Insuring the risk: what AI liability coverage exists, what it excludes, and what that tells you
The short answer
An exclusion is a free risk assessment
The insurance market is a disciplined, financially motivated risk assessor with no reason to flatter your AI, even though individual carriers still compete on price and capacity, which shapes how aggressively a given risk is priced, not whether the underlying exposure is real. When it refuses to cover something, that refusal is priced intelligence about where your risk is real, large, and hard to bound. Read the exclusion before you file it.
What you will be able to do
- Analyze an AI insurance exclusion as a risk signal: read the excluded language and infer what the insurer believes about the likelihood, size, and correlation of the loss.
- Distinguish the three states of AI coverage that exist in the 2026 market: silent AI (covered by accident under old wordings), affirmative AI cover (bought on purpose, on conditions), and excluded AI (deliberately carved out).
- Map your own AI systems inventory against the actual coverage and exclusions in your organization's real policies, and locate every gap.
- Explain why AI risk frightens insurers for reasons beyond severity: correlation and aggregation (one model failing everywhere at once) and ambiguity (loss data too thin to price).
- Decide, for each coverage gap, among the three honest responses: transfer the risk (buy affirmative cover), reduce the exposure (change the deployment), or retain the risk (self-insure with a funded reserve and explicit board sign-off).
- Connect the conditions insurers attach to affirmative AI cover (documented governance, an AI risk assessment, an evaluation report) to the exact artifacts you have been building all program.
- Communicate the coverage position to a chief financial officer and board in the language of retained risk and reserves, not the language of engineering.
The lesson
Between November 2025 and April 2026, the global insurance market executed a highly synchronized abrupt retreat from artificial intelligence. Major corporate liability carriers, including AIG, W.R. Berkeley, Chubb, and Travelers, filed explicit requests with regulators to carve AI out of their coverage. Simultaneously, standard form drafters like ISO released off-the-shelf generative AI exclusions.
This allowed thousands of carriers to bolt on tested exclusionary language overnight, effectively arming the entire industry at once. When these exclusion endorsements arrive during policy renewals, the standard executive reaction is a heavy sigh. Most leaders view them as administrative hurdles or routine legal paperwork.
The immediate reflex is to forward the document to a broker to handle. That is a severe operational error. Delegating this document unread forfeits the single most useful piece of risk intelligence your organization will receive all year.
Insurers occupy a unique position in the AI ecosystem. They do not attend your demos, and they do not care about your board deck. They are the only party with actual financial skin in the game, and they have zero incentive to flatter your AI project.
When underwriters rewrite their contracts so your system is no longer covered, they are delivering a priced adversarial verdict. An exclusion is a brutally honest risk assessment of your technology, handed to you for free. Prior to this market shift, organizations relied heavily on silent AI, accidental coverage existing only because legacy policies were drafted before AI was a recognized peril.
Its broad language simply happened to sweep the technology in. The 2026 market deliberately ended this era of ambiguity. Insurers replaced accidental inclusion with explicit policy language, forcing every corporate exposure down one of two paths.
The first path is affirmative cover. Here, AI coverage is granted explicitly, but it is heavily conditioned on strict governance, requiring documented risk assessments and rigorous evaluation evidence before an underwriter will quote a premium. The second path is the excluded state.
In this scenario, the carrier deliberately and completely carves the AI risk out of the policy. If your current policy does not mention AI at all, you do not have permanent coverage. You have a ticking clock tied directly to your next renewal cycle.
Every AI exposure is being forced out of the ambiguous middle. Relying on silence simply means waiting for an inevitable exclusion to arrive. Because an exclusion is written by a financially motivated risk assessor, it doubles as a diagnostic tool.
By reading the exclusion backward, you can infer exactly what the insurer believes about the likelihood, size, and correlation of your risk. Consider Berkeley's absolute exclusion for any actual or alleged use of AI. Fencing everything signals deep uncertainty, specifically targeting their biggest fears, chatbots and agents.
This is a calculated risk distinction. An internal drafting tool has a human reviewer who breaks the causal chain. Chatbots and agents face customers and take autonomous actions.
They convert a model's error directly into third-party financial harm. This market retreat's timing reveals a critical metric. Insurers cover severe independent risks through diversification.
A synchronized industry-wide withdrawal indicates they are pricing in correlation. Because thousands of companies build on the same handful of upstream foundation models, one flaw can trigger simultaneous claims across unrelated policyholders everywhere. This shared dependency turns independent corporate deployments into a catastrophe-like systemic peril.
Reading the contract backward translates legalese into a clean financial thesis. The market officially views AI as an unbounded, high-severity, and highly correlated threat. Beyond the exclusion's broad scope, analyze the trigger phrase connecting the exclusion to the loss.
Standard endorsements heavily rely on three words, arising out of. Under settled US law, arising out of requires only a loose causal connection, not a direct or primary cause. A loss barely touched by an AI system can fall entirely inside this exclusion, making it far more dangerous than a standard caused-by trigger.
The second trap is how policies define the technology. To set the exclusion's scope, insurers write definitions of artificial intelligence directly into the contracts. These definitions are not drafted from scratch by individual underwriters.
They are lifted almost verbatim from sweeping global standards established by organizations like the OECD. They also borrow heavily from frameworks like the European Union's AI Act, adopting language describing any machine-based system inferring from inputs how to generate outputs. Definitions constructed this broadly capture far more than generative models.
They easily sweep in traditional data analytics, recommendation engines, and software your organization has relied on for years without ever labeling it AI. The combination of a loose causal trigger and a sweeping international definition casts a massive net. It catches almost any automated system, rendering the exclusion significantly wider than the underwriter's own mental image of the technology.
Every dollar of loss an exclusion removes from your policy is a dollar instantly transferred to your own balance sheet. An exclusion silently converts a transferred risk into a retained risk. Consider a logistics firm deploying an autonomous rebooking agent.
