Insurance Tech  Trovix ReachInsurance · Financial Services

When AIG's CEO says AI data center insurance is 'maxing out' P&C capacity, UK insurers should hear an uncomfortable truth: the constraint isn't the number of policies they can write. It's that they're trying to underwrite 21st-century infrastructure risks using 20th-century assessment methods. The FCA's Consumer Duty (PS22/9) requires firms to understand and price risk accurately. Yet most UK mid-market insurers still rely on manual data gathering, fragmented spreadsheets and rule-of-thumb underwriting for emerging technology risks—exactly the approach that breaks down when faced with AI infrastructure's novel, interconnected hazards spanning construction defects, cyber vulnerability, supply chain exposure and operational continuity. AIG's candour should alarm every insurer in London: you're not reaching capacity because demand is high. You're reaching capacity because you cannot process the underwriting complexity fast enough.

This story is part of a wider pattern: the insurance industry conflates AI with automation, then gets surprised when AI-free processes collapse under volume. What's actually happening is that old underwriting frameworks cannot scale because they cannot interpret emerging risk patterns. Data centers need holistic coverage—construction liability bleeding into cyber, operational risk bleeding into property claims—but traditional underwrit­ing silos cannot see these connections. Meanwhile, competitors in continental Europe and North America are building proper AI governance frameworks aligned to ISO 42001 and the incoming EU AI Act, learning to extract signal from complex infrastructure data. UK firms that wait for clarity are already losing ground. The PRA's SS1/23 framework on operational resilience makes this worse: you cannot demonstrate resilience in underwriting if your underwriting process itself is brittle.

Trovix's perspective: the capacity crisis is really an intelligence crisis. Firms like those using Harvey or Luminance have tried to solve underwriting by throwing document AI at contracts. That misses the point. What data center policies need is risk synthesis—the ability to connect construction records, cyber assessments, operational protocols and supply chain data into a coherent risk picture. That requires not just document intelligence but knowledge-aware AI that understands how different risk vectors interact. This is where shallow RAG systems fail. They retrieve relevant contract clauses or historical claims, but they cannot tell you whether a particular configuration of supply chain exposure plus cooling system redundancy plus insurance limits actually leaves a gap. You need systems built on proper knowledge representation, not keyword matching dressed up as AI.

If you lead underwriting at a mid-market UK insurer or broker, do three things immediately. First, audit your current underwriting process for AI data center risk—not to fix it, but to map where human judgment is making bets it has no basis for. Second, pilot a proper risk synthesis platform (not a document classifier) on a small cohort of new AI infrastructure submissions. Use Trovix Audit or similar to track which underwriting decisions correlate with actual outcomes—you'll find gaps that your current capacity metrics hide. Third, engage the FCA on how your risk assessment framework for emerging technologies aligns with the Consumer Duty. If you cannot explain your pricing model for something new, you cannot defend it. The insurers winning in this market are not the ones with the biggest teams. They're the ones with the clearest, most auditable thinking about what they do not yet know.

Related Trovix product:

Trovix Reach →Book a demo →