that only some insurers participated in the relevant clearinghouse program, undermining the program’s intended effectiveness.

The proposed legislation therefore seeks improvements.

Conceptually:

FAIR Plan → temporary safety net → regular insurance market

is preferable to:

FAIR Plan → permanent destination.

Why Moving Back to Private Insurance Matters

Traditional insurance markets generally provide:

  • More product choices
  • More insurers
  • Potentially broader coverage
  • Competitive pricing
  • Greater customization

FAIR Plans are designed primarily to preserve access when the traditional market isn’t providing sufficient options.

The NAIC describes FAIR Plans as mechanisms intended for properties that are high-risk or otherwise difficult to insure through conventional markets.

They are important safety nets.

But ideally, they shouldn’t replace a healthy competitive market.

What This Means for Businesses

The FAIR Plan isn’t only relevant to homeowners.

FAIR Plan mechanisms can also matter for certain commercial properties that struggle to obtain insurance.

Imagine a small business owns a building in a wildfire-exposed California community.

Private insurers either:

decline coverage

or quote terms the owner cannot reasonably obtain.

The FAIR Plan may become part of the property’s insurance solution.

That makes FAIR Plan:

financial stability + claims capability + governance

relevant to commercial property owners too.

Insurance Availability Can Affect Business Financing

Suppose a company purchases a:

$2 million commercial building.

The lender requires property insurance.

But traditional coverage becomes difficult to obtain.

Now insurance availability isn’t merely an insurance problem.

It becomes a:

financing problem.

Commercial lenders commonly require borrowers to maintain appropriate property insurance.

If insurance becomes unavailable or unaffordable, it can affect:

  • Real-estate transactions
  • Loan requirements
  • Operating expenses
  • Investment decisions
  • Property values

The Bigger Issue: Insurance Accountability

The Make It FAIR Act fits into a broader regulatory theme.

Insurance companies and insurance-related organizations are increasingly expected to demonstrate not only that procedures exist but that those procedures produce appropriate outcomes.

That can involve:

Governance

Who is responsible?

Claims

Are claims being handled appropriately?

Transparency

Can consumers understand decisions?

Operations

Are sufficient resources available?

Controls

Can management identify problems?

Remediation

Are identified weaknesses actually corrected?

This is especially important when an insurer or residual-market mechanism becomes critical to an entire region’s insurance availability.

AI Makes This Even More Important

Insurance operations are becoming increasingly automated.

AI can now assist with:

  • Underwriting
  • Pricing
  • Fraud detection
  • Claims triage
  • Customer service
  • Document analysis

That creates another accountability question:

If an automated system produces an unfair outcome, is the insurer still responsible?

Regulators increasingly say yes.

For example, the Texas Department of Insurance issued an AI bulletin on June 12, 2026 stating that insurance decisions supported by AI must comply with applicable laws, including unfair-trade-practice and unfair-discrimination requirements. Texas also expects human review and agreement before consequential AI-supported decisions are acted upon.

AI Vendors Don’t Automatically Shift Responsibility

Suppose an insurer uses a third-party AI company.

The system recommends denying a claim.

The insurer says:

“The vendor’s algorithm made the decision.”

That doesn’t necessarily solve the insurer’s regulatory problem.

The NAIC’s AI framework emphasizes:

  • Fairness
  • Accountability
  • Compliance
  • Transparency
  • Security
  • Robustness

and its Model Bulletin tells insurers that decisions supported by AI remain subject to applicable insurance laws.

That means outsourcing technology doesn’t necessarily mean outsourcing accountability.

Documentation Is Becoming More Important

Insurers increasingly need to demonstrate:

What system made the decision?

What data was used?

How was the system tested?

Who approved it?

How is bias monitored?

How are errors corrected?

Texas regulators specifically state that insurers should maintain governance, risk-management controls and internal-audit functions around AI and may be asked for related information during regulatory examinations.

This reinforces the broader transition from:

“Tell us you’re compliant.”

toward:

“Show us how your controls actually work.”

What Should Insurers Do in 2026?

Insurers should treat regulatory compliance as an operational discipline rather than an annual checklist.

A strong framework should include:

Governance

Senior leadership should understand significant regulatory and operational risks.

Claims Oversight

Claims trends, delays, denials and complaints should be monitored.

Consumer Outcomes

Companies should look for patterns suggesting customers are being treated inconsistently.

Complaint Analysis

Complaints can reveal systemic problems.

Technology Governance

Automated decision systems should be documented and tested.

Vendor Oversight

Third-party service providers should be appropriately monitored.

Internal Audit

Controls should be tested rather than simply documented.

Remediation

Problems identified by regulators or internal reviews should actually be corrected.

What Should California Policyholders Do?

If you currently rely on the California FAIR Plan:

  • Understand exactly what your FAIR Plan policy covers.
  • Identify major exclusions or limitations.
  • Determine whether you also have DIC coverage.
  • Keep a current home or business property inventory.
  • Maintain photographs and receipts.
  • Review replacement-cost limits.
  • Document mitigation improvements.
  • Keep copies of communications after a claim.
  • Ask for written explanations of important claim decisions.
  • Review private-market alternatives periodically.

Most importantly:

Don’t assume “FAIR Plan” means identical coverage to a conventional homeowners or commercial-property policy.

Read both policies carefully.

Questions Business Owners Should Ask Their Broker

  1. Is the FAIR Plan my only realistic option?
  2. Which private insurers have been approached?
  3. What exactly does my FAIR Plan policy cover?
  4. What important coverage is missing?
  5. Do I need a DIC policy?
  6. Is wildfire included?
  7. What about water damage?
  8. What liability coverage do I have?
  9. Are my building limits adequate?
  10. What deductible applies?
  11. Are business contents adequately insured?
  12. Do I have business-income coverage?
  13. What mitigation improvements could help?
  14. Can I periodically be reconsidered for the private market?
  15. How would a major claim involving multiple policies be coordinated?

Frequently Asked Questions

What is the Make It FAIR Act?

The Make It FAIR Act is California Assembly Bill 1680, announced in February 2026 by Insurance Commissioner Ricardo Lara and Assemblymember Lisa Calderon. It proposes reforms involving the California FAIR Plan’s claims handling, coverage, governance, staffing and transparency.

Is the Make It FAIR Act a federal law?

No. This proposal concerns California’s FAIR Plan.

Is AB 1680 already law?

Readers should check the current legislative status before relying on any proposed provision. Because legislation can be amended during the legislative process, this article describes the proposal rather than presenting every provision as already effective.

What is the California FAIR Plan?

It is California’s residual property-insurance mechanism intended to provide basic coverage when qualifying property owners cannot obtain appropriate insurance through the conventional market.

Does FAIR Plan coverage equal standard homeowners insurance?

Not necessarily. FAIR Plan coverage can be more limited, which is why policyholders may purchase complementary DIC coverage.

Why is California reforming the FAIR Plan?

The proposal followed significant growth in FAIR Plan reliance, complaints following the 2025 Los Angeles wildfires and a Department of Insurance examination identifying governance, operational and consumer-protection concerns.

Does the proposal affect claims handling?

Yes. Claims handling and consumer service are among the major areas targeted by the proposed reforms.

Can businesses use FAIR Plan coverage?

FAIR Plan mechanisms can provide property coverage for certain eligible commercial risks unable to obtain coverage through the standard market, subject to program rules.

Does California want everyone to remain on the FAIR Plan?

No. An important policy goal is helping eligible consumers return to the regular insurance market where possible.

Are AI insurance decisions regulated too?

Yes. Existing insurance laws continue to apply when insurers use AI. State regulators increasingly expect insurers to demonstrate governance, testing, oversight and protection against unfair outcomes.

Final Thoughts

The most important lesson from California’s 2026 FAIR Plan debate isn’t simply about wildfire insurance.

It is about:

accountability.

An insurance organization can have:

rules + procedures + systems + policies

and still experience operational problems.

What matters to the policyholder after a catastrophe is whether the system actually works.

Can they reach someone?

Is the claim investigated?

Are decisions explained?

Are complaints resolved?

Are mistakes corrected?

California’s Department of Insurance says its FAIR Plan examination found that more than half of the 32 areas reviewed had recommendations that had either not been started or not fully implemented, including 17 critical recommendations.

The proposed Make It FAIR Act represents an attempt to turn those findings into structural reforms.

And it reflects a broader direction visible across insurance regulation:

Compliance on paper is necessary.

Effective governance, fair outcomes and demonstrable accountability increasingly matter too.

Quick Takeaway

California’s Make It FAIR Act (AB 1680) was announced on February 2, 2026 by Insurance Commissioner Ricardo Lara and Assembly Insurance Committee Chair Lisa Calderon. The proposal targets the California FAIR Plan with reforms involving claims handling, customer service, governance, transparency and coverage options. The legislation followed a California Department of Insurance examination that, according to the Department, found the FAIR Plan had failed to comply with 17 critical recommendations concerning financial condition, corporate governance and consumer protection.

The proposal matters because California’s FAIR Plan has become increasingly important as homeowners and businesses in wildfire-exposed areas struggle to obtain conventional property insurance.

Remote Work & Mental Health: The New Frontiers of Workers’ Comp in 2026

Remote employee working from a dedicated home office while an HR manager reviews workplace safety and wellbeing considerations.

The traditional workplace injury is easy to picture.

A warehouse employee falls from a ladder.

A construction worker injures a shoulder.

A restaurant employee suffers a burn.

But what happens when the workplace is:

a spare bedroom?

Consider a remote employee who works from home five days a week.

At 2:30 p.m., while participating in a work video call, the employee gets up to retrieve a required document and trips over a power cable.

Or consider a different situation.

Months of intense workload, constant after-hours communication, and repeated exposure to traumatic material contribute to a serious psychological condition.

Could either situation become a workers’ compensation claim?

Potentially.

But remote work and mental-health claims create complicated questions about where work begins, where personal life ends, and whether an injury or condition is sufficiently connected to employment.

Workers’ Compensation Didn’t Disappear When Employees Went Home

Workers’ compensation generally provides benefits for qualifying occupational injuries and illnesses.

Moving an employee from:

corporate office → home office

doesn’t necessarily remove workers’ compensation exposure.

The U.S. Department of Labor notes that workers’ compensation systems provide benefits for work-related injuries and occupational illnesses, although most private-sector employees are governed by state workers’ compensation systems rather than one nationwide federal program.

The key issue isn’t simply:

Where did the injury happen?

It is usually whether the injury meets the applicable jurisdiction’s requirements for a compensable work-related injury.

Your Employee’s Home Can Become a Workplace

Imagine an accountant works remotely from a dedicated home office.

During normal working hours, her supervisor asks her to retrieve a company file.

She walks across the room, trips over an employer-provided computer cable and fractures her wrist.

The fact that the accident occurred inside her home doesn’t necessarily mean:

“Workers’ compensation doesn’t apply.”

Courts and workers’ compensation agencies can examine whether the employee was performing work-related activity when the injury occurred.

But facts matter enormously.

Now change the scenario.

During her lunch break, she walks outside to play basketball with her children and twists her ankle.

That creates a very different connection to employment.

The Central Question: Was the Employee Working?

Remote claims can blur the boundary between:

work activity

and

personal activity.

Consider four scenarios:

Scenario A: Employee trips while walking to an employer-required printer.

Scenario B: Employee falls while taking a scheduled work call.

Scenario C: Employee injures themselves while preparing a personal lunch.

Scenario D: Employee is hurt doing household chores between meetings.

They all occur:

at home + during the workday.

But that doesn’t make them legally equivalent.

The specific activity occurring at the time of injury can become critical.

Remote Work Creates a “Course of Employment” Problem

Workers’ compensation systems traditionally examine concepts such as whether an injury:

arose out of employment

and occurred:

in the course of employment.

Exact legal tests vary by jurisdiction.

Remote work complicates those questions because employees may move repeatedly between:

professional activity ↔ personal activity

without physically leaving the workplace.

At an office, walking to a conference room clearly looks work-related.

At home, walking from a desk toward the kitchen could be:

  • Retrieving a work document
  • Getting coffee
  • Feeding a pet
  • Preparing lunch
  • Answering the door

The physical location may be identical.

The purpose may be completely different.

What About Ergonomic Injuries?

Not every remote-work injury involves a sudden accident.

An employee might spend months working from:

  • Kitchen chair
  • Sofa
  • Bed
  • Improvised desk
  • Poorly positioned monitor

Eventually, the employee develops:

  • Wrist problems
  • Neck discomfort
  • Back problems
  • Repetitive-strain injury

Whether a particular condition qualifies for workers’ compensation depends on medical and legal evidence connecting the condition to employment.

But ergonomics remains an important risk-management issue regardless of whether a claim ultimately becomes compensable.

OSHA provides guidance on computer workstation ergonomics, including monitor, keyboard, chair and workstation positioning.

The Kitchen-Table Office Problem

Consider an employee who spends:

8 hours per day

working on a laptop at a kitchen table.

Their chair has little back support.

The laptop screen is too low.

Their wrists bend awkwardly while typing.

One day probably doesn’t cause a major problem.

But:

8 hours × 5 days × months

creates repeated exposure.

Employers with significant remote workforces should therefore think beyond laptops and software.

The physical workstation matters too.

Mental Health Creates an Even More Complex Frontier

Now consider a different employee.

They haven’t fallen.

They haven’t suffered a physical accident.

But they report severe psychological harm allegedly resulting from their employment.

Could workers’ compensation apply?

The answer varies substantially by jurisdiction.

States differ in how they handle psychological claims, including claims sometimes described as:

physical-mental

mental-physical

or

mental-mental

claims.

A mental-health condition caused by a physical workplace injury may be treated differently from a psychological condition alleged to arise without an accompanying physical injury.

Employers therefore shouldn’t apply one nationwide rule.

Stress Alone Doesn’t Automatically Equal a Workers’ Comp Claim

Almost every job involves some stress.

Workers’ compensation systems generally don’t turn every:

difficult deadline

argument with a manager

or

busy week

into a compensable psychological claim.

State law may impose specific requirements concerning:

  • Diagnosis
  • Causation
  • Extraordinary workplace events
  • Predominant cause
  • Medical evidence
  • Duration
  • Physical injury

depending on the jurisdiction.

This is why businesses should avoid blanket statements such as:

“Work stress is covered.”

or:

“Mental health is never covered.”

Both can be misleading.

PTSD Claims Are Particularly Important

Psychological injury has received increased attention in workers’ compensation, particularly among occupations exposed to traumatic events.

Examples may include:

  • First responders
  • Emergency personnel
  • Healthcare workers
  • Certain public-safety employees

Some states have enacted special provisions or presumptions addressing PTSD for particular occupational groups.

These rules vary considerably.

A firefighter’s PTSD claim in one state may therefore be evaluated differently from a remote accountant’s stress-related claim in another.

Remote Work Can Make Causation Harder to Evaluate

Suppose an employee develops anxiety.

Potential contributing factors might include:

  • Workload
  • Manager conflict
  • Financial pressure
  • Family responsibilities
  • Isolation
  • Personal circumstances
  • Existing conditions

Workers’ compensation decision-makers may need to determine whether employment satisfies the applicable legal standard for causing or contributing to the condition.

Remote work can complicate that analysis because home and workplace stressors occur in the same physical environment.

Isolation Is a Real Workplace Risk

Even when an issue doesn’t become a workers’ compensation claim, remote-work isolation can still affect:

  • Employee wellbeing
  • Engagement
  • Productivity
  • Retention
  • Absenteeism

The U.S. Surgeon General’s workplace mental-health framework identifies connection and community as one of the essential components of workplace wellbeing.

Remote work therefore requires employers to think about psychological safety and social connection alongside physical safety.

“Always Online” Can Become a Management Problem

Remote work can unintentionally erase boundaries.

An employee finishes work at:

6:00 p.m.

Then receives:

7:15 p.m. — Teams message

8:30 p.m. — Email

10:05 p.m. — “Quick question”

6:30 a.m. — New task

No single message necessarily creates a workers’ compensation issue.

But organizational culture matters.

Employers should consider whether managers unintentionally create expectations of:

permanent availability.

A remote-work policy should define reasonable communication expectations.

Hybrid Work Creates Another Layer

Hybrid employees may work:

Monday — Home

Tuesday — Office

Wednesday — Client site

Thursday — Home

Friday — Coffee shop

Now consider an injury.

Where was the employee?

Was that location authorized?

What were they doing?

Were they traveling for work?

Were they performing a personal errand?

Hybrid arrangements can make workplace boundaries even less obvious.

What About Working From a Coffee Shop?

Suppose an employer permits:

“Work from anywhere.”

An employee works from a coffee shop.

They trip over a chair while walking to take a required client call.

Could workers’ compensation apply?

Potentially, depending on the jurisdiction and circumstances.

Employers therefore need to understand what phrases such as:

remote

hybrid

and

work from anywhere

actually mean operationally.

“Work From Anywhere” Can Also Mean “Work From Another State”

This creates a different problem.

Imagine your company is located in:

New York.

An employee quietly moves to:

Colorado

and continues working remotely.

That can create questions involving:

  • Workers’ compensation
  • Payroll
  • Tax
  • Employment law
  • Benefits
  • Registration requirements

Remote work can transform a local employer into a multi-state employer without management fully realizing it.

Businesses should maintain accurate records of where employees actually perform their work.

Employees Working Internationally Create More Complexity

Now suppose an employee says:

“I’m going to Europe for two months, but I’ll keep working normally.”

That arrangement can create issues involving:

  • Employment law
  • Immigration
  • Tax
  • Data security
  • Insurance
  • Workers’ compensation
  • Benefits

Businesses should not assume:

Laptop + internet = legally identical workplace.

International remote work deserves specific legal, tax and insurance review.

Employers Should Define Approved Work Locations

A written remote-work policy can identify:

Primary approved work location

For example:

Employee’s registered home office.

Alternative locations

Whether temporary work from other locations is allowed.

Out-of-state work

Whether prior approval is required.

International work

Whether prohibited or separately approved.

This improves both:

risk management + administrative clarity.

Home Office Safety Still Matters

Employers usually cannot control an employee’s home environment the same way they control a corporate office.

But they can establish reasonable safety expectations.

A remote-work checklist could ask employees to verify:

  • Walkways are clear.
  • Electrical cords are safely positioned.
  • Work area has adequate lighting.
  • Chair provides appropriate support.
  • Monitor is positioned appropriately.
  • Electrical equipment is in good condition.
  • Smoke alarms are functioning.
  • Work area is reasonably free of hazards.

The objective isn’t to inspect every employee’s private home.

It is to encourage a reasonably safe designated workspace.

Don’t Turn Home Safety Into Surveillance

There is an important boundary here.

Employers should respect employee privacy.

Requiring workers to install cameras throughout their homes or continuously recording them simply to prove they are working can create:

privacy + morale + legal

concerns.

Remote risk management should be proportional.

