Willis Put a Ceiling on the Market, Then Told Buyers Not to Chase It
On 29 July 2026, Willis told data centre owners, developers, builders, operators and investors that the global marketplace can now provide up to US$15 billion of insurance capacity for a single large-scale data centre risk if the placement genuinely calls for it. The headline travelled fast, and Asia Insurance Review summarised it the same day as 'Willis urges smarter data centre insurance buying as capacity demand nears $15bn'.
The second half of the message is the part worth acting on. Willis argued that many organisations are securing capacity beyond their actual quantified exposure, and urged buyers to rethink the traditional approach to purchasing. Alastair Swift, Head of Global Specialties and of the Global Digital Infrastructure Group at Willis, put it directly:
Buying more insurance is not always the same as being better protected... a more tailored approach can often deliver greater value.
Swift also acknowledged the pressure that produces oversized towers: lenders and equity partners expect serious protection, and the easiest way to demonstrate it is a large number on a summary schedule. That is the tension this post is about. The number that satisfies a financing committee and the number that a loss model supports are rarely the same number, and in India they are usually set by different people at different times.
We have covered the other side of this market, where a single campus is so large that full-value cover cannot be assembled at any acceptable price. Both things are true at once. Capacity is scarce at the top of a hyperscale tower, and it is routinely over-bought in the middle of a mid-size one.
Why Indian Developers Inherit Limits Instead of Modelling Them
India is building into this question at speed. Wood Mackenzie projected on 27 July 2026 that Indian data centre capacity will reach 12 GW by 2030 as AI and digital-economy demand pull infrastructure investment forward. The Economic Times reported two days later that India may need US$350 to 435 billion of investment in AI and data centre infrastructure by 2030. Most of that is debt-financed, and debt comes with insurance covenants.
The sequence in a typical Indian AI campus financing runs like this. The term sheet is negotiated first, and the insurance schedule inside it is often drafted by a lender's counsel working from a precedent document used on an earlier project, sometimes a power project rather than a data centre. It specifies a limit, occasionally a full-value reinstatement requirement, and a list of perils. The risk manager and broker arrive afterwards and are asked to place what has already been promised.
That is inheritance, not modelling. The limit is a number the developer agreed to before anyone ran a loss scenario on the actual layout, and once it is in a signed facility agreement it becomes expensive to revisit. Two failure modes follow. The developer buys more limit than any credible single loss can produce and pays for it every year for the tenor of the loan. Or the covenant specifies a headline limit while saying nothing about the sub-limits and indemnity periods that actually determine recovery, so the developer is simultaneously over-insured on the number and under-insured on the loss.
The First Test: Maximum Foreseeable Loss on One Hall, Not the Whole Campus
The most common reason an Indian data centre limit is too high is that it is anchored to the total declared value of the campus rather than to the largest loss the campus can actually suffer. Those are different quantities, and the gap between them is the money at stake.
A campus is a set of separated data halls, each with its own electrical topology and its own fire compartment, plus shared plant. The relevant question for limit setting is the maximum foreseeable loss: the worst outcome from a single event given the physical separation that exists, assuming protection systems perform as designed and are then stress-tested for failure. If four halls sit behind rated compartment walls with independent suppression, a fire in one hall is a one-hall loss plus smoke and water damage to adjacent space, not a four-hall loss.
The sum insured on the property section must still be declared at full reinstatement value for the whole site, because the average clause applies proportionate reduction if declared values fall short on a partial loss. Under-declaring to save premium is a false economy that surfaces at the worst moment. The limit purchased above that declared value, and the layers built on top of it, are where the modelling question bites.
What the loss scenario has to include
The MFL work only holds if the assumptions behind it are written down and testable:
- Fire compartmentation between halls, including the rating of penetrations for cable trays and cooling pipework, which are where compartment integrity usually fails in practice.
- The suppression design and its intended outcome. Detection and early suppression limit a hall loss; a system that only protects life safety does not.
- Battery energy storage and UPS chemistry. Lithium installations change the fire scenario and the smoke-damage footprint, and underwriters increasingly rate them separately.
- Cooling architecture and whether a liquid-cooling failure can propagate across halls through shared distribution.
- Electrical single points of failure, especially shared switchgear rooms and transformer yards that serve more than one hall.
If a campus cannot evidence those assumptions, the underwriter will price the whole site as one risk, and the buyer is then paying a whole-campus limit because of a documentation gap rather than a physical one.
The Second Test: Where the Sub-Limit, Not the Headline Limit, Binds
A tower can read as fully placed while the covers that would actually respond to a data centre loss sit at a fraction of exposure. This is the failure Swift's 'tailored approach' point is really aimed at, and it is the easiest one to check.
On an Indian data centre placement the recurring sub-limited items are off-premises utility interruption, contingent business interruption from an upstream power or fibre failure, debris removal and expediting expenses, professional fees, and denial of access. A campus whose grid connection is its dominant availability risk may hold a US$500 million property limit above a utility-interruption sub-limit of a few tens of crore. The headline limit is not the constraint. The sub-limit is.
The test is arithmetic rather than judgement. For each of the top five loss scenarios the risk team can describe, work out which section of the policy responds, then find the applicable sub-limit and the applicable deductible, and compare that figure against the modelled loss. Where a sub-limit is exceeded by a credible scenario, that is a real gap. Where a headline limit sits far above every scenario total, that is spare limit being paid for annually.
