Multinational programs: Managing fragmented AI-risks and related regulation

TrendsArticleSeptember 22, 2026

As Artificial Intelligence reshapes the risk landscape, multinational insurance programs can help global organizations navigate emerging exposures and an increasingly fragmented regulatory environment, according to Zurich’s Debra Burford and Luca Ravazzolo.

Share this

While the onwards march of AI is a global phenomenon, attitudes and approaches to regulation and risk vary greatly by territory. The share of the working-age population using AI is currently around 18% globally, but reaches as high as 70% in the UAE, according to Microsoft. A recent IPSOS survey found that people in the US and Europe are more likely to feel nervous about the technology, while respondents in Asia and Latin America are more inclined to see it as beneficial overall.

For multinational companies looking to roll-out AI at scale and at pace, this divergence poses a significant challenge: AI-related adverse outcomes were the fastest-rising risk in this year’s WEF Global Risks Report, jumping from #30 on the two-year outlook to #5 on the 10-year outlook. An AI-related loss can have a global impact, yet losses and claims are likely to playout differently at a national level.

Fragmented AI legislation

AI is one of the hottest legislative topics today. At the start of 2026, at least 72 countries had proposed over 1,000 AI-related policy initiatives and legal frameworks, according to Oxford University spin-off Mind Foundry. However, despite growing public concerns around AI safety and cyber security, few countries have implemented comprehensive AI regulation. And where rules are coming online, the landscape is increasingly complex and fragmented.

EU member states are currently preparing for the application of the groundbreaking AI Act, a comprehensive, risk-based framework that imposes specific obligations on AI providers (developers), deployers, and other actors in the AI value chain. The UK, in contrast, has opted for a more principle-based, approach rather than a single comprehensive AI legislation, relying on existing sectoral regulations to address AI-related risks. In Asia, countries have pursued different paths to balance innovation with safety and security. South Korea and Taiwan have implemented dedicated AI legislation while China has introduced a fast-evolving patchwork of laws, regulations and guidelines.

The US does not yet have a single comprehensive federal AI legislation comparable to the EU AI Act. At the federal level, the focus has been on promoting while issuing guidance and measures on safety, security and trustworthy use. Concerns about national security and cyber security, particularly in relation to testing of frontier AI models, have contributed to a shift towards greater federal oversight. Meanwhile, a growing number of US states, including California, New York, Colorado and Texas, have enacted or proposed AI-related laws. These focus on areas such as automated decision-making tools, algorithmic pricing, chatbots, transparency and government use of AI.

Evolving liability and litigation

Beyond safety and security, the growing use of AI in products and services will increasingly interact with regulatory regimes and liability frameworks across many areas of liability, including data privacy, motor, products, employment, medical and professional indemnity, to name but a few. AI use and automation will test many established legal and regulatory concepts, potentially requiring changes to existing legislation, and in some cases new rules and regulations.

The EU, for example, has now updated its product liability laws to incorporate AI. The EU Product Liability Directive, which must be transposed by member states into local national laws by 9 December 2026, expands the definition of a product to include software, including AI systems. It also extends liability into the digital supply chain —including products manufactured outside the EU — and extends the definition of damage to psychological health as well as the corruption or destruction of data.

And when AI goes wrong, affected parties are increasingly resorting to legal action. There are currently over 200 AI-related lawsuits valued at more than $6bn covering copyright, privacy, employment/discrimination, antitrust, securities and deepfakes, according to AI Lawsuit Tracker. In D&O, for example, boards face so-called AI-washing claims while the use of chatbot advisors and AI-powered HR screening tools have given rise to multiple legal actions, mostly in the US.

Global oversight, local response

Many large organizations are now turning to their multinational insurance programs as a tool for managing, mitigating and transferring AI-related exposures. They help risk managers navigate the complex risk landscape and fragmented regulatory environment through central oversight, control and co-ordination. But they also provide valuable access to local expertise, capabilities and services across underwriting, risk engineering and claims.

A multinational program also facilitates the conversation on risk transfer, helping to clarify how insurance will respond to AI-related losses and what is covered. Good local standards of coverage under a multinational program will ensure cover is globally consistent while a master policy can be used to plug identified gaps. In addition, a local policy may be preferred, for example, where dedicated limits, admitted cover or certificates of insurance are required.

Fast, effective local response

Dealing with uncertainty also requires a fast, coordinated claims response that combines central oversight and resources with on-the-ground expertise and services. Local claims professionals are familiar with national laws, regulations, business practices and policy definitions. For example, handlers in-country can appoint appropriate loss adjusters and technical specialists to mitigate business interruption losses or recommend the best legal counsel and experts to defend liability claims.

Faced with increased complexity and uncertainty, companies are keen to learn more about AI-related risks, mitigation and risk transfer solutions. In particular, risk managers are interested in insurers’ insights into claims and understanding potential losses and scenarios. Zurich has been working with many customers to help identify and quantify AI-related exposure scenarios, as well as clarify how insurance would respond.

Following an assessment of AI risks, many companies have opted to increase limits and broaden coverage in areas like directors and officers (D&O) insurance, crime, professional liability and product liability. Zurich has seen, for example, increased demand for investigations cover under D&O, while more companies are exploring global crime and cyber insurance programs to address heightened exposures from the growing use of AI by cyber criminals and fraudsters.

Framework to manage emerging risk

AI technology is increasingly becoming embedded in everyday business processes, products and services, and will touch on almost all aspects of risk. Meanwhile, companies are under intense pressure to adopt and integrate AI systems at breakneck speed, despite evolving regulation, governance and risk controls.

For multinational companies, they face the additional challenge of implementing AI across multiple jurisdictions, amid disparate regulatory, legal and business environments. A global insurance program provides a framework to help multinational businesses better understand and respond to this emerging and evolving area of risk at both a group and local level.

Originally published on Commercial Risk on September 22, 2026.