If you fail to read a new exclusion endorsement, that agent's potential failure instantly becomes an uninsured six-figure liability carried entirely by the company. Compounding this problem is the fact that AI exposure does not live neatly in a single policy. The liability is fragmented across cyber, technology errors and omissions, and directors and officers lines.
This fragmentation creates gap risk as each policy independently narrows AI coverage. Because of this misalignment, a single AI incident falls straight through the cracks. Cyber, ENO and general liability carriers all invoke exclusions and point fingers, leaving you totally uncovered.
Ignoring these exclusions and the resulting gap risks leads directly to accidental self-insurance. It allows unmodeled catastrophic liabilities to hijack the organization's financial reserves without any executive ever making a deliberate choice. When you map your systems and discover a coverage gap, there are exactly three mathematically honest responses available to your organization, transfer, reduce or retain.
The first option is to transfer the risk. This means purchasing specialty standalone AI coverage like Munich Re's Assure or a dedicated Lloyd's policy to move the liability back to a third party. To execute a transfer, internal governance becomes a strictly priced asset.
Underwriters will not quote a premium without demanding concrete evaluation reports, conformity files and documented risk assessments to prove the system is robust. The second option is to reduce the risk. By altering the deployment, such as placing a human sign-off or placing hard financial caps on an autonomous agent, you break the causal chain of liability and physically shrink the exposure footprint.
The third option is to retain the risk. This requires deliberately self-insuring. You must accurately size the expected loss, fund a dedicated financial reserve and secure formal executive sign-off accepting the liability.
These are the only defensible paths. Any organizational response outside of deliberately choosing to transfer, reduce or retain the risk is simply choosing one by accident. Many leaders operate under a pervasive dangerous misconception.
They believe that simply holding an active errors and omissions or cyber policy automatically guarantees their AI deployments are covered. In the liability market, the ironclad rule is the exact opposite. The presence of a policy proves nothing.
Coverage is proven only by the explicit absence of an applicable exclusion read directly against a specific system's architecture. To establish true governance, you must build a formal one-page AI coverage review. This document maps every corporate AI system against actual active exclusions, formally assigning a transfer, reduce or retain decision complete with executive sign-off for every identified gap.
Executing this introduces a global complication. While the reinsurance appetite for AI risk hardens worldwide, the underlying liability law dictating your exposure varies drastically from one region to another. Because of this international legal variation, your coverage review cannot be a single global document.
An exclusion that protects you in the United States may leave you dangerously exposed in Europe. The review must be executed strictly on a per-jurisdiction basis. An unread exclusion is nothing more than accidental self-insurance.
Professionals do not delegate this intelligence away. They read the market's brutal verdict and they choose exactly how they will carry their risk on purpose.
The ideas, one by one
Read the exclusion backward
The breadth of a carve-out maps to the depth of the insurer's uncertainty; what it names first is what it fears most; a market-wide synchronized retreat signals correlated, systemic risk, not just severe individual losses. These four inferences turn a denial into a diagnosis.
The ambiguous middle is gone
Silent AI, coverage that existed only because old wordings never mentioned AI, is being deleted across the 2025 to 2026 market, the dominant trend in the major United States liability lines this topic tracks; pockets of silent or transitional wording still persist elsewhere and at smaller carriers. Every AI exposure is being pushed toward an explicit covered or an explicit excluded. Relying on silence is relying on a deadline someone else set, one that may already have arrived in your lines even if it has not everywhere.
"Arising out of" is a very wide net
The dominant trigger phrase in these exclusions needs only a loose causal connection, not a direct cause. A loss barely touched by AI can fall inside. Always find and weigh the trigger phrase and the policy's own broad definition of AI.
An exclusion silently converts transferred risk into retained risk, once it actually reaches your system
Every dollar an applicable exclusion stops covering, verified against your system's facts and the policy's own AI definition, lands on your balance sheet whether or not anyone decided to accept it. The failure is not carrying the risk; it is carrying it by accident. Make the retention deliberate, funded, and signed.
Three honest responses, no fourth
For every gap: transfer it (buy affirmative cover on conditions), reduce it (human sign-off, agent caps, kill), or retain it (funded reserve plus board sign-off). Any other outcome is one of these chosen by accident.
Governance is now priced
Affirmative AI cover is underwritten on documented governance and model-robustness evidence, the exact artifacts you have been building. Your evaluation report and conformity file move your risk from uninsurable toward insurable and set the premium. Governance lowers your real cost of carrying AI risk.
Assess all policies together
AI risk is fragmented across cyber, Tech E&O, D&O, fiduciary, and employment lines, each narrowing independently. The real danger is gap risk between two policies. Never assess coverage one policy at a time.
Coverage is dated, not permanent
Your exposure can change at renewal without a line of code changing. Track coverage against the renewal calendar, and re-run the review whenever a policy renews or a new AI system ships.
"Uninsurable" really means "unpriceable without evidence."
Specialist standalone products affirmatively cover AI underperformance for organizations that can show model evidence, so a system the generalist market excludes may still be insurable through the specialist market. Get a quote before defaulting to retention on anything that matters. The one exception: a narrow class of loss (your own intentional wrongdoing, or a statutory fine in a jurisdiction that bars insuring it) is not insurable at any price or with any evidence, because insurance covers fortuitous loss, not expected or penal loss; for that class, reduce to zero is the only honest answer, not a better pitch to underwriters.
Your insurance position is jurisdiction-specific
Reinsurance appetite hardens globally but the underlying liability law varies by country, so a coverage review correct for one entity can be wrong for another. Run the review per jurisdiction, and never assume a group-wide answer.
Retained risk has a cost even in quiet years
The true cost of carrying AI risk yourself is the expected loss plus the opportunity cost of the reserve plus the volatility you now bear alone. That number belongs in the investment memo, not in a footnote.
You read it. Now prove it.