Buying up a binding sub-limit is almost always cheaper than buying more headline capacity, because the sub-limited exposures are smaller and the market prices them on their own merits rather than on the rate-on-line for a catastrophe layer. It also produces a better answer for the lender, which cares about whether the asset can be restored and serviced rather than about the size of a number.
The Third Test: Indemnity Period Against GPU Replacement Lead Time
Business interruption is where the modelled-versus-inherited distinction shows up most sharply on AI campuses, because the reinstatement timeline is set by hardware supply rather than by construction.
A standard loss of profits section on an Indian industrial risk carries a 12-month indemnity period by default, and lender covenants frequently repeat that figure without examining it. On an AI facility, the recovery path after a hall loss runs through structural repair, MEP replacement, and then the delivery of replacement accelerators from an allocation-constrained global supply chain, followed by commissioning and tenant re-acceptance testing. If accelerator lead times run beyond the indemnity period, cover expires while revenue is still impaired, and the loan continues to be serviced from the developer's own funds.
The corollary matters as much. On a colocation model where the operator's revenue is a rental stream under contracts that survive an outage subject to service credits, the modelled BI loss may be far smaller than a gross-revenue calculation suggests, and a large BI limit is simply unused. The contract terms with tenants determine which of those two situations applies, and they are the first document to read before setting the BI figure.
Construction-phase exposure needs the same treatment through delay in start-up cover, which is dealt with separately in the post on EAR, DSU and GPU cargo on AI factory builds.
Aon's $5 Billion Programme and What Depth Actually Buys You
Willis was not the only broker moving on this in July 2026. On 20 July 2026 Aon announced an expansion of its Data Center Lifecycle Insurance Program to US$5 billion of capacity, described around a 'Reliable by Design' approach to digital infrastructure and reported by Data Center Dynamics the following day. Two of the largest brokers in the world enlarged their data centre offering within nine days of each other.
Read together, the two announcements say something specific about market conditions. Capacity depth for this class is increasing, and a lifecycle structure that follows a facility from construction through operation is now available in size. That weakens the case for buying limit defensively: when capacity is scarce, buyers over-purchase in advance because they fear not being able to buy later, and when it is deep that precautionary premium is harder to justify.
Depth also creates a negotiating position. A developer that arrives with a documented MFL study, a sub-limit map, and an evidenced fire and suppression standard is asking the market for a specific structure rather than accepting a quoted one. That is where a tailored programme costs less than an inherited one at the same or better level of protection, which is the value Swift was pointing at.
The practical use of a lifecycle structure on an Indian build is continuity of definition. A campus that moves from an erection all risks and delay in start-up programme into an operational property and BI programme frequently changes insurer, wording, and valuation basis at handover, and the seams are where late-manifesting construction defects fall between two policies. Holding one structure across both phases removes that seam, which is worth more than an extra layer of limit.
A Working Test: Is This Limit Modelled or Inherited?
Five questions separate a limit somebody calculated from a limit somebody copied. A CFO can run them in an hour with the broker in the room.
- Where did the number come from? Ask for the document that produced it. If the answer is the facility agreement or a prior project's schedule, it is inherited. If it is an MFL study or a probable maximum loss estimate with named assumptions, it is modelled.
- What is the largest single-event loss the site can produce? Get the figure for one hall including smoke, water, shared plant and the BI tail, and compare it against the property limit purchased. A limit several multiples above that figure is spare capacity unless the whole-campus scenario is genuinely credible.
- Which sub-limit fails first? Rank the top five scenarios against the sub-limit schedule. The first sub-limit a credible scenario exceeds is the binding constraint on the programme, and it is where the next rupee of premium should go.
- Does the indemnity period cover the actual replacement path? Compare it against current accelerator, transformer and switchgear lead times, and against the tenant contracts that determine whether revenue is actually lost.
- What would the lender accept instead? Most insurance covenants can be renegotiated from a limit test to a protection standard, expressed as MFL coverage plus named sub-limits plus a defined indemnity period. Lenders generally accept that once it is evidenced, because it answers their real question about restoration.
The same discipline applies on the cyber side of the same campus, where limit sizing has its own quantification method covered in the post on cyber risk quantification and limit sizing. A data centre programme that models its property limit and inherits its cyber limit has only done half the work.
The Answer Lives in the Wordings, Not the Limit Line
Willis's US$15 billion figure describes what the market can do, and the advice attached to it describes what most buyers should do instead. For an Indian AI campus developer signing lender-driven covenants against a 12 GW national build-out, the choice is not between more cover and less cover. It is between a limit that somebody modelled and a limit that somebody copied from a precedent facility agreement.
Every test above resolves into clause language. What counts as one occurrence, how the sub-limit schedule is drafted, whether the indemnity period runs from damage or from reinstatement, how compartmentation warranties are worded and what happens if they are breached, whether the reinstatement basis is new-for-old on IT hardware that has been superseded. Two programmes with identical headline limits can behave completely differently once those clauses are read side by side, which is exactly the comparison a limit summary hides.
Sarvada maintains a searchable index of Indian insurer policy wordings, so a broker or risk manager can compare how carriers treat utility interruption sub-limits, indemnity period definitions, reinstatement conditions and occurrence definitions on large property and engineering risks, and see where a proposed data centre tower is buying limit it does not need while leaving a binding sub-limit short. If you are setting or defending a limit for a 2026 financing, you can Request Access and work from the actual clause language.
