# Bootstrapping Frontier AI Governance by Mutualizing Risk

> Source: <https://www.lawfaremedia.org/article/bootstrapping-frontier-ai-governance-by-mutualizing-risk>
> Published: 2026-09-22 20:05:30+00:00

# Bootstrapping Frontier AI Governance by Mutualizing Risk

Managing frontier artificial intelligence’s (AI’s) [growing](https://www.nytimes.com/2026/09/03/technology/openai-hugging-face-hacking.html) [risks](https://www.nytimes.com/2026/09/12/technology/anthropic-dario-amodei-ai-slowdown.html) needs an owner. Common law [liability](https://www.americafirstpolicy.com/issues/autonomous-ai-cyberattacks-what-happened-and-how-to-prevent-them) as it stands will not suffice: Courts are [slow](https://www.lawfaremedia.org/article/tort-law-and-frontier-ai-governance) [and ill](https://www.thefp.com/p/tyler-cowen-ai-regulation-private-public?hide_intro_popup=true)-[equipped](https://www.rand.org/pubs/research_reports/RRA3243-4.html), and most cases end in lawyer-drafted settlements rather than expert investigations into what went wrong and what could be done differently.

One proposal is to form a [self-regulatory organization](https://www.lawfaremedia.org/article/designing-a-finra-for-frontier-ai) (SRO) styled after the Financial Industry Regulatory Authority (FINRA). However, [this is struggling](https://www.theinformation.com/articles/trump-administration-executive-order-new-ai-regulator-stalls?rc=yi2jul) to get the support needed from Washington and runs a very real risk of being [captured by the companies](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2829592) it polices. The industry now appears to be working toward a voluntary [private standards body](https://www.theinformation.com/articles/inside-ai-industrys-behind-scenes-push-police?rc=yi2jul). We support the idea but believe such a body needs teeth and skin in the game to be effective.

We offer a solution that rests on settled case law and centuries of precedent, drawing on our [recent](https://www.underwriting-agents.com/) [research](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5588732): Build a frontier AI mutual insurance company to hold the risk. Owned by the frontier AI companies it covers, this mutual would develop and enforce shared safety commitments, given members have a direct stake in each other’s safety practices: Each member puts capital into a fund that pays out when any member causes harm. 

Mutuals have a long record of [actively reducing risk](https://www.repository.law.indiana.edu/ilj/vol98/iss1/5/), not simply pricing it. The U.S. nuclear mutual, for instance, requires [on-site inspections](https://onlinelibrary.wiley.com/doi/10.1111/rmir.12257) by nuclear engineers and can suspend coverage if dangerous conditions are discovered and not promptly remediated. Medical malpractice mutuals [pool incident data](https://pubmed.ncbi.nlm.nih.gov/21550550/) and member expertise to [develop standards and technologies](https://pubmed.ncbi.nlm.nih.gov/32665466/) that have greatly [reduced patient deaths](https://pubmed.ncbi.nlm.nih.gov/2929993/) and have since been adopted worldwide. [Legal malpractice mutuals](https://insurancelawreview.rso.uconn.edu/2026/04/06/legal-malpractice-insurance-and-loss-prevention-a-comparative-analysis-of-economic-institutions/) peer review each other’s incidents and send lawyers from competing member firms to audit one another’s practices.

Mutuals trace their roots to the “[friendly societies](https://www.proquest.com/openview/c0fc0ff01a8909fca76a1322aceb4505/1?pq-origsite=gscholar&cbl=1817197)” of the 17th–19th centuries, instrumental in managing the novel risks of the Industrial Revolution (for example, [steam boiler explosions](https://www.cambridge.org/core/services/aop-cambridge-core/content/view/D7903FF66F584B9203165B0DE26965CF/S0020859000006222a.pdf/div-class-title-the-state-and-the-steam-boiler-in-nineteenth-century-britain-div.pdf), [coal-mining hazards](https://www.ncbi.nlm.nih.gov/books/NBK513201/), and [factory](https://www.erudit.org/en/journals/uhr/2002-v30-n2-uhr0601/1015909ar/) [fires](https://muse.jhu.edu/article/33718)). Today, they form where conventional insurance markets fail and governments leave private actors to manage an emerging risk—exactly where frontier AI sits. This is not a mass-market auto insurer; picture instead a [privately organized fire department](https://philadelphiaencyclopedia.org/essays/philadelphia-contributionship/) that [runs a fire safety lab](https://www.fmapprovals.com/en/about-us/history).