Explain this lesson in your own words, the way you would to a colleague, without looking back at it. It is graded against the lesson itself, by the same grader our learners face. One free try a day, no account needed.
The conversation
The same lesson, talked through at length by two hosts: the full transcript of the audio deep dive.
Listen to it as episode 63 of the podcast.
Read the full conversation
You know, usually when we talk about a medical diagnosis, there is this expectation of just like clinical precision. You break your arm, the x-ray shows that jagged white line, and the doctor just points right to the screen. Right.
It is visible. It is categorized. Exactly.
It provides this comforting binary that we build entire operational frameworks around. But when you step into the world of artificial intelligence risk, that diagnostic machinery completely breaks down. We are operating in a landscape that is remarkably murky.
Yeah, you can spend months optimizing your AI models. You can build elaborate governance frameworks, calculate the ROI down to the decimal point, and run all these intensive red teaming exercises to find the flaws. And yet there is a second brutally honest risk assessor out there that honestly you are probably ignoring entirely.
And that is the insurance market. Right. Because when insurers rewrite their contracts so that your AI is no longer covered, they are sending a financial signal that your software vendors, your engineering teams, and frankly your own internal corporate optimism will simply never tell you.
Well, because the insurance market doesn't care about your product roadmap. I mean, there is a deeply capitalized ecosystem of professionals whose entire mandate is to look at a risk, calculate the probability of it causing catastrophic financial harm, and put a hard price on carrying that risk for you. They definitely do not attend your upbeat product demos.
No, not at all. They look at lost data, they model the tail risk, and they either quote a number or they walk away. And right now we are seeing a historic walkaway.
So we're going to read that walkaway signal today. Think of this as an executive briefing. We're going to analyze what AI liability coverage actually exists in the market right now, what it excludes, and what that explicitly tells you about the systems you are deploying in your own company.
And to set the boundaries here, we really need to clarify what kind of insurance we're actually talking about today. Right. So we are focusing on liability insurance.
Just to define that up front, this is the coverage that pays for the harm your organization causes to others, whether that is a customer, a patient, or an investor. Which is distinctly different from first-party cover. First-party cover just pays for harm to you, like, you know, a fire destroying your own servers.
Exactly. And AI governance failures are overwhelmingly third-party harm stories. It is the customer service chatbot that confidently hallucinates a refund policy, or the autonomous agent that acts against a user's financial interest.
Liability cover is the front line of this whole AI risk fight. It absolutely is. So to give you a roadmap of this deep dive, we are going to cover the structural pillars of this shift step by step.
First, we will look at how the ambiguous middle is gone. Second, why an exclusion is actually a free risk assessment. Then third, how to read that exclusion backwards.
Right. Fourth, why the phrase arising out of is a very wide net. Fifth, how an exclusion silently converts transferred risk into retained risk once it hits your system.
And finally, the three honest responses to this situation, because there is no fourth. It is a rigid framework. But to really understand the reality of your AI liability today, you know, you have to look at the tectonic shift that just occurred.
Between late 2025 and early 2026, the global insurance market basically executed a synchronized retreat. We went from a state of ambiguity to a state of rigid exclusion. So let's trace that timeline.
Because industries with trillions of dollars in capital, I mean, they don't just rewrite their baseline assumptions overnight without a massive underlying catalyst. Yeah, they don't. For a long time, companies were operating in this gray area.
Like if you asked a CFO if their AI was insured, they would probably say, well, it is not explicitly excluded. So yes. Yeah, that gray area is known in the industry as silent AI or non-affirmative coverage.
And it is really a phantom safety net. It only exists by accident. How so? Well, when an older liability policy was drafted 10 or 15 years ago, generative AI wasn't a named modeled peril.
So the broad wording of the policy just happened to sweep AI-related losses in by default. Just because it didn't say no. Exactly.
But the defining event of the 2025 to 2026 market cycle was the deliberate systematic assassination of silent AI. And we actually saw the exact same playbook play out a decade ago with silent cyber. Oh, right.
I remember that. Like when ransomware first exploded, things like NotPetya around 2017, companies tried to claim cyber losses on their standard property damage policies. Yeah, because their servers were technically damaged.
Right. And the insurers just panicked because they were suddenly paying out billions for a risk they literally never priced into the premium. And the market learned a brutal lesson from that era.
I mean, they completely refused to make the same mistake twice. So in November 2025, the opening shots were fired. Three major U.S. liability insurers, AIG, Great American, and W.R. Berkeley, followed formal requests with state insurance regulators.
This was first reported by the Financial Times, right? Yes. They asked for permission to sell policies that surgically carved AI out of their coverage across all key liability lines. And they were highly specific about it.
They named the exact exposures keeping their underwriters awake at night, which were chatbots and AI agents. Okay, so they fired the warning shot. But AIG and W.R. Berkeley, I mean, those are just individual carriers.
How does that translate into a market-wide phenomenon? Through the central nervous system of the insurance industry, which is the ISO, the Insurance Services Office. Right. Which is owned by Verisk.
Exactly. You can think of ISO as the organization that writes the underlying legal source code for the insurance industry. Thousands of individual carriers just license ISO's boilerplate templates.
So they don't have to invent their own legalese. Right. So in January 2026, ISO issued three off-the-shelf generative AI exclusions.
Specifically forms CG4047, CG4048, and CG3508. These were for commercial general liability policies. Which means any local or regional carrier could just bolt this exclusion onto their policies instantly.
They don't need to hire a massive team of legal experts to figure out how to define AI. ISO did all the heavy lifting for them. Yeah, that mechanism is incredibly efficient.
By April 2026, the dominoes just fell across the entire Tier 1 landscape. Chubb, Travelers, Berkshire Hathaway, Cincinnati Financial. They all filed their own versions or adopted the ISO forms.
