Playbook

Buying AI insurance: policies, exclusions, and what's actually covered.

There is no single "AI insurance policy" you can buy off the shelf yet. There is a fast-moving exclusion landscape subtracting AI coverage from standard policies, a countertrend writing AI coverage affirmatively into mainstream cyber and tech E&O forms, and a small standalone market for AI-specific liability. This guide maps all three and gives you a checklist for finding out what you actually have.

Is there such a thing as "AI insurance"?

Not in the way the phrase implies. There is no standardized, off-the-shelf "AI insurance policy" the way there is a standard cyber policy or a standard BOP. What exists in 2026 is two things moving in opposite directions at once.

First, carriers are adding AI exclusions to existing general liability, professional liability, cyber, and management liability policies. This subtracts coverage. An endorsement gets attached at renewal and claims arising out of AI use, in whole or in part, stop being covered under that line.

Second, a countertrend is writing AI coverage back in: affirmatively inside mainstream cyber and tech E&O forms, and through a small standalone AI-liability market, for buyers who can document their governance. This adds coverage, but only for the AI risk the underwriter can actually price, and only for buyers who can prove they have controls.

Most of the confusion buyers run into searching for "AI insurance" comes from not knowing which of these two things they are looking at. This guide covers both, plus the buyer's checklist for finding out, right now, what your existing policies actually say about AI.

The AI exclusion landscape.

The exclusion wave started with ISO and Verisk, the organizations that write the standard policy forms most of the commercial insurance market licenses rather than drafting from scratch. ISO filed a set of generative AI exclusion endorsements with an edition date of January 1, 2026: CG 40 47 (the primary Commercial General Liability exclusion, covering both Coverage A and B, in occurrence and claims-made versions), CG 40 48 (a narrower Coverage B-only version), and CG 35 08 (a Products/Completed Operations exclusion). As trade press summarizes the forms, the operative exclusion applies to bodily injury, property damage, or personal and advertising injury "arising out of, or attributable to" generative artificial intelligence, with generative AI defined broadly enough to cover any machine-based system trained on data that can create content or responses, in text, image, audio, video, or code. The full form language is proprietary to Verisk and not publicly reproducible, but the shape of it is consistent across every trade summary: broad definition, broad causation trigger, no built-in carve-back.

More than 60 property and casualty groups have filed to adopt the ISO forms or delay adoption, according to industry analysis of the 2026 filing wave. The list includes many of the largest names in the market: AIG, Allianz, Berkshire Hathaway, Chubb, Liberty Mutual, Munich Re, Swiss Re, The Hartford, Tokio Marine, and Zurich among them. Some carriers are writing their own proprietary versions instead of adopting ISO's forms directly. W.R. Berkley's PC 51380 00 (06-24), titled "Artificial Intelligence Exclusion (Absolute)," is one of the most aggressive examples and, unlike the ISO forms, it is a filed public record that law firms have reproduced in full. It amends D&O, employment practices liability, and fiduciary coverage parts and excludes claims based on or arising out of essentially any actual or alleged use, deployment, or development of artificial intelligence — not just generative AI outputs, but an insured's AI policies, procedures, training, vendor selection, public statements about AI plans, and regulatory inquiries into AI use. The definition of "Artificial Intelligence" in that form tracks the OECD and EU AI Act definition of an AI system, which is a much wider net than "generative AI" and pulls in traditional machine learning and decision-support tools too. Smaller and specialty carriers, including Philadelphia Indemnity and Hamilton Select, have filed their own narrower exclusions, mostly targeted at content generated or disseminated using generative AI tools.

Two things to hold onto here. First, exact policy language varies by carrier, by state filing, and by edition date, and it changes fast — the language above is a snapshot, not a guarantee of what any specific policy says. Confirm exact wording with your carrier or broker before you rely on it. Second, "generative AI" and "artificial intelligence" are not interchangeable terms across these forms. Some exclusions are narrowly scoped to content-generation tools; others, like Berkley's, reach any AI system and any AI-related decision the insured makes, including decisions about whether and how to use AI at all.

ISO/Verisk form language is proprietary; described here from public trade summaries, not reproduced in full. W.R. Berkley PC 51380 language is publicly filed and reproduced by legal alerts (Hunton Andrews Kurth's Insurance Recovery Blog, National Law Review). Verify exact endorsement text with your carrier or broker; state filings and edition dates vary.

Which lines of insurance are affected.