A frontier AI mutual would pull forward catastrophic third-party liability and convert it into reliable incident reporting, standards, third-party evaluations, safety research and development (R&D), and an antitrust-compliant mechanism for [pacing the frontier](https://www.pacingthefrontier.com/). This requires no new laws or regulations, and the mutual could be issuing its first policies in three months. Figure 1 is a visualization of how we predict this mutual could look in practice.

**Figure 1. A frontier AI governance regime with mutual insurance.*

Here’s a perfectly plausible alternate timeline of one of the recent [incidents at](https://www.reuters.com/legal/litigation/openai-agents-attacked-software-service-rubygems-before-hugging-face-incident-2026-09-11/) [frontier AI](https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals) [companies](https://www.bbc.com/news/articles/cx2kgdnyk2po): Within 48 hours of realizing something has gone wrong, OpenAI notifies AI Mutual Insurance Limited (AIMIL), the industry’s mutual that covers these emerging risks. Like any [cyber insurer](https://www.coalitioninc.com/panel), AIMIL immediately activates a preagreed contract with a third party such as [METR](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/) to help OpenAI contain the incident and collect forensic data. Data flows back to AIMIL, where engineers seconded from member AI companies aggregate and analyze it. Lessons are synthesized, new guardrails developed, and, given the severity of the incident, a bulletin issued to all members. Those lessons then feed into AIMIL’s public standards, against which members are audited and new AI models evaluated. To ensure members [can’t shop for their referees](https://ai-frontiers.org/articles/dont-let-ai-developers-hire-their-own-referees) and incentives are aligned, these audits and evaluations are selected, contracted, and paid for by AIMIL. However, they are conducted by [qualified third parties](https://aievaluatorforum.org/) such as [Accenture](https://www.reuters.com/business/anthropic-accenture-invest-2-billion-ai-model-evaluation-safety-concerns-rise-2026-09-18/) or [METR](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/): AIMIL [creates a](https://arxiv.org/abs/2304.04914) [market](https://arxiv.org/abs/2504.11501) for [third-party assurance](https://arxiv.org/abs/2601.11699). Members cannot deploy new models until a minimum testing period is complete and a minimum safety threshold is met. If elevated risks are discovered, premiums increase and remediations are recommended. If severe risks are discovered and not promptly remediated, coverage is suspended or the member is expelled, and authorities are notified in accordance with [recent state laws](https://www.lawfaremedia.org/article/the-forensic-gap-in-ai-safety-laws).

This is not a fantasy but the [default outcome](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5588732) for a mutual insurer with billions in exposure to a novel, catastrophic risk concentrated in a small membership. 

**The Basic Mechanics of a Frontier AI Mutual**

Several components are built into the mutual form. In this context, these include:

- Capital (billions, we expect) to pay claims, with the excess returned to member AI companies if few incidents occur.
- A CEO with a fiduciary duty to the membership as a whole rather than to any single company.
- Membership criteria based on minimum safety requirements and a good track record of remediating problems promptly.
- Oversight from insurance regulators, whose [macroprudential solvency and conduct rules](https://link.springer.com/chapter/10.1007/978-3-031-69674-9_16) are mature.
- A staff of underwriters and actuaries specialized in AI risk alongside safety engineers seconded from member AI companies to determine which audits and evaluations to run, quantify the risk, analyze incidents, develop safety guidance for members, and set the mutual’s minimum safety standard.

