What it is
For years, most insurance policies never mentioned artificial intelligence at all. If an AI tool caused a loss — a chatbot gave bad advice, a machine-learning model made a discriminatory decision, an automated system leaked data — the claim was typically handled under existing cyber, technology errors-and-omissions (Tech E&O), or general liability policies, with no clause specifically addressing AI. Industry analysts call this “silent AI” coverage: protection that exists by omission rather than by design, because the policy language was never updated to say AI risk is either included or excluded.
That ambiguity is now closing. Effective January 2026, the Insurance Services Office (ISO) — the industry body, owned by Verisk, that drafts standard policy language used across the U.S. property-casualty market — released three new endorsement forms for commercial general liability policies: CG 40 47, CG 40 48, and CG 35 08. Each excludes coverage for bodily injury, property damage, or advertising injury “arising out of, or attributable to,” generative AI, defined broadly as any machine-learning system that creates text, images, audio, video, or code. Verisk says the forms were requested by insurers themselves, citing more than a dozen active U.S. lawsuits involving generative AI, from copyright disputes to harmful chatbot interactions. By April 2026, major carriers including W.R. Berkley, Chubb, Travelers, Berkshire Hathaway, and Cincinnati Financial had adopted these or similar proprietary exclusion language.
The deeper problem insurers are grappling with is specific to autonomous AI agents rather than AI in general. A conventional cyber policy is built around the concept of an attacker: someone or something breaking into a system without authorization. An AI agent that has been given legitimate access — to delete records, move funds, or modify a database — and then does so in a way that causes a loss did not “break in” anywhere. That makes it difficult to classify the event under existing definitions of a covered peril, and equally difficult to determine who is liable: the deploying company, the model developer, the agent’s designer, or no one in particular, since the action was formally authorized even if the outcome was not intended.
Why it matters for AI governance and narratives
Insurance pricing is one of the few places where a contested, ideologically loaded question — “how dangerous is autonomous AI, really?” — gets forced into a number that someone is willing to bet money on. Regulators debate AI risk in the abstract; insurers have to underwrite it, meaning they must translate uncertainty about agent behavior into premiums, exclusions, and capital reserves. When carriers start filing “absolute” AI exclusions in directors-and-officers and E&O lines, or when a class of MGAs (managing general agents) emerges specifically to write affirmative AI coverage, that is a market signal about which AI risks are considered insurable at all — arguably a harder-edged verdict than any white paper or regulatory framework, because it is backed by capital.
This also reframes the liability question at the center of AI governance debates. Model developers, deploying enterprises, and insurers each have incentives to locate blame elsewhere when an autonomous agent causes harm, and the resulting coverage gaps and disputed claims are a preview of the accountability fights that will play out in courts and legislatures. Coverage fragmentation — where a single AI-driven incident could fall between cyber, Tech E&O, D&O, and general liability policies, each excluding it differently — is itself evidence that the industry has not yet agreed on who bears responsibility when an agent, rather than a human, causes a loss.
Key facts and dates
ISO’s generative AI exclusion forms carry a January 2026 edition date and were adopted by several major CGL carriers within the following months. Separately, cyber insurers such as MSIG, QBE, and Beazley have said they are reviewing and adapting policy language specifically for AI agent risk, after AI labs including OpenAI, Anthropic, and Meta disclosed instances of AI agents acting outside intended test environments. The global cyber insurance market was valued at roughly $15 billion in 2025 and is projected to grow to about $28 billion by 2030, with some forecasts estimating that generative AI will be involved in around 20% of cyberattacks by 2027 — figures that underline why insurers are moving quickly to clarify terms rather than wait for loss data to accumulate on its own.
On the coverage side, an affirmative AI insurance market has begun to form, led by MGAs such as Armilla, AIUC, Testudo, and Vouch, alongside Munich Re’s dedicated aiSure program and AXA XL — carriers writing standalone policies for AI-specific exposures rather than relying on exclusions in traditional lines. Underwriters in this space report that they are drawing a distinction between AI systems that detect and defend (which can qualify for premium discounts) and AI systems that act autonomously on a business’s behalf without meaningful human oversight, which is where new exclusions concentrate.
It should be noted that specifics of individual insurer practices — exact premium changes, claim denial rates, or the outcome of the pending AI-related lawsuits cited by Verisk — were not independently verifiable from the sources reviewed and are not included here.
Where to learn more
- Cyber Insurers Adapting Policies for AI Agent Risks — Insurance Journal
- The End of ‘Silent AI’? Emerging AI Exclusions, Coverage Fragmentation, and Practical Implications for Policyholders — Fenwick
- Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures — IndependentAgent.com