And the regulators just let this happen? Well state regulators, their primary job is to ensure insurance companies remain solvent so they can actually pay standard claims. So they looked at the systemic threat of AI and approved over 80% of these exclusion requests. So in just two quarters, the baseline assumption completely flipped from our AI is probably covered to our AI is probably excluded.
Yeah. The market forces all exposure into an explicit Yes, which is an affirmative AI endorsement where coverage is granted on purpose usually with conditions or an explicit no meaning excluded. Exactly.
But wait, let me push back on this. Let me check my own assumptions here. If I am an executive listening to this and I go to my filing cabinet right now, I pull out my policy and I read it cover to cover.
And it doesn't say a single word about artificial intelligence. Shouldn't I consider that a massive win? Like I haven't been excluded yet. No, that is the most dangerous misconception circulating in corporate governance right now.
Relying on silent coverage is essentially relying on a deadline that someone else controls. Okay. The ambiguous middle is gone.
If your policy doesn't mention AI today, that silence simply means your accidental coverage will vanish at the exact moment of your next renewal cycle. Wow. Not a single line of your engineering code will change.
Yeah. Your AI will operate on Tuesday exactly as it did on Monday. But the financial protection shielding it will evaporate because the market is systematically deleting that oversight at renewal.
You don't have coverage. You have a countdown. You have a countdown.
That completely reorients how you have to look at your renewal documents. Because most executives, you know, they see an insurance exclusion attached to a renewal package. They sigh, they call it paperwork, and they just forward it to their broker to handle.
Which is a massive strategic error. Right. Because what you are saying is that an exclusion is actually a free risk assessment.
An exclusion is the highest fidelity intelligence you can gather about your technology stack. Think about the incentives here. Your vendors want to sell you software.
Your engineers want to ship exciting products. Sure. The insurer is the only party in the ecosystem with their own capital on the line.
So when they draft an exclusion, which is contractual language that removes the category of loss from what the policy will pay, they are handing you a priced adversarial money-on-the-line verdict. They have absolutely no incentive to lie or flatter your AI project. Let me use a business analogy to ground this.
If you are a commercial real estate developer and you want to buy an office building, you go to a major bank for a mortgage. If that bank looks at the property and flat out refuses to underwrite the loan, you don't just complain about the loan officer and walk across the street to another bank. No, you definitely don't.
Right. You immediately send a team of inspectors into the basement to investigate the property's foundation. You assume the bank found black mold or structural damage or a sinkhole.
The insurer's exclusion is a structural engineering report on your AI project that you didn't even have to pay for. That is a perfect parallel. And you really have to realize this sinkhole isn't just appearing under one building.
It is under the entire neighborhood. AI risk doesn't live in one neat little policy. Right.
It is highly fragmented. We are seeing these exclusions aggressively narrowing coverage across three critical vectors simultaneously. Let's map those out.
What are the specific policies in the crosshairs? First is directors and officers liability. So D&O. This protects the company's leadership and board against claims of bad management, specifically misleading investors.
So like AI washing. Exactly. If your organization boasts about its proprietary AI capabilities to inflate the stock price, and it turns out you are just wrapping an open AI API with a flimsy interface, the SEC or angry shareholders will sue.
The D&O policy is what defends the board. But insurers are currently carving AI out of D&O to avoid paying for that exact corporate hubris. Okay, so D&O is the first vector.
What is the second? Errors and omissions or E&O. Specifically technology E&O for Saqua vendors. This covers claims that your product failed to perform as promised and directly harmed a client financially.
So if you sell a B2B AI tool that automates payroll and it hallucinates the tax code causing your client to face massive IRS penalties, they're going to sue you to recover that money. E&O is the policy that stands in the line of fire for product failure. Precisely.
And the third vector is the commercial general liability, the CGL. Which is pretty broad. It is the bedrock policy.
It covers bodily injury, property damage, and crucially personal and advertising injury. That last category includes defamation and copyright infringement. Which is huge for generative AI.
Huge. If your marketing team uses an AI image that infringes on a competitor's IP, or your chat bot defames a public figure, the CGL is the target. And because almost every single organization holds a CGL policy, a standard AI exclusion added here reaches the widest population of businesses simultaneously.
So we have this wave of exclusions rolling across the D&O, E&O, and CGL policies. But to actually extract the intelligence from this free risk assessment, you cannot read it the way you read a standard vendor agreement. You really can't.
You have to read the exclusion backward. You have to look at the exact legal wording and reverse engineer the underwriter's mindset. Reading the exclusion backward is a master analytical skill.
You sit down with the text and ask just one question. What must the actuary and the underwriter believe about this technology to have refused it using exactly these words? And we can break this down into a step-by-step framework, right? There are four specific inferences you can draw. Yes.
Let's look at inference one breath maps to uncertainty. Give me a real world example of what that looks like in the text. Well, let's look at WR Berkeley's 2025 filing.
They implemented an absolute exclusion. It removes coverage for any claim based upon or arising out of any actual or alleged use, deployment, or development of artificial intelligence. And it even excludes statements, disclosures, or representations concerning AI.
This is what legal drafters call an absolute fence. So they aren't just saying, uh, we won't cover your chatbot if it hallucinates. They are saying we won't even cover the press release you wrote about the chatbot.
Exactly. Your marketing copy and your regulatory posture are now uninsured liability surfaces. And the breadth of that carve-out is a direct readout of the insurer's inability to model the risk.
Because if they could model it, they would price it. Right. A narrow exclusion tells you the insurer has localized the danger.
They know exactly what breaks and how much it costs. But an absolute fence means the insurer cannot find the edge of the blast radius. They don't know where the liability stops.
So they just fence the entire perimeter. If you see an absolute exclusion on your policy, the market is telling you that your technology is currently unquantifiable. That makes total sense.
So what is the second inference in this framework? Inference two. What they name first is what they fear most. Go back to those November 2025 filings from AIG and Great American.
The carriers didn't just say AI generally. They explicitly named chatbots and AI agents. Why those specific deployments? I mean, AI is everywhere.
