On September 28, the U.S. Senate passed legislation to extend the Terrorism Risk Insurance Program until 2034. Although the program isn't set to expire until the end of 2027, insurers pushed for early action. This timing highlights a crucial point: the insurance industry is acutely aware of the risks when a critical backstop becomes uncertain.
This isn't a hypothetical scenario. It's an examination of a market failure that has already occurred and the vulnerabilities that could lead to its recurrence.
The Historical Context
After the September 11 attacks, terrorism risk insurance vanished from the U.S. market. Insurers couldn't model the risk, reinsurers withdrew, and policyholders struggled to secure financing for construction projects and commercial operations. In response, the federal government created TRIA in 2002, a public-private partnership providing a federal backstop when certified terrorism losses exceed specific thresholds.
The program has required reauthorization in 2005, 2007, 2015, and 2019, each time creating market uncertainty. The current reauthorization cycle began early because insurers and policyholders are already negotiating policies extending past 2027.
Key Timeline Events
September 11, 2001: Terrorism attacks lead to widespread insurer withdrawals from terrorism risk coverage.
2002: Congress enacts TRIA to restore market capacity through a federal backstop.
2005, 2007, 2015, 2019: Program requires periodic reauthorization, creating pre-expiration uncertainty.
June 2024: House of Representatives passes reauthorization legislation.
September 2024: Senate Banking Committee votes 24-0 to advance reauthorization; full Senate passes by unanimous consent.
Current status: Senate and House versions require reconciliation before final approval.
Structural Failures Revealed
The 2001 market collapse exposed three major structural failures:
Risk modeling capacity: Insurers couldn't quantify terrorism risk using traditional methods. Unlike natural disasters, terrorism events are intentional and informed by classified intelligence. The National Association of Mutual Insurance Companies notes that "any relevant data on attempted attacks is unavailable for national security reasons," making frequency-severity modeling impossible.
Reinsurance availability: When primary insurers withdrew, reinsurers followed. Without a way to transfer catastrophic risk, the entire coverage stack collapsed.
Portfolio aggregation limits: Insurers discovered their exposure concentration in urban properties and critical infrastructure created unmanageable risk. A single event could bankrupt multiple carriers simultaneously.
These were systemic gaps in how the private insurance market handles low-frequency, high-severity risks when loss data is classified and attackers seek maximum impact.
Understanding TRIA's Structure
TRIA establishes a three-layer risk-sharing structure:
Layer one: Insurers must offer terrorism coverage to commercial policyholders. They bear losses up to their deductible, calculated as a percentage of their direct earned premiums from the prior year.
Layer two: The federal government covers 80% of losses above the insurer deductible, up to the program cap. Insurers retain 20% as a copay.
Layer three: If aggregate losses exceed the program cap, the Treasury Secretary can impose surcharges on commercial policyholders to recoup federal payments.
The program activates only when the Secretary of the Treasury certifies an act of terrorism and losses reach the statutory threshold. To date, TRIA has never been triggered by a certified terrorism event.
Action Steps for Your Team
Review your terrorism coverage now: Don't wait until 2027 to understand your policy. Your property policy likely includes terrorism coverage as a mandatory offer under TRIA. Check if you accepted or declined it. If declined, verify that your lender or lease agreements don't require it.
Understand "certified" acts: TRIA coverage only responds to certified acts of terrorism. The Secretary of the Treasury must determine that the act was committed by foreign persons or interests, was violent or dangerous, and resulted in damage within the U.S. Domestic terrorism, cyberattacks without physical damage, and uncertified events fall outside the program. Your policy may include broader terrorism coverage through an endorsement, but don't assume it.
Map your exposure to policy expiration cycles: If you're negotiating multi-year property policies or project-specific coverage extending past 2027, address TRIA reauthorization explicitly in your discussions. The American Property Casualty Insurance Association notes that insurers are already negotiating policies extending past the current sunset date. Ask your broker how your policy language handles a scenario where TRIA expires mid-term.
Separate terrorism risk from cyber risk: TRIA applies to property and casualty policies. It doesn't cover cyber-only losses unless they cause physical damage. If you're relying on TRIA as part of your critical infrastructure protection strategy, verify that your cyber policy includes coverage for physical damage resulting from cyberattacks. The two programs operate under different frameworks and definitions of covered events.
Incorporate reauthorization uncertainty into your risk register: TRIA has required reauthorization five times since 2002. Each cycle creates a window where insurers reduce capacity, lenders demand additional collateral, and policyholders face coverage gaps. Treat reauthorization cycles as a recurring operational risk, not a one-time legislative event.
The Senate's early action on the 2027 reauthorization shows that even a program with unanimous bipartisan support creates market friction when its future is uncertain. Your job isn't to predict whether Congress will reauthorize TRIA. Your job is to ensure your organization can operate regardless of whether they do.





