Skip to content
Securafy AI Lab by Securafy
AI Governance

The New AI Exclusion Hiding in Your Insurance Policy

Standard commercial general liability policies stopped assuming generative AI risk on January 1, 2026, when new ISO endorsements gave carriers language to exclude AI-related claims outright. If your business builds, resells, or simply relies on AI tools day to day, your coverage may already have narrowed, and the fix depends on documentation you probably have not started.

In this article

Standard commercial general liability policies stopped assuming generative AI risk on January 1, 2026, when new ISO endorsements gave carriers language to exclude AI-related claims outright. If your business builds, resells, or simply relies on AI tools day to day, your coverage may already have narrowed, and the fix depends on documentation you probably have not started.

What Do the New ISO AI Exclusion Endorsements Actually Exclude?

The Insurance Services Office, the advisory organization that drafts standard policy language used across most of the U.S. property and casualty market, filed three generative AI endorsements with a January 1, 2026 edition date. CG 40 47 excludes bodily injury, property damage, and personal and advertising injury arising out of generative AI under both Coverage A and Coverage B of a commercial general liability policy. CG 40 48 applies the same exclusion but only to Coverage B, personal and advertising injury. CG 35 08 extends the exclusion into the products and completed operations coverage part, which matters most for businesses that sell a product or deliverable built with AI assistance.

EndorsementWhat it excludesCoverage part affected
CG 40 47Bodily injury, property damage, personal and advertising injury from generative AICoverage A and Coverage B
CG 40 48Personal and advertising injury from generative AICoverage B only
CG 35 08Losses tied to generative AI in delivered products or completed workProducts and completed operations

None of these three forms is mandatory. Each carrier decides whether to attach one, which means two businesses in the same industry can carry identical limits and completely different AI exposure depending on what their carrier chose. That makes the schedule of endorsements on your own declarations page the only reliable source of truth, not a broker's general assurance that "you're covered."

What Kinds of AI Claims Are Insurers Actually Worried About?

Insurers are pricing for a specific set of claim triggers, not AI in the abstract. A generative tool that produces marketing copy, product descriptions, or customer-facing content can create a copyright or trademark dispute if the output reuses protected material too closely. A support chatbot that states something false about a customer, a competitor, or a product can generate a defamation or false advertising claim the same way a human employee's statement would, except at a volume no single employee could reach in a day.

Automated decisions carry a second category of risk. A hiring tool, a pricing engine, or a claims triage system that relies on a model can produce a discrimination claim if its outputs skew against a protected class, even when nobody intended that outcome. Add professional services work where an AI system contributed to a deliverable that turned out to be wrong, and you have the errors and omissions exposure that technology and professional liability carriers are actively trying to carve out or price separately. A fourth trigger sits underneath the others: data. Feeding customer records, employee data, or third-party content into a model without checking the vendor's terms can create a privacy or intellectual property claim before the AI system ever produces an output anyone sees. None of these categories are new to liability insurance. What changed is that a single AI system can now touch all of them inside one business at once, which is exactly why carriers stopped treating AI as an incidental tool and started treating it as its own line of exposure.

Why Are Insurers Pulling Back on AI Risk Right Now?

Insurers are managing two pressures at the same time, and both point toward tighter AI terms. The first is what the industry calls silent AI exposure: policies written years before generative AI reached daily business use, where it is genuinely unclear whether a claim tied to an AI tool falls inside or outside the original intent of the coverage. Carriers dislike ambiguity they never priced for, and the new endorsements are a direct response to closing that gap rather than litigating it claim by claim.

The second pressure sits on the insurers themselves. The National Association of Insurance Commissioners adopted a Model Bulletin on the use of AI systems by insurers, and more than 20 states have now formally adopted it, with additional states moving through their own rulemaking. The bulletin requires insurers to run a written AI governance program with senior management and board accountability, testing for bias and errors, and documented oversight of any third-party AI tool used in underwriting or claims. Several participating states are already running market conduct exams built around an NAIC evaluation tool that asks carriers to produce their full inventory of AI systems and the case files showing how those systems influenced a decision.

Put those two pressures together and the incentive is straightforward. An insurer under its own new governance mandate has less appetite for open-ended exposure to a policyholder's undocumented AI use. Excluding what cannot be assessed, or pricing it separately once it can be, is the rational response.

Does This Stop at General Liability Coverage?

