AIG's CEO has said publicly what UK insurers are already losing sleep over: AI data center risk is overwhelming traditional P&C capacity. This matters urgently because data centers—particularly those running large language models and training infrastructure—sit at the intersection of property, business interruption, technology errors and omissions, and cyber. A single unplanned outage can cost millions per hour. Yet most UK insurers are still pricing these risks using models designed for conventional manufacturing and infrastructure. The FCA's expectation under Consumer Duty PS22/9 that firms understand and articulate their risks with precision should be setting off alarms in every underwriting team. You cannot fulfill that duty if your risk assessment methodology cannot actually model the failure modes of GPU clusters.
This story is a symptom of a much deeper structural problem: the industry has been handed a new class of risk that demands real-time, probabilistic underwriting rather than historical data fitting. Traditional actuarial models work because they have decades of loss history. AI infrastructure has none. You cannot price what you cannot predict, and you cannot predict what you cannot see. The EU AI Act's coming enforcement will add another layer: insurers will need to demonstrate not just that they understand their client's AI system, but that they understand the compliance and governance footprint around it. That is not a spreadsheet problem anymore. It is an intelligence problem. Lloyd's Blueprint Two already signals this shift—the underwriting of tomorrow demands synthetic data generation, scenario modeling, and continuous monitoring of emerging risk profiles.
Here is what Trovix believes is the wrong response: buying an off-the-shelf risk model from a vendor, bolting it onto your pricing engine, and calling it AI-smart. Harvey and Luminance have built strong reputations in legal and document work, but they operate in domains with stable, repeatable workflows. Insurance underwriting for AI infrastructure does not have stable workflows yet. Every data center is different. Every AI workload stack is different. The right response is to build underwriting teams that can see what they are actually insuring. That means real-time access to technical audit data, compliance documentation, incident histories, and architectural diagrams—extracted, normalized, and synthesized into a live risk profile. Trovix Audit exists precisely because we saw that insurers and brokers needed governance visibility that does not require hiring five PhDs in ML ops.
If you are an underwriting team, a broker, or a risk placement specialist in a mid-market UK firm, the action is immediate: audit your current AI data center portfolio. Find out if you actually understand what you have on your books. If your risk assessment is still based on a paper proposal and a site visit, you are exposed. If you do not have a way to monitor whether your client's infrastructure has changed since underwriting, you are flying blind. Start building a data acquisition process now—integrate with your clients' compliance and audit logs, pull their technical documentation into a standardized format, use Trovix Sift or equivalent document intelligence to extract the material risk factors, and build a live risk dashboard. The PRA's expectations under SS1/23 already require firms to understand their third-party AI risks. This is how you do it.
Source: Bloomberg News