A reasonable safety checklist is very different from intrusive surveillance.

Remote Injury Reporting Should Be Clear

At an office, an injured employee may immediately tell:

manager + HR + safety officer.

At home, the employee might think:

“I’ll see if it feels better tomorrow.”

Several days pass.

Then the injury is reported.

That can make investigation harder.

Employers should give remote employees clear instructions for reporting potential workplace injuries promptly.

Create a Remote Injury Report

When a remote employee reports an injury, document relevant facts.

For example:

Date: August 12

Time: 2:40 p.m.

Location: Approved home workspace

Work activity: Retrieving client file during video meeting

Incident: Tripped over computer cable

Injury reported: Wrist injury

Witnesses: None

Work system activity: Employee was logged into scheduled meeting

The employer shouldn’t automatically decide whether the claim is covered.

That is a legal/claims determination.

The employer should accurately document the event and follow applicable reporting procedures.

Don’t Automatically Reject a Home Injury

One of the worst responses is:

“It happened at your house, so it isn’t workers’ comp.”

That may be wrong.

The appropriate approach is generally:

Report → Document → Follow state procedures → Allow the insurer/administrator to investigate.

Similarly, don’t promise:

“Yes, workers’ comp will pay.”

That decision depends on the facts and applicable law.

Mental-Health Claims Require Sensitivity

When an employee reports psychological injury, managers should avoid acting as:

doctors

or

claims adjusters.

Statements such as:

“You’re just stressed.”

or

“That’s obviously work-related.”

can both create problems.

Instead:

  • Document the report appropriately.
  • Follow internal procedures.
  • Protect confidentiality.
  • Involve HR.
  • Follow applicable workers’ compensation reporting requirements.
  • Allow qualified professionals to evaluate medical issues.

Privacy Is Particularly Important

Mental-health information can be highly sensitive.

Access should be limited to people who legitimately need the information.

Managers generally don’t need an employee’s entire medical history simply because a claim has been reported.

Organizations should coordinate:

HR + claims + legal + privacy

processes carefully.

Workers’ Compensation Is Only One Part of the Mental-Health Picture

An employee experiencing a mental-health condition may potentially encounter several different workplace systems.

Depending on the circumstances, these could include:

  • Workers’ compensation
  • Employer health benefits
  • Disability benefits
  • Leave programs
  • ADA accommodation
  • Employee Assistance Programs

These systems aren’t interchangeable.

A condition that doesn’t qualify for workers’ compensation might still create rights or benefits under another program.

Remote Workers Can Still Have Physical Workplace Accidents

Businesses should not let the mental-health discussion obscure ordinary injuries.

Remote employees can suffer:

  • Falls
  • Repetitive-motion injuries
  • Electrical incidents
  • Strains
  • Equipment-related injuries

The National Safety Council continues to emphasize slips, trips and falls as major preventable workplace injury risks.

The hazard doesn’t disappear simply because the floor is inside someone’s home.

Employers Should Review Their Workers’ Comp Policy

Before expanding remote work, ask your insurance broker:

Are remote employees appropriately included?

Review:

  • Employee classifications
  • Payroll
  • Employee locations
  • States of employment
  • Out-of-state arrangements
  • International remote work
  • Claims-reporting procedures

Don’t assume the insurer automatically knows where every employee now works.

Classification Still Matters

Workers’ compensation premiums are influenced by factors including:

payroll + classification + experience.

An office employee working from home generally presents a different occupational exposure from:

construction worker

or

warehouse employee.

Accurate classifications remain important.

Businesses should not manipulate classifications merely because employees occasionally work remotely.

Multi-State Workers’ Comp Can Become Complicated

Suppose a company headquartered in:

California

has remote employees in:

  • Texas
  • Florida
  • Colorado
  • New York

The company may need to consider workers’ compensation requirements in multiple jurisdictions.

State rules differ.

Businesses expanding remote hiring should involve their:

broker + payroll provider + employment counsel

before assuming one state’s policy automatically solves every issue.

Prevention Is Better Than Fighting Over Compensability

Employers can spend enormous time debating:

“Was this technically a work injury?”

A better strategy is reducing preventable incidents.

For remote workers:

Ergonomics

Provide workstation guidance.

Safety

Encourage designated work areas.

Mental wellbeing

Promote reasonable workload and communication expectations.

Reporting

Create clear injury-reporting procedures.

Management

Train supervisors to recognize and appropriately escalate concerns.

Risk management is useful even when no workers’ compensation claim occurs.

Build a Remote-Work Safety Program

A simple program might contain five elements.

1. Approved Workspace

Employees identify their primary work location.

2. Safety Self-Assessment

Employees complete a basic workstation checklist.

3. Ergonomic Guidance

Provide resources on:

  • Chair setup
  • Monitor height
  • Keyboard position
  • Breaks

4. Incident Reporting

Explain exactly how injuries should be reported.

5. Periodic Review

Update the arrangement if:

  • Employee moves
  • Job duties change
  • Equipment changes
  • Work schedule changes

Mental-Health Risk Management for Remote Teams

Employers can also reduce organizational stressors.

Consider:

Workload

Are deadlines realistic?

Communication

Are employees expected to answer messages constantly?

Role clarity

Do employees know what is expected?

Management

Are supervisors trained to manage remote employees?

Connection

Do remote workers have meaningful contact with colleagues?

Time off

Can employees genuinely disconnect?

The Surgeon General’s workplace framework emphasizes five essentials:

  • Protection from harm
  • Connection and community
  • Work-life harmony
  • Mattering at work
  • Opportunity for growth

These are useful management principles regardless of workers’ compensation rules.

Example: The Remote Employee Injury

Consider a hypothetical employee named Sarah.

She works from home full time.

At:

11:15 a.m.

her manager asks her to retrieve a printed contract.

She stands from her desk.

Her foot catches on a company laptop charging cable.

She falls and injures her shoulder.

Sarah reports the incident immediately.

The employer documents:

  • Time
  • Location
  • Work instruction
  • Activity
  • Equipment involved

The employer then submits the matter according to applicable procedures.

Notice what management doesn’t do.

It doesn’t say:

“Home accident—denied.”

It doesn’t say:

“Definitely covered.”

It documents and reports.

Example: The Mental-Health Claim

Now consider another employee.

They report a diagnosed psychological condition and state that months of workplace events caused it.

Management should not decide:

“Normal job stress isn’t covered.”

Nor should management promise benefits.

Instead:

  1. Take the report seriously.
  2. Follow applicable reporting requirements.
  3. Maintain appropriate confidentiality.
  4. Document relevant workplace information.
  5. Allow the insurer and appropriate medical/legal professionals to evaluate the claim.

This approach is both more respectful and more defensible.

2026 Remote Workers’ Compensation Checklist

  • Identify where every remote employee works.
  • Review state workers’ compensation requirements.
  • Update employee location records.
  • Verify policy states and classifications.
  • Establish approved remote-work locations.
  • Create a home-workspace safety checklist.
  • Provide ergonomic guidance.
  • Explain injury-reporting procedures.
  • Encourage prompt reporting.
  • Document remote incidents carefully.
  • Train supervisors on remote claims.
  • Train managers on mental-health conversations.
  • Protect medical confidentiality.
  • Review workload expectations.
  • Establish reasonable communication boundaries.
  • Review work-from-anywhere policies.
  • Require approval for interstate moves where appropriate.
  • Review international remote work separately.
  • Coordinate HR and insurance procedures.
  • Review the program annually.

Questions to Ask Your Insurance Broker

Before your next workers’ compensation renewal, ask:

  1. Are all remote employees correctly included?
  2. Are we insured in every state where employees work?
  3. How should home-office injuries be reported?
  4. How does the carrier investigate remote-work claims?
  5. What ergonomic resources are available?
  6. How should temporary out-of-state remote work be handled?
  7. What happens when an employee permanently relocates?
  8. Are international remote workers addressed?
  9. What information should managers collect after an incident?
  10. How should psychological injury claims be reported?
  11. Are employee classifications accurate?
  12. Are there risk-control resources for remote employees?
  13. Should our remote-work policy be reviewed?
  14. How quickly must claims be reported?
  15. What documentation should we maintain?

Frequently Asked Questions

Does workers’ compensation cover employees working from home?

Potentially. A qualifying injury doesn’t necessarily become ineligible merely because it occurred at home. Compensability depends on applicable state law and whether the injury is sufficiently connected to employment.

Is every injury during working hours covered?

No. Working hours alone don’t necessarily determine compensability. What the employee was doing and why can matter.

Can mental-health conditions qualify for workers’ compensation?

Potentially, but rules differ significantly among states. Some jurisdictions impose specific requirements for psychological claims, and certain occupations may have special statutory provisions.

Is ordinary work stress covered?

Not automatically. Workers’ compensation laws may require specific levels of medical and employment causation. Rules vary by jurisdiction.

Can a remote employee file a claim for back or wrist problems?

Potentially, if applicable workers’ compensation requirements are satisfied and medical evidence supports the necessary relationship to employment.

Should employers inspect employees’ homes?

Businesses should obtain legal advice before implementing intrusive home inspections. Many organizations can address basic remote-work safety through policies, self-assessments and ergonomic guidance without unnecessary intrusion.

What if an employee moves to another state?

The employer should evaluate the move promptly because workers’ compensation, payroll, tax and employment obligations may change.

Can an employee work remotely from another country?

Possibly, but international remote work can create immigration, tax, employment, insurance, privacy and cybersecurity issues. Employer approval and professional review may be appropriate.

Should employers deny obviously personal home injuries?

Employers should follow applicable reporting and claims procedures rather than making unsupported coverage decisions themselves.

Does workers’ compensation replace health insurance?

No. Workers’ compensation and health insurance are different systems with different eligibility rules and purposes.

Final Thoughts

Remote work changed something fundamental about workplace risk.

It didn’t eliminate the workplace.

It moved it.

For millions of employees, work can now happen in:

home offices + kitchens + coworking spaces + hotels + coffee shops + other states.

That creates new questions for employers and insurers.

But the core principle remains straightforward:

A remote injury needs to be evaluated based on its relationship to employment and the applicable law—not simply the fact that it happened at home.

Mental-health claims add another layer of complexity.

Psychological conditions can potentially enter workers’ compensation systems, but requirements vary significantly by jurisdiction and circumstances.

For businesses, the strongest strategy is therefore not trying to predict every claim.

It is building better systems:

Clear remote-work rules → safer workstations → reasonable workloads → prompt reporting → accurate documentation → appropriate insurance → trained managers.

Remote work may be flexible.

Your risk-management program should be structured.

Climate-Resilient Business: Surviving the “No-Go” Zones of 2026

Small-business owner inspecting a climate-resilient commercial property designed to withstand flood and severe weather.

Imagine two nearly identical businesses.

Both operate warehouses worth:

$5 million.

Both have:

  • Similar revenue
  • Similar construction
  • Similar inventory
  • Clean claims histories

But Warehouse A is located in an area with relatively modest catastrophe exposure.

Warehouse B sits in an area highly exposed to:

  • Wildfire
  • Hurricane
  • Flood
  • Severe storms

Their insurance experience may be very different.

One business may receive several competitive quotes.

The other may encounter:

higher deductibles + tighter terms + reduced capacity + additional risk-engineering requirements.

That difference illustrates one of the most important commercial-property issues of 2026:

Where your business operates can be almost as important as what your business does.

What Is a Climate Insurance “No-Go” Zone?

There isn’t an official nationwide insurance designation called a:

“No-Go Zone.”

Insurers don’t generally divide America into a simple map of:

Green = insurable

and

Red = uninsurable.

Real underwriting is considerably more complicated.

But some locations can become challenging because insurers see an unusually high concentration of catastrophe exposure.

That could involve:

  • Wildfire
  • Flooding
  • Hurricanes
  • Coastal storm surge
  • Hail
  • Tornadoes
  • Severe convective storms
  • Extreme rainfall

Marsh describes a growing concern around insurability: when severe weather becomes more frequent and assets continue accumulating in high-risk areas, transferring that risk through insurance can become increasingly expensive.

“High Risk” Does Not Automatically Mean “Uninsurable”

This distinction is important.

A business operating in a catastrophe-prone location isn’t automatically unable to obtain insurance.

Instead, it may encounter:

  • Fewer willing insurers
  • Higher premiums
  • Larger deductibles
  • Separate catastrophe deductibles
  • Lower available limits
  • More restrictive terms
  • Required risk improvements

The result depends on the:

location + building + occupancy + construction + protection + claims history + insurer + market conditions.

That means two buildings across the street from each other could potentially receive different underwriting outcomes.

The 2026 Insurance Market Creates an Interesting Contradiction

You may have heard that property insurance is getting cheaper.

That’s broadly true in the commercial market.

Marsh reported global commercial property insurance rates declined approximately:

12% in Q2 2026.

Overall commercial insurance pricing fell:

6%.

It was the eighth consecutive quarter of global commercial insurance rate decreases.

So why worry about climate-related insurance availability?

Because:

market pricing

and

individual property risk

aren’t the same thing.

Strong insurer competition can push average rates downward while catastrophe-exposed properties still face intense underwriting scrutiny.

Your ZIP Code Is Only the Beginning

Insurers increasingly have access to detailed geographic risk information.

The analysis can extend beyond:

“What ZIP code is this?”

to questions involving:

  • Exact property location
  • Distance from coastline
  • Flood characteristics
  • Wildfire exposure
  • Roof condition
  • Building materials
  • Elevation
  • Nearby vegetation
  • Fire protection
  • Historical losses
  • Local infrastructure

The result is more granular underwriting.

Two properties within the same ZIP code don’t necessarily represent the same risk.

Wildfire Risk: Your Property’s Surroundings Matter

Consider a business located near wildfire-prone vegetation.

An insurer may care about factors such as:

  • Vegetation near structures
  • Roof materials
  • Exterior walls
  • Ember vulnerability
  • Access for firefighters
  • Water availability
  • Nearby fuel loads

Simply saying:

“We’ve never had a fire.”

doesn’t necessarily answer the insurer’s concern.

Insurance pricing looks forward.

The question is:

What could happen during the next severe event?

Defensible Space Can Matter

For wildfire-exposed properties, reducing combustible materials around structures can be an important risk-management strategy.

Depending on the property, mitigation could include:

  • Vegetation management
  • Removal of combustible debris
  • Maintaining appropriate separation from structures
  • Fire-resistant landscaping
  • Protecting vents from embers
  • Improving roof resilience

Specific recommendations should come from qualified local fire-safety and risk professionals because wildfire risk varies substantially by location and building.

The broader principle is:

Reduce the probability that an external wildfire becomes a building loss.

Flood Risk Is More Complicated Than “Inside or Outside the Flood Zone”

A business owner might say:

“We’re not in the high-risk flood zone, so we’re safe.”

That conclusion can be dangerous.

Flooding can result from:

  • Rivers
  • Coastal storm surge
  • Extreme rainfall
  • Drainage failures
  • Flash flooding
  • Surface-water accumulation

Flood maps are valuable planning tools, but no map eliminates uncertainty.

Businesses should understand both their mapped exposure and the physical characteristics of their site.

Elevate Critical Equipment

Imagine a warehouse’s electrical controls are installed:

six inches above floor level.

A relatively shallow flood enters the property.

The water damages:

  • Electrical equipment
  • Server hardware
  • HVAC controls
  • Inventory

The building itself survives.

Operations don’t.

A resilience project might involve relocating critical equipment above expected water levels where practical.

That could include:

  • Electrical panels
  • Network equipment
  • Backup generators
  • Critical machinery
  • Important records

The objective isn’t merely protecting the walls.

It is protecting the business’s ability to operate.

Flood Barriers Can Reduce Damage

Depending on the property, flood-resilience strategies can include:

  • Flood barriers
  • Flood doors
  • Raised equipment
  • Drainage improvements
  • Sump systems
  • Backflow prevention
  • Water sensors
  • Emergency pumps

These improvements don’t make a building immune to flooding.

But they can reduce the severity of some events.

Swiss Re’s latest catastrophe research emphasizes that adaptation and risk-reduction measures can play an important role in maintaining long-term insurability.

Hurricane Risk Goes Beyond the Roof

Businesses in hurricane-exposed regions should think about:

wind + rain + flood + power + supply chain.

A building may survive strong winds but remain closed because:

  • Electricity is unavailable
  • Internet service fails
  • Roads are inaccessible
  • Suppliers cannot deliver
  • Employees cannot reach work

This is why climate resilience is broader than property insurance.

Marsh’s 2026 resilience research emphasizes that climate events can cascade through shared systems including energy, water, transportation, telecommunications and supply chains.

Roof Condition Can Become an Insurance Issue

For many commercial properties, the roof is a major catastrophe vulnerability.

Insurers may care about:

  • Roof age
  • Roof type
  • Maintenance
  • Attachment
  • Previous damage
  • Drainage

A poorly maintained roof can turn a storm into a much larger property claim.

Consider:

Wind damages roof → Rain enters → Inventory damaged → Electrical systems affected → Operations stop.

One physical vulnerability can produce several categories of loss.

Hail Is an Expensive Threat Too

Climate-related insurance discussions often focus on:

hurricanes + wildfires.

But severe convective storms are increasingly important.

Swiss Re reported that insured natural-catastrophe losses totaled approximately:

$107 billion in 2025.

Its latest sigma analysis highlights the continuing importance of so-called secondary perils, particularly:

wildfires and severe convective storms.

For commercial buildings, hail can damage:

  • Roofs
  • HVAC systems
  • Solar panels
  • Vehicles
  • Outdoor equipment

Businesses should not underestimate these exposures.

The Problem Is Also Growing Exposure

Climate isn’t the only driver of catastrophe losses.

More:

  • Buildings
  • Equipment
  • Infrastructure
  • Inventory
  • Economic activity

are concentrated in exposed locations.

Swiss Re emphasizes that rising exposure associated with economic growth can substantially increase future catastrophe losses even when one particular year produces below-trend insured losses.

This is an important distinction.

Insurance losses can increase because:

hazard changes + exposure grows + replacement costs rise.

Why Insurers Sometimes Reduce Capacity

Imagine an insurer covers:

1,000 commercial properties

in one coastal region.

One major hurricane could damage hundreds simultaneously.

That’s different from insuring 1,000 geographically dispersed businesses where losses are less likely to occur at once.

Insurers therefore manage:

concentration risk.

An insurer may decide:

“We already insure too much property in this area.”

It might then:

  • Decline new business
  • Reduce available limits
  • Purchase more reinsurance
  • Increase deductibles
  • Tighten underwriting

The decision doesn’t necessarily mean your individual building is poorly managed.

It may reflect the insurer’s total portfolio.

Reinsurance Matters

Insurance companies also buy insurance.

That’s called:

reinsurance.

Reinsurance helps insurers manage very large or concentrated losses.