It comes down to the causal chain of liability. A chatbot makes an open-ended, unscripted promise directly to a third-party customer. An AI agent takes an autonomous, unreviewed action in the real world.
So they are bypassing human oversight entirely. Exactly. They convert algorithmic errors directly into third-party harm, and they do it with a clear, identifiable plaintiff ready to sue.
Contrast that with, say, an internal AI co-pilot that drafts a legal contract for an employee to review. If a human lawyer has to read and sign that contract before it goes to the client, the human sign-off breaks the causal chain. So the insurance market is using its capital to tell you that customer-facing and action-taking AI is the severe class of risk.
Okay, so that leads to inference three, which touches on how widespread this is, the synchronization of these filings. Inference three is that synchronization signals correlation. Within six months, the entire industry adopted these boilerplate ISO forms.
Now, let me challenge that interpretation for a second. If the whole industry adopts ISO standard forms in a six-month window, isn't that just herd behavior? Like one major carrier gets spooked, they download the verus boilerplate, and the rest just copy it to be safe? Why should a CFO view that as actual fundamental intelligence about the technology rather than just corporate groupthink? It is a totally valid challenge, but you have to look at the regulatory plumbing behind it. The state insurance commissioner has still had to independently review and approve 80% of these filings.
Right, because they are heavily regulated. Their statutory mandate is to protect policyholders and ensure coverage remains available, yet they let these sweeping exclusions through anyway. That transforms mechanical synchronization into a genuine signal of correlation.
Meaning what exactly? What is correlation in this context? Well, insurers happily cover severe risks as long as they are independent. Like a car crash in Seattle has nothing to do with a car crash in Miami. That is how risk pooling works.
What an insurer cannot cover is correlated risk. That is the nightmare scenario called aggregation or systemic risk. So like a natural catastrophe.
Exactly. Think of a massive hurricane hitting the entire eastern seaboard at once. All the claims come in on the exact same day.
So what is the hurricane in the AI context? The hurricane is the shared upstream dependency. If 10,000 enterprise applications are built on top of the same underlying foundation model or they are fine-tuned on the same poison open source dataset, they share a single point of failure. Oh, wow.
Yeah, if a fundamental flaw in that model is exposed on a Tuesday, thousands of companies will experience simultaneous AI failures. And the insurers realize they can't possibly pay out 10,000 E&O claims on a single Tuesday. It would bankrupt them.
Yes. That is systemic risk. When you see a synchronized market-wide retreat, the signal is that the insurers perceive the risk as systemic.
Your company's dependence on a shared foundation model isn't just a technical architecture decision. It is a correlated financial liability. Which brings us to the fourth inference, which we will unpack even more deeply later.
Inference four is that excluded dollars equal retained risk. Right. The moment that exclusion drops into your policy, the financial liability doesn't just disappear.
It just transfers from the insurance company's balance sheet directly onto yours. And to understand exactly how much liability is transferring to your balance sheet, you have to pay obsessive attention to the exact drafting of the exclusion. Specifically, the connector words.
This is where I think most beginners get tripped up. They read an insurance policy and skip straight to the subject. They use CTRLLLF to look for the words generative AI.
But experts read the trigger phrase right before it. Because the trigger phrase dictates the entire scope of the net. Let's contrast two legal phrases caused by versus arising out of.
Under settled U.S. insurance law, these two phrases are worlds apart. Break down the mechanics of that. If a policy excludes loss caused by AI, what does the insurer have to prove? Caused by implies proximate cause.
The AI had to direct primarily cause the harm. But arising out of requires only a loose causal connection. It does not have to be the direct or sole cause.
It is arguably the broadest trigger a legal drafter can utilize. So arising out of is a very wide net. A very wide net.
If an analyst uses an AI tool to summarize a dense 100-page earnings report and the AI misses a nuance, and the analyst relies on that bad summary to execute a trade that loses a client millions of dollars, well, the AI didn't directly cause the trade. The human pushed the button. The human pushed the button.
So it wasn't strictly caused by the AI. But the loss undeniably arose out of the use of the AI tool. The insurer will point to the arising out of clause, cite the loose causal connection, and deny the claim entirely.
Just because it touched the process? Exactly. If AI touches a process at all, the loss might fall inside the exclusion. And this raises an even more foundational question.
How do these policies actually define artificial intelligence? Right, because my definition of AI might just be chat GPT or mid-journey. But I'm guessing the insurance underwriter has a much more expansive definition. Far more expansive.
Forms like the WR-Berkeley form or the ISO CG4047 use definitions modeled very closely on the OECD and the EU AI Act. Okay, and how do they define it? They define it as any machine-based system that infers from the input it receives how to generate outputs. Wait, really? Any system that infers from input to generate an output, that is not just generative AI.
That encompasses almost any algorithmic system or automated decision tool. That is the terrifying realization here. The exclusionary definition is vastly wider than your own mental image of your AI estate.
It will silently sweep up ordinary analytics, automated decision tools, and recommendation engines that you have been running safely for a decade without ever calling them AI. But. Yeah, you might think your basic inventory forecasting algorithm is perfectly safe, but under an arising out of AI exclusion, any loss connected to that algorithm is suddenly carved out of your coverage.
And when we talk about what is actually being carved out, we need to understand policy duties. There are two distinct duties an insurer has. Explain the difference between the duty to defend and the duty to indemnify and how an exclusion targets them.
Sure, a standard liability policy is actually two separate promises bundled together. First is the duty to defend. This means the insurer pays for your lawyers from day one, regardless of whether the claim has any merit at all.
They fund the defense. Okay, so that is the lawyer money. Right.
Second is the duty to indemnify. This means paying the actual settlement or court judgment if you lose the case. So they pay the victim.
Yes. Now, listeners must read the exclusion to see if it strips both duties or just one. Some exclusions strip both.
