Abstract
When ontological distortion in clinical AI can be induced deliberately, a liability question follows: is the resulting risk insurable? This paper is a model-and-protocol contribution, not a completed empirical study. We construct a per-pipeline expected-loss model parameterised by two inputs: a loss-severity distribution and a cross-site correlation structure of the exploitable coding channels. Using a published adversarial cascade simulation (Synthea-derived cohort, n=1,000 patients, 100 Monte Carlo iterations), we show that loss severity is regime-dependent: coordinated multi-node injection produces 1.55 times the error of single-node injection under identical magnitude and feedback, and a persistent low-magnitude stealth-ramp reaches total error 2.94 against an accidental-drift baseline of 0.31. We then argue, and pre-register as the paper's empirical arm, that the exploitable channels share a common structural driver (the coding and billing process), so that failures are correlated across insured units rather than independent. The correlation is a directional prediction, not a measured result. Conditional on it holding, correlated tail loss violates the independence assumption underlying standard actuarial pooling: the per-unit portfolio standard deviation no longer diversifies as 1/sqrt(n) but floors at sqrt(rho), so ontological-attack risk is best modelled as a systemic accumulation risk rather than an idiosyncratic per-site risk. This is the substantive content of the insurance gap for clinical AI: the loss is not uninsurable because it is small or rare, but because it is correlated.



![Author ORCID: We display the ORCID iD icon alongside authors names on our website to acknowledge that the ORCiD has been authenticated when entered by the user. To view the users ORCiD record click the icon. [opens in a new tab]](https://www.cambridge.org/engage/assets/public/coe/logo/orcid.png)