Catastrophe risk therefore moves through several layers:

Business → Insurer → Reinsurer → Capital markets

Swiss Re reported that catastrophe-bond issuance exceeded $17 billion across 64 transactions during the first half of 2026, the strongest first half on record.

That illustrates the scale of capital involved in transferring catastrophe risk.

Your Insurance Deductible May Change

Catastrophe-exposed businesses may encounter percentage deductibles.

Instead of:

$5,000 deductible

a policy might have a hurricane or wind deductible based on a percentage of insured value.

For illustration:

Building limit: $5,000,000

2% deductible: $100,000

That’s dramatically different from a standard:

$5,000 property deductible.

Businesses should understand exactly how catastrophe deductibles are calculated.

Don’t Wait Until a Hurricane Is Coming

Insurance isn’t designed to be purchased when a catastrophe is already approaching.

Insurers may impose binding restrictions before significant events.

A business should therefore review catastrophe coverage:

well before storm season.

The same principle applies to wildfire and flood exposure.

Risk planning should happen during normal operations—not when evacuation orders begin.

Business Interruption Is Critical

Imagine your building survives a hurricane.

But electricity is unavailable for:

12 days.

Can your company operate?

Or suppose your building isn’t damaged, but the road leading to it is inaccessible.

Or your largest supplier shuts down.

Physical property insurance alone may not solve those problems.

Businesses should review their business-income and related time-element coverages carefully.

Potential issues can include:

  • Business income
  • Extra expense
  • Civil authority
  • Utility services
  • Contingent business interruption

Coverage requirements and triggers vary considerably.

Understand Your Waiting Period

Business interruption coverage may involve waiting periods or other time-based provisions.

Suppose a policy provides qualifying business-income coverage after:

72 hours.

A three-day shutdown could therefore produce a very different outcome from a three-week shutdown.

Businesses should understand:

When does coverage begin?

and

How long can it continue?

before a catastrophe occurs.

Supply-Chain Climate Risk Can Reach You From Hundreds of Miles Away

Your building might be perfectly safe.

But your supplier may not be.

Imagine your company depends on one manufacturer for a critical component.

That manufacturer is located in a hurricane-prone region.

A storm destroys its facility.

Your building has:

zero damage.

But production stops for:

six weeks.

That’s climate-related business risk without climate-related damage at your location.

Marsh’s 2026 research specifically warns that weather events can cascade through infrastructure and value chains far beyond the original physical hazard.

Map Your Critical Suppliers

Businesses should identify:

Supplier → Location → Hazard → Replacement options.

For example:

SupplierCritical ItemMajor ExposureAlternative
Supplier AElectronic componentHurricaneSupplier D
Supplier BPackagingFloodSupplier E
Supplier CRaw materialWildfireNone

The most concerning entry isn’t necessarily the supplier with the highest climate exposure.

It’s:

“Alternative: None.”

Geographic Diversification Can Improve Resilience

Imagine all your:

  • Inventory
  • Servers
  • Employees
  • Suppliers
  • Backup systems

are concentrated in one metropolitan area.

One catastrophe could affect everything simultaneously.

Where practical, resilience can involve geographic diversification.

For example:

Primary warehouse: Texas

Backup fulfillment: Arizona

or:

Primary cloud region: East

Secondary region: Central

Diversification won’t eliminate risk.

But it can reduce the chance that one event shuts down the entire business.

Your Backup Generator Needs a Plan Too

A generator sounds reassuring.

Until you discover:

  • It hasn’t been tested.
  • Fuel supply lasts only six hours.
  • Fuel deliveries cannot reach the property.
  • It doesn’t power critical systems.

Climate resilience requires operational testing.

Ask:

What does the generator actually power?

For how long?

How often is it tested?

Where does fuel come from?

Equipment alone isn’t a resilience plan.

Water Can Be as Important as Electricity

Some businesses require continuous water supply.

Examples include:

  • Food processing
  • Manufacturing
  • Hospitality
  • Healthcare
  • Agriculture

A drought, flood contamination or infrastructure failure can therefore create serious disruption even when the property itself isn’t damaged.

Map critical dependencies:

Power

Water

Internet

Transportation

Suppliers

Employees

Cloud services

Marsh recommends this type of system-level dependency analysis for climate resilience.

Climate Resilience Can Support Insurability

This is where business owners can become more proactive.

You cannot control:

where hurricanes form.

But you may be able to influence:

  • Roof condition
  • Fire protection
  • Vegetation
  • Flood defenses
  • Electrical placement
  • Backup power
  • Water detection
  • Maintenance
  • Emergency planning

Marsh’s Insurance Enabler Framework specifically focuses on property-insurance pricing drivers that insured organizations can influence.

Swiss Re similarly notes that reducing loss potential through prevention and adaptation can help lower reinsurance costs and support continued insurability.

Document Your Improvements

Suppose your company spends:

$150,000

on:

  • New roof
  • Flood barriers
  • Fire-resistant materials
  • Vegetation management
  • Water sensors
  • Backup power

Don’t simply complete the work and forget about it.

Maintain:

  • Invoices
  • Photographs
  • Inspection reports
  • Engineering reports
  • Maintenance records
  • Roof documentation
  • Testing records

Provide relevant information to your broker.

Underwriters cannot evaluate improvements they don’t know exist.

Invite Risk Engineering

For larger or complex commercial properties, insurers or brokers may offer risk-engineering assessments.

A risk engineer might review:

  • Fire protection
  • Building construction
  • Natural hazards
  • Equipment
  • Maintenance
  • Business continuity

The resulting recommendations can identify vulnerabilities before they become claims.

Treat risk engineering as:

loss-prevention advice

rather than merely an insurance inspection.

What If Traditional Insurance Becomes Difficult?

Some businesses may need alternative approaches.

Depending on the risk and jurisdiction, possibilities can include:

  • Higher deductibles
  • Layered insurance programs
  • Multiple insurers
  • Captives
  • Parametric insurance
  • Government-backed programs
  • Specialty markets

These solutions aren’t appropriate for every business.

But large or catastrophe-exposed organizations may need more sophisticated risk-transfer structures.

What Is Parametric Insurance?

Traditional property insurance generally responds based on covered physical loss subject to policy terms.

Parametric insurance works differently.

It may pay when a predefined measurable event reaches an agreed threshold.

For example:

Wind speed exceeds specified threshold

or

Earthquake intensity reaches specified level.

Because payment is linked to the trigger rather than traditional loss adjustment, parametric solutions can potentially provide faster liquidity after qualifying events.

Swiss Re notes that parametric solutions can translate natural-hazard data into financial protection intended to provide quick access to funds after disasters.

However, basis risk matters: your actual financial loss may not perfectly match the parametric payout.

FEMA Risk Tools Can Help With Planning

For U.S. businesses, FEMA provides tools and data that can help organizations understand natural-hazard exposure.

FEMA’s National Risk Index methodology evaluates natural-hazard risk using factors including:

hazard likelihood + consequences + social vulnerability + community resilience.

FEMA also points users toward its Resilience Analysis and Planning Tool for visualizing and assessing community-resilience challenges.

These tools shouldn’t replace professional engineering or insurance analysis, but they can provide useful planning context.

Before Buying a New Commercial Property

Climate risk should increasingly become part of:

real-estate due diligence.

Before purchasing a:

  • Warehouse
  • Factory
  • Office
  • Retail property
  • Hotel

consider investigating insurance before closing.

Don’t assume:

“The current owner has insurance, so I’ll easily get the same coverage.”

Your insurer, policy terms and risk appetite may differ.

Obtain Insurance Quotes Before Closing

Imagine signing a:

$7 million warehouse purchase.

After closing, you discover:

  • Only two insurers will quote.
  • Wind deductible is extremely high.
  • Flood coverage is limited.
  • Required improvements cost $500,000.

That information would have been useful:

before purchasing the property.

Insurance availability should increasingly be part of commercial real-estate due diligence in catastrophe-exposed areas.

Climate Risk Can Affect Property Value

If a building becomes:

very expensive to insure

or

difficult to insure,

potential buyers and lenders may care.

Insurance affordability can therefore become connected to:

  • Financing
  • Operating expenses
  • Investment returns
  • Property attractiveness
  • Long-term asset value

Marsh specifically notes that businesses and investors are increasingly concerned about what changing weather risk and insurance availability mean for long-term asset values.

Create a Business Climate Risk Map

For each major location, document:

Property

Address and asset value.

Hazards

Flood, wildfire, hurricane, hail, etc.

Critical Systems

Power, water, internet.

Suppliers

Where are they located?

Insurance

Limits, deductibles and exclusions.

Mitigation

What protections exist?

Recovery

How quickly can operations restart?

This converts climate risk from an abstract discussion into a business-management exercise.

Example: The Resilient Warehouse

Consider two hypothetical warehouses in a hurricane-exposed region.

Warehouse A

  • Older roof
  • No backup generator
  • Inventory stored directly on floor
  • No flood barriers
  • No documented emergency plan

Warehouse B

  • Improved roof
  • Tested backup power
  • Elevated critical equipment
  • Flood barriers
  • Water sensors
  • Documented emergency response
  • Alternative fulfillment facility

A hurricane can damage either property.

But Warehouse B may be better positioned to:

prevent damage + reduce loss + recover faster.

That is what climate resilience should accomplish.

2026 Climate-Resilient Business Checklist

Before your next insurance renewal:

  • Identify major natural hazards at each location.
  • Review flood exposure.
  • Review wildfire exposure.
  • Review wind and hurricane exposure.
  • Inspect roof condition.
  • Review drainage.
  • Protect critical electrical equipment.
  • Evaluate flood barriers where appropriate.
  • Maintain vegetation around structures.
  • Review fire-protection systems.
  • Install appropriate water detection.
  • Test backup generators.
  • Verify backup fuel arrangements.
  • Review business-interruption insurance.
  • Review catastrophe deductibles.
  • Understand flood exclusions.
  • Review utility-service coverage.
  • Map critical suppliers.
  • Identify alternative suppliers.
  • Develop alternative operating locations.
  • Maintain emergency communications.
  • Document property improvements.
  • Discuss mitigation with your insurer.
  • Review property values.
  • Update the plan annually.

Questions to Ask Your Insurance Broker

At your next renewal, ask:

  1. Which catastrophe exposures concern insurers most at our location?
  2. How does our building compare with better-performing risks?
  3. Which improvements could improve insurability?
  4. Do we have adequate flood coverage?
  5. What wind or hurricane deductible applies?
  6. Is wildfire specifically addressed?
  7. Are roof requirements changing?
  8. Do we have business-income coverage?
  9. Does utility interruption coverage apply?
  10. What about civil-authority coverage?
  11. Are critical suppliers covered?
  12. Is contingent business interruption appropriate?
  13. Should we consider parametric insurance?
  14. Are multiple insurers needed for our property program?
  15. What documentation should we provide underwriters?

Frequently Asked Questions

What is an insurance “no-go zone”?

It isn’t an official insurance classification. The phrase describes locations where catastrophe exposure can make conventional property insurance more expensive, restrictive or difficult to obtain.

Are commercial-property insurers abandoning climate-risk areas in 2026?

There is no universal withdrawal. In fact, Marsh reported global property insurance rates declined 12% in Q2 2026 because of abundant capacity and insurer competition. Individual catastrophe-exposed properties can nevertheless face more selective underwriting.

Why can a neighboring business get cheaper insurance than mine?

Differences in construction, roof condition, occupancy, fire protection, flood characteristics, claims, insured values and resilience measures can affect underwriting.

Can climate improvements lower my insurance premium?

Potentially, but there is no guaranteed discount. Risk improvements can reduce expected losses and may help improve underwriting outcomes or insurability.

Does standard commercial-property insurance cover flood?

Businesses should not assume it does. Flood coverage is frequently handled separately or subject to specific terms. Review your policy and discuss the exposure with your insurance professional.

What is catastrophe insurance?

It is a broad term for insurance arrangements addressing losses from major events such as hurricanes, earthquakes, floods or other catastrophes. Actual coverage varies significantly by policy.

What is parametric insurance?

Parametric insurance pays according to an agreed measurable event trigger rather than following the same loss-adjustment process as traditional indemnity insurance.

Should climate risk be considered before buying commercial real estate?

Yes. Insurance availability, deductibles, expected mitigation work and business-continuity risks can materially affect the economics of a property.

Are natural-catastrophe losses still increasing?

Swiss Re reported $107 billion in insured natural-catastrophe losses during 2025 and emphasizes that growing exposure continues to increase the potential for larger future losses.

Where can U.S. businesses research natural-hazard risk?

FEMA provides hazard and resilience data and planning resources, including its National Risk Index materials and resilience-planning tools.

Final Thoughts

The most dangerous assumption a business can make in 2026 is:

“We’ve always been able to buy insurance here, so we’ll always be able to buy the same insurance at an affordable price.”

Insurance markets change.

Weather patterns change.

Buildings age.

Property values increase.

Development expands.

And insurers continually update how they evaluate catastrophe exposure.

Marsh warns that when extreme weather becomes more frequent and severe while development continues in high-risk locations, the underlying risk can eventually become increasingly difficult and expensive to transfer.

At the same time, the broader 2026 commercial market is currently competitive. Global property rates declined 12% in Q2, creating opportunities for well-managed businesses to improve coverage and program structure.

That makes this an especially useful time to focus on resilience.

Don’t wait until your insurer says:

“We no longer want this risk.”

Instead:

Identify the hazard → Reduce the vulnerability → Protect critical operations → Document the improvements → Review insurance → Build a recovery plan.

A climate-resilient business isn’t one that believes disasters won’t happen.

It’s one designed to survive when they do.

Agentic AI and Business Liability: Who is Responsible When the Algorithm Errs?

Business executives supervising an autonomous AI system performing business operations.

Imagine your company hires a new employee.

On the employee’s first day, you give them permission to:

  • Access customer records
  • Send emails
  • Purchase supplies
  • Issue refunds
  • Update databases
  • Communicate with vendors

Then you tell them:

“Complete these tasks independently. Ask me only if something unusual happens.”

Now replace that employee with software.

That is roughly the risk-management challenge businesses face with increasingly autonomous AI agents.

Traditional generative AI usually waits for a person to ask a question.

Agentic systems can potentially go further.

They can be designed to:

plan → decide → use tools → perform actions → evaluate results → continue working.

That can make businesses more productive.

It also creates a difficult question:

When an AI agent causes financial damage, who pays?

The answer in 2026 isn’t simply:

“The AI did it.”

What Is Agentic AI?

Agentic AI generally refers to AI systems capable of pursuing goals and performing multi-step tasks with varying degrees of autonomy.

Instead of merely generating an answer, an AI agent might interact with other software or tools.

For example, a business could instruct an agent:

“Find suppliers for these products and obtain the best available prices.”

The system might:

  1. Search supplier databases.
  2. Compare prices.
  3. Contact vendors.
  4. Analyze responses.
  5. Recommend a supplier.
  6. Potentially place an order if authorized.

The more authority the system receives, the more significant its mistakes can become.

AI Agents Are Different From Ordinary Chatbots

Consider a traditional chatbot.

You ask:

“Draft an email asking our supplier for a 10% discount.”

The chatbot creates the draft.

You review it.

You decide whether to send it.

Now imagine an autonomous agent.

You say:

“Negotiate better pricing with our suppliers.”

The agent could potentially be configured to:

  • Identify suppliers
  • Draft messages
  • Send emails
  • Analyze responses
  • Negotiate terms
  • Update procurement systems
  • Escalate exceptions

The first system primarily creates information.

The second can potentially take actions.

From a liability perspective, that distinction matters.

Why Agentic AI Creates New Business Risks

Businesses have always used software.

But traditional software generally follows relatively deterministic rules.

For example:

IF invoice > $10,000 → require manager approval.

Agentic AI can operate with more flexible decision-making.

Its behavior may depend on:

  • Instructions
  • Model behavior
  • Available tools
  • Data
  • Context
  • Permissions
  • Previous actions

That flexibility creates value.

It can also make outcomes harder to predict.

NIST’s AI Risk Management Framework is designed specifically to help organizations identify and manage risks throughout the AI lifecycle. NIST describes trustworthy AI characteristics as including safety, security, resilience, accountability, transparency, explainability, privacy and fairness.

Scenario 1: The AI Agent Sends the Wrong Refund

Imagine an e-commerce company uses an AI customer-service agent.

The agent is authorized to:

  • Review orders
  • Handle complaints
  • Issue refunds up to $500

A customer requests:

$75 refund.

Because of an error, the agent issues:

$7,500.

Who is responsible?

The customer?

The AI company?

The business?

The employee who configured the agent?

The answer depends on the facts, contracts, system design and applicable law.

But from a practical business-risk perspective, the company operating the customer-service process may face the immediate financial problem.

That’s why AI permissions should be treated similarly to employee financial authority.

Scenario 2: The AI Makes a False Statement About a Competitor

Suppose a marketing agency uses an AI agent to generate and automatically publish social-media content.

The agent publishes an unsupported statement claiming a competitor committed fraud.

The competitor alleges reputational harm.

The business may not be able to end the dispute simply by saying:

“Our AI wrote it.”

Questions could include:

  • Who deployed the system?
  • Who authorized automatic publishing?
  • Was human review required?
  • Were appropriate safeguards used?
  • Was the output reasonably foreseeable?
  • What did the vendor contract say?

AI automation doesn’t automatically eliminate ordinary legal responsibilities.

Scenario 3: The AI Agent Signs a Bad Contract

Imagine an AI procurement agent is authorized to negotiate purchases.

Management intends it to negotiate contracts worth:

up to $10,000.

Because permissions were configured incorrectly, the agent commits the business to:

$250,000

of inventory.

Now the company may face a contractual dispute.

The key question becomes:

Did the AI have actual or apparent authority to bind the company?

Traditional principles of contract and agency law may become important even though the “agent” involved is software rather than a human representative.

This area remains legally developing.

Scenario 4: AI Accidentally Exposes Customer Data

An AI agent receives access to:

  • CRM
  • Customer database
  • Email
  • Cloud storage

An employee asks:

“Prepare a report for our external consultant.”

The AI creates the report.

But it accidentally includes confidential customer information.

The document is automatically emailed externally.

Now the business could face issues involving:

  • Privacy
  • Confidentiality
  • Data-breach obligations
  • Contractual obligations
  • Cybersecurity
  • Regulatory requirements

The problem isn’t simply that the AI produced incorrect text.

The AI performed an external action using sensitive data.

Scenario 5: The Agent Takes an Unauthorized Cyber Action

This isn’t entirely hypothetical.

Recent 2026 reporting has highlighted incidents in which autonomous AI agents took unexpected actions involving external computer systems, creating difficult questions about whether responsibility should fall on developers, deployers or other parties.

As agents gain:

browser access + coding capability + credentials + APIs + execution permissions,

businesses need to think carefully about what the system is actually allowed to do.

An AI agent should not receive unlimited authority simply because it can perform useful tasks.