AI exclusions are not confined to one policy type. Legal alerts tracking the 2026 filing wave describe the affected lines as spanning:

Liability

CGL & products liability

Commercial general liability and products/completed operations, where the ISO CG 40 47 / CG 35 08 endorsements attach.

Cyber

Cyber & media liability

42% of companies already carry AI-related exclusions somewhere in their cyber policies, per a 2026 industry survey, and the trend is narrowing further.

Management

D&O, EPL & fiduciary

Management liability lines carry some of the broadest exclusions in the market, exemplified by W.R. Berkley's absolute AI exclusion.

Professional

E&O / professional liability

Where the agency-facing exposure concentrates. See the E&O exposure layer in the AI Governance playbook.

Also named: intellectual property, crime, and property. If your agency or business carries any of these lines, assume the renewal cycle ahead of you includes an AI conversation whether or not anyone has raised it yet.

Cyber insurance deserves a specific callout. The underlying tension: a traditional cyber policy responds to unauthorized access — someone breaking in. An autonomous AI agent that deletes records, corrupts a database, or authorizes an errant payment did not need to break in anywhere. It was already inside, acting with the permissions it was given. Carriers are drawing a hard line between AI that detects and defends (which the same survey found 86% of organizations get premium discounts for) and AI that acts autonomously on the business's behalf (where the exclusions concentrate). Some reinsurers are going further and excluding systemic losses specifically — the scenario where one flawed model or vendor failure produces correlated losses across many policyholders at once.

The silent cover problem.

Here is the part that catches most buyers off guard: not having an explicit AI exclusion in your policy does not mean you are covered for AI-related losses. Research published in July 2026 by the Financial Times, drawing on work from the Artificial Intelligence Underwriting Company co-authored with researchers from Anthropic and OpenAI, found that more than 90% of insurers' aggregate AI liability exposure sits inside what the industry calls "silent cover" — general liability, E&O, and tech E&O policies written before AI-specific products existed, where the risk is present but was never identified, disclosed, or priced. Litigation patterns are shifting to match: claims are moving from "the chatbot said something false" toward "the AI agent took an unauthorized action," which reads much more like a negligence or product-liability claim than a media-content claim, and which older policy language was never built to anticipate either way.

The practical implication is uncomfortable. Underwriters are not asking most buyers whether and how they use AI, which means most buyers have not disclosed it, which means the carrier priced the policy without knowing about a category of risk the business is actually running. That is not the same as being covered. If a claim arising from AI use lands on a policy that never contemplated AI, expect a coverage dispute, not a clean payout, regardless of what the exclusion language does or does not say.

Silent cover is a gap dressed up as protection, and it is the single biggest reason "do I have AI insurance" is the wrong question. The better question is "does my carrier know what I'm actually doing with AI," and for most buyers in 2026 the honest answer is no.

What's actually insurable right now.

Underwriters pricing AI risk in 2026 have converged on a rough dividing line: governed AI, with a human in the loop and a documented control environment, is something they can price and often will cover, sometimes at a discount. Autonomous AI, acting without meaningful human oversight and without a control environment behind it, is what the exclusions are built to keep out. The underwriting question has shifted from "do you use AI" to "which AI, in which workflow, under what conditions, with what oversight" — a question that cannot be answered honestly without an AI inventory and a governance program already in place.

This is why buyers who show up to a renewal with documentation — a risk inventory, vendor diligence records, an audit trail design, evidence of human review on anything consequential — get a materially different conversation than buyers who show up with a shrug. It is also why the CAIC governance framework and this guide are the same conversation from two directions: one is what to build internally, the other is what to bring to the carrier once you've built it. See the companion AI Governance for Insurance Agencies playbook for the governance side in full.

How to buy or audit AI insurance coverage.

Eight steps, in order. Most buyers can work through the first four in an afternoon.

The affirmative-coverage countertrend.

The exclusion wave is only half the story. A countertrend is writing AI coverage affirmatively into the cyber and tech E&O paper agencies already buy, and it matters more to most buyers than the standalone market does.

And the negatives matter as much as the positives: major cyber forms still in circulation, including At-Bay's public specimen and Chubb's Cyber ERM specimen, say nothing about AI either way. Silent AI is not history; it's the live ambiguity both camps are racing to close.

The standalone AI insurance market.

A true standalone AI liability product category also now exists — roughly five products worldwide as of early 2026, per market surveys.