All members would get the same terms for their coverage and undergo the same audits and evaluations.

Cooperating on risk management and sharing sensitive incident data are well-established practices among mutuals, enabled by the [McCarran-Ferguson Act’s](https://www.law.cornell.edu/uscode/text/15/1012) broad antitrust carve-out for the “[business of insurance](https://www.gao.gov/products/b-304474).” The only relevant exceptions—boycott, coercion, and intimidation—have been read narrowly by courts. For example, “boycott” means a [concerted refusal to deal on any terms](https://supreme.justia.com/cases/federal/us/509/764/), as leverage over some unrelated transaction. An insurer refusing to cover a risk except on its own terms—say, a [minimum safety standard](https://www.verisk.com/resources/faqs/public-protection-classification-ppc-program/)—is the normal business of insurance. The same goes for [underwriting](https://www.fm.com/insights/manufacturing-risk) [inspections](https://onlinelibrary.wiley.com/doi/abs/10.1111/rmir.12257), [pooling](https://www.candello.com/About/About-Us) [incident data](https://cyberacuview.com/), and providing [risk](https://atticrrg.com/our-program/) [mitigations](https://www.myneil.com/getmedia/9fe6a82b-817a-49a3-bbf1-b5656c4925fa/AM-BEST-REPT-REVISED-2025.pdf) [for policyholders](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2820654). 

Central to the mutual is the coverage it provides—coverage unavailable in the commercial market for the foreseeable future, barring government intervention. We see three potential products (in order of importance):

1. [Third-party liability](https://www.rand.org/pubs/research_reports/RRA3084-1.html) coverage, including liability for catastrophic risks such as mass-casualty events; chemical, biological, radiological, and nuclear (CBRN) attacks; and attacks on critical infrastructure. These are perils almost universally excluded by commercial insurers.
2. First-party AI cyber coverage for a member’s own losses when its systems misbehave: corrupted or deleted data, damaged software, exfiltrated intellectual property, and the cost of containment and forensics. This is essentially standard cyber coverage that also covers [insider threats from AI agents](https://arxiv.org/abs/2510.05179) . This coverage is important for getting more exposure to[risks that arise during training and internal deployment](https://arxiv.org/abs/2504.12170) .
3. Business interruption coverage that triggers when unforeseen dangerous capabilities or safety incidents force a member to interrupt their service and roll back deployments. This further exposes the mutual to [near misses](https://arxiv.org/abs/2504.12170) .

The mutual is thus financially disciplined by its own operating costs and by incidents large and small across the model life cycle: training runs, internal deployments, pauses, and external deployments.

The mutual’s coverage comes with rights and obligations. For any incident that could become a claim, the member must notify the mutual within 24 to 72 hours—standard for insurance policies. The mutual reserves the right to contract third-party incident response and forensics firms of its choosing, much as any [cyber insurer](https://www.coalitioninc.com/panel). And it has a duty to pay good-faith claims after review. This could include [peer review](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2820654) by other [members](https://www.medicalmutual.com/physicians/claims), as many mutuals do and as [industry leaders](https://x.com/elonmusk/status/2098986888572907643?s=46) have suggested. 

But where do these affordances come from, and why do we expect a mutual to use them prudently?

**Incentives: Mutualizing Risk Neutralizes the Race to the Bottom**

Frontier AI companies face binding compute and talent constraints while locked in fierce competition for runaway market dominance. Many argue that the reliable returns from scaling up AI systems to make them more powerful trounce the returns from safety efforts—which may or may not reduce liabilities that may or may not materialize—resulting in [underinvestment](https://arxiv.org/abs/1907.04534) [in safety](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5588732). Liability is not inducing precaution as intended. Rather, eating future liability costs is simply the fee for participating in the race. Safety commitments have been [quietly revised](https://arxiv.org/abs/2609.08789) or [openly abandoned in the name of this competition](https://time.com/7380854/exclusive-anthropic-drops-flagship-safety-pledge/?utm_source=chatgpt.com).