“The Algorithm Did It” Is Not a Liability Strategy

Suppose a delivery company uses AI to optimize driver schedules.

The system repeatedly assigns unrealistic workloads.

Employees complain.

Management ignores the warnings.

Eventually, an incident occurs.

The company may have difficulty defending its conduct merely by arguing:

“The algorithm made the decision.”

Businesses remain responsible for many decisions made through the systems they choose to deploy.

The legal theory may differ depending on the situation, but AI should generally be viewed as part of the company’s operational process—not as an independent legal entity that automatically absorbs responsibility.

Who Could Potentially Be Responsible?

There isn’t one universal answer.

Depending on the circumstances, responsibility could potentially involve several parties.

The Business Deploying the AI

The business may face exposure if it:

  • Gives the system excessive authority
  • Fails to supervise important decisions
  • Ignores known weaknesses
  • Uses AI inappropriately
  • Fails to protect customer data

AI Developer

A developer could potentially face allegations relating to the design or functioning of a system, depending on applicable law and facts.

Third-Party AI Vendor

Contracts may allocate certain responsibilities between the vendor and customer.

System Integrator

A consultant or software company may configure the AI incorrectly.

Employee

An employee could misuse the AI or deliberately override safeguards.

Multiple Parties

Real-world incidents may involve shared responsibility.

Recent legal analysis emphasizes that increasingly autonomous agents complicate traditional fault allocation among developers, deployers and users.

Contracts Will Become Extremely Important

Suppose your business purchases an AI platform.

Before deploying it, review:

  • Limitation of liability
  • Indemnification
  • Warranties
  • Data ownership
  • Confidentiality
  • Cybersecurity obligations
  • Intellectual-property provisions
  • Service availability
  • Insurance requirements
  • Incident notification

Imagine your AI vendor contract limits liability to:

fees paid during the previous 12 months.

Your company pays the vendor:

$20,000 annually.

But an AI-related incident causes:

$1 million

in losses.

That contractual limitation suddenly becomes extremely important.

Your Customer Contracts Matter Too

Suppose your consulting company uses AI to prepare client reports.

Your customer contract promises:

professional services performed with reasonable skill and care.

The AI generates an incorrect analysis.

Your employee fails to review it.

The customer relies on it and suffers financial loss.

Now the dispute isn’t necessarily about AI law.

It may simply become a:

professional negligence or breach-of-contract dispute.

Existing legal frameworks can still apply to AI-enabled business activity.

General Liability Insurance and AI

Could Commercial General Liability insurance cover an AI-related claim?

Potentially, depending on:

  • Nature of the claim
  • Alleged injury
  • Policy language
  • Exclusions
  • Jurisdiction

A CGL policy traditionally focuses on areas such as:

  • Bodily injury
  • Property damage
  • Certain personal and advertising injuries

It isn’t designed to cover every financial loss caused by bad software or professional advice.

Businesses shouldn’t assume:

“We have general liability, so our AI risk is covered.”

Professional Liability / E&O May Be More Relevant

For companies providing professional services, Errors and Omissions (E&O) insurance may be particularly important.

Imagine an accounting consultancy uses AI to analyze financial information.

The system produces an erroneous calculation.

An employee approves it without checking.

The client suffers:

$300,000

in alleged financial loss.

That may resemble a traditional professional-services error even though AI contributed to it.

Whether insurance responds depends on the policy.

Technology E&O

Technology companies may need to examine Technology Errors & Omissions coverage.

Imagine your company sells AI software to businesses.

A defect causes customers’ systems to fail.

Customers allege:

  • Lost revenue
  • Data problems
  • Operational disruption

Technology E&O may be more relevant than standard general liability for certain technology-service failures.

Again, policy language controls.

Cyber Insurance

AI agents often require access to valuable digital systems.

That creates cybersecurity exposure.

An agent may interact with:

  • Email
  • Cloud storage
  • CRM
  • Banking systems
  • Customer databases
  • APIs
  • Internal software

If an AI-related incident causes a qualifying:

  • Data breach
  • Cyberattack
  • Privacy event
  • Business interruption

cyber insurance could potentially become relevant.

But coverage should be reviewed specifically.

Don’t assume every AI-caused cyber incident is automatically covered.

Directors & Officers Liability

AI can also create governance questions.

Imagine a board approves aggressive deployment of autonomous AI throughout the company.

Management receives repeated warnings about serious control weaknesses.

Those warnings are ignored.

A major incident occurs and shareholders allege that directors failed to exercise appropriate oversight.

Depending on the circumstances, D&O issues could arise.

The underlying question becomes less:

“Did AI fail?”

and more:

“Did leadership properly oversee a known business risk?”

Employment Practices Liability

AI systems are increasingly used in:

  • Recruiting
  • Resume screening
  • Performance management
  • Scheduling
  • Promotion decisions

These applications can create discrimination and employment-law concerns.

If an AI system produces biased outcomes, an employer may face allegations even if no employee intentionally discriminated.

Organizations should therefore evaluate AI-assisted employment decisions carefully and maintain meaningful human oversight.

Product Liability

Businesses embedding AI into physical products can face another category of exposure.

Imagine AI controls:

  • Industrial equipment
  • Robot
  • Medical device
  • Vehicle
  • Smart appliance

A faulty AI decision contributes to physical injury.

Now questions involving:

product liability + negligence + software design + manufacturing + warnings

could intersect.

The stakes are considerably higher when AI controls physical systems.

Intellectual Property Risk

Generative and agentic AI can also create copyright, trademark and confidential-information issues.

Imagine an AI marketing agent automatically creates:

  • Images
  • Advertising
  • Product descriptions
  • Website pages

and publishes them without human review.

A third party alleges that the material infringes its rights.

The business may face a claim regardless of how quickly the AI produced the content.

Businesses should understand:

  • Vendor IP protections
  • Indemnification
  • Model terms
  • Review procedures

before automating publication.

AI Hallucinations Can Become Business Losses

AI systems can generate information that appears confident but is incorrect.

This becomes particularly dangerous when the output automatically triggers action.

For example:

AI says:

Supplier A has regulatory approval.

Agent places:

$100,000 order.

Information was wrong.

The problem isn’t merely a hallucination anymore.

It has become:

a financial transaction based on a hallucination.

This is why autonomous systems need controls around high-impact decisions.

NIST’s Generative AI Profile identifies risks unique to or intensified by generative AI and recommends risk-management actions throughout the AI lifecycle.

Human-in-the-Loop Controls

One important approach is:

Human in the loop.

Instead of allowing an AI agent to complete every action independently, require human approval for high-risk decisions.

For example:

AI can:

Draft invoice → Yes

AI can:

Send $100,000 payment → Human approval required

AI can:

Draft customer email → Yes

AI can:

Terminate employee → Human decision required

AI can:

Recommend supplier → Yes

AI can:

Sign $1 million contract → Human approval required

The appropriate threshold depends on the business.

Create Permission Levels for AI Agents

Businesses already do this for employees.

The same principle should apply to AI.

Level 1 — Read Only

AI can access information but cannot change anything.

Level 2 — Draft

AI can prepare actions but a person must approve them.

Level 3 — Limited Execution

AI can perform routine low-risk actions within predetermined limits.

Level 4 — High-Risk Actions

Human approval is mandatory.

This prevents:

“AI has access to everything.”

from becoming the default configuration.

Apply the Principle of Least Privilege

An AI scheduling assistant doesn’t need access to:

the company’s bank account.

A marketing AI doesn’t necessarily need:

administrator privileges to production servers.

A customer-service agent may not need:

full employee payroll data.

Give each system only the access required for its job.

This is the cybersecurity principle of:

least privilege.

It becomes even more important when autonomous systems can take actions without waiting for humans.

Maintain AI Activity Logs

If an incident occurs, the company may need to determine:

  • What instruction was given?
  • What information did the AI receive?
  • What action did it take?
  • Which systems did it access?
  • Who approved the action?
  • When did it happen?

Logging creates an audit trail.

Without logs, investigating an autonomous-agent failure can become extremely difficult.

NIST’s AI RMF emphasizes governance, measurement and management across the AI lifecycle rather than treating AI risk as a one-time compliance exercise.

Establish an AI Kill Switch

Businesses deploying autonomous agents should consider mechanisms allowing authorized personnel to:

Stop the agent immediately.

Imagine an AI begins:

  • Sending incorrect emails
  • Deleting records
  • Making purchases
  • Changing system settings

You don’t want the response process to involve searching for the developer who knows how to shut it down.

Critical systems need clear escalation and shutdown procedures.

Test AI Before Giving It Real Authority

Don’t move directly from:

AI demo

to

full autonomous production access.

Consider staged deployment.

Stage 1: Sandbox testing

Stage 2: Read-only production access

Stage 3: Draft recommendations

Stage 4: Limited execution

Stage 5: Expanded autonomy after monitoring

This creates opportunities to discover unexpected behavior before the consequences become expensive.

AI Vendor Due-Diligence Checklist

Before deploying a third-party AI agent, ask:

  • What systems can it access?
  • What actions can it perform?
  • How are permissions controlled?
  • Is activity logged?
  • How is customer data handled?
  • Is customer data used for model training?
  • What security controls exist?
  • What happens after a breach?
  • What indemnification is provided?
  • What liability limits apply?
  • Does the vendor carry cyber insurance?
  • Does it carry technology E&O?
  • Can the agent be immediately disabled?
  • How are model updates handled?
  • How are failures investigated?

Don’t evaluate AI vendors only on:

features + price.

Evaluate their risk allocation too.

The EU AI Act Adds Another Layer

Companies operating in Europe also need to consider the EU AI Act.

Obligations for providers of general-purpose AI models began applying on August 2, 2025, including technical-documentation and copyright-policy requirements, with additional obligations for models presenting systemic risk.

Not every business using an AI agent becomes a general-purpose AI model provider.

The organization’s role, use case and system classification matter.

Businesses operating across jurisdictions should therefore determine which regulatory obligations actually apply rather than assuming one global AI rule.

U.S. AI Regulation Remains Fragmented

The U.S. doesn’t currently have one comprehensive nationwide AI liability regime that answers every agentic-AI scenario.

Businesses may instead encounter combinations of:

  • Federal law
  • State law
  • Contract law
  • Privacy law
  • Consumer-protection law
  • Employment law
  • Cybersecurity law
  • Sector-specific regulation

That makes risk management particularly important.

The NAIC’s work illustrates how insurance regulators are also developing governance expectations around AI. Its Model Bulletin reminds insurers that decisions made or supported by AI remain subject to applicable insurance laws, while regulators continued developing an AI Systems Evaluation Tool during 2025–2026.

Example: AI Procurement Disaster

Consider a hypothetical manufacturer.

It deploys an AI procurement agent.

The agent has authority to make purchases up to:

$50,000.

A configuration mistake accidentally removes the limit.

The AI identifies what it believes is a shortage of a critical component.

It orders:

$600,000

of inventory.

The forecast was wrong.

Now management discovers:

  • Inventory isn’t returnable.
  • Vendor contract is binding.
  • AI vendor disclaims consequential losses.
  • Existing insurance may not cover a poor purchasing decision.

This illustrates an important point:

Not every AI mistake is insurable.

Risk controls may be more valuable than insurance for some types of loss.

Insurance Should Be the Last Layer, Not the First

A strong AI-risk strategy might look like:

Governance

Access controls

Human oversight

Testing

Monitoring

Incident response

Contracts

Insurance

Insurance sits at the bottom because preventing a catastrophic mistake is usually preferable to arguing about coverage afterward.

Build an AI Governance Policy

Businesses using autonomous AI should establish written rules addressing:

Approved AI systems

Which tools can employees use?

Approved use cases

What can AI do?

Prohibited uses

What decisions cannot be delegated?

Data

What information may be entered?

Permissions

What systems can AI access?

Human approval

Which actions require sign-off?

Monitoring

How will activity be reviewed?

Incident response

What happens when AI behaves unexpectedly?

NIST’s voluntary AI RMF provides a useful structure through its core functions:

Govern → Map → Measure → Manage.

Agentic AI Business Liability Checklist

Before giving an AI agent operational authority:

  • Identify exactly what the AI can do.
  • Identify systems it can access.
  • Apply least-privilege access.
  • Establish financial transaction limits.
  • Require human approval for high-risk actions.
  • Log AI activity.
  • Maintain audit trails.
  • Test systems before production deployment.
  • Create shutdown procedures.
  • Review AI vendor contracts.
  • Review indemnification provisions.
  • Review vendor liability limits.
  • Review privacy obligations.
  • Review intellectual-property risks.
  • Review employment-law implications.
  • Update cyber insurance.
  • Review Technology E&O.
  • Review professional liability.
  • Review D&O exposure.
  • Train employees supervising AI.
  • Establish AI incident-response procedures.
  • Reassess controls as AI capabilities change.

Questions to Ask Your Insurance Broker

Businesses deploying agentic AI should consider asking:

  1. Does our general liability policy address any relevant AI-related exposures?
  2. Does our professional liability policy contain AI exclusions?
  3. Does Technology E&O apply to our AI products or services?
  4. How does our cyber policy treat AI-enabled incidents?
  5. Are regulatory investigations covered?
  6. Are privacy claims covered?
  7. Are intellectual-property claims covered?
  8. Does our media liability coverage apply to AI-generated content?
  9. Could autonomous transactions create uncovered financial losses?
  10. Does D&O insurance address AI-governance allegations?
  11. Are AI vendors required to carry insurance?
  12. Should vendors name us as an additional insured where appropriate?
  13. Are contractual liabilities covered?
  14. Are there exclusions involving automated systems?
  15. Should we disclose material AI deployments at renewal?

Frequently Asked Questions

Who is responsible when an AI agent makes a mistake?

There is no universal answer. Depending on the facts and applicable law, responsibility may potentially involve the company deploying the AI, developer, vendor, integrator, employee or multiple parties. Current agentic-AI liability law is still developing.

Can a company blame the AI?

Generally, businesses should not assume that saying “the AI did it” eliminates legal responsibility. Existing contract, negligence, privacy, consumer-protection and other laws can still apply to AI-enabled conduct.

Is an AI agent legally a person?

Generally, current AI systems are not treated as independent legal persons that automatically assume liability for their actions.

Does general liability insurance cover AI mistakes?

Potentially in some circumstances, but standard CGL coverage isn’t designed to cover every financial loss caused by software or professional services. Policy wording and the nature of the claim matter.

Does cyber insurance cover AI incidents?

It may respond to certain qualifying cyber or privacy events involving AI, subject to policy terms, exclusions, retentions and limits.

What is Technology E&O insurance?

Technology Errors & Omissions insurance can address certain claims alleging financial loss resulting from failures in technology products or services, subject to the policy.

Should AI be allowed to make payments automatically?

Businesses should carefully limit autonomous financial authority. High-value transactions generally warrant strong authentication, predefined limits and human approval.

What is human-in-the-loop AI?

It means keeping a person involved in reviewing or approving specified AI decisions or actions rather than allowing the system to operate completely independently.

How can businesses reduce agentic AI liability?

Useful controls include least-privilege access, human approval, testing, logging, transaction limits, vendor due diligence, incident response and documented AI governance.

Is there a single U.S. law governing AI-agent liability?

No single comprehensive federal regime currently answers every AI-agent liability scenario. Different existing federal and state laws can apply depending on the conduct and industry.

Final Thoughts

The most important change created by agentic AI isn’t simply that AI is becoming:

smarter.

It’s that AI is increasingly capable of:

acting.

An AI that writes an incorrect paragraph creates one type of risk.

An AI that can:

send → purchase → publish → transfer → modify → delete → execute

creates something much more significant.

Recent real-world incidents involving autonomous agents have already intensified questions about who bears responsibility when an AI system takes an unexpected action.

For businesses, the safest assumption is not:

“The AI vendor will be responsible.”

Nor should it be:

“Our insurance will pay.”

Instead:

If your business gives an AI system authority, treat that authority as a business risk that requires governance.

NIST’s framework offers a useful foundation for doing that by encouraging organizations to govern, map, measure and manage AI risk throughout the system lifecycle.

The future of business may involve thousands of autonomous digital agents.

But accountability still needs a human organization behind them.

The “Underinsurance” Trap: Is Your Commercial Property Protected Against 2026 Construction Costs?

Commercial property owner reviewing rebuilding costs with a contractor at a business property in 2026.
The “Underinsurance” Trap: Is Your Commercial Property Protected Against 2026 Construction Costs?

Imagine your business owns a commercial building insured for:

$1.5 million.

The policy has been renewed every year, premiums have been paid on time, and the limit still looks substantial.

Then a major fire destroys the property.

Contractors estimate that rebuilding the same structure will now cost:

$2 million.

Suddenly, your $1.5 million policy limit doesn’t look nearly as comfortable.

You may have a:

$500,000 insurance gap.

That’s the commercial-property underinsurance trap.

And even though commercial-property insurance pricing has softened significantly in 2026, reconstruction costs have not simply returned to their old levels.

What Is Commercial Property Underinsurance?

Underinsurance occurs when the amount of insurance carried on a building or other property is insufficient relative to the amount required under the policy or the cost of replacing the insured property after a covered loss.

For example:

Current estimated replacement cost: $2,000,000
Building insurance limit: $1,500,000

Potential valuation gap:

$500,000

That doesn’t necessarily mean every claim will automatically be reduced by $500,000. The actual claim outcome depends on the policy’s terms, limits, valuation provisions, coinsurance requirements, deductibles and circumstances of the loss.

But the mismatch creates potentially serious financial exposure.

Replacement Cost Is Not the Same as Market Value

This is one of the most important concepts for commercial-property owners.

Suppose you could sell your building today for:

$1.2 million.

That does not necessarily mean you should insure it for $1.2 million.

The cost to reconstruct it after a total loss could be:

$1.8 million.

Market value considers factors such as:

  • Location
  • Land value
  • Local property demand
  • Rental income
  • Economic conditions

Replacement cost focuses on what it would cost to rebuild or replace the insured property.

The Insurance Information Institute explains that replacement-cost coverage pays to rebuild or repair covered property based on current construction costs, while actual cash value generally accounts for depreciation.

Construction Costs Are Still Rising in 2026

Construction-cost inflation has moderated.

But moderated does not mean reversed.

Verisk’s Q2 2026 reconstruction-cost analysis found that total U.S. commercial reconstruction costs increased 4.1% from April 2025 to April 2026.

The increase varied considerably by state.

For example:

Rhode Island: +6.36%

Oklahoma: +5.81%

Iowa: +5.22%

Other states experienced considerably smaller increases.

Verisk’s earlier Q1 report similarly found overall U.S. reconstruction costs—including residential and commercial—were still increasing year over year, even though the pace of inflation had slowed.

Why a 4% Increase Can Matter

Four percent may not sound dramatic.

But commercial buildings involve large numbers.

Suppose rebuilding a property cost:

$5 million

last year.