No, the same recalibration is moving through cyber, technology errors and omissions, and directors and officers forms, not only commercial general liability. Some cyber carriers have started attaching AI sublimits, capping what a policy will pay on an AI-related incident well below the overall policy limit even when the rest of the coverage stays intact. Other carriers have taken the opposite path and begun writing affirmative AI coverage on purpose, pricing it against the strength of a buyer's documented governance rather than leaving the question unresolved. A small group of specialized carriers now sell standalone AI liability products aimed at companies that can produce a real underwriting file rather than a verbal assurance.

Directors and officers coverage deserves its own attention inside that pattern. Shareholder and derivative claims already allege that boards failed to oversee cybersecurity risk adequately, and AI oversight is following the same legal theory. A board that cannot show it asked basic questions about how the company deploys AI, what could go wrong, and who is accountable for it is a harder file for a D&O underwriter to price with confidence, independent of whether a claim has actually been filed yet.

Whichever path a given carrier takes, the pattern underneath is the same. Underwriters are asking to see the governance behind the AI use before they will commit capital to it, and businesses without an answer are the ones absorbing exclusions, sublimits, or higher premiums by default.

What Should You Document Before Your Next Renewal?

Brokers working AI-related placements are converging on a short list of artifacts regardless of which insurer or form is involved. Having these ready before a renewal conversation changes the negotiation from defensive to informed.

  • A current inventory of every AI tool, model, and vendor integration actually in production, not just the ones a policy application asks about by name
  • A documented risk assessment for each significant use, covering what decisions the system influences and what happens when it is wrong
  • Evidence of human review on any AI output that affects a customer, employee, or regulated decision
  • Written vendor due diligence showing what your AI suppliers can demonstrate about their own controls
  • A record of who inside the company owns AI governance and how often that program gets reviewed

A practical AI readiness assessment produces the first two items in that list in a single pass, and it gives you a gap analysis against the rest before a broker or underwriter asks for it directly. Most businesses that go looking for this file for the first time discover the inventory step alone is the hard part, since AI tools tend to arrive through individual teams and vendor add-ons long before anyone in risk management or IT knows they are in production.

Building the Paper Trail Underwriters Actually Want

None of this works as a one-time exercise assembled the week before a renewal deadline. Underwriters can tell the difference between a policy binder written for the occasion and a governance program that has been running for a year. That is part of why ISO/IEC 42001, the international standard for AI management systems, has moved from a niche technical certification into a line item on enterprise vendor questionnaires over the past year, particularly in financial services and healthcare procurement. A business does not need a formal certificate to benefit from the same discipline, but the underlying structure, a documented policy, defined roles, risk treatment, and ongoing monitoring, is precisely what an underwriter is trying to verify exists.

Putting the people who operate your AI systems day to day through a recognized AI governance certification gives an underwriter independent evidence that the controls in your file reflect how the team actually works, not just how it describes itself on paper.

That distinction is exactly what AI University's governance curriculum is built around, walking a team through constructing an AI systems program section by section, from inventory through testing through vendor oversight, instead of assembling one from scratch the week a renewal notice arrives. A program built that way holds up under a market conduct exam as well as it does under a certificate of insurance review, because the underlying discipline is the same either way.

Your Next Step

Review your current declarations page for CG 40 47, CG 40 48, or CG 35 08 before you assume your general liability policy responds to an AI-related claim the way it used to. If you cannot produce the inventory, risk assessments, and oversight records an underwriter would ask for today, that gap is worth closing before your next renewal rather than after a claim. Book a strategy call to walk through what your business needs to document and where the biggest coverage gaps are likely sitting.

Rodney Hall
Rodney Hall

Rodney Hall is the President and COO of Securafy, with 2 decades of experience in IT service management and operations.

He writes about the less glamorous but essential side of IT: support systems, documentation, business continuity, recurring issues, downtime, and the processes that keep client environments running well. His perspective comes from years spent improving how service is delivered, how teams respond, and how small problems are prevented from becoming much larger ones.

Outside of work, Rodney enjoys home improvement projects, woodworking, and dirt bike riding. His personal mission mirrors Securafy’s: helping businesses stay secure, compliant, and ready for whatever comes next.

Writes about: Managed IT, IT operations, service delivery, business continuity, downtime prevention, support processes, operational risk

More from Rodney Hall

Learn AI by building with it

AI University helps teams move beyond AI curiosity through practical lessons, secure workflows, guided experiments, and real projects built for everyday business use.

Explore AI University

Stay current on practical business AI

Get practical updates on AI security, governance, tools, compliance, and implementation without the daily hype cycle.

Join the conversation

Have a question or a different take on this? Add it below.