That is a total walkaway. You are paying your own lawyers out of pocket for the moment the lawsuit lands on your desk. But other policies might exclude indemnity, but preserve the duty to defend.
In that scenario, the insurer will still fund your expensive legal team to fight a frivolous AI lawsuit. But they make it clear they will walk away when it is time to write the settlement check. So a policy that funds your lawyers, but won't pay the settlement is vastly different from a total walkaway.
Understanding which duty is stripped changes your immediate cash flow risk entirely. It completely changes it. Because when that wide arising out of net drops over your entire tech stack, sweeping up your analytics and stripping your defense coverage, something fundamental shifts in the financial posture of your company.
And frankly, whether the CFO knows it or not. This is the hardest truth of the deep dive. An exclusion silently converts transferred risk into retained risk once it actually reaches your system.
Every single dollar the insurer stops covering lands directly on your balance sheet. Exactly. And we need to define retained risk clearly.
Retained risk just means self-insurance. Right. Which isn't always bad.
Not at all. The failure mode here is not retaining risk. Retention is a routine, completely valid business choice.
The catastrophic failure is retaining risk by accident because no one read the exclusion. It is the difference between a governed financial position and a lucky one. So let's see the math on this.
If I am the CFO, how do I calculate the genuine cost of carrying this risk myself? It is not just the average cost of an incident, right? No, the true cost formula has three parts. Part one is expected loss. This is the average annual cost of AI incidents, like your baseline burn.
Okay, part one is the expected loss. What is part two? Part two is the opportunity cost of the reserve. The capital you must legally or practically set aside to absorb a bad year cannot earn returns elsewhere.
Money sitting in a low-yield reserve account cannot be deployed into R&D or returned to shareholders. Right. The lost return on that locked up capital is a very real financial cost.
And part three? Part three is the volatility cost. You bear the full swing of a bad year alone. Without insurance pooling, a single large loss lands entirely in one quarter's results.
Let's ground this with a concrete example. Let's invent a fictional company. We will call them Rivergate Logistics.
They have an autonomous rebooking agent. Okay, let's run their math. Rivergate estimates their expected loss, part one, at $200,000.
But they must hold a $500,000 reserve to cover a bad year. Which is part two. And let's say that reserve costs them $30,000 in lost 6% returns.
Exactly. So they are humming along, but then a bad glitch hits them. Because there is no insurance pooling, that volatility cost part three hits them for $500,000 in a single Q3 earnings report.
Just a massive shock to the system. Yes. If they had an insurance policy, the insurer would have absorbed the shock.
Instead, they absorb it alone. Now take that one step further. Because what happens when you have multiple policies like cyber, tech, E&O, and D&O? Can't Rivergate just look at their stack of policies and find one that catches the fall? You are describing gap risk.
And it is incredibly dangerous. Gap risk is when a single AI incident falls between two policies. Because each carrier narrowed AI independently and points the finger at the other.
So the tech E&O carrier points to their AI exclusion. The cyber insurer says, this was an authorized AI, not a cyber breach. Right.
And you are left completely uncovered. You cannot assess AI coverage by looking at one policy. You have to lay them all side by side.
And we have to look at the global angle here, too. Because it isn't just a U.S. ISO issue, right? No. It is driven by the global reinsurance market.
Reinsurance is simply insurance for insurers. It is dominated by global players like Munich Re and Swiss Re. So they dictate the terms for the primary insurers.
Exactly. Reinsurance hardens appetite globally. Even if your EU or Asian entities have different liability laws, global reinsurance pressure means appetite is shrinking everywhere.
Your coverage must be reviewed per jurisdiction. So you do the review. You find a gap.
Your chatbot is excluded. Your agent is excluded. What exactly are you supposed to do about it? When you find an AI coverage gap, there are exactly three honest responses.
No fourth. Any fourth option is just one of these three chosen by accident. Let's walk through that step-by-step framework.
Response number one. Response one is transfer. This means you buy affirmative cover.
You pay a premium so a third party carries the loss. But wait, didn't we just establish that the standard market is running away? The standard market is, yes. But specialty players are stepping in.
For example, Munich Re has offered a product called iSure since 2018, which guarantees performance. And in early 2026, they partnered with Mosaic to offer up to 15 million in limits. Oh, wow.
15 million. Yeah. And in the Lloyd's of London market, a cover holder named Armilla partnered with Chaucer in April 2025, scaling to 25 million dollar limits.
But there is a catch, right? The catch is that governance is priced. Underwriters require your evaluation reports and conformity files. Good governance literally moves your risk from uninsurable to insurable.
And uninsurable just means unpriceable without evidence. That is a great way to put it. But is anything truly uninsurable? Yes, due to the fortuity rule.
Insurance only covers genuinely uncertain loss, not expected penalties or intentional wrongdoing. Statutory fines for AI bias cannot be insured at any price. Which brings us to the second honest response.
Reduce. You change the deployment to lower the severity. You add a human sign-off to break the causal chain.
You cap the dollar amount an autonomous agent can transact. Limit the customer facing surface. And if it cannot be reduced or insured? Kill the system.
Wow. Okay, and the third honest response. Retain.
You self-insure on purpose. Estimate the exposure, fund a dedicated reserve, and get an accountable executive or the board to sign a document accepting it. Right.
If you choose retain, you are stepping into the shoes of the underwriter for your own company. You need to do the math and collect the premium internally. Exactly.
So as we wrap up this deep dive, we need to turn theory into a Monday morning action plan. Because an unread insurance policy is an unfunded liability waiting to destroy a quarter's earnings. The gap between your engineering reality and your financial reality is exactly where careers end.
They absolutely do. The single most valuable concrete action you must make this Monday morning is to build a one-page AI insurance coverage review. List every AI system in your inventory.
Lay your actual policies side by side. Find the trigger phrases and definitions. Mark each system covered, excluded, or silent.