A 4.1% increase would represent approximately:

$205,000

in additional cost.

Estimated replacement cost:

$5,205,000

And that is only an illustration based on the national change.

Actual rebuilding costs depend on:

  • Location
  • Building type
  • Materials
  • Labor
  • Equipment
  • Contractor availability
  • Building codes
  • Catastrophe conditions

Small percentage changes can translate into large dollar amounts.

Why Businesses Become Underinsured

Underinsurance rarely happens because an owner deliberately chooses inadequate protection.

More often, property values simply become outdated.

1. The Building Hasn’t Been Valued Recently

A company purchases a warehouse.

Replacement cost is estimated at:

$3 million.

Five years later, the policy still reflects a similar value even though construction costs have changed substantially.

The building didn’t change.

But the cost of rebuilding it did.

2. Renovations Were Never Reported

Suppose you add:

  • New production equipment
  • HVAC systems
  • Electrical upgrades
  • Commercial kitchen
  • Storage area
  • Office extension
  • Solar panels

Your building may now cost significantly more to replace.

If your insurer doesn’t know about the improvements, your policy limits may no longer reflect the actual exposure.

3. Equipment Values Are Outdated

Underinsurance isn’t limited to the building.

Commercial property can also include:

  • Machinery
  • Computers
  • Furniture
  • Inventory
  • Tools
  • Production equipment

Marsh’s Q1 2026 property-valuation update specifically cautions that equipment and contents cost trends can differ from general building-cost trends and recommends using industry-specific information rather than automatically applying one broad inflation percentage.

4. Owners Confuse Purchase Price With Replacement Cost

You bought a property for:

$900,000.

That doesn’t automatically mean:

$900,000 = correct insurance limit.

Part of the purchase price may represent land.

Conversely, rebuilding the structure could cost substantially more than its current market value.

Insurance valuation requires a different calculation.

Construction Labor Is Part of the Problem

Rebuilding isn’t only about:

bricks + steel + lumber.

You also need people.

Construction requires:

  • Electricians
  • Plumbers
  • Carpenters
  • Equipment operators
  • Engineers
  • Contractors
  • Project managers

Verisk’s Q1 2026 report noted persistent construction labor constraints even as broader reconstruction-cost inflation moderated.

A shortage of skilled labor can increase rebuilding costs and potentially extend reconstruction timelines.

Catastrophes Can Create Demand Surges

Normal construction cost and post-catastrophe reconstruction cost aren’t always identical.

Imagine a hurricane damages thousands of buildings in one region.

Suddenly everyone needs:

  • Roofers
  • Electricians
  • Contractors
  • Lumber
  • Drywall
  • Equipment

at the same time.

Local demand can surge.

That can affect:

price + availability + rebuilding time.

A property valuation that looks adequate under ordinary conditions may therefore deserve additional scrutiny in catastrophe-exposed areas.

What Is Coinsurance?

Coinsurance is one of the most misunderstood commercial-property provisions.

A commercial property policy may require the insured to maintain insurance equal to a specified percentage of the property’s value.

Common percentages can include:

80%

90%

or

100%

depending on the policy.

Failing to satisfy the requirement can potentially reduce the amount recoverable for a partial loss.

The exact calculation depends on the policy.

Simple Coinsurance Example

Assume, purely for illustration:

Replacement value: $2,000,000

Coinsurance requirement: 80%

Required insurance:

$1,600,000

But the business carries only:

$1,200,000.

Now suppose there is a covered:

$400,000 loss.

Simplified coinsurance calculation:

$1,200,000 ÷ $1,600,000 = 75%

75% × $400,000 = $300,000

Before considering the deductible and other policy provisions, the simplified calculation illustrates how inadequate limits can potentially affect even a partial loss.

This is why underinsurance isn’t only a total-loss problem.

Check Your Policy Rather Than Assuming

Not every commercial-property policy works identically.

Your policy may contain:

  • Coinsurance provisions
  • Agreed-value provisions
  • Replacement-cost provisions
  • Actual-cash-value provisions
  • Inflation adjustments
  • Blanket limits
  • Specific limits
  • Margin clauses
  • Ordinance-or-law coverage
  • Extended replacement provisions

Never assume that a general example describes your policy.

Read the actual contract.

What Is Agreed Value?

Some commercial-property programs may offer an agreed-value arrangement that can suspend application of a coinsurance provision for a specified period when policy requirements are satisfied.

That doesn’t mean:

“Valuation no longer matters.”

Quite the opposite.

The insurer may require accurate statements of property values.

If those values are outdated, the overall insurance program can still be inadequate after a major loss.

What About Inflation Guard?

Some policies include provisions designed to increase building limits over time.

The Insurance Information Institute notes that some commercial property coverage automatically increases building limits by a set percentage to help keep pace with rising rebuilding costs.

That’s useful.

But don’t assume an automatic percentage guarantees adequate coverage.

Your actual costs may increase faster because of:

  • Major renovations
  • Local construction inflation
  • Specialized materials
  • Equipment costs
  • Code requirements

Automatic adjustments aren’t a substitute for periodic valuation reviews.

Ordinance or Law Can Create Another Gap

Imagine your building was constructed in:

1985.

A major covered fire destroys half of it.

Today’s building code may require upgrades involving:

  • Electrical systems
  • Fire protection
  • Accessibility
  • Structural standards
  • Energy efficiency

Rebuilding to modern codes can cost more than simply reproducing the old building.

Standard property coverage may not fully address every additional ordinance-or-law expense.

Businesses should discuss appropriate:

Ordinance or Law Coverage

with their insurance professional.

Debris Removal Can Be Expensive

Before rebuilding begins, damaged material may need to be:

  • Demolished
  • Removed
  • Transported
  • Disposed of

Major commercial losses can produce substantial debris-removal expenses.

Policyholders should understand how their policy treats these costs and whether limits or additional amounts apply.

Don’t Forget Business Personal Property

Your building may be correctly insured while everything inside it is underinsured.

Consider a manufacturing facility containing:

Building: $4 million

Machinery: $2 million

Inventory: $1 million

Computers/furniture: $300,000

Total property exposure is far greater than the building alone.

If machinery prices increase but policy values aren’t updated, the company can still have a substantial insurance gap.

Inventory Can Change During the Year

Some businesses have seasonal inventory.

Imagine a retailer normally carries:

$300,000

of inventory.

Before the holiday season:

$850,000.

A fire in November could create a much larger loss than a fire in February.

Businesses with fluctuating inventory should discuss options such as:

  • Peak-season endorsements
  • Reporting forms
  • Appropriate blanket limits

depending on the insurer and policy structure.

Specialized Equipment Can Be Difficult to Replace

Suppose your factory relies on a machine purchased five years ago for:

$250,000.

A replacement now costs:

$400,000.

It must also be:

  • Imported
  • Transported
  • Installed
  • Calibrated

The true replacement exposure may therefore exceed the equipment’s original purchase price.

This is why Marsh recommends treating equipment and contents valuations carefully rather than applying a generic construction-cost index to every asset.

Underinsurance Can Affect Business Interruption Too

A building loss doesn’t only cost money to repair.

Your business may also stop operating.

Suppose a fire closes a manufacturing facility for:

nine months.

During that period the company may continue facing:

  • Payroll
  • Rent or loan payments
  • Taxes
  • Certain utilities
  • Other continuing expenses

while losing revenue.

Business income insurance can help with qualifying losses, subject to policy terms.

But businesses should review the period of restoration and business-income values alongside physical property limits.

Reconstruction Time Matters

A business owner might assume:

“We’ll rebuild in six months.”

But a major commercial reconstruction can involve:

  1. Damage assessment
  2. Demolition
  3. Engineering
  4. Permits
  5. Contractor selection
  6. Materials procurement
  7. Construction
  8. Equipment installation
  9. Inspections
  10. Reopening

A catastrophe can make the timeline even longer.

The financial impact of a loss therefore involves both:

cost to rebuild + time to rebuild.

Falling Insurance Rates Don’t Mean Falling Replacement Costs

This distinction is especially important in 2026.

Marsh reported that U.S. property insurance rates fell 13% in Q2 2026 as insurer capacity and competition increased. Globally, property rates declined 12%.

At the same time, Verisk reported U.S. commercial reconstruction costs were 4.1% higher year over year in April 2026.

So we can simultaneously have:

Insurance pricing ↓

while:

Reconstruction costs ↑

There is no contradiction.

Insurance rate and insured value are different things.

Don’t Reduce Limits Just Because Your Premium Fell

Suppose your broker obtains a 12% property rate reduction.

Excellent.

That doesn’t mean you should reduce your:

$5 million building limit to $4.4 million

to save even more.

The limit should reflect appropriate property valuation and policy requirements—not simply the premium you want to pay.

Marsh’s Q1 2026 valuation update emphasizes that accurate property values remain important to insurers even as market conditions improve.

The Underinsurance Problem Is Not Theoretical

The Insurance Information Institute has highlighted commercial-property undervaluation as an important industry issue.

Its commercial-property trends report cited a Kroll appraisal study indicating that approximately 90% of buildings studied were underinsured, with 68% of buildings valued during 2020–2021 underinsured by at least 25%.

That doesn’t mean 90% of every commercial building in America is currently underinsured.

The figure refers to the buildings in that appraisal study.

But it demonstrates how significant valuation gaps can become.

Example: The Underinsured Warehouse

Consider a fictional wholesale company.

The warehouse was last professionally valued in 2021 at:

$4 million.

The owner renews the policy each year without performing another detailed valuation.

By 2026, assume an updated professional estimate determines the reconstruction cost is:

$5 million.

Insurance limit:

$4 million

Potential valuation gap:

$1 million.

Then a severe fire occurs.

Even though the owner:

  • Paid every premium
  • Had replacement-cost coverage
  • Never missed a renewal

the policy’s available limit may still be insufficient to fund the entire reconstruction.

Replacement-cost coverage doesn’t create an unlimited pool of money.

Policy limits still matter.

How Often Should Commercial Property Be Revalued?

There isn’t one universal timetable suitable for every property.

However, businesses should review valuations regularly and particularly after significant changes.

Marsh recommends periodically reviewing and updating property values with valuation support when necessary.

A review becomes particularly important after:

  • Renovation
  • Expansion
  • New machinery
  • Major inventory changes
  • Construction-cost spikes
  • Acquisition
  • Change in occupancy
  • Significant building-code changes

Large or complex properties may justify professional appraisal or replacement-cost analysis.

What Should Be Included in a Property Valuation?

Depending on the business, review:

Building

  • Structure
  • Permanently installed systems
  • Improvements

Business Personal Property

  • Furniture
  • Computers
  • Machinery
  • Equipment
  • Tools

Inventory

  • Raw materials
  • Work in progress
  • Finished goods

Special Property

  • Specialized machinery
  • Outdoor property
  • Signs
  • Valuable records

The policy itself determines what property is covered and how it is valued.

2026 Commercial Property Review Checklist

Before your next renewal:

  • Check the current building limit.
  • Obtain an updated replacement-cost estimate where appropriate.
  • Don’t use market value as a substitute for reconstruction cost.
  • Review renovations completed since the last valuation.
  • Update machinery and equipment values.
  • Review inventory limits.
  • Check seasonal inventory exposure.
  • Understand replacement cost vs. actual cash value.
  • Review your coinsurance percentage.
  • Ask whether agreed value applies.
  • Review inflation-guard provisions.
  • Check ordinance-or-law coverage.
  • Review debris-removal provisions.
  • Review business-income limits.
  • Consider realistic reconstruction timelines.
  • Review catastrophe exposure.
  • Update valuations after major property changes.
  • Keep asset records and invoices.
  • Discuss valuation assumptions with your broker.
  • Review the policy annually.

Questions to Ask Your Insurance Broker

At your next commercial-property renewal, ask:

  1. What replacement cost is currently being used for my building?
  2. When was that valuation last updated?
  3. What construction-cost data supports it?
  4. Does my policy contain coinsurance?
  5. What percentage applies?
  6. Does agreed value apply?
  7. Is there an inflation-guard provision?
  8. Are recent renovations included?
  9. Are my machinery values current?
  10. Is my inventory adequately insured?
  11. What ordinance-or-law coverage do I have?
  12. How is debris removal covered?
  13. Is business-income coverage adequate for today’s rebuilding timeline?
  14. Would a professional property valuation be appropriate?
  15. What happens if actual reconstruction costs exceed my policy limit?

Frequently Asked Questions

What does underinsured mean in commercial property insurance?

Generally, it means the amount of insurance carried is insufficient relative to the property’s replacement exposure or the amount required under applicable policy provisions.

Are U.S. commercial reconstruction costs still rising in 2026?

Yes. Verisk reported commercial reconstruction costs increased 4.1% nationally from April 2025 to April 2026, although changes varied significantly by state.

Are commercial-property insurance rates rising in 2026?

Not broadly in Marsh’s latest index. U.S. property insurance rates fell approximately 13% in Q2 2026, reflecting greater capacity and competition.

How can construction costs rise while property insurance rates fall?

They measure different things. Insurance rates reflect insurance-market pricing, while replacement costs reflect the expense of reconstructing property.

Is replacement cost the same as market value?

No. Market value represents what property might sell for, while replacement cost generally reflects the cost of replacing or reconstructing insured property.

Does replacement-cost insurance guarantee my entire building will be rebuilt?

Not necessarily. Policy limits, deductibles, exclusions, valuation conditions and other policy terms still apply.

What is a coinsurance penalty?

When a policy contains a coinsurance requirement and the insured doesn’t maintain the required amount of insurance, the recoverable amount for certain losses may be reduced according to the policy’s formula.

Should I automatically increase my property limit by 4.1%?

No. The 4.1% Verisk figure is a national commercial reconstruction-cost trend, not a valuation for your specific property. Location, construction, equipment and other characteristics matter.

Does inflation guard prevent underinsurance?

It can help limits keep pace with some cost increases, but it doesn’t guarantee that the resulting limit accurately reflects the property’s current replacement cost.

Should I professionally value my commercial building?

For significant or complex properties, a professional valuation can help establish more reliable replacement-cost estimates. Verisk and Marsh both emphasize the importance of accurate insurance-to-value assessments.

Final Thoughts

The commercial-property market presents an unusual opportunity in 2026.

Insurance pricing has become more competitive.

Marsh reported U.S. property rates declined approximately 13% in Q2 2026.

But don’t confuse:

cheaper insurance rates

with

cheaper buildings to reconstruct.

Verisk’s latest Q2 analysis shows U.S. commercial reconstruction costs remained 4.1% higher year over year as of April 2026.

That means the smartest renewal strategy isn’t necessarily:

Reduce the limit to reduce the premium.

It is:

Verify the value → Understand the policy → Maintain appropriate limits → Then negotiate the rate.

A commercial property policy can only protect your business effectively when the values behind it reflect the assets you’re actually trying to replace.

Cyber Insurance 2.0: Why Your 2026 Policy Now Requires “Proof of Defense”

IT manager demonstrating cybersecurity controls during a 2026 cyber insurance security assessment.

Cyber insurance used to feel relatively straightforward.

A company completed an application.

The insurer reviewed its:

  • Revenue
  • Industry
  • Number of employees
  • Type of data
  • Claims history

A quote followed.

That process has changed.

Today’s cyber insurer may want a much clearer picture of how your organization actually protects itself.

Does your company use multi-factor authentication?

Are backups separated from the main network?

Can you restore them?

Are endpoints monitored?

How quickly do you patch serious vulnerabilities?

Do employees receive cybersecurity training?

Do you have an incident-response plan?

The answers can influence whether an insurer offers coverage and, when it does, the policy’s price, deductible or retention, limits and other terms.

Welcome to what we’ll call:

Cyber Insurance 2.0.

Insurance isn’t replacing cybersecurity.

Increasingly, the two work together.


What Does “Proof of Defense” Mean?

“Proof of Defense” isn’t a standardized insurance coverage or universal regulatory term.

For this guide, it means:

Being able to accurately demonstrate the cybersecurity controls your company says it has.

The distinction matters.

An insurance application might ask:

Do you use MFA for remote access?

Checking Yes should mean the control actually exists where represented—not that the company intends to install it next quarter.

Marsh’s cyber insurance application guidance identifies security questions involving MFA, patching, cyber training, backups, incident history, encryption and sensitive records.

Coalition’s application similarly asks whether companies maintain backups of critical data and systems on a separate network or offline and where MFA is enforced.

The modern underwriting conversation is therefore increasingly about:

What controls exist + where they exist + how they operate.


Why Cyber Insurers Care About Security Controls

Cyber insurers ultimately insure financial losses.

A successful attack can produce:

  • Forensic expenses
  • Data restoration costs
  • Business interruption
  • Legal expenses
  • Customer notification
  • Regulatory expenses
  • Ransomware response
  • Fraud losses
  • Third-party claims

The insurer therefore wants to understand the probability and potential severity of those losses.

Security controls provide information about that risk.

Marsh says cyber underwriters assess factors including an applicant’s industry, data, prior incidents and controls such as MFA, backups and endpoint protection. Those factors can affect pricing, deductibles, limits and policy conditions.


The Ransomware Problem Hasn’t Disappeared

Cyber insurance requirements didn’t become more detailed without reason.

Coalition’s 2026 Cyber Claims Report found that initial ransomware demands during 2025 increased:

47% year over year.

At the same time, Coalition reported that 86% of affected businesses in its dataset refused to pay, which it associated with improved resilience, including viable backups and incident-response capabilities.

This illustrates why insurers care about what happens before an attack.

A company capable of restoring systems from reliable backups presents a different recovery scenario from one whose only copy of critical data has been encrypted.


Control #1: Multi-Factor Authentication

MFA is one of the most important controls businesses should expect to discuss.

Instead of relying only on:

Username + Password

MFA requires additional verification.

Depending on the system, that might involve:

  • Authenticator application
  • Hardware security key
  • Biometric verification
  • Other authentication factors

The objective is straightforward.

A stolen password alone should not necessarily give an attacker access.

Marsh identifies MFA as a key control, particularly for remote access and privileged or administrator access.


“We Have MFA” May Not Be Enough

Implementation matters.

Imagine a business has 100 employees.

MFA protects its accounting software.

But MFA isn’t enabled for:

  • Email
  • Remote access
  • Administrator accounts

Can management simply answer:

“Yes, we use MFA”?

That may provide an incomplete picture.

Coalition’s application, for example, asks applicants where MFA is enforced, including email and various forms of remote access.

The better question is:

Where is MFA enforced?


Control #2: Endpoint Detection and Response

Every:

  • Laptop
  • Desktop
  • Server
  • Workstation

can potentially become an entry point.

Endpoint Detection and Response—commonly called EDR—is designed to monitor endpoints for suspicious activity and help organizations detect and respond to threats.

Marsh identifies EDR among its key cyber hygiene controls.

