Click to toggle navigation menu.

AI Insurance Exclusions: How to Tell If Your Policy Still Covers AI Risk

< BACK

By Ryan Windt | Head of Growth Marketing | Updated September 2026


For years, AI risk was covered by accident. If an AI tool your business used caused a loss, your cyber or technology errors and omissions policy would often respond, not because it named AI, but because it did not exclude it. That quiet, unwritten coverage had a name in the industry: silent AI. In 2026, insurers began ending it on purpose. New exclusions are being added to policies at renewal, and many buyers will not notice until they file a claim and learn their single biggest exposure was carved out months ago.

This guide explains what is changing, which policies are affected, and exactly how to check whether your own coverage still responds to an AI-related loss before your next renewal.


What silent AI was, and why it is ending

Most business policies were written long before generative AI was in daily use, so their language never mentioned it. That created ambiguity: an AI-driven loss might plausibly fall under a cyber policy, a Tech E&O policy, a general liability policy, or none of them. For a while, that ambiguity often worked in the policyholder’s favor, because a loss that is not clearly excluded is frequently covered.

Insurers do not like pricing a risk they cannot measure. As AI moved into production across nearly every industry, carriers moved to remove the ambiguity, and they removed it in the direction that protects them. Rather than wait for courts to decide whether old language covers new technology, they are rewriting the language. The result is a fast, quiet shift from silent coverage to explicit exclusion.


The signal that made it official

The clearest marker came from the Insurance Services Office (ISO), the organization whose standardized forms underpin the large majority of U.S. property and casualty policies. With a January 2026 edition date, ISO published new generative AI exclusion endorsements for commercial general liability policies. Because so many carriers build on ISO forms, an endorsement like this spreads quickly.

The endorsements are not identical, and the differences matter:

  • CG 40 47 is the broad version. It excludes bodily injury, property damage, and personal and advertising injury arising out of generative AI, across both main coverage parts of a general liability policy.
  • CG 40 48 is narrower, excluding only the personal and advertising injury piece.
  • CG 35 08 applies the exclusion to the products and completed operations coverage.

There is no public registry of which carrier uses which form, and some insurers write their own proprietary exclusion language instead of adopting the ISO version. That is precisely why you cannot assume your position from industry headlines. You have to read your own endorsement schedule.


Coverage is fragmenting, not disappearing

The important nuance is that different policy lines are moving in different directions at the same time. This is what creates gap risk, where a loss falls between policies that each assume another one covers it.

Policy lineGeneral 2026 direction
General liabilityAdding AI exclusions, led by the new ISO endorsements
Directors & officers, fiduciarySome carriers filing broad, in places near-absolute, AI exclusions
Technology E&O / professional liabilityMixed: some narrowing AI language, some offering affirmative buy-backs
CyberMost carriers affirming AI-driven attack coverage, but some introducing AI sublimits that cap it

The cyber side deserves special attention. Rather than excluding AI outright, some cyber carriers are reported to be capping it with an AI sublimit, an approach that limits the payout for an AI-related loss to a fraction of your overall limit. If that sounds familiar, it should: it is the same mechanism at the center of recent court fights over cyber sublimits. A firm carrying a large cyber tower could still find its AI exposure capped far below its actual risk. Our guide to how cyber sublimits work explains why that gap matters.


Why this is not the same as AI liability coverage

It is easy to confuse two different questions. One is whether your business is liable when your AI causes harm, which we cover in our guide to AI liability and cyber insurance and in how Tech E&O responds to AI and model errors. This guide is about the other question: whether your policy will pay at all, or whether an exclusion now sits between you and the claim.

The counter-trend is worth knowing. A growing set of carriers are writing AI coverage back in affirmatively, either inside cyber and Tech E&O forms or through standalone AI liability policies. The catch is that affirmative coverage is generally available only to buyers who can document their AI governance and controls. This mirrors how cyber insurance itself matured: silent coverage first, then exclusions, then coverage returning for buyers who could prove they managed the risk.


How to check your own coverage before renewal

You do not need to interpret endorsement language yourself. You need to ask the right questions and get answers in writing. Send these to your broker before you sign any general liability, Tech E&O, D&O, or cyber renewal in 2026.

  • Has an AI exclusion been added at this renewal? Ask specifically whether an ISO form or a proprietary exclusion was attached, and request the exact endorsement language, not a summary.
  • What is the trigger standard? An exclusion for losses “arising out of” AI is far broader than one for losses “solely caused by” AI. That wording decides how easily a claim gets denied.
  • Does it reach incidental AI use? Ask whether a claim is excluded if an employee merely used an AI tool, even when AI was not the primary cause of the loss.
  • Is there an AI sublimit on the cyber policy? If AI is covered but capped, find out the cap and compare it to your realistic AI exposure.
  • Is affirmative AI coverage available? Ask whether the carrier offers a buy-back endorsement or a standalone AI policy, and what governance you would need to document to qualify.

Reading these endorsements is exactly the kind of fine print our guide to reading a cyber insurance policy and our renewal checklist are built to help with. If your business builds or deploys AI, our overview of cyber and Tech E&O for technology companies covers where these exposures tend to concentrate.


Frequently Asked Questions

Often, but it is no longer safe to assume. Most cyber carriers are affirming coverage for AI-driven attacks, but some are adding sublimits that cap AI losses, and general liability and management lines are increasingly excluding AI outright. The only reliable answer comes from reading your specific policy’s endorsements.

What is an AI exclusion?

It is endorsement language that removes coverage for losses connected to artificial intelligence. Some are narrow, targeting only generative AI output; others are broad, excluding any claim arising out of the use, deployment, or development of AI.

What are the ISO AI exclusions?

They are standardized generative AI exclusion endorsements for general liability policies, with a January 2026 edition date, including forms numbered CG 40 47, CG 40 48, and CG 35 08. Because most U.S. carriers build on ISO forms, they spread across the market quickly.

How do I know if my policy has an AI exclusion?

Check the endorsement schedule of each policy, or ask your broker in writing to confirm whether an AI exclusion was added at renewal and to send the exact language. Do not rely on the declarations page alone.

Can I still get AI coverage?

Yes. A growing number of carriers offer affirmative AI coverage through buy-back endorsements or standalone policies, typically for buyers who can document their AI governance and controls.


Not sure whether your current policies still cover your AI exposure, or whether an exclusion slipped in at your last renewal? Talk to a specialist who works cyber and Tech E&O every day, and we will help you find the gap before a claim does.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.