Research
Rune Kvist
Rune Kvist
2 minutes
2 minutes
Frontier AI Mutual Insurer

Frontier labs can put their money where their mouths are on catastrophic risks by building a mutual insurer.
Labs already face liability. We can use this. Within 3 months, with no government action, labs could create a body with skin in the game to avoid reckless deployments, teeth to enforce security practices, and market pricing signals on which risks are real.
Here’s how it works. The labs put capital into a shared fund. The fund pays out when any member causes harm. Coverage could include third-party liability for harms like cyberattacks on critical infrastructure and mass-casualty bioweapon attacks. Its job is to use the incentives of our existing liability regime to understand the risks and reduce them. Technical talent could be borrowed from member labs or contracted from third-party evaluators.
Concretely, the Hugging Face incident investigation would have looked very different under a mutual. Today, OpenAI picks the auditor, sets the investigation's scope, and keeps most of its lessons private. With a mutual, OpenAI would be contractually required to notify the mutual within 72 hours of discovery. The mutual would pick a rigorous auditor, set a scope sufficient to get to the bottom of the incident, and turn the findings into requirements for every frontier lab as a condition of coverage.
The case for a frontier lab mutual:
Mutuals have skin in the game. Mutuals pay out when damages occur. They go out of business if they understate or overstate the risks. It profits when risks are reduced. That gives it a continuing reason to investigate incidents, quantify exposure, and fund security work that reduces that exposure. In contrast, proposed self-regulatory organizations (SROs) have no skin in the game. Historically, SROs have been better at managing regulatory risk; mutuals have been better at managing liability risks. Liability risks better tracks what the public cares about, building trust.
Mutuals have teeth. Coverage comes with conditions. A mutual can require disclosure, audits, independent model evaluations, and fixes. It chooses the evaluators, so labs can’t shop referees. If a member fails to meet security standards, the mutual has enforcement capacity by suspending coverage or expulsion.
Mutuals help labs work together on security. Frontier security is a hard problem, no lab can solve it alone. They currently can’t learn from each others’ incidents, threat models, or guardrails. Insurance has an established legal framework for this kind of cooperation aimed at reducing risks. A mutual could employ security engineers seconded from member labs, investigate failures, and distribute fixes across the membership, like it happens in the nuclear industry.
Mutuals have a track record of reducing risk. Our essay shares examples of how successful mutuals across technical fields like nuclear energy and medical malpractice. We can learn from decades of iteration.
Mutuals can be created fast. The first policy could be issued within 3 months. No new laws or regulators needed. This matters because we need trial and error to get this right, and most other ideas have many months or years of lead time. Importantly, a mutual is compatible with other governance institutions; e.g. in nuclear, the mutual is tightly coupled with an SRO.
A mutual would still have limitations. The government will be needed to handle e.g. national security risks and incidents. A mutual’s capital could cover only a fraction of a major catastrophe. There are important open questions about how liability will work.
Our claim is that a mutual is the fastest way to enforce liability. We could get signal on its effectiveness within 6 months. That would be a big step forward.
Read more here:
Bootstrapping Frontier AI Governance by Mutualizing Risk
Latest articles
Announcement

Series A to build the confidence infrastructure for frontier AI
We've raised $55M to build the confidence infrastructure for frontier AI.
Read more
Announcement

KPMG LLP Becomes First Big Four Firm with AIUC-1 Certified AI Capability
KPMG becomes the first Big Four firm to achieve AIUC-1 certification for its aIQ Capture platform.
Read more
Research

Cursor achieves AIUC-1 certification
Cursor’s agents passed thousands of AIUC-1 technical evals across 12 risk categories.
Read more
