AIG's admission that the AI data centre boom is maxing out property and casualty insurers cuts to the real issue: this is not a capacity problem dressed up as one. It is a knowledge problem. UK insurers are being asked to price risk on infrastructure, operational patterns and failure modes that did not exist five years ago. The FCA's recent Consumer Duty focus (PS22/9) and the EU AI Act's incoming compliance demands mean mid-market insurers cannot simply raise premiums and hope. They need to understand what they are actually insuring—the cyber exposure, the construction complexity, the concentration risk. Most are using spreadsheets and human judgment. That is why they are maxing out.
This story reveals a pattern: the insurance sector is repeating a mistake it made with mortgage-backed securities and synthetic CDOs. When something is new, complex and generating revenue, the industry defaults to copying competitors' terms rather than building genuine underwriting capability. The data centre boom is accelerating into a vacuum. Investment in AI infrastructure is running at $500 billion annually. Underwriting frameworks have not moved. Worse, many firms are buying generic AI document review tools—platforms like Luminance or Harvey that promise to 'analyse risk automatically'—without asking whether those tools were trained on data centre risks or whether they can explain their reasoning in a way that satisfies the PRA's SS1/23 guidance on third-party AI governance.
Here is where Trovix's view diverges. We do not believe the answer is smarter algorithms for risk scoring. The answer is better intake and structured intelligence capture at the point a client describes their exposure. What a solicitor knows about a client's data centre location, power supply chain, cooling systems and staffing matters more than any black-box risk model. The difference is practical: tools like Harvey or Luminance were built to summarise documents and spot clauses. They do not help an underwriter ask the right questions in the first place, or flag when answers are incomplete or contradictory. That is why Trovix Brief starts with intake discipline, not post-hoc analysis. You cannot price what you cannot describe.
If you run an insurance or financial services firm in the UK, stop waiting for your competitors to solve this. Your next 90 days should focus on three things: audit what you actually know about your largest AI infrastructure clients (most firms will find this sobering); map your underwriting questions against the Lloyd's Blueprint Two standards and the ICO's UK GDPR guidance on data processor risk; and build a repeatable intake process that captures the operational and cyber detail you actually need. Do not buy another risk analytics platform. Buy discipline. Use Trovix Watch to track regulatory change on AI underwriting standards as the FCA and PRA sharpen their own guidance—it is coming faster than you think.
Source: Bloomberg News