Most businesses running AI tools are no longer covered for AI-related claims under their general liability, professional liability, or management liability policies. Insurers are adding AI exclusions to CGL, E&O, and D&O policies on separate schedules, with different wording. One AI failure can trigger denied claims under all three at once, leaving your business exposed.
This is not a distant renewal-cycle problem. It is happening now, policy by policy, often without your broker walking you through what actually changed in the fine print. If you have renewed a CGL, E&O, or D&O policy in the last year, there is a real chance new AI language slipped in and nobody flagged it as a coverage decision.
A CGL AI exclusion strips out coverage for bodily injury, property damage, or advertising injury connected to your use of artificial intelligence in daily operations. Carriers have filed new ISO endorsements built specifically for this: CG 40 47 for AI-driven outputs and decisions, CG 40 48 for AI-generated intellectual property and copyright disputes, and CG 35 08 for damage caused by autonomous systems. According to RM Study Group's analysis of GL renewals, more than 80 percent of carrier requests to exclude AI-related damages have already cleared state regulatory approval, with some exclusions taking effect as early as January 2026.
The practical result: the CGL policy you renewed without reading the endorsement schedule line by line may no longer respond the way it did last year, even though your operations have not changed. Risk & Insurance reports that some carriers are filing these exclusions less from careful underwriting and more because excluding AI risk outright is simpler than pricing something new. That distinction matters for you: the exclusion was not built around your specific use case. It was built to remove the carrier's uncertainty, and your business absorbs whatever got removed along with it.
The pattern echoes how cyber insurance emerged two decades ago. Carriers first excluded risks they could not price, then let standalone products fill the gap later, on their own timeline and at their own price. AI exclusions are following the same playbook, except this time the exclusion is landing across three policy types you already carry, not one specialty line you have to go shop for separately.
Not reliably. E&O carriers are narrowing what counts as a covered claim when an AI tool contributes to an error, a bad recommendation, or a flawed deliverable that reaches a client. Shumaker's client alert on the AI coverage fight documents carriers adding exclusions and endorsements that narrow the professional liability response specifically around AI involvement, and denied claims tied to this language are already surfacing.
This lands hardest on businesses that let AI touch client-facing work: drafting reports, generating recommendations, screening applicants, producing analysis a client acts on directly. If an AI-assisted error triggers a claim and the carrier points to the exclusion, you are defending that claim on your own budget, one that assumed coverage you no longer have.
Silent AI coverage describes older policies that never mentioned AI at all, so AI-related claims were evaluated under ordinary policy language instead of being automatically denied. Fenwick's analysis of the end of silent AI explains that carriers are closing that ambiguity on purpose, replacing silence with explicit exclusions across cyber, tech E&O, D&O, and employment practices liability lines, each moving independently of the others.
That independence is the trap. Each line of coverage narrows AI protection on its own schedule, so a single AI-driven incident, a data exposure that also exposes a governance failure, for example, can fall into the gap between two or three policies that each assumed another policy would pick it up. Silence used to work in your favor by default. Now it works against you unless you have confirmed otherwise in writing.
Directors and officers can be held personally exposed when an AI failure turns into a claim that the board failed to oversee AI risk adequately, and D&O policies are not automatically built to absorb that exposure. Harvard Law School's Forum on Corporate Governance frames this as a hidden C-suite risk: the AI failure itself may start as an operational problem, but the liability question that follows lands on the decisions leadership made, or did not make, about governance and oversight.
This is the part most business owners miss. The conversation about AI risk tends to stay focused on the tool and the vendor. But when a claim or a regulator looks for accountability, they look up, at who approved the deployment and what oversight process existed before it went live. If your D&O policy also carries an AI exclusion, the people ultimately responsible for that approval are personally exposed at the exact moment the company itself may be denied under its CGL or E&O policy.
| Policy | What It Is Supposed to Cover | Where the AI Exclusion Hits |
|---|---|---|
| CGL | Bodily injury, property damage, and advertising injury from normal operations | New ISO endorsements strip coverage tied to AI outputs, AI-generated IP disputes, and autonomous system damage |
| E&O | Errors, omissions, and bad professional advice delivered to clients | Endorsements narrow what counts as a covered error when an AI tool contributed to the deliverable, producing denied claims |
| D&O | Leadership decisions and oversight failures that trigger shareholder or stakeholder claims | Exclusions target claims tied to AI governance failures, leaving directors and officers personally exposed |
Read across the table and the shape of the problem becomes obvious: three different policies, three different exclusion strategies, and no single carrier responsible for coordinating what happens when an AI incident touches more than one category at once. A flawed AI recommendation that reaches a client is not just an E&O question. If it also involves a product or service failure, it can pull in CGL. If it later becomes a shareholder claim about inadequate oversight, it pulls in D&O too. Each policy can point to its own exclusion and deny its own slice of the claim, leaving you to cover whatever falls between them.
Start by asking your broker for a plain-language explanation of exactly how AI is addressed, or excluded, in each of your CGL, E&O, and D&O policies before your next renewal. Lathrop GPM's overview of the AI coverage gap recommends treating this as a specific line-item review rather than assuming your broker has already caught the change, since exclusions get added quietly inside standard renewal paperwork.
That documentation step is where most businesses fall short, not because the information does not exist, but because it is scattered across email threads and vendor contracts instead of a single record an underwriter or a regulator can review. Running a cybersecurity assessment gives you a scored, structured starting point for that record: it shows where your AI and data controls actually stand today, which is exactly the kind of evidence a broker or underwriter asks for when you push back on an AI exclusion.
Regulated businesses face a double bind: regulators want more documented AI accountability at the same time insurers are pulling back coverage for AI-related failures. A denied claim in a regulated industry does not just cost money. It can also become evidence in a regulatory inquiry about whether your oversight was adequate in the first place, turning one problem into two.
Healthcare practices using AI for documentation or triage support, financial services firms using it for underwriting or fraud screening, and professional services firms using it to draft client deliverables all carry this same exposure, just wrapped in different regulatory language. A healthcare AI error can trigger a compliance inquiry on top of a denied E&O claim. A financial services AI error can trigger a regulator asking for model governance records at the same moment a CGL or D&O carrier is asking why coverage should apply at all.
This is why the coverage gap should not be treated as a pure insurance-procurement task you hand to a broker once a year. It is a governance issue that touches how AI tools get approved, monitored, and documented across your business, and it deserves the same operational attention as any other compliance obligation tied to regulated work. Businesses that already run structured IT and security operations through Securafy's Essential Care service have an easier version of this problem, because monitoring, documentation, and asset tracking are already built into how the business runs day to day, instead of being reconstructed from scratch when a broker asks for evidence.
If you are building or updating vendor requirements around AI and security, use a fixed checklist instead of judgment calls made on the fly. Securafy's Cybersecurity Buyer's Guide includes a vendor evaluation checklist built for exactly this kind of decision, and it doubles as a reference for the questions your broker and your board should both be able to answer about how AI is deployed and overseen inside your business.
Closing this gap starts with knowing exactly where your CGL, E&O, and D&O policies stand today, not after a claim gets denied. The fastest way to close the distance between your AI use and your actual coverage is to build the governance record now, while you still have time to act on it.
If your team is moving faster with AI than your guardrails are, start with structured training rather than another tool. Securafy AI University gives your people role-based AI training with security built into the material, not bolted on afterward.
If you would rather talk through your specific environment first, book a strategy call with Securafy and we will walk your current AI usage, exposure, and the fastest path to safe adoption.