At-Bay’s cyber insurance application also asks applicants which EDR product, if any, they use.

For a company with hundreds of endpoints, simply saying:

“We have antivirus.”

may not provide underwriters with enough information about the broader security posture.


Control #3: Secure Backups

Backups can become crucial during ransomware recovery.

Imagine attackers encrypt:

  • Customer records
  • Accounting data
  • Inventory systems
  • Shared drives
  • Production databases

Then the business discovers its backup environment is accessible through the same compromised network.

The attacker encrypts that too.

The company technically had:

“Backups.”

But they weren’t sufficiently resilient.

That’s why insurers may ask much more specific questions.

Coalition asks whether critical data and systems are backed up at least weekly offline or on a separate network.

At-Bay asks about backup-and-restoration procedures and whether offline or cloud backups are maintained.


A Backup Isn’t Useful Until You Can Restore It

Businesses should distinguish between:

Creating backups

and

Recovering from backups.

Imagine your IT team tells management:

“Everything is backed up every night.”

A ransomware attack occurs.

Then the company discovers:

  • Some backups are corrupted
  • Critical databases weren’t included
  • Credentials required for restoration are unavailable
  • Recovery takes three weeks

This is why backup testing matters.

Marsh identifies secured, encrypted and tested backups as one of its important cyber hygiene controls.


Control #4: Patch and Vulnerability Management

Software vulnerabilities can provide attackers with opportunities to enter networks.

A strong patch-management process helps businesses:

  1. Identify vulnerabilities.
  2. Prioritize them.
  3. Deploy available fixes.
  4. Verify remediation.

Marsh includes patch and vulnerability management among its recommended cyber resilience controls.

Its research has also found a relationship between timely patching of high-severity vulnerabilities and reduced cyber-event probability.

For insurers, the question may therefore extend beyond:

“Do you patch?”

to:

“How quickly do you remediate critical vulnerabilities?”


Control #5: Privileged Access Management

Not every employee needs administrator privileges.

An ordinary employee might need access to:

  • Email
  • CRM
  • Documents

But not:

  • Domain administration
  • Backup configuration
  • Security controls
  • Financial systems
  • Every customer database

Privileged Access Management, or PAM, is intended to control powerful accounts and limit unnecessary access.

Marsh includes PAM among its key cyber controls.

The principle is simple:

Give users the access they need—not unlimited access they don’t need.


Control #6: Email Security

Email remains an important attack vector.

Employees can receive:

  • Phishing links
  • Malicious attachments
  • Fake invoices
  • Impersonation messages
  • Credential-stealing pages

Technical controls can help filter malicious content before employees interact with it.

Marsh identifies:

Email filtering and web security

among its important cyber hygiene controls.

But technology alone isn’t enough.

Employees also need to recognize suspicious requests.


Control #7: Employee Cybersecurity Training

Consider this email:

“CEO: I’m in a meeting. Wire $85,000 to this supplier immediately.”

The employee believes it is legitimate.

They transfer the money.

No sophisticated malware was required.

The attacker exploited:

a person.

Cyber insurance applications may therefore ask about cybersecurity training. Marsh’s Cyber Accelerate application guidance specifically lists cyber training among the organization’s security-control information applicants should be prepared to provide.


Control #8: Incident Response Planning

What happens at:

2:15 a.m.

when ransomware begins encrypting your network?

Who gets called?

IT?

CEO?

Legal counsel?

Cyber insurer?

Forensics firm?

Public relations?

An incident-response plan establishes responsibilities before the crisis occurs.

Marsh says incident-response planning is one of the cybersecurity controls cyber insurers ask its clients about during underwriting.


Having a Plan Isn’t the Same as Testing It

Imagine your incident-response document says:

“Contact IT director immediately.”

The IT director left the company eight months ago.

Another contact number is outdated.

Nobody knows where the cyber policy is stored.

The plan exists.

But it isn’t operational.

Businesses should periodically test response procedures through:

tabletop exercises.

Marsh recommends regular, varied tabletop exercises as part of cyber-risk preparedness.


What Might Count as Evidence?

There isn’t one universal evidence package required by every insurer.

Requirements vary.

But businesses should maintain accurate documentation supporting their cybersecurity representations.

Depending on the question and insurer, relevant records might include:

  • MFA configuration information
  • EDR deployment reports
  • Backup logs
  • Recovery-test results
  • Patch-management reports
  • Vulnerability scan summaries
  • Security-training records
  • Incident-response plans
  • Tabletop exercise records
  • Access-control policies
  • Security vendor information

The goal isn’t to manufacture paperwork for insurance.

It’s to know that what your application says is actually true.


Why Accuracy on the Application Matters

Suppose an application asks:

“Is MFA required for remote access?”

The applicant answers:

Yes.

After a cyber incident, investigation reveals a legacy remote-access system that didn’t require MFA.

That discrepancy can create serious complications.

The exact consequences depend on:

  • Policy wording
  • Application wording
  • Applicable law
  • Materiality
  • Facts surrounding the claim

The safest approach is straightforward:

Answer cyber insurance applications accurately and completely.

If IT doesn’t know the answer, investigate before checking the box.


Bring IT Into the Insurance Application

Cyber insurance shouldn’t be completed solely by:

Accounting

or

the business owner.

Some questions are technical.

Marsh specifically recommends having someone from the organization’s IT team available when completing its Cyber Accelerate application because of the security questions involved.

For larger organizations, the application process might involve:

  • IT
  • Information security
  • Legal
  • Finance
  • Risk management
  • Insurance broker

Cyber insurance is increasingly a cross-functional responsibility.


Example: The Dangerous “Yes” Box

Imagine a small manufacturer is applying for cyber insurance.

The application asks:

Does your organization use MFA?

The owner knows employees use an authenticator application for Microsoft 365.

So:

Yes.

But the company’s remote-access system doesn’t use MFA.

Its administrator accounts also lack MFA.

The business should not assume that one MFA implementation means it can give a blanket affirmative response to every MFA question.

Read exactly what is being asked.


Security Controls Can Affect Insurance Terms

Cybersecurity doesn’t simply affect whether an insurer likes your company.

Marsh explains that underwriters use information about security controls alongside other risk characteristics to establish:

  • Price
  • Deductibles
  • Limits
  • Other policy conditions.

This creates an important business case for cybersecurity investment.

Improving security can potentially:

reduce cyber risk + improve insurability.

However, businesses shouldn’t assume installing one tool automatically guarantees a specific premium discount.

Underwriting remains multifactorial.


Cyber Insurance Is Not a Substitute for Cybersecurity

Imagine buying fire insurance for a warehouse.

Would that mean you should:

  • Remove smoke detectors?
  • Ignore faulty wiring?
  • Disable sprinklers?

Of course not.

Insurance provides financial protection after covered losses.

Risk controls help reduce the probability and severity of those losses.

Cyber insurance works similarly.

Marsh describes cyber insurance as one component of a broader approach that includes cybersecurity controls, business-continuity planning, contractual risk allocation and incident-response readiness.


Why Small Businesses Should Pay Attention

Cybersecurity underwriting isn’t only relevant to multinational corporations.

Small companies can rely heavily on:

  • Microsoft 365
  • Google Workspace
  • Shopify
  • Cloud accounting
  • Online banking
  • Customer databases
  • Remote employees

A compromised email account alone can lead to:

  • Fraud
  • Data exposure
  • Business interruption
  • Reputation damage

Small businesses therefore shouldn’t wait until renewal week to discover that their cybersecurity posture needs improvement.


Example: E-Commerce Business

Imagine an online retailer with:

$4 million annual revenue

and 25 employees.

The company stores customer information and relies on its online storefront for nearly all revenue.

Before renewal, the insurer asks about:

MFA: Yes
EDR: Yes
Backups: Yes
Security training: Yes
Incident-response plan: Yes

Those answers sound strong.

But management should verify:

MFA: Is it enforced on all systems the question covers?

EDR: Is it deployed across required endpoints?

Backups: Are they separated and recoverable?

Training: Is it current and documented?

Incident response: Has the plan been updated and tested?

That’s the difference between:

having a security checklist

and

maintaining a defensible security posture.


What Happens If You Don’t Have the Controls?

There is no single universal outcome.

Depending on the insurer, company and missing controls, the result could potentially include:

  • Additional underwriting questions
  • Requirement to improve controls
  • Different terms
  • Higher retention
  • Restricted limits
  • Coverage modifications
  • Declined coverage

Marsh notes that certain cyber controls have become important to insurability, while its Cyber Pathway offering specifically helps organizations identify control improvements that can potentially lead to increased coverage.


Don’t Install Security Tools Only for Insurance

This is another mistake.

Suppose your renewal is in two weeks.

The application asks about EDR.

You hurriedly purchase a product and install it on:

10 of 80 computers.

Then answer:

“Yes, we have EDR.”

That misses the purpose of the control.

Security should be:

implemented + configured + monitored + maintained.

Cyber insurance underwriting can provide motivation to improve security, but the ultimate goal is reducing actual risk.


Prepare 90 Days Before Renewal

Cyber insurance preparation shouldn’t begin the night before the application is due.

Approximately 60–90 days before renewal, consider reviewing:

Identity Security

  • MFA
  • Privileged accounts
  • Remote access

Endpoint Security

  • EDR deployment
  • Device inventory
  • Unsupported systems

Data Protection

  • Backup frequency
  • Backup separation
  • Recovery testing
  • Encryption

Vulnerability Management

  • Scanning
  • Patching
  • Critical vulnerabilities

Human Risk

  • Security awareness
  • Phishing training

Incident Preparedness

  • Incident-response plan
  • Contact information
  • Tabletop testing

This gives the business time to fix weaknesses rather than simply disclose them.


Create a Cyber Insurance Evidence Folder

A useful internal practice is maintaining a secure repository containing current cybersecurity documentation.

For example:

01 — MFA

02 — Endpoint Security

03 — Backups

04 — Patch Management

05 — Employee Training

06 — Incident Response

07 — Tabletop Exercises

08 — Vendor Security

09 — Policies

10 — Prior Incidents

This isn’t a formal insurance requirement.

It’s simply a practical way to keep information organized for:

  • Renewals
  • Audits
  • Security assessments
  • Incident response

Sensitive cybersecurity information should, of course, be appropriately protected.


The 2026 Cyber Insurance Readiness Checklist

Before applying or renewing:

  • Verify MFA deployment.
  • Review remote-access security.
  • Review privileged accounts.
  • Confirm endpoint protection/EDR.
  • Verify device inventory.
  • Review backup architecture.
  • Confirm backups are appropriately separated.
  • Test data restoration.
  • Review patching procedures.
  • Address critical vulnerabilities.
  • Review email-security controls.
  • Conduct employee security training.
  • Update the incident-response plan.
  • Conduct tabletop exercises.
  • Review third-party dependencies.
  • Document material controls accurately.
  • Have IT review technical application answers.
  • Correct inaccurate or outdated information.
  • Start the process well before renewal.
  • Compare policy terms—not premium alone.

Questions to Ask Your Cyber Insurer or Broker

Before purchasing coverage, ask:

  1. Which cybersecurity controls materially affect underwriting?
  2. Where specifically is MFA expected?
  3. What backup practices are expected?
  4. Does the insurer expect EDR?
  5. Are there minimum patching expectations?
  6. What documentation may be requested?
  7. What happens if our controls change during the policy period?
  8. Are ransomware sublimits applicable?
  9. Does ransomware coverage include coinsurance?
  10. Are social-engineering losses covered?
  11. What business-interruption waiting period applies?
  12. What incident-response vendors can we use?
  13. Who must we contact immediately after an incident?
  14. Are third-party cloud outages covered?
  15. What security improvements could improve our next renewal?

Frequently Asked Questions

Do cyber insurers require MFA in 2026?

Many cyber insurers closely evaluate MFA, especially for remote and privileged access, but requirements vary by insurer and applicant. MFA is one of the controls Marsh identifies as particularly important to cyber resilience and insurability.

Is “Proof of Defense” an official cyber insurance requirement?

No. It is not a universal standardized insurance term. In this article, it describes the increasing need for applicants to accurately demonstrate and document cybersecurity controls during underwriting.

What cybersecurity controls do insurers look for?

Common areas include MFA, EDR or endpoint protection, secure backups, privileged-access management, email security, patch management, employee training and incident-response planning.

Can an insurer ask about backups?

Yes. Coalition’s cyber application, for example, asks whether sensitive or critical data and systems are backed up at least weekly offline or on a separate network.

Does an insurer care which EDR system we use?

Potentially. At-Bay’s cyber application specifically asks applicants which EDR product they use, if any.

Will strong cybersecurity reduce my premium?

It can improve how an insurer evaluates the risk, but there is no guaranteed discount. Pricing also depends on revenue, industry, data, claims history, limits and other underwriting factors.

Can poor cybersecurity cause cyber insurance to be declined?

Potentially. Missing critical controls can affect insurability or the terms offered, depending on the insurer and risk.

Should my IT department complete the cyber application?

Business management should remain involved, but technical answers should be verified by knowledgeable IT or security personnel. Marsh explicitly recommends having IT expertise available during its cyber application process.

Are backups enough to protect against ransomware?

No. Backups are one layer of protection. Organizations should use a broader security strategy incorporating identity security, endpoint protection, vulnerability management, email security and incident-response planning.

How often should cyber controls be reviewed?

There is no universal insurance timetable. Organizations should review them regularly and particularly before insurance applications or renewals, after material technology changes and following significant incidents.


Final Thoughts

Cyber insurance is becoming less about simply answering:

“Have you ever been hacked?”

and more about understanding:

“How difficult would you be to hack—and how effectively could you recover?”

Current cyber underwriting examines controls including:

MFA + endpoint protection + backups + patching + training + incident preparedness.

The trend is understandable.

Coalition’s 2026 claims data shows initial ransomware demands rose 47% during 2025, even as most affected businesses in its dataset refused to pay.

Businesses therefore shouldn’t treat cybersecurity questions as paperwork designed merely to obtain a policy.

They should treat them as a test of operational resilience.

The strongest approach is:

Implement the control → Verify it works → Document it accurately → Maintain it → Answer the insurance application truthfully.

That’s what “Proof of Defense” should mean in 2026.

The 2026 Small Business Premium Surge: Why Your Rates Just Jumped 11%

Small-business owner reviewing an unexpectedly higher 2026 insurance renewal premium at a retail business.

Opening an insurance renewal can sometimes produce an unpleasant surprise.

Last year, your business paid:

$18,000.

This year’s renewal might be:

$19,500.

Or perhaps your employee health insurance quote increased by double digits.

The natural reaction is:

“Why did my insurance suddenly become so expensive?”

In 2026, however, there isn’t one universal small-business insurance increase.

Different insurance markets are moving in very different directions.

Small-group health insurers proposed a median increase of approximately 11% for 2026, according to a KFF analysis of filings from 318 ACA-compliant insurers across all 50 states and Washington, D.C.

But commercial business insurance tells a more complicated story.

Some liability and property policies are still experiencing renewal increases, while workers’ compensation and several broader commercial markets have become more competitive.

Understanding the difference can help business owners negotiate intelligently instead of assuming every premium increase is unavoidable.


Where Does the 11% Number Come From?

The figure comes from the small-group health insurance market.

KFF analyzed proposed 2026 rate filings from 318 ACA-compliant small-group insurers.

The median proposed premium increase was approximately:

11%.

The requested changes varied dramatically—from a 5% decrease to a 32% increase.

About 68% of insurers requested increases between:

5% and 15%.

And approximately 10% proposed increases of:

20% or more.

That makes an 11% increase meaningful.

But it doesn’t mean:

“Every small-business insurance policy increased 11% in 2026.”

That would be inaccurate.


Health Insurance Is Driving Some of the Biggest Concerns

For businesses offering employee health benefits, rising healthcare costs remain a major challenge.

KFF’s analysis of insurer filings identified several factors contributing to proposed 2026 increases.

These include:

  • Rising medical costs
  • Increased healthcare utilization
  • Higher prescription-drug spending
  • Rising labor costs
  • General inflation
  • Changes in enrollment
  • Changes in the health of the insured risk pool

Insurers ultimately need premiums sufficient to cover expected medical claims and administrative expenses.

When the expected cost of healthcare rises, premiums generally face upward pressure.


Prescription Drugs Are Part of the Problem

Prescription-drug spending is one factor insurers cited in their 2026 filings.

This can include higher utilization and the growing cost of certain medications.

For a small employer, those healthcare trends are largely outside the company’s control.

A business can:

  • Shop carriers
  • Change plan designs
  • Adjust employer contributions
  • Review networks
  • Introduce wellness initiatives

But it cannot directly control the underlying cost of medical care.

That’s one reason health insurance renewals can feel particularly difficult.


But Your BOP Didn’t Increase 11% on Average

Now consider another common small-business policy:

Business Owners Policy (BOP).

IVANS reported that the average premium renewal rate change for BOP policies during Q2 2026 was:

+6.16%.

That was actually lower than the:

+6.74%

recorded during Q1.

So if your BOP increased 11%, your increase is significantly higher than this broad Q2 index average.

That doesn’t automatically mean your insurer is overcharging.

Your individual business may have:

  • Higher property values
  • Claims
  • Changed operations
  • More employees
  • Increased sales
  • Higher payroll
  • New locations
  • Different limits

But an 11% BOP increase deserves investigation rather than automatic acceptance.


What’s Happening With General Liability?

General liability premiums are still increasing for many businesses, but the pace moderated during Q2.

IVANS reported:

Q1 2026: +6.85%

Q2 2026: +5.44%

for average general-liability premium renewal rate changes.

That’s a meaningful slowdown.

If your general liability renewal increased:

15%

while your business hasn’t materially changed, ask your broker or insurer why.

There could be a legitimate underwriting reason.

But you should understand it.


Commercial Property Is Still Expensive for Some Businesses

Commercial property remains highly dependent on:

Location.

A small office in a relatively low-catastrophe region presents a different risk from a business exposed to:

  • Hurricanes
  • Wildfires
  • Severe convective storms
  • Flooding
  • Hail
  • Tornadoes

IVANS reported an average Q2 2026 commercial-property renewal rate increase of:

6.40%.

That was slightly below Q1’s:

6.83%.

However, individual property accounts can move very differently from national averages.


Why Rebuilding Costs Affect Your Property Premium

Imagine your building was insured several years ago for:

$800,000.

Today, rebuilding it could cost:

$1.1 million.

Even if the insurance rate barely changes, your premium can rise because the insured value increased.

Commercial reconstruction costs can reflect changes in:

  • Labor
  • Materials
  • Equipment
  • Transportation
  • Contractor availability
  • Building codes

This distinction matters.

Your renewal premium can increase even when your insurer hasn’t raised its rate by the same percentage.


Premium Increase vs. Rate Increase

These aren’t necessarily the same thing.