Write a one-sentence backward read extracting the insurer's fear. For every gap, assign the specific decision transfer, reduce, or retain. Crucially, total the retained risk into a dollar figure reserve and put a physical signature line at the bottom for the CFO or the board.
Assigned coverage review turns accidental self-insurance into a governed deliberate financial position. You no longer carry your AI risk by accident. You carry it on purpose.
And a final provocative thought for you to mull over. We think of governments as the ones regulating AI, but underwriters at Munich Re and Swiss Re are effectively acting as the ultimate global regulators. They aren't passing laws.
They're just adjusting premiums. The true boundary of artificial intelligence won't be drawn by a politician's pen. It will be drawn by an actuary's spreadsheet.
Absolutely. Thanks for joining us on this deep dive. Get that review signed this Monday.
Real cases
These examples show the analysis applied. Each is grounded in a verified event; the reasoning is stated so you can transfer it.
Example 1: The anchor, the synchronized retreat (United States, 2025 to 2026). AIG, Great American, and W.R. Berkley filed in November 2025 to exclude AI liabilities across D&O, E&O, fiduciary, and cyber; ISO issued standard generative-AI exclusions (CG 40 47, CG 40 48, CG 35 08) for general liability in January 2026; Chubb, Travelers, Berkshire Hathaway, and Cincinnati Financial followed by April 2026, with regulators approving most requests.
Read backward: the synchronization is the signal. When the whole market carves out the same risk in the same two quarters, it is pricing correlation and aggregation, the fear that one upstream flaw hits everyone at once. The lesson is not "insurers are cautious"; it is "the market now treats AI loss like a catastrophe peril, and so should you." (Sources: Financial Times reporting; CSO Online / CIO, "Insurance carriers quietly back away from covering AI outputs," 2025 to 2026; Gallagher and Fenwick analyses of the ISO endorsements, 2026.)
Example 2: The absolute exclusion (W.R. Berkley, 2025). Berkley's exclusion reaches "any actual or alleged use, deployment, or development of Artificial Intelligence," plus statements about AI and alleged violations of AI law.
Read backward: excluding statements and legal-compliance claims, not just malfunctions, tells you the insurer sees your words about AI and your regulatory posture as loss sources in their own right. The transferable inference: your marketing page and your investor disclosures are part of your AI liability surface, which is why aligning claims to the shipped reality (see Topic 8.5) and disciplined disclosure (see Topic 3.7) are risk controls, not just honesty for its own sake. (Source: Policyholder Pulse, "AI Exclusions in Insurance Policies," 2026, quoting the Berkley form.)
Example 3: Affirmative cover as a governance dividend (Munich Re aiSure, 2018 onward; Mosaic partnership, early 2026). Munich Re has sold performance-guarantee cover for AI models since 2018, underwritten after a technical due-diligence review of model robustness; in early 2026 Mosaic added specialty capacity for AI vendors on top of aiSure.
Read forward this time: the existence of affirmative cover proves AI risk is not uninsurable in principle, only unpriceable without evidence. The organizations that can show robustness evidence get cover; the organizations that cannot, do not. Your evaluation report (see Topic 4.6) and conformity file (see Topic 5.6) are the admission ticket. (Sources: Munich Re aiSure product pages; Mosaic Insurance and Reinsurance News, 2026.)
Example 4: The end of silent AI (market-wide, 2025 to 2026). Across the market, insurers moved to replace non-affirmative "silent" AI cover, coverage that existed only because old wordings never mentioned AI, with explicit language pushing every exposure to a clear yes or no.
Read backward: the industry decided that ambiguity favored policyholders and priced that ambiguity out. The transferable lesson for any risk owner: relying on silence is relying on the other party's oversight, and the other party eventually notices. If your only "coverage" is that nobody wrote an exclusion yet, you do not have coverage; you have a deadline. (Source: Fenwick, "The End of 'Silent AI'," 2026.)
Example 5: A gap-risk near miss (illustrative pattern, grounded in the fragmentation reporting). Consider the common structure the analyses describe: an AI chatbot gives a customer wrong, damaging advice. The customer sues. The Tech E&O insurer points to a new AI exclusion; the general-liability insurer points to CG 40 47; the cyber insurer says it was not a data breach. Each policy assumed another would respond.
Read backward: fragmentation across lines is not an accident, it is the predictable result of each underwriter narrowing AI in isolation. The defense is to map all your policies together, which is exactly the lab in Section 7. (Pattern documented in Fenwick and Lathrop GPM coverage-gap analyses, 2026; presented here as an illustrative structure, not a single named claim.)
Example 6: A purpose-built standalone AI policy (Armilla and Chaucer, Lloyd's of London, April 2025). The AI-assurance firm Armilla, working with the Lloyd's underwriter Chaucer, launched a standalone AI liability policy at Lloyd's of London in April 2025, with per-organization limits reported growing to 25 million United States dollars or more by January 2026. Its trigger is affirmative and unusual: it pays for damages arising from the underperformance of an AI application, including hallucinations, model drift (see Topic 4.5), and critical errors, plus legal defense costs.
Read this alongside the exclusions: the same risk the standard market is carving out is being deliberately underwritten by a specialist who first assesses the model. The lesson is that "uninsurable" is really "unpriceable without evidence and expertise"; a player willing to evaluate the model can price and carry the very risk a generalist refuses. If you need cover for an excluded system, the standalone specialist market, not your incumbent carrier, is where to look, and it will want to see your evaluation evidence.
Treat this as one specialist option, not proof the whole Lloyd's market is open. Many Lloyd's syndicates were filing their own AI exclusions on the same timeline, so a standalone product like this exists alongside, not instead of, a broader market retreat, and its own limits and deductibles must be checked against your worst case before you count on it. (Sources: Armilla and Chaucer press releases, April 2025; Reinsurance News; Insurance Business, 2025 to 2026.)