A frontier AI mutual would sit outside this race and [face no trade-off](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5588732) between making systems safer and more powerful. Focused solely on reducing liability cost-effectively, it is incentivized to fill the gap in precaution by investing in third-party evaluations and safety R&D.

Since a mutual is owned by those it covers, it’s particularly effective at solving [coordination problems](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5588732), such as pooling sensitive private data or providing public goods like [safety R&D](https://openyls.law.yale.edu/server/api/core/bitstreams/a117c441-d4e0-4183-8778-eeddd17fb3d2/content). Witness the aforementioned [medical malpractice mutuals](https://pubmed.ncbi.nlm.nih.gov/32665466/) and their [safety innovations](https://pubmed.ncbi.nlm.nih.gov/21550550/).

The pace of frontier development should also, in equilibrium, land much closer to the social optimum, with the mutual acting as a counterweight to the current race dynamic. The mutual’s CEO gains nothing from any particular member being ahead of another. The coordination problem therefore flips, with members needing to coordinate not on slowing down, but on overriding the mutual’s due diligence: When one member wants to deploy sooner than safety practices recommend, competitors would happily let the mutual slow it down. And this setup is resistant to defection: Membership in the mutual is tied to maintaining coverage, coverage backed by the mutual’s funds. Canceling coverage is visible and could involve forfeiting funds committed.

A frontier AI mutual would thus aim to keep [safety in step with the frontier](https://www.macroscience.org/p/do-not-surrender-to-the-tech-tree) and help avoid a potential AI Chernobyl, which is in nobody’s interest. But well-aligned incentives are only part of the story; the mutual also needs the power to act on them.

**Power: Fears of Free Riders Empower a Mutual to Police Members**

Buying insurance can sometimes incentivize less precaution, a problem known as [moral hazard](https://www.jstor.org/stable/1884469?origin=JSTOR-pdf&seq=1). (Indeed, this entire article can be read as arguing that [the benefits of mutualization](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5588732) far outweigh any moral hazard it might generate.) With a mutual, moral hazard is equivalent to a free-rider problem: members exploiting a collective pool of funds for paying liabilities.

In the AI race, this “problem” is a blessing in disguise: Fear of free riders is exactly what drives members to grant mutual contractual rights to enforce minimum standards and police them. And in general, mutuals are particularly effective at controlling moral hazard because of [reduced](https://www.jstor.org/stable/2962281?seq=1) [information](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2820654) [asymmetry](https://openyls.law.yale.edu/server/api/core/bitstreams/a117c441-d4e0-4183-8778-eeddd17fb3d2/content) between insurer and insured, given that members bring with them industry expertise.

Legal malpractice mutuals exemplify these dynamics. Their staff—lawyers drawn from competing member firms—can walk into a firm and demand to see its financial planning, risk management, and case management. They [peer review](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2820654) malpractice claims [in person](https://insurancelawreview.rso.uconn.edu/2026/04/06/legal-malpractice-insurance-and-loss-prevention-a-comparative-analysis-of-economic-institutions/), applying [peer pressure](https://onlinelibrary.wiley.com/doi/abs/10.1111/1467-9930.t01-1-00033).

In AI, this might look like ensuring [safety frameworks](https://www.frontiermodelforum.org/technical-reports/risk-taxonomy-and-thresholds/) meet a minimum bar, auditing for [compliance with these frameworks](https://arxiv.org/abs/2505.01643), verifying [safety](https://arxiv.org/abs/2403.10462) [cases](https://arxiv.org/abs/2410.21572), contracting [third-party technical evaluations](https://arxiv.org/abs/2601.11699) of models, enforcing [minimum testing periods](https://www.clear-eyed.ai/p/a-minimum-testing-period-for-frontier), and peer reviewing critical incidents. OpenAI and Anthropic already ran a pilot for [evaluating each other’s models](https://www.theinformation.com/articles/openai-anthropic-neared-deal-stress-test-others-ai?rc=yi2jul); a mutual would formalize that exercise through a dedicated vehicle. 