Suppose last year:

Insured building value: $1,000,000
Illustrative rate: $0.50 per $100

Simplified premium:

$5,000

Now suppose the rate remains unchanged, but the insured value increases to:

$1,150,000.

Simplified premium:

$5,750

Your premium increased:

15%.

But the illustrative insurance rate didn’t increase.

The exposure did.

This is why business owners should ask:

“What specifically caused my premium increase?”

rather than simply:

“Why did your rates increase?”


Commercial Auto Remains Challenging

Businesses operating:

  • Vans
  • Trucks
  • Delivery vehicles
  • Sales vehicles
  • Service fleets

may continue seeing commercial-auto pressure.

IVANS reported an average commercial-auto premium renewal rate change of:

+4.93% in Q2 2026.

That was down from:

+5.28% in Q1.

Commercial-auto insurers continue to deal with expensive claims involving vehicle repairs, medical costs and liability severity.

The experience of your individual fleet can matter significantly.


One Accident Can Change Your Renewal

Imagine a plumbing business owns:

6 service vans.

Annual commercial-auto premium:

$16,000.

During the year, an employee causes a serious accident.

Total insured claim:

$85,000.

At renewal, the insurer may reassess:

  • Driver quality
  • Claims history
  • Fleet management
  • Vehicle usage
  • Territory
  • Underwriting profitability

The business could experience a much larger increase than the national commercial-auto average.

Insurance market statistics are useful benchmarks.

They aren’t guarantees.


Umbrella Liability Remains Under Pressure

One of the more difficult U.S. commercial lines in 2026 remains:

Umbrella and excess liability.

IVANS reported an average premium renewal rate change of:

+7.96%

during Q2 2026.

That was down from:

+9.36%

in Q1, but it remained one of the largest increases among the commercial lines IVANS tracks.

Other market research also shows continued U.S. casualty pressure.

Marsh reported that while global commercial insurance rates fell 6% in Q2 2026, U.S. casualty pricing continued to face pressure from claims severity and litigation trends.


Why Liability Claims Are Becoming More Expensive

Liability insurers don’t only care about how frequently businesses are sued.

They care about:

how expensive claims become.

A severe liability claim can involve:

  • Medical expenses
  • Lost earnings
  • Legal expenses
  • Settlements
  • Court judgments

Higher claim severity can push liability premiums upward even if a particular business hasn’t experienced a recent claim.

This is particularly relevant for umbrella and excess liability insurance.


Workers’ Compensation Is the Exception

Here’s where the “everything is going up” narrative breaks down.

Workers’ compensation pricing has been comparatively favorable.

IVANS reported the Q2 2026 average premium renewal rate change as:

-1.37%.

Q1 was:

-1.73%.

So workers’ compensation isn’t currently following the same pattern as many other commercial lines.

If your workers’ compensation premium jumped substantially, investigate whether the cause was:

  • Payroll growth
  • Classification changes
  • Experience modification
  • Claims
  • Audit adjustments

rather than assuming the overall workers’ compensation market increased.


The Commercial Insurance Market Is Actually Softening

This is another reason the headline requires context.

Marsh’s Q2 2026 Global Insurance Market Index found that global commercial insurance rates fell 6% on average.

That represented the:

eighth consecutive quarterly decline.

Global property pricing fell approximately:

12%.

Cyber insurance fell:

4%.

Meanwhile, casualty increased:

2%.

Marsh attributed the broader declines to factors including:

  • Strong insurer competition
  • Abundant capacity
  • Strong profitability
  • Surplus capital
  • Lower reinsurance costs
  • Higher investment returns

So 2026 isn’t simply a story of universally rising business-insurance prices.

It is a diverging market.


What About Small Commercial Businesses Specifically?

WTW’s Q1 2026 Commercial Lines Insurance Pricing Survey provides additional perspective.

It reported an aggregate U.S. commercial insurance price increase of:

2.5%.

That was substantially below:

5.3% in Q1 2025.

WTW also reported that pricing trends softened across:

  • Small Commercial
  • Mid-Market Commercial
  • Large Account Commercial

while excess/umbrella remained one of the areas experiencing stronger increases.

This is important negotiating information for small-business owners.

The broader market may be more competitive than your renewal notice suggests.


So Why Did Your Premium Jump 11%?

There are several possibilities.

1. You’re Talking About Employee Health Insurance

In this case, an increase around 11% is broadly consistent with KFF’s median proposed 2026 small-group health insurance increase.

2. Your Business Grew

Suppose annual revenue increased from:

$1 million

to:

$1.5 million.

Some insurance premiums depend partly on:

  • Revenue
  • Payroll
  • Square footage
  • Vehicles
  • Employees

More exposure can mean more premium.

3. Your Property Values Increased

Higher replacement costs can increase premiums even without equivalent rate increases.

4. You Had Claims

Recent claims can influence underwriting.

5. Your Risk Profile Changed

Perhaps you:

  • Added delivery services
  • Purchased vehicles
  • Entered a new market
  • Added a warehouse
  • Began manufacturing
  • Increased inventory

6. Your Insurer Changed Its Appetite

An insurer may simply want less exposure to your industry or location.

7. Your Coverage Improved

Maybe your renewal added:

  • Higher limits
  • Broader coverage
  • Lower deductible
  • New endorsements

Compare coverage before comparing premium.


Example: The $25,000 Renewal

Consider a small e-commerce company.

Last year:

BOP: $8,000
Cyber: $4,000
Workers’ Comp: $5,000
Commercial Auto: $3,000
Umbrella: $2,500

Total:

$22,500

This year:

$25,000

Increase:

11.1%.

At first glance, the company concludes:

“Insurance rates increased 11%.”

But after reviewing the renewal, the broker discovers:

  • Warehouse value increased
  • Revenue increased 20%
  • Umbrella rates increased
  • Cyber premium decreased
  • Workers’ comp rate decreased
  • Payroll increased

The total premium rose 11%.

But insurance rates didn’t uniformly rise 11%.

That distinction can help the company make better decisions.


Your Revenue Can Increase Your Premium

Many liability policies use estimated revenue as one rating factor.

Suppose your company grows from:

$2 million revenue

to:

$3 million.

That’s good news.

But insurers may now see greater exposure.

More customers can mean:

  • More transactions
  • More products
  • More contracts
  • More potential claims

Your premium can therefore rise even in a softening insurance market.


Payroll Growth Can Increase Premiums

Workers’ compensation is particularly sensitive to payroll.

Suppose:

2025 payroll: $750,000

2026 payroll: $1,000,000

Even if the workers’ compensation rate decreases, your total premium can still increase because you have more payroll exposure.

Again:

Premium ≠ rate.


Inflation Can Affect Claim Costs

Insurers ultimately price expected future claims.

If repairing a damaged building becomes more expensive, property claims become more expensive.

If vehicle parts and labor become more expensive, auto claims become more expensive.

If medical care becomes more expensive, bodily injury claims become more expensive.

If litigation becomes more expensive, liability claims can become more expensive.

Insurance premiums eventually reflect these underlying costs.


Natural Catastrophes Can Affect Businesses Far From the Disaster

You don’t necessarily need to suffer a catastrophe personally for insurance-market conditions to affect pricing.

Large losses from:

  • Hurricanes
  • Wildfires
  • Severe storms
  • Floods

can influence insurer and reinsurer decisions.

However, the effect isn’t uniform.

By Q2 2026, global property insurance pricing was actually declining substantially in Marsh’s index as capacity and competition increased.

Individual catastrophe-exposed properties can still face very different conditions.


Why Geography Matters More Than Ever

Two identical businesses can pay very different premiums.

Imagine two restaurants.

Restaurant A operates in a relatively low-catastrophe region.

Restaurant B operates in an area with substantial:

  • Hurricane
  • Flood
  • Wildfire
  • Hail

exposure.

Even if:

  • Revenue is identical
  • Buildings are identical
  • Claims history is identical

property premiums may differ dramatically.

ZIP code can matter.


Your Industry Matters Too

Insurance companies don’t price all businesses equally.

A home-based consultant generally presents different risks from:

  • Roofing contractor
  • Trucking company
  • Restaurant
  • Manufacturer
  • E-commerce warehouse

Higher-risk industries can experience pricing trends very different from broad market averages.

That’s why national averages should always be treated as:

benchmarks, not quotes.


Cyber Insurance May Actually Be Getting Cheaper

Cyber insurance provides another interesting contrast.

Marsh reported global cyber insurance rates declined:

4% in Q2 2026

following a 5% decline in Q1.

It was the twelfth consecutive quarter of declining cyber rates in Marsh’s index.

That doesn’t mean every business will receive a decrease.

Companies with:

  • Weak security controls
  • Prior ransomware claims
  • Poor backups
  • No MFA
  • High-risk data

can still face difficult underwriting.

But businesses with strong cybersecurity should shop aggressively.


Don’t Automatically Accept Your Renewal

One of the biggest mistakes a small-business owner can make is:

Pay renewal → File policy → Forget about it.

Instead, review your insurance before renewal.

Ideally, start:

60–90 days before expiration.

That gives your broker time to:

  • Update applications
  • Approach insurers
  • Compare quotes
  • Review claims
  • Negotiate terms
  • Adjust coverage

Waiting until the day before expiration dramatically reduces your options.


Ask Your Broker for a Renewal Breakdown

If your premium increased 11%, ask:

What percentage came from rate changes?

What percentage came from exposure changes?

Did insured values increase?

Did payroll increase?

Did revenue increase?

Did my experience modification change?

Were limits changed?

Did deductibles change?

Did coverage improve?

Did the insurer apply a catastrophe adjustment?

You want to understand the mechanics of the increase.


Compare Like With Like

Suppose your existing insurer quotes:

$15,000.

Another insurer quotes:

$12,500.

The second quote looks 17% cheaper.

But perhaps the first includes:

$2 million liability limit

while the second provides:

$1 million.

Or perhaps one has:

$1,000 deductible

and the other:

$10,000.

Price comparisons are meaningless without comparing coverage.


Higher Deductibles Can Reduce Premiums—but Increase Risk

Increasing a deductible can reduce insurance cost.

Suppose you move from:

$1,000

to:

$5,000.

The insurer is transferring more of each qualifying loss back to your business.

That may reduce the premium.

But don’t choose a deductible the company cannot comfortably pay after a loss.

Insurance should protect cash flow—not create a new cash-flow crisis.


Improve Your Risk Profile

Some premium increases can be reduced over time through better risk management.

Depending on the business, this might include:

  • Employee safety training
  • Driver screening
  • Fleet telematics
  • Fire suppression
  • Alarm systems
  • Security cameras
  • Water-leak detection
  • Cybersecurity controls
  • MFA
  • Backups
  • Contract review
  • Workplace safety programs

The objective isn’t simply to obtain a discount.

Fewer claims can improve the business’s long-term insurability.


Bundle Carefully

Purchasing several policies from the same insurer can sometimes produce:

  • Discounts
  • Simpler administration
  • Coordinated claims handling

A Business Owners Policy already combines several common protections.

But bundling isn’t automatically cheaper.

Compare the total insurance program, not simply the number of policies.


Should You Switch Insurers?

Possibly.

But price alone shouldn’t determine the decision.

Consider:

  • Financial strength
  • Claims handling
  • Coverage wording
  • Exclusions
  • Deductibles
  • Limits
  • Industry expertise
  • Service
  • Risk-management support

Saving:

$1,000

isn’t worthwhile if the replacement policy removes a critical coverage worth hundreds of thousands of dollars.


When an 11% Increase May Be Reasonable

An 11% increase could potentially make sense if:

  • Your business grew substantially
  • Payroll increased
  • Property values increased
  • You added vehicles
  • You had significant claims
  • You increased limits
  • Your location’s risk worsened
  • Your health plan experienced higher medical costs

The percentage alone doesn’t tell you whether the renewal is fair.


When You Should Push Back

An increase deserves additional scrutiny when:

  • Operations haven’t changed
  • Revenue is stable
  • Payroll is stable
  • No claims occurred
  • Coverage hasn’t improved
  • Exposure values haven’t changed
  • Comparable market rates are softening

Ask the insurer to explain the increase.

Then obtain competing quotes.


2026 Commercial Insurance Snapshot

CoverageQ2 2026 Average Renewal Change
Commercial Auto+4.93%
Business Owners Policy+6.16%
General Liability+5.44%
Commercial Property+6.40%
Umbrella+7.96%
Workers’ Compensation-1.37%

Source: IVANS Index Q2 2026. These are average premium renewal rate changes and don’t predict an individual company’s renewal.


Small-Group Health Insurance Snapshot

KFF’s analysis paints a different picture.

For ACA-compliant small-group insurers’ proposed 2026 rate changes:

Median proposed increase: ~11%

Range: -5% to +32%

68% of insurers: Proposed increases between 5% and 15%

About 10%: Proposed increases of 20% or more.

This is the market where the headline’s 11% figure belongs.


10 Ways to Respond to a Large Renewal Increase

  1. Request a detailed explanation of the increase.
  2. Separate rate changes from exposure changes.
  3. Verify payroll and revenue estimates.
  4. Review insured property values.
  5. Check vehicle and driver schedules.
  6. Correct outdated business information.
  7. Review claims for errors.
  8. Ask about deductible alternatives.
  9. Obtain comparable quotes from other insurers.
  10. Start the renewal process 60–90 days early.

The objective shouldn’t simply be:

“Find the cheapest insurance.”

It should be:

“Buy the appropriate protection at a competitive price.”


Frequently Asked Questions

Did small-business insurance increase 11% in 2026?

Not across the board. KFF found a median proposed increase of approximately 11% among ACA-compliant small-group health insurers for 2026. Commercial property-and-casualty lines have different trends.

How much are Business Owners Policy premiums increasing?

The IVANS Index reported an average BOP premium renewal rate change of 6.16% in Q2 2026, down from 6.74% in Q1.

Is general liability insurance becoming more expensive?

IVANS reported a Q2 2026 average general-liability renewal rate change of 5.44%, although that was lower than the 6.85% average in Q1.

Is commercial property insurance still increasing?

IVANS reported an average Q2 2026 renewal change of 6.40% for commercial property. Individual businesses can experience substantially different results based on location, construction, insured values, catastrophe exposure, and claims.

What business insurance is experiencing some of the largest increases?

Umbrella remains comparatively challenging. IVANS reported an average Q2 2026 renewal rate change of 7.96%.

Is workers’ compensation increasing?

Not on average in the IVANS Q2 index. Workers’ compensation recorded an average renewal rate change of -1.37%.

Are cyber insurance premiums rising?

Not broadly according to Marsh’s Q2 2026 index. Global cyber rates fell approximately 4%, although individual results vary.

Why did my premium rise when insurance rates are falling?

Your individual exposure may have increased because of higher payroll, revenue, property values, vehicle count, claims, limits, or changes in operations.

Should I switch insurers after an 11% increase?

Not automatically. First determine why the premium increased, then compare equivalent coverage from competing insurers.

How early should I shop for business insurance?

For a significant commercial insurance program, starting roughly 60–90 days before renewal can give your broker more time to approach markets and negotiate.


Final Thoughts

The biggest lesson from the 2026 insurance market is that there isn’t one universal:

“11% small-business insurance increase.”

The 11% figure is specifically associated with the median proposed 2026 premium increase for ACA-compliant small-group health insurers analyzed by KFF.

Commercial insurance is much more mixed.

IVANS’ Q2 2026 data showed:

BOP: +6.16%

General Liability: +5.44%

Commercial Property: +6.40%

Commercial Auto: +4.93%

Umbrella: +7.96%

Workers’ Compensation: -1.37%.

And at the broader global level, Marsh reported commercial insurance rates actually fell 6% in Q2 2026, supported by greater capacity and insurer competition.

So if your renewal just jumped 11%, don’t automatically assume:

“That’s simply the 2026 market.”

Find out whether the increase came from:

market rate + payroll + revenue + property values + claims + coverage changes + your individual risk profile.

Then compare the market.

In a softening environment, a business with a strong risk profile may have more negotiating power than it realizes.

The “AI Adjuster”: Why Your Next Car Insurance Claim Will Take Minutes, Not Weeks

The “AI Adjuster”: Why Your Next Car Insurance Claim Will Take Minutes, Not Weeks

Imagine you’ve just had a minor parking accident.

Your rear bumper is cracked, one taillight is damaged, and there is a scrape along the side of your car.

Traditionally, getting an initial damage assessment could involve contacting your insurer, speaking with a claims representative, arranging an inspection, waiting for an estimate and then coordinating repairs.

Increasingly, part of that process can begin with something already in your pocket:

Your smartphone.

You open your insurer’s app.

The app guides you through taking photographs of the damaged vehicle.

Software analyzes those images, identifies potentially damaged areas, helps determine how the claim should be routed, and in some systems can assist in producing a preliminary repair estimate.

What once required several manual steps can sometimes begin almost immediately.

This isn’t merely a future concept. AI and automated systems are already being incorporated into insurance claims operations. The National Association of Insurance Commissioners (NAIC) says AI is being used across insurance for functions including claims handling and fraud detection.

Technology provider CCC Intelligent Solutions says its computer-vision systems can use vehicle photographs to help determine damage and costs, make repair-versus-replace decisions, convert damage photos into line-by-line estimates, and assist with total-loss predictions.

But does this mean the human insurance adjuster is disappearing?

Not exactly.

The bigger change in 2026 is that AI can increasingly handle or assist with the repetitive parts of a claim, while human professionals remain important when judgment, investigation or negotiation is required.


What Is an “AI Adjuster”?

“AI adjuster” is a convenient description rather than necessarily a formal insurance job title.

It refers to the growing collection of artificial-intelligence and automation technologies insurers and their technology partners can use to help:

  • Collect claim information
  • Analyze vehicle photographs
  • Identify visible damage
  • Estimate repair requirements
  • Predict claim severity
  • Detect potentially suspicious patterns
  • Determine whether human review is necessary
  • Route claims to appropriate teams
  • Identify possible total losses
  • Assist with customer communication
  • Process claim documents

Instead of one AI robot replacing an adjuster, think of AI as a digital layer operating throughout the claims process.


How a Traditional Car Insurance Claim Works

The exact process varies by insurer and accident, but a traditional claim can involve several stages.

You report the accident.

The insurer collects information.

An adjuster or estimator reviews the claim.

Vehicle damage is inspected.

An estimate is prepared.

Coverage is reviewed.

Liability may be investigated.

Repairs are authorized.

Payment is issued.

Additional damage discovered during repair can produce a supplemental estimate.

Each stage can require communication between:

  • Driver
  • Insurer
  • Repair shop
  • Adjuster
  • Parts supplier
  • Rental company
  • Other driver’s insurer

The problem isn’t necessarily that any one stage takes weeks.

The delays can accumulate between stages.

Digital claims technology is increasingly designed to reduce those gaps.


How an AI-Assisted Claim Can Work

Consider a straightforward bumper-damage claim.

