Triple-I and Munich Re's RiskScan 2026, published June 8 from a survey of more than 1,700 participants across five insurance market segments, finds cyber incidents, economic pressures and AI at the top of the concern list for carriers, brokers and policyholders alike.

The alignment is the finding. When every segment names the same interacting pressures, the modelling question stops being which peril to price and becomes whether the independence assumption underneath the aggregation still holds.

Key Takeaways

  • More than 1,700 participants across consumers, small business owners, middle-market decision-makers, agents and brokers, and carriers, in the U.S. and U.K., conducted by RTi Research against a RiskScan 2024 baseline.
  • Non-peak perils are now viewed as frequent, high-impact risks across every segment, matching Swiss Re's finding that secondary perils drove 92% of the $107 billion in 2025 insured nat cat losses.
  • 74% of small businesses already use AI tools, while 63% say their existing policies do not address AI-generated attack risks.
  • Demand surge raises the severity of every claim in an affected area by 20% to 40%, scaled by concurrent claim volume rather than by any policy characteristic.
  • The North American property coverage ratio has sat between 40% and 42% since 2015, against a global natural catastrophe protection gap of $424 billion in 2025, up from $395 billion.

What RiskScan 2026 Found

Cyber incidents rank as the top concern across carriers, brokers and commercial policyholders. Economic pressures, inflation, potential decline and rising property costs, form the second cluster. AI ranks as the most impactful emerging technology, named alongside operational, regulatory, liability and systemic concerns rather than as an opportunity alone.

The reclassification of non-peak perils is the finding with the most direct modelling consequence. Floods, severe storms, winter weather and wildfire are now treated as frequent, high-impact risks across every segment, which is market perception catching up to the 92% of 2025 nat cat losses secondary perils actually produced.

Two other shifts are worth noting. Middle-market and small business respondents newly identified legal system abuse as a significant cost driver, reversing the 2024 result where those segments largely did not. And protection gaps persist despite the awareness: flood take-up stays low, cyber adoption in small commercial and personal lines stays inadequate, and inconsistent policy language across insurers complicates coverage decisions in specialty.

Where the Independence Assumption Breaks

The standard framework builds loss costs per line: frequency times severity, catastrophe models layered on for nat cat, separate triangles for general liability, auto, workers' compensation and professional liability. That works when the perils behave independently. The survey documents three specific ways they no longer do.

Shared economic drivers move every line at once. Construction cost inflation does not reach homeowners severity alone. It raises commercial property severity, extends business interruption duration because repairs take longer, and lifts auto physical damage through shared parts and labor markets. Applying a separately calibrated severity trend to each line, each fitted to its own experience, understates the aggregate, because the common driver induces positive correlation the line-level fits cannot see.

Demand surge is event-dependent, not risk-dependent. After a major catastrophe, adjusting capacity, materials and skilled labor all become constrained, and severity on every claim in the affected area rises 20% to 40%. The magnitude scales with the volume of concurrent claims, not with anything about the individual policy. A per-risk severity model calibrated on historical claims that occurred at varying surge levels averages the effect away rather than modelling it.

Coverage triggers overlap on a single event. A ransomware attack can trigger cyber, business interruption, professional liability and D&O at once. The correlation between the line-level losses is not random, it is structurally positive because all of them respond to the same event. Summing independent line-level distributions therefore produces confidence intervals that are too narrow and tail estimates that are too low, which is a bias in the aggregate rather than noise around it.

The AI exposure is the version of this arriving fastest. 74% of small businesses already use AI tools, and 63% report that their existing policies or standalone AI liability coverage does not address AI-generated attack risks, with the same 63% interested in buying dedicated cover. AI liability spills across professional indemnity, general liability, cyber and D&O, so it enters four books through four separate pricing models, none of which sees the others.

A reserve model inherits whatever correlation the pricing model assumed, so reserve adequacy monitoring in a softening market has to allow for favorable development in one line running alongside adverse development in a correlated one, which a combined triangle nets out rather than reveals. Same for the four-factor compounding in P&C severity.

The Aggregation Method Is the Binding Constraint

The vendors are moving, and the aggregation convention is what has not moved with them.

Peril models still deliver separate loss distributions for hurricane, earthquake, severe convective storm, wildfire and flood, and the aggregate view is typically assembled by a square root of the sum of squares approximation or a comparable formula that assumes independence. Every improvement in the individual peril model flows through an aggregation step that discards the correlation the survey documents.

Both are building toward the alternative. Verisk's Synergy Studio became available from June 15, 2026, unifying modelling, exposure management and analytics in one environment,, and added KatRisk's multi-peril models to its Model Exchange in late May so third-party correlation models can run beside proprietary ones. Moody's RMS took the physical route with its North America Severe Convective Storm HD models, released December 2025 and calibrated against more than $55 billion of location-level and policy-level claims validating over 2,700 damage curves, so correlation between exposed risks emerges from simulated event footprints rather than from an imposed dependency parameter.

Carrier adoption lags vendor availability, and the market conditions push the wrong way in the meantime. Global reinsurance capital reached a record $785 billion at the April 2026 renewals, traditional up 8% to $649 billion and alternative up 18% to $136 billion, producing risk-adjusted rate reductions across property and specialty. Reinsurers competing for that premium are expanding across lines and geographies simultaneously, which concentrates aggregate exposure rather than diversifying it whenever the underlying risks are correlated.

Cyber is where the traditional control fails outright. Accumulation frameworks bound exposure by peril zone, Florida hurricane, California earthquake, European windstorm, each with a capped PML. A single cloud provider outage or widespread software vulnerability generates correlated losses across thousands of cedants in multiple countries at once, and no zone cap touches it.

The gap that leaves is measurable at the edges. The global natural catastrophe protection gap reached $424 billion in 2025, widened from $395 billion, while the North American property coverage ratio has sat between 40% and 42% since 2015. A decade of flat coverage against rising exposure is what an aggregation assumption looks like from the policyholder side.

Feedback

We are seeking feedback on how to improve the site and deliver high-quality content relevant to actuaries. Help us make it better.

Submit feedback

Stay ahead with daily actuarial intelligence - news, analysis, and career insights delivered free.

Subscribe to Actuary Brew Browse All Insights