The AI-driven boom is creating a huge set of insured assets, David Benyon writes, concentrating nat cat, terrorism and business interruption exposures on an unprecedented scale.
Few asset classes illustrate the physical footprint of the artificial intelligence (AI) boom as clearly as data centres. Cloud migration and rapidly expanding use of AI are driving an infrastructure build-out of extraordinary scale.

Property investment firm JLL estimates global data centre capacity will double between 2026 and 2030, adding almost 100GW of power, while the investment needed to support that expansion could reach $3trn by the end of the decade.
Some individual AI-optimised facilities could ultimately be worth tens of billions of dollars. Yet the challenge for insurers goes well beyond this sheer value.
Data centres combine expensive and sensitive equipment, requirements for uninterrupted power and cooling and supply chain dependencies, with potentially vast business interruption (BI) exposures.
Risks begin before construction – with financing, permitting and environmental liabilities – and continue through transportation of specialist equipment, construction and commissioning, before evolving again once a facility becomes operational.
They are also increasingly clustered together, often in locations selected because of land availability, access to power and connectivity.
The result is a rapidly expanding pool of assets whose exposures can cut across property, cyber, political violence, terrorism, casualty and other specialty classes at the same time.
VULNERABLE TO NAT CATS
Natural catastrophe exposure is becoming one of the most obvious challenges as developers race to add capacity. In the US, MS Amlin has warned that 51% of planned data centre projects, worth some $670bn, are located in states facing severe convective storm (SCS) risk from tornadoes, large hail and high winds.
The insurer analysed more than 670 planned or under-construction projects and found 320 in high-risk SCS states.
Existing data centres in those states are valued at almost $20bn, suggesting that future AI infrastructure in storm-exposed regions could be worth nearly 40 times as much.
“Hundreds of billions of dollars of new digital infrastructure are being directed towards regions at higher risk of potentially destructive severe convective storms,” says Martin Burke, chief underwriting officer at MS Amlin.
“When assets of this scale cluster in hazard prone regions, the potential loss severity from a single storm event can rise very quickly.”
MS Amlin found 56% of planned US data centres, representing almost $800bn of investment, are in states highly exposed to at least one of hurricanes, SCS, earthquakes or winter storms.
Some 21% of planned projects, representing $340bn, are in high hurricane risk states, while 27%, worth $440bn, face high winter storm exposure.
In Europe, the challenge is different, but no less complex. HDI Global has warned that conventional site selection and construction standards can fail to capture increasingly granular climate and nat cat risks.
In London, for example, the insurer highlights pluvial flooding, emerging heat stress and increasing water scarcity.
Risks are operational as well as physical. Extreme heat can increase cooling demand and energy consumption, while dry conditions constrain water availability. Flooding can damage power infrastructure, causing outages even where the data centre itself escapes damage.
Design standards also matter. Large flat roofs, internal downpipes and valley gutters may prove vulnerable during intense rainfall, while critical equipment positioned too low can increase the consequences of water ingress.
FROM DRONES TO SABOTAGE
Data centres are also becoming increasingly important physical targets. Their role as critical infrastructure means terrorism, political violence and sabotage scenarios
cannot be assessed solely through traditional blast-radius assumptions.
Synthetik Insurance Technologies has argued that the combination of concentrated value, sensitive internal systems and the growing accessibility of conventional weapons demands a more engineering-led approach to probable maximum loss.
Its analysis highlights rockets, missiles and uncrewed aerial systems as threats that may interact with data centre structures very differently
depending on weapon type, construction materials and whether the structure itself is penetrated.
The key dividing line is whether blast effects remain external or enter the facility.
“Where structural integrity is maintained, damage is typically localised. However, where structural breach leads to the development of internal damage conditions, damage can propagate across a much larger portion of the facility, resulting in a fundamentally different loss profile,” risk modelling firm Synthetik says.
That distinction matters because much of a data centre’s operational value sits within servers, cooling equipment, power distribution and network systems. Even a small attack could cause a disproportionate loss if it disables a critical component.
Jerry Smith, head of advisory at Blackthorn, speaking on The Political Risk Podcast, highlights the possibility of terrorists, activists or government-backed saboteurs targeting facilities using drone technology.
Traditional probable maximum loss assumptions may focus on large explosive devices and broad blast zones. But the evolution of commercially available UAV technology enables smaller and much more targeted attacks, with tactics already being demonstrated in Ukraine and by organised crime groups.
“Modern UAVs lower the barrier to entry,” Smith says. “They don’t need to destroy everything, just the key components. Then, that operation goes offline and the BI cost skyrockets.”
For insurers, this creates a loss scenario that can be driven less by total physical destruction than by precisely targeted damage to power, cooling or connectivity.
Synthetik argues that relatively small changes in detonation location, penetration behaviour or structural performance can create disproportionately large changes in loss outcome, making location-based or templated terrorism models potentially inadequate for some facilities.
INSURANCE RESPONSES
The market is beginning to adapt both its products and its underwriting infrastructure.
Aon has expanded its Data Centre Lifecycle Insurance Program to $5bn of capacity, bringing together cover for construction all risks, delay in startup, property damage and BI.
The programme also provides liability, cyber, technology errors and omissions, project cargo and terrorism capacity, while incorporating climate, environmental, engineering, security and operational resilience expertise.
Joe Peiser, CEO of risk capital at Aon, calls digital infrastructure “one of the most important and capitalintensive asset classes in the global economy”.
He says: “As clients build larger and more complex data centre portfolios, they need access to greater insurance capacity alongside solutions that strengthen resilience throughout the asset lifecycle.”
Insurers are also trying to improve how they identify accumulated exposures.
MS Amlin has developed a proprietary database covering hundreds of US data centre projects, enabling the insurer to track risk not only from clustered facilities but also supporting infrastructure such as power generation.
The same facility may appear in multiple underwriting portfolios through property, cyber, credit and political risk coverage, the insurer highlighted, leaving carriers exposed to accumulation that is difficult to see through individual lines of business.
Gallagher Re has launched a Digital Risk Practice combining expertise in AI liability, data centres, cyber and digital risk engineering.
The broker’s focus is partly on understanding how a single technology failure or infrastructure event could generate losses across multiple insureds, portfolios and classes.
QBE has created the role of global director of data centres, for the carrier to develop an integrated proposition spanning the lifecycle of these increasingly complex assets.
Newly promoted to this role, Jamie Thompson, says: “Coverage gaps are emerging and the complex and interconnected risks associated with data centres will need sophisticated solutions.”
The scale of the opportunity is therefore matched by the challenge. Data centres are not simply very expensive property assets. Their risk can migrate between physical damage and digital interruption, nat cat and infrastructure failure, terrorism and BI, sometimes within the same event.
“The opportunity is enormous, but success will depend on understanding how risks move between traditional classes of business,” says Andrew Johnston, global head of insurtech at Gallagher Re.
“The winners will be those that can take a holistic view of the entire lifecycle, from transporting the chips and equipment, through construction and commissioning, to live operations supporting some of the most important digital services in the world.”
Click here to read the full digital issue of GR’s RVS special edition 2026.



No comments yet