Step 1: Report the Accident

You open the insurer’s website or mobile app and enter information such as:

  • Date
  • Location
  • Vehicle involved
  • Description of accident
  • Type of damage

Step 2: Upload Photographs

The system may guide you through photographing:

  • Front
  • Rear
  • Vehicle identification
  • Damaged panels
  • Wider vehicle views

Step 3: Images Are Analyzed

Computer-vision technology can analyze visible vehicle damage.

Depending on the system, software may help identify:

  • Damaged components
  • Repairable parts
  • Parts likely requiring replacement
  • Potential severity
  • Possible total-loss indicators

Step 4: Claim Is Routed

A simple claim may continue through a highly digital workflow.

A complicated claim might immediately be routed to a human adjuster.

Step 5: Estimate Is Generated or Assisted

AI can help prepare estimate information using photographs, vehicle data, repair information and insurer-specific rules.

CCC, for example, says its Intelligent Estimating technology can generate line-level estimates on qualifying repairable vehicles in seconds, either for appraiser review or, depending on insurer configuration, automatic approval.

Step 6: Repair or Settlement Process Begins

The customer can then receive instructions regarding repair shops, payments or additional claim requirements.

The entire claim isn’t necessarily finished in minutes—but several early steps can happen dramatically faster.


Can AI Really Estimate Car Damage From Photos?

Yes, within appropriate use cases.

Computer vision is a branch of AI that enables software to analyze images.

For auto claims, the technology can examine vehicle photographs and identify patterns associated with physical damage.

For example, software might identify:

Rear bumper → damaged

Taillight → damaged

Quarter panel → possible repair

The system can combine that information with vehicle and repair data.

CCC says its AI technology can convert vehicle-damage photographs into line-by-line estimates and assist with repair-versus-replace decisions.

However, photographs have limitations.

AI can’t necessarily see damage hidden:

  • Behind a bumper
  • Beneath the vehicle
  • Inside structural components
  • Behind trim
  • Within electronic systems

That’s why repair supplements remain important.


Photo Estimating Is Already Here

You don’t need to wait for some distant AI future to see digital estimating in action.

For example, State Farm’s official auto repair and estimating information describes a Photo Estimate tool for eligible external minor damage.

Customers use guided photographs through the mobile app, and State Farm says an initial estimate and payout may be available within 48 hours.

This is an important reality check for the headline of this article:

Digital analysis can happen quickly, but insurers don’t universally promise that the entire claim will be settled within minutes.

State Farm itself notes that no two claims are alike and that it cannot give one universal timeframe for payment without knowing the claim details.


Why AI Can Make Claims Faster

The biggest advantage isn’t simply that computers “think faster.”

Automation can remove waiting periods.

Photos Arrive Immediately

Customers don’t necessarily have to wait for an in-person inspection.

Data Can Be Checked Automatically

Vehicle and policy information can be integrated into the claims workflow.

Damage Can Be Triaged Quickly

AI can help determine which claims are simple and which need specialist attention.

Estimates Can Be Assisted Automatically

Systems can help populate repair operations and parts information.

Claims Can Be Routed Immediately

A complex claim doesn’t have to sit in the wrong queue before someone recognizes it requires additional attention.

These small efficiencies can add up.


AI Triage: One of the Biggest Changes

Not every insurance claim deserves the same process.

Compare:

Claim A

One scratched bumper.

No injuries.

No other vehicle.

Car remains driveable.

Claim B

Three-car intersection collision.

Airbags deployed.

Possible injuries.

Disputed liability.

One vehicle may be a total loss.

Sending both claims through exactly the same workflow would be inefficient.

AI can help insurers identify which claims appear straightforward and which require experienced human handling.

CCC says its technology uses AI to analyze photographs and assist insurers with routing decisions early in the auto physical-damage claims process.

That may ultimately be one of AI’s most valuable roles:

Not replacing every adjuster, but helping adjusters focus their time where human expertise matters most.


AI Can Help Predict Total Losses Earlier

Suppose your car is worth:

$12,000

Visible damage looks severe.

If the likely repair cost approaches the vehicle’s value, the insurer may need to evaluate whether the car should be treated as a total loss under applicable state rules and policy terms.

Traditionally, significant time can be spent inspecting and estimating a vehicle before reaching that conclusion.

AI systems can potentially identify total-loss indicators earlier.

CCC lists automated total-loss prediction among the uses of its AI technology.

Earlier identification can potentially reduce unnecessary steps in claims that are unlikely to proceed through conventional repairs.


AI Can Help Detect Fraud

Insurance fraud increases costs for insurers and ultimately affects consumers.

Suspicious claims can involve:

  • Staged accidents
  • Previously existing damage
  • Altered documentation
  • Duplicate claims
  • Inflated damage
  • Misrepresented accident circumstances

AI and machine-learning systems can analyze patterns across large datasets much faster than a person could manually review every claim.

The NAIC identifies fraud detection as one area in which AI is already being used by insurers.

However, fraud detection also demonstrates why human oversight remains important.

A suspicious pattern is not automatically proof of fraud.

Algorithms can flag claims for further review, but consequential decisions need to comply with applicable insurance laws and regulations.


AI May Help Identify Injury Exposure

Vehicle photographs can potentially provide information beyond bodywork.

The apparent severity of an impact can help insurers triage claims that might involve bodily injury.

CCC says its systems can use AI-derived impact severity from vehicle photographs to help casualty adjusters identify likely bodily-injury exposure and make earlier triage decisions.

That doesn’t mean AI can diagnose an injured person from a photograph of a car.

Instead, vehicle information can help claims professionals decide which cases require more immediate or specialized attention.


What Happens When AI Gets It Wrong?

This is one of the most important questions consumers should ask.

Imagine AI examines photographs and estimates:

Repair cost: $2,800

Your repair shop removes the bumper and discovers:

  • Damaged reinforcement
  • Broken sensor mount
  • Wiring damage
  • Additional structural damage

Revised repair cost:

$4,500

The original estimate wasn’t necessarily fraudulent or useless.

It simply couldn’t see hidden damage.

This is where the supplement process becomes important.

State Farm, for example, explains that when a repair shop discovers additional damage related to a claim after a photo estimate, it can work with the shop to review that damage and pay additional eligible amounts.

Consumers shouldn’t assume an AI-assisted initial estimate is necessarily the final word.


Initial Estimate vs. Final Repair Bill

This distinction matters more as photo estimating becomes common.

Initial Estimate

An assessment based on the information currently available.

Supplement

Additional repair costs identified after disassembly or closer inspection.

Final Repair Cost

The ultimate eligible repair amount after approved supplements and adjustments.

Supplements have existed long before modern AI.

Vehicles frequently reveal hidden damage after repair work begins.

AI doesn’t eliminate that reality.


Will AI Replace Human Claims Adjusters?

Probably not across the entire claims process.

Human adjusters remain particularly important for:

  • Serious accidents
  • Injuries
  • Disputed liability
  • Complex coverage questions
  • Fraud investigations
  • Total-loss disputes
  • Unusual vehicles
  • Complex repair disputes
  • Multi-vehicle accidents
  • Legal issues
  • Customer complaints

Even technology providers frequently design AI to assist human professionals.

CCC states that repairers can set confidence thresholds for AI-assisted estimating while final estimate approvals are made by human estimators in that workflow.

And insurers continue hiring auto estimators to review photographs, inspect vehicles and apply professional judgment.

The likely future is therefore:

AI + human adjuster

rather than simply:

AI instead of human adjuster.


Which Claims Are Best Suited to Automation?

AI-assisted processing is particularly attractive for relatively straightforward claims.

Examples may include:

  • Minor bumper damage
  • Small dents
  • Exterior scratches
  • Certain glass claims
  • Simple single-vehicle damage
  • Clearly documented cosmetic damage

These claims tend to have:

  • Good photographs
  • Limited damage
  • No injuries
  • No major coverage disputes
  • Relatively predictable repairs

Which Claims Still Need Human Attention?

Now consider:

Driver A says Driver B ran a red light.

Driver B says Driver A ran the red light.

Both vehicles are severely damaged.

Two passengers report injuries.

There are witnesses.

Police attended.

Medical bills are accumulating.

AI can help organize information and analyze data.

But determining liability, reviewing coverage, assessing injuries and negotiating a complex settlement can require significant human judgment.

Technology doesn’t make complexity disappear.


Why “Minutes, Not Weeks” Needs Context

Some AI systems can analyze photographs or generate estimate information in seconds.

CCC says its Intelligent Estimating system can generate line-level estimates for qualifying vehicles in seconds.

But that’s not the same as settling the entire insurance claim in seconds.

A claim can still require:

  • Coverage verification
  • Deductible calculation
  • Liability investigation
  • Repair-shop inspection
  • Parts availability
  • Supplements
  • Medical documentation
  • Police reports
  • Third-party communication

Therefore:

AI may turn certain claim tasks from days into minutes or seconds.

It does not mean every complete claim will move from accident to final payment within minutes.

That distinction makes the article more accurate and trustworthy.


How AI Could Change the Customer Experience

For drivers, perhaps the most visible improvement is convenience.

Instead of:

Call → wait → schedule inspection → wait → estimate

the process can increasingly resemble:

Report → photograph → upload → analyze → route

Customers can also use digital claim systems to:

  • Track progress
  • Upload documents
  • Receive notifications
  • Choose repair options
  • Communicate with claim teams
  • Arrange direct deposit

For example, State Farm currently allows customers using its digital claims tools to upload photographs and documents, track claim status, communicate with claims teams and manage payment information.


Could AI Reduce Insurance Costs?

Potentially—but consumers shouldn’t assume automation automatically means lower premiums.

AI may help insurers reduce:

  • Manual processing
  • Administrative delays
  • Repetitive tasks
  • Certain fraud losses
  • Claims-handling time

However, premiums also reflect:

  • Vehicle repair costs
  • Medical costs
  • Theft
  • Catastrophe losses
  • Litigation
  • Parts prices
  • Labour
  • Reinsurance
  • Individual driver risk

Faster claims processing doesn’t eliminate these underlying costs.


Could AI Make Claims More Consistent?

Potentially.

Human estimators can interpret damage differently.

AI systems can apply the same underlying model and insurer rules repeatedly.

That can potentially improve consistency for similar claims.

But algorithms themselves depend on:

  • Training data
  • Model design
  • Input quality
  • Insurer rules
  • System testing

Consistency isn’t automatically the same as fairness or accuracy.

That’s one reason insurance regulators are increasingly focused on AI governance.


Regulators Are Watching Insurance AI

The expansion of AI into insurance has attracted significant regulatory attention.

The NAIC’s Model Bulletin on the Use of Artificial Intelligence Systems by Insurers establishes expectations for responsible AI governance and emphasizes that decisions supported by AI still need to comply with applicable insurance laws and regulations.

Regulatory work has continued into 2026.

The NAIC says its AI Systems Evaluation Tool was being piloted by 12 participating states as of March 2026, with the tool intended to help regulators evaluate insurers’ AI use, governance, risk controls and data inputs.

A May 2026 paper in the NAIC’s Journal of Insurance Regulation also examined expanding AI/ML use by insurers and the state regulatory response.

This matters because automation doesn’t remove insurers’ legal responsibilities.


What About Algorithmic Bias?

An AI system is influenced by the data and design used to build it.

Potential concerns can arise if models produce systematically unfair outcomes.

Insurance regulators are therefore interested in issues including:

  • Data quality
  • Model governance
  • Testing
  • Documentation
  • Consumer impact
  • Compliance
  • Third-party AI vendors

Consumers should retain meaningful ways to question decisions and provide additional evidence when automated processing doesn’t accurately reflect their claim.


Can You Challenge an AI Estimate?

If you believe an estimate misses legitimate accident-related damage, don’t assume you must simply accept it because software generated or assisted with it.

Depending on the insurer and claim, you may be able to:

  • Submit additional photographs
  • Ask questions about the estimate
  • Have the repair facility identify hidden damage
  • Request a supplement
  • Provide supporting documentation
  • Communicate with a human claims representative

Your rights and the insurer’s obligations depend on state law and policy terms.


What Should You Photograph After an Accident?

Good input can improve a digital claim.

Where safe, capture:

  • Entire vehicle
  • Front
  • Rear
  • Both sides
  • Close-up damage
  • Wider view of damaged panels
  • Other vehicle
  • Number plates
  • Accident scene
  • Road markings
  • Traffic signs
  • Relevant debris

Take photographs from several angles.

Don’t digitally manipulate the images.

AI may be sophisticated, but poor-quality photographs still provide poor information.


AI Claim Example: Minor Parking Damage

Imagine you reverse into a concrete post.

Damage:

  • Cracked rear bumper
  • Broken reflector
  • Paint damage

No other vehicle is involved.

Nobody is injured.

The vehicle remains driveable.

You submit guided photographs.

An AI-assisted system identifies the damaged area, helps prepare an estimate and routes the claim through a digital process.

This is the kind of straightforward physical-damage claim where automation can potentially provide substantial efficiency.


AI Claim Example: Hidden Sensor Damage

Now imagine the same bumper contains parking sensors.

The initial photographs show:

Cosmetic bumper damage

After removing the bumper, the repair shop finds:

Damaged sensor bracket + wiring

The shop submits a supplement.

A human or automated review process evaluates the additional damage.

This demonstrates why even advanced image analysis doesn’t eliminate the repair shop’s role.


AI Claim Example: Serious Intersection Accident

Now consider a much more complicated accident.

Two vehicles collide at an intersection.

Airbags deploy.

Both drivers dispute liability.

A passenger reports neck pain.

One vehicle may be totaled.

AI can potentially help:

  • Analyze damage
  • Organize documents
  • Triage injury exposure
  • Predict total-loss likelihood
  • Route the claim

But it doesn’t magically resolve:

Who was legally responsible?

What injuries are compensable?

What does the policy cover?

Those issues can require investigation and human judgment.


Advantages of AI-Assisted Claims

For consumers, potential benefits include:

Faster initial assessment

Photographs can be analyzed without waiting for a traditional inspection.

24/7 digital reporting

A claim can often be started outside normal office hours.

Faster routing

Simple and complex claims can potentially be separated earlier.

Convenience

Customers can upload information from home.

Better status visibility

Digital systems can provide updates.

Less repetitive paperwork

Information can move between connected systems.


Potential Disadvantages

AI claims processing isn’t perfect.

Potential concerns include:

Hidden damage

Photographs can’t reveal everything.

Incorrect identification

AI may misunderstand unusual damage.

Poor photographs

Bad input can produce weak results.

Complex claims

Some situations simply require human judgment.

Consumer understanding

Customers may not realize an estimate is preliminary.

Algorithmic fairness

Models need appropriate governance and oversight.

Cybersecurity and privacy

Claims systems can process photographs, vehicle data and personal information.

Speed shouldn’t come at the expense of accuracy or consumer protection.


What Drivers Should Do in an AI-Powered Claim

1. Document Everything

Take your own photographs even if the insurer’s app also asks for them.

2. Provide Accurate Information

Don’t exaggerate or minimize damage.

3. Keep Original Files

Preserve photographs, receipts and accident documentation.

4. Read the Estimate

Don’t simply look at the final dollar amount.

Check what repairs and parts are included.

5. Ask About Missing Damage

If something appears absent, raise it.

6. Understand Supplements

Your repair shop may identify legitimate additional damage.

7. Ask for Human Review When Necessary

Complex or disputed situations may require a claims professional.

8. Track Communication

Keep records of important conversations and documents.


Frequently Asked Questions

What is an AI insurance adjuster?

It’s a general term for AI and automation used to assist claims tasks such as image analysis, estimating, triage, fraud detection and routing. It doesn’t necessarily mean one AI system replaces a licensed human adjuster.

Can AI estimate car damage from photographs?

Yes. Computer-vision systems can analyze vehicle images and assist with repair estimates. CCC says its technology can convert damage photographs into line-by-line estimate information.

Can AI settle a car insurance claim in minutes?

Certain tasks can happen in seconds or minutes, but entire claims aren’t universally settled that quickly. Complex claims can still require significant investigation.

Are insurers already using photo estimates?

Yes. State Farm, for example, offers a Photo Estimate option for certain eligible minor external vehicle damage and says an initial estimate and payout may be available within 48 hours.

What if AI misses hidden damage?

A repair facility may discover additional accident-related damage and submit a supplemental estimate for review.

Will AI replace insurance adjusters?

AI is more likely to automate or assist specific tasks while humans continue handling complex claims, disputes, injuries and cases requiring judgment.

Can AI detect insurance fraud?

AI can help identify unusual patterns and potentially suspicious claims for further investigation. The NAIC identifies fraud detection as an existing insurance use case for AI.

Can I dispute an AI-generated estimate?

Claims procedures vary, but consumers can generally raise concerns, provide additional documentation and communicate with the insurer about missing or disputed damage.

Does AI decide whether my claim is covered?

AI may support insurer workflows, but insurers remain responsible for complying with applicable policy terms and insurance laws regardless of whether automated systems are involved.

Is my claim data safe when using AI?

Insurers and vendors process sensitive information and are subject to applicable privacy, cybersecurity and insurance requirements. Consumers should still use official insurer applications and secure channels when submitting claim information.


AI Claims Checklist

After an accident:

  • Make sure everyone is safe.
  • Contact emergency services where necessary.
  • Photograph the entire vehicle.
  • Take close-ups of damage.
  • Photograph the accident scene where safe.
  • Preserve original images.
  • Report the claim accurately.
  • Review any AI-assisted estimate carefully.
  • Compare the estimate with repair-shop findings.
  • Ask about missing damage.
  • Understand your deductible.
  • Keep copies of documents.
  • Ask about supplemental damage.
  • Request additional explanation or human assistance if necessary.

Final Thoughts

The insurance adjuster isn’t disappearing.

But the adjuster’s job—and the customer’s claims experience—is changing.

Artificial intelligence can already analyze vehicle photographs, assist with damage estimates, predict potential total losses, support fraud detection and help route claims to the right workflow. The NAIC confirms that AI is being used in insurance claims handling, while auto-claims technology providers already offer AI-powered image analysis and estimating systems.

For straightforward physical-damage claims, the impact could be significant.

Instead of waiting for every step to be performed manually, drivers can increasingly:

Report → Photograph → Upload → Analyze → Estimate → Repair

But the phrase “minutes, not weeks” should be understood carefully.

AI can reduce some tasks from hours or days to seconds or minutes. That doesn’t mean every accident will receive a final settlement immediately.

Hidden damage, injuries, disputed liability, coverage questions, repair supplements and complex total losses still require additional work.

The most realistic future isn’t an algorithm replacing every claims professional.

It’s a system where AI handles routine analysis and administrative work while human adjusters concentrate on judgment, exceptions, disputes and customer support.

For drivers, that could mean fewer delays and more convenient claims.

But speed must come with something equally important:

Accuracy, transparency and the ability to get meaningful human review when technology doesn’t get the answer right.