Example 7: The market admits it has no loss data (Lloyd's Market Association, 2025 to 2026). The Lloyd's Market Association, the body representing the underwriting businesses in the Lloyd's market, ran an AI loss-scenarios survey in 2025 explicitly because there was, in its words, an absence of market underwriting and claims data on AI exposures, and published an errors-and-omissions AI report with example underwriting questions.
Read backward: when sophisticated underwriters survey each other's opinions because there is no loss history to price against, that is the ambiguity signal in its purest form. A risk with no loss data is a risk no one can price with confidence, which is exactly why appetite swings so sharply between broad exclusion and cautious, evidence-heavy affirmative cover.
For you, the absence of industry loss data means your own incident log and evaluation evidence (see Topic 3.5)(see Topic 4.6) are disproportionately valuable: in a data vacuum, your data is the underwriting case. (Sources: Lloyd's Market Association, "Understanding AI Exposures: AI Loss Scenarios Survey Results" and "The Impact of Artificial Intelligence on the International E&O Market," 2025 to 2026.)
Where people go wrong
- "We have insurance, so we are covered." Having a policy proves nothing about a specific AI loss. Coverage is determined by whether the relevant exclusion, read against your actual system, applies. The right question is never "do we have E&O?" but "does our E&O, as it reads at this renewal, respond to this AI system if it fails?" Read the exclusions, not the declarations page.
- "An exclusion is just legal paperwork for the broker to handle." An exclusion is the most valuable risk assessment you will get all year, written by a party with money on the line and no reason to flatter you. Delegating it away unread forfeits the intelligence. Read it backward first, then send it to the broker with your analysis attached.
- "Silent coverage is good enough, nobody has excluded us yet." Silent AI cover exists only because an old wording overlooked AI, and the entire market is deleting that oversight at renewal. Relying on silence is relying on a deadline you did not set. If your only protection is that no exclusion has been added yet, you are self-insured on a countdown.
- "The exclusion only bites if the AI malfunctions." The broad forms reach further. W.R. Berkley's absolute exclusion also removes cover for statements and disclosures about AI and for alleged violations of AI law. Your marketing and your compliance posture are part of the liability surface, not just the model's output.
- "'Arising out of' and 'caused by' mean the same thing." They do not. "Arising out of" needs only a loose causal connection and is one of the broadest triggers in insurance drafting. A loss barely connected to an AI system can fall inside an "arising out of AI" exclusion. Always find and weigh the trigger phrase.
- "The exclusion only covers what we call AI." The policy's own definition of "artificial intelligence" sets the scope, and those definitions (modeled on the OECD and EU AI Act wording) are broad enough to capture ordinary analytics and recommendation systems you never labeled "AI." The exclusion can be wider than your mental image of your AI estate.
- "Retaining the risk is irresponsible." Retention is a legitimate, routine choice. The irresponsible thing is retaining risk by accident, because nobody read the exclusion or set a reserve. Deliberate retention with a funded reserve and a board signature is governance; accidental retention is the silent-AI mistake wearing a different hat.
- "Governance is a cost center with no financial upside." Affirmative AI cover is underwritten on documented governance and model-robustness evidence. Your evaluation report and conformity file are what move your risk from uninsurable to insurable and what set the premium. Good governance is now directly priced; it lowers your cost of carrying AI risk.
- "One policy either covers our AI or it does not." AI risk is fragmented across cyber, Tech E&O, D&O, fiduciary, and employment practices lines, each narrowing AI at its own pace. The real danger is gap risk, a loss that falls between two policies because each assumed the other responded. Assess all policies side by side, never one at a time.
- "AI is uninsurable, so there is no point looking for cover." The broad exclusions are real, but standalone specialist products (from Munich Re's aiSure to the Armilla and Chaucer policy at Lloyd's) affirmatively cover AI underperformance for organizations that can show model evidence. "Uninsurable" overstates it; the accurate statement is "unpriceable by a generalist without evidence." If a system matters enough, the specialist market is worth a quote before you default to retention.
- "This is a United States problem; our overseas entities are fine." Reinsurance is global and appetite hardens worldwide, while the underlying liability law varies by country. Your AI insurance position is jurisdiction-specific: a review that is correct for one entity can be wrong for another, because both the local market and the local loss law differ. Run the review per jurisdiction, not once for the whole group.
- "We reduced the risk with a human sign-off, so the exclusion no longer matters." Reducing the exposure is the right move, but it does not make the exclusion disappear; it lowers the severity of what you are retaining. You still record the system as excluded, note the reduction as the control, and estimate the residual exposure. Reduction changes the size of the retained risk, not the fact that you are carrying it.
Questions people ask
- What is liability insurance?
- Insurance that pays for harm your organization causes to a third party (a customer, patient, investor, or member of the public), as distinct from first-party insurance that pays for harm to you. AI governance failures are mostly third-party harm stories, so liability lines are where AI coverage is being fought over.
- What is directors and officers (D&O) liability insurance?
- Coverage protecting a company's leaders and the company against claims of mismanagement, including misleading statements to investors. If an organization overstated its AI's capabilities, D&O is the policy most exposed.
- What is errors and omissions (E&O) insurance?
- Also called professional liability; covers claims that a product or professional service failed and harmed a client. Technology errors and omissions (Tech E&O) is the version AI and software vendors carry, and it is in the line of fire when an AI gives a customer damaging advice.
- What is commercial general liability (CGL)?
- The broad, common business policy covering bodily injury, property damage, and personal and advertising injury (such as defamation). Because nearly every organization holds CGL, a standard AI exclusion added to it reaches the widest population at once.
- What is exclusion?
- Contract language that removes a category of loss from what a policy will pay. Exclusions are where insurers do their sharpest risk thinking, and reading them backward reveals what the insurer believes about the risk. More on Exclusion
Keep going
This lesson builds AI risk and impact assessment, and that page shows the roles that hire for it. Every Certified AI Governance Professional (CAIGP) lesson.