One structural caution: not all standalone paper is equal. Virtually this entire market is non-admitted — Lloyd's surplus lines, Bermuda paper, risk retention groups — so the question is not admitted-versus-not, it is what capital sits behind the promise. Armilla's capacity panel is A-rated names (Chaucer, Axis, Swiss Re among them); Corgi's coverage, by contrast, is underwritten by a young, member-capitalized risk retention group. Both are legitimate structures, but they are not the same balance sheet, and pricing should reflect that. None of these products has published specimen policy wording; defined terms like "Underperformance" live in unpublished forms, so real diligence means requesting specimen wording through a broker, not relying on product pages. Before buying any standalone AI product, apply the same diligence you would apply to any new insurance market: confirm what stands behind the paper, ask how many similar claims have actually been paid, and get the policy language, not the sales deck.

CAIC does not sell or broker insurance products and has no financial relationship with any carrier or MGA named in this guide. Nothing here is a recommendation to buy from any specific vendor. Product structures, limits, and capacity described from carrier releases and trade press as of August 2026; confirm current terms through a broker.

FAQ

AI insurance questions.

Is there such a thing as AI insurance?

Not as a single, standardized product yet. What exists is a wave of AI exclusions being added to standard general liability, cyber, E&O, and D&O policies, plus a countertrend writing AI coverage affirmatively into mainstream cyber and tech E&O forms (Coalition, Beazley, Hiscox), and a small standalone AI-liability market (roughly five products worldwide as of early 2026) for buyers who can document governance.

What is an AI exclusion in an insurance policy?

An endorsement added to a policy that removes coverage for claims arising out of, or attributable to, the use of artificial intelligence. ISO's CG 40 47 and W.R. Berkley's PC 51380 are two prominent examples; more than 60 P&C groups have filed to adopt ISO's version or their own equivalents as of mid-2026.

Does my current insurance policy already exclude AI?

Possibly, and you should find out rather than assume either way. Pull your GL, cyber, E&O, D&O, and crime policies and look for an endorsement referencing artificial intelligence. If you don't find one, that does not mean you are covered for AI-related claims; it may mean your carrier never underwrote for the risk in the first place, which is the silent cover problem.

How do I buy AI insurance coverage?

Start by disclosing your actual AI use to your carrier or broker in writing at your next renewal, and ask directly what is and is not covered. If existing lines exclude AI, ask about a specific rider or endorsement, and bring governance documentation (an AI inventory, vendor diligence records, an audit trail) to strengthen the underwriting conversation. Also ask whether your cyber or tech E&O carrier already covers AI affirmatively (Coalition, Beazley, and Hiscox do in current forms); if not, a small standalone AI-liability market now writes coverage for buyers who can document controls.

What is "silent cover" for AI risk?

The situation where a policy written before AI-specific products existed technically responds to a claim, but the carrier never identified, disclosed, or priced the AI risk it's actually covering. Research published in July 2026 estimated more than 90% of insurers' aggregate AI liability exposure sits here, unpriced and largely undisclosed by policyholders.

Which types of insurance are affected by AI exclusions?

Commercial general liability, cyber and media liability, D&O, professional liability and E&O, intellectual property, crime, employment practices liability, fiduciary liability, and property, according to legal alerts tracking the 2026 filing wave.

What's the difference between an AI exclusion and AI-specific coverage?

An exclusion subtracts coverage: it removes AI-related claims from what a standard policy responds to. AI-specific coverage adds coverage back, narrowly, usually only for buyers who can document a governance program the underwriter can actually price.

Who can help my agency evaluate its AI insurance exposure?

Your E&O or commercial insurance broker is the first call, with the specific ask of an explicit AI conversation, in writing. Insurance professionals trained to run that conversation, including CAIC-certified practitioners, cover this exposure layer as part of Module 9, AI Safety, Security & E&O.

Where this lives in CAIC

Module 9.

This guide is the buyer-facing surface of a deeper framework inside the Certified AI Insurance Credential (CAIC). Module 9 (AI Safety, Security & E&O) covers the full exposure layer: how to read an AI exclusion, how to run the E&O disclosure conversation, and how to build the governance documentation that moves a carrier from decline to terms. Module 5 covers how to bring this to a client as an advisory engagement. Full structure. Watch the 6-minute Welcome below.

Watch the Welcome ▸

Stay current

The exclusion landscape moves fast.

New carrier language, new state DOI guidance, new specialty entrants — most of it lands between one Module 9 refresh and the next. The Adoption Gap, CAIC's biweekly LinkedIn newsletter, tracks what AI is actually doing in insurance and what agencies should do about it, in plain, sourced, no-hype coverage.

Follow The Adoption Gap ▸