The mutual form enables audits and hands-on risk management, but these are costly and high-friction. Would a frontier AI mutual bother with these? Why wouldn’t it just risk-price premiums and call it a day?

**Rigor: Underwriting Novel Catastrophic Risk Drives Technical Audits and Causal Risk Modeling**

When insurers underwrite catastrophic risk with no historical data, they have little choice but to build catastrophe models and rely on technical audits and evaluations performed by domain experts. Nuclear insurers, for example, are staffed with nuclear engineers who [develop risk mitigations and run on-site inspections](https://onlinelibrary.wiley.com/doi/10.1111/rmir.12257). These are [needed for underwriting](https://arxiv.org/abs/2409.06673), since traditional actuarial models—simple models based solely on historical loss frequency and severity—remain unreliable. This is also the only cost-effective way to control the [volatility of losses](https://papers.ssrn.com/sol3/Papers.cfm?abstract_id=5588732), which is critical to reducing the capital needed to cover a risk.

Whereas actuarial models derive loss frequency and severity from historical data, [catastrophe models](https://www.governance.ai/research-paper/dual-use-ai-capabilities-and-the-risk-of-bioterrorism-converting-capability-evaluations-to-risk-assessments) attempt to map all causal pathways to harm and estimate the probability of each link in the chain. This yields a comprehensive catalog of threat models, whereas in AI we [currently](https://www.governance.ai/research-paper/dual-use-ai-capabilities-and-the-risk-of-bioterrorism-converting-capability-evaluations-to-risk-assessments) [have](https://www.governance.ai/research-paper/estimating-global-yearly-cybercrime-damage-costs) [only](https://www.governance.ai/research-paper/report-assessing-the-risk-of-ai-enabled-computer-worms) [a handful](https://www.governance.ai/research-paper/could-ai-enable-catastrophic-cyberattacks-on-the-us-power-grid). Pricing this risk forces the insurer to understand it causally, not just statistically. That work is vital in itself for prioritizing safety research and shaping deployment decisions.

None of this is cheap; exposure must be large enough to justify invasive technical underwriting and catastrophe modeling. We expect [roughly $1 billion](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5588732) in coverage per member is the minimum needed to kick-start meaningful work. Should frontier AI companies want more effort from the mutual, they can simply increase limits.

Given the novel, rapidly evolving nature of frontier AI, the catastrophe model’s outputs will carry [great](https://www.governance.ai/research-paper/report-assessing-the-risk-of-ai-enabled-computer-worms) [uncertainty](https://arxiv.org/abs/2511.21838). However, it’s not clear what institution would do better. Insurers have [proved themselves](https://papers.ssrn.com/sol3/Papers.cfm?abstract_id=5588732) where governments have struggled. For example, as early as the 1970s, commercial nuclear insurance pricing was remarkably accurate despite very limited data; most power plants had come online [fewer than five years prior](https://www.eia.gov/totalenergy/data/annual/pdf/sec9_3.pdf). Insurers estimated the frequency of serious incidents (“core-melts”) at roughly [1-in-400 reactor years](https://inis.iaea.org/records/p4v10-nhz04), which turned out to be [within the correct](https://www.nrc.gov/docs/ML2011/ML20114B527.pdf) order of magnitude, unlike the [1-in-20,000 reactor years](https://www.nrc.gov/docs/ML1533/ML15334A199.pdf) estimate from the latest government report at the time.

We expect a frontier AI mutual’s loss estimates to fall within the correct order of magnitude, [premiums to be](https://link.springer.com/article/10.1007/BF01065315) [conservative](https://onlinelibrary.wiley.com/doi/abs/10.1111/j.1539-6924.1991.tb00637.x), and [insurance regulation](https://link.springer.com/chapter/10.1007/978-3-031-69674-9_16) to ensure a healthy capital buffer. 

