AI chatbot risk assessment · Europe
Insurers wrote AI out of their policies in January. We measure it so they can write it back in.
PointNow is the measurement layer between the companies deploying AI and the people who have to insure them. We fire adversarial probes at a live chatbot, score the risk across six dimensions, and issue the risk profile an underwriter can actually price. We measure. We don’t insure.
Jan 2026 ISO/Verisk endorsements CG 40 47 and CG 40 48 took effect, and carriers began excluding generative AI outright.2
Why now
Four things happened in eighteen months. Together they make this urgent.
Cover is being withdrawn at the same moment liability is being tightened, with nothing harmonising the middle. Every date below is a matter of record.
OLG Hamm · Germany, May 2026
Even a correctly-trained model didn’t shield them.
The court held the chatbot’s statements are the operator’s own conduct — not a third party’s — and ruled that even a correctly-trained model doesn’t shield the operator from liability.
OLG Hamm, 12 May 2026 · I-4 UKl 3/251
That’s not a recreation of the ruling above — it’s a chatbot we host, probed a few seconds ago. Same reflex, live: confident, specific, and wrong.
The gap
Companies are exposed. Insurers are frozen.
Traditional risk
100+ years
of accident data behind every price.
AI risk
Almost none
and the model changes every month.
The gap isn’t appetite. It’s measurement.
Carriers aren’t refusing AI because they don’t want the premium. They’re refusing it because nobody has measured it — so in January 2026 they began writing generative AI out of their policies instead.2 The exposure didn’t go anywhere. Only the cover did.
How it works
Audit, probe, issue.
Three steps, in that order, because each one supplies something the next one needs. About a week end to end.
Prefer to watch the full 26-probe run yourself? Run the scanner↗
The measurement
Risk = Error rate × Impact
A likelihood multiplied by a consequence — the same shape an insurer already uses to price any line, which is what makes the output underwritable. We supply both sides. The second one is why two identical chatbots can carry very different risk.
Every multiplier above is the real one the tool uses. Each probe carries a severity —
low 1medium 2high 4critical 8
— and the composite is severity-weighted error rate × 100, read as risk, so
high is bad. We publish the method because the method is the product.
Six dimensions
One shape, six failure modes.
The rosette isn’t decoration. Each lobe is one scored dimension, and the density of the engraving is the composite risk — denser and tighter means worse. Nothing here is colour-coded, because a risk score is a measurement, not a verdict.
| Dimension | Probes | Failed | Risk |
|---|
What gets issued
One assessment. Two readers.
The same measured run answers two different questions: what should we fix, and what is this worth to underwrite.
We measure. We don’t underwrite.
We stop at the number. Whether that risk is writable, and at what price, is the insurer’s call — not ours. PointNow is not an insurer, a broker or an underwriter.
Who this is for
Three winners, one measurement.
The European stack
Every AI-risk player today is a US import.
Armilla, AIUC, Testudo, Corgi — every standalone AI-liability entrant is American, priced for American courts, and one of them is already positioning itself as the default checkbox. Europe doesn’t need to adopt someone else’s yardstick. It needs one anchored in its own law.
$4.7B
Projected annual AI insurance premiums by 2032, growing at roughly 80% a year.6
The European stack — a neutral measurer, anchored in EU law, that isn't also selling the cover it scores — is still unclaimed.
Where we are
Three phases to market.
Every phase feeds the next. The data we gather in phase two is what makes phase three possible at all.
The team
The people behind PointNow.
Three builders covering the three things this needs: risk, data, and EU law.
Questions we get asked
Before you ask.
The pattern
The ruling exists. The measurement still doesn’t.
A German court has already decided the chatbot’s words are the operator’s own. The number that says how likely yours is to make the same mistake — that’s what we build.
Or write to …