We do not, however, expect the mutual’s premiums to matter much. More concrete than uncertain future liability, they are of interest for their information value, but a naked price signal would change behavior little more than raw liability exposure does; premiums would simply replace liability as the cost of participating in the race. What matters for governance are the audits, evaluations, and standards applied uniformly to every member.

**SROs Lack Skin in the Game**

We suggest that the comparative advantage of SROs like FINRA lies in managing regulatory risk; mutuals, in managing liability risk. We believe the latter is more tightly coupled with the risk of actual harm.

Most, if not all, SROs were [built to](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2002755) [preempt](https://onlinelibrary.wiley.com/doi/abs/10.1111/1467-9930.t01-1-00033) [regulation](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4547667) [or legislation](https://publications.aaahq.org/accounting-horizons/article-abstract/17/3/189/1735/How-the-U-S-Accounting-Profession-Got-Where-It-Is): This is partly what this structure was designed for. Their chief selling point over government regulators is their [access to industry expertise](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2002755) [and private information](https://onlinelibrary.wiley.com/doi/abs/10.1111/1467-9930.t01-1-00033), promising more efficient and nimble governance. We agree that is a feature—a feature mutuals have as well.

Structurally, SROs are only incentivized to pursue the public interest insofar as it serves their members. They face no financial or market discipline and, absent competent public oversight, their only external discipline is reputational. Since they don’t bear the financial cost of harms their members cause, SROs rarely make a serious attempt at threat modeling or quantifying expected dollar losses. By contrast, a mutual is a business venture that must protect its members’ pooled capital, with its incentives set by the liability losses it must pay. It has no choice but to quantify its risks.

The consequences of these incentive problems are evident in the histories of [FINRA](https://www.jstor.org/stable/40688239?seq=1) [and](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4547667) [many](https://publications.aaahq.org/accounting-horizons/article-abstract/17/3/189/1735/How-the-U-S-Accounting-Profession-Got-Where-It-Is) [other](https://publications.aaahq.org/accounting-horizons/article-abstract/17/4/267/1723/How-the-U-S-Accounting-Profession-Got-Where-It-Is?redirectedFrom=fulltext) SROs: cycles of scandal, reform, and drift; regulatory capture [by](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4547667) [incumbents](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2829592) or the [industry as a whole](https://onlinelibrary.wiley.com/doi/abs/10.1111/1467-9930.t01-1-00033). [Scholars debate](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=960168) how adding an independent board here or there helps on the margin, but there is little disagreement about [the overall picture](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=2002755).

A mutual and an SRO can also be complementary: Rulemaking and auditing could live in the SRO; risk modeling and technical evaluations in the mutual. The mutual then bolsters the SRO with enforcement levers (such as suspending coverage or expulsion) and a commitment mechanism (such as capital locked up or members contractually exposed to one another’s risk). The Institute of Nuclear Power Operations (INPO), the nuclear SRO, demonstrates this complementarity well. It never received congressionally delegated authority, yet scholars hold it up as [one of the few irrefutable success stories](https://onlinelibrary.wiley.com/doi/abs/10.1111/1467-9930.t01-1-00033) of self-regulation. Part of the explanation lies in the gradual binding of INPO to the industry’s [vital mutual insurer](https://books.google.com/books/about/Hostages_of_Each_Other.html?id=02FTAAAAMAAJ). Soon after INPO’s creation, the mutual tied premiums to INPO ratings and later made [membership a condition of coverage](https://onlinelibrary.wiley.com/doi/10.1111/rmir.12257), yielding a stable, incentive-aligned self-regulatory regime.

**The Limits of Insurability Are Not the Limits of a Mutual**

Some will object that a mutual would attend only to insurable risks, not the catastrophic risks that animate AI policy debates. We make three rebuttals.

First, nothing prevents members from directing the mutual toward catastrophic risks, whether technically insurable or not. The mutual can’t, in good faith, charge premiums for risks it will never pay out on (such as [human extinction](https://www.nytimes.com/2026/09/10/science/ai-humanity-risk.html)), but it can still use its data and expertise to model and mitigate them. A mutual would receive no loss feedback from such an event, losing that advantage over an SRO, but there’s no obvious reason it would do worse.

Second, insurability (a [notoriously fuzzy concept](https://www.jstor.org/stable/41950168?seq=1)) extends further than readers may realize. For instance, life insurers are inevitably exposed to pandemics, once-in-a-generation events costing tens of trillions of dollars. They cover only a small portion of those losses, but enough to invest in [epidemiological](https://www.tandfonline.com/doi/full/10.1080/10920277.2024.2349159) [modeling](https://www.tandfonline.com/doi/abs/10.1080/10920277.2011.10597612); life insurers [weathered COVID-19 just fine](https://link.springer.com/chapter/10.1007/978-3-031-69561-2_9). The same goes for nuclear insurers: They have a [profitable business](https://www.nrc.gov/docs/ML2133/ML21335A064.pdf). In brief, insurers can hold billions in exposure to events whose damages run to the trillions, and that exposure suffices to trigger the efforts we describe above. Commercial insurers simply tend to exclude most catastrophic risks because capital is scarce and margins are better elsewhere. They’ve painted themselves out of the picture, but a frontier AI mutual would be purpose-built for covering exactly these risks.

Third, reducing insurable catastrophes will likely reduce truly uninsurable catastrophes by generating safety R&D spillovers, solving coordination problems, and addressing common root causes. For example, effective monitoring of how AIs are used in biological design is useful for averting not only $100 billion epidemics but also world-ending pandemics.

**Looking Ahead: The Role of Government**

Frontier AI companies are not sufficiently sensitive to raw liability, but a mutual would be: It has no purpose other than to model and manage that risk. Its structure supplies the incentive and contractual power to develop and enforce risk-reducing practices; the nature of novel, catastrophic risk demands the technical rigor of audits, evaluations, and causal modeling. That is how a mutual would harness the existing authority of tort law to deliver the behavioral change liability is meant to induce.

A mutual cannot deliver every policy goal. For example, beyond defining what “good” reporting looks like, it will likely do little for public visibility into incidents on its own. Apart from public safety research, transparency is likely to run between members only. However, scholars find, [across](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=5122871) [many](https://press.uchicago.edu/ucp/books/book/chicago/H/bo3618989.html) [industries](https://ojs.aaai.org/index.php/AAAI/article/view/41139), that confidentiality increases the volume and candor of reporting; [reporting for learning](https://ojs.aaai.org/index.php/AAAI/article/view/41139) should probably be decoupled from reporting for public accountability. A mutual solves the learning problem; public accountability must come from elsewhere. Mutualization thus pairs well with laws [requiring public incident reporting](https://www.underwriting-agents.com/) as well as [clarifications](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6588958) [of liability](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6979919), but does not depend on them.

The mutual would begin with frontier AI companies but could later extend coverage to smaller players, for whom the risk transfer is actually material. The balance sheets of bigger companies would [help manage smaller companies’ risk](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=4568702), encouraging competition alongside responsible development. If the regime proves itself, it could be strengthened and spread by mandating insurance, as we do for countless other activities (driving a car, flying a plane, operating a nuclear power plant, and so on).

If the risks prove [as existential as many experts fear](https://aistatement.com/work/statement-on-ai-extinction-risk) and the [evidence increasingly suggests](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/), the government will need to regulate frontier AI directly. We claim only that the private sector can and should lead, developing and testing which mitigations work in practice before codifying them in law. For better or worse, nearly all the expertise lives in the private sector; it needs only the right incentives and resources. A frontier AI mutual can supply both, as mutuals have for centuries.
