The Industry That Prices Every Risk on Earth Just Refused to Price This One
Insurers filed to stop covering AI claims, and regulators approved four filings in five. Here's how to find out whether your policy still pays — before the day you need it to.
I have bought insurance in three countries, for cars, flats, a business and a very ordinary life — and I almost never read the exclusions.
The declarations page, sure — that's where the number lives, and the number is the part you argue about. But the exclusions sit in the back, in the section with the form numbers and the tiny type, and I have signed my name under them perhaps twenty times without reading a word. So has almost everyone. It isn't laziness; it's a division of labor. You pay the premium, they carry the risk, and the fine print is the boring middle nobody expects to matter.
Here's the thing about that page, though. You only ever meet it on the day you need it — the one document in your life that stays invisible until it's the only thing that counts, by which point it's far too late to negotiate.
I'm telling you this because something was added to that page this year, and almost nobody read it.
We established the liability leg in June: when an AI agent acts for you and gets it wrong, the law quietly leaves the bill with you. That piece asked who was responsible. This one asks the colder follow-up — who pays — and the answer changed while we were watching model releases.
What actually happened, in the order it happened
Start with the mechanism. Most commercial insurance in the United States is not written from scratch; it is assembled from standard forms drafted by ISO — the Insurance Services Office, the standard-forms unit of the analytics company Verisk — which thousands of carriers then bolt onto their policies. This year's change arrived as two new endorsements with form numbers, which is how the insurance industry announces that something has stopped being covered.
There are in fact three endorsements, not one, and the distinctions matter:
CG 40 47, the broad one: bodily injury, property damage and personal and advertising injury arising out of generative AI, across the whole Commercial General Liability coverage part.
CG 40 48, the narrow one: personal and advertising injury only — the coverage that answers a defamation or copyright claim.
CG 35 08: products and completed operations, the things you already shipped.
They take effect at US general liability renewals from January 1, 2026 — the part people keep getting wrong. Nothing switched on at midnight on New Year's Day; it happens as policies renew, all year long. What it converts is "silent AI," coverage that existed only because nobody had thought to rule it out. The renewal is where silent AI becomes an explicit exclusion: no announcement, no letter, just a form number added to the back of the policy.
Meanwhile, carriers were going further on their own. The Financial Times reported — and Tom's Hardware relayed the detail — that AIG, WR Berkley and Great American had each sought regulatory clearance to deny claims tied to the use or integration of AI systems. TechCrunch counted a slightly different set — Great American, Chubb and W. R. Berkley — asking regulators for permission to exclude widespread AI-related liabilities from corporate policies. AIG told Illinois regulators that generative AI represents a broad and far-reaching technology — which, in a filing, is not praise. It is the size of the hole.
Two corrections before we go on. First, AIG. It is widely listed among the carriers "excluding AI," and that is not what AIG says. The company told TechCrunch it "was not specifically seeking to use these [reported upon] exclusions and has no plans to implement them at this time," while telling the FT it wanted the option available as claims grew. Sought the right; says it isn't exercising it.
Second, and more importantly: filing is not excluding. A carrier that files an endorsement has bought the right to attach it at renewal, not attached it to your policy. What follows is about permissions, not coverage already gone.
By April 2026, Wolfe Research's analysis of thousands of regulatory filings found that more than 80% of those filings were approved, with subsidiaries of Berkshire Hathaway, Chubb, Travelers and AIG among the filers. Regulators looked at requests to stop covering the defining technology of the decade and, four times in five, said yes. Why fifty regulators and not one? Because insurance regulation is reserved to the states under the McCarran-Ferguson framework — so it happened fifty times over, in a filings process no journalist covers on an ordinary Tuesday.
And carrier-drafted wording goes further than ISO's. ISO excluded generative AI; one carrier's language reaches any actual or alleged use, deployment, or development of artificial intelligence, full stop, with a definition covering any machine-based system that infers outputs from inputs. That fits your spam filter as comfortably as ChatGPT. It fits your fraud-scoring vendor and the résumé screener your HR platform quietly switched on in 2023.
Nor is it only the company's cover at stake: the same carrier is excluding AI-related losses from its D&O policies, the insurance protecting the humans who approved the AI rollout in the first place.
A coverage lawyer at Reed Smith said the quiet part plainly to Bloomberg Law: I don't know how anything would be left if the exclusion is written broadly. If everything down to the phone in your pocket runs on AI, what still gets covered?
Give the underwriters their due — they are not being cowards
The insurers have a real argument, and it deserves a hearing.
Insurance runs on the law of large numbers: many similar events, a long history of them, losses that don't all arrive at once. Generative AI fails all three. As the insurability analysis in The Actuary lays out, these systems are opaque and genuinely unpredictable, the average loss per incident looks large, and historical data to model such events is scarce. You cannot build a price out of nothing. Insurers also can't see how a business governs its AI — textbook adverse selection, where the firms keenest to buy cover run the sketchiest deployments.
Then there is the shape of the risk. Aon's head of cyber named it in the same FT reporting: a systemic, correlated, aggregated risk. The industry can absorb a $400 or $500 million hit from one company's misfiring agent. What it cannot absorb is an upstream failure at a model provider producing a thousand losses on the same Tuesday, all traceable to the same bad weights. Hurricanes hit one coast; a model update hits everyone who called the API. The head of cyber at another specialist insurer put it in six words — too much of a black box — a strange thing to hear from an industry that prices earthquakes, but he isn't wrong.
And the claims curve is not imaginary. US generative-AI lawsuits went past 700 in five years to 2025, a 978% climb, and the rate is accelerating, not leveling off — up 137% year over year in 2024–25 against 59% the year before. Much of that is noise; most litigation is. But the decided cases exist: a Canadian tribunal ordered Air Canada to honor a discount its own chatbot invented. Others — a $110m defamation claim over an AI-generated search summary, a wrongful-death suit against a chatbot maker — remain unproven allegations. Underwriters don't wait for verdicts. They price the pile.
There is even a commercial brake, and it is the most honest thing the industry has said all year: as a Lathrop GPM insurance lawyer noted, aggressive exclusions may make their policies less attractive, given how pervasive AI now is. An insurer that excludes everything has, functionally, stopped selling insurance.
So this is not a market that has decided AI is uninsurable. It's a market that hasn't finished pricing it, and has taken the exposure off the books while it works that out.
Lloyd's has seen this film before, and it ends differently
Anyone who thinks the American carriers have delivered a final verdict should look east. Lloyd's of London is the market that made its name insuring the uninsurable — satellites, war zones, a violinist's hands, the things nobody else would touch. It also ran exactly this play seven years ago, on a risk that looked every bit as unpriceable then as AI does now.
In 2019, Lloyd's told the market to stop being vague about cyber. From January 1, 2020, every policy had to say plainly whether cyber was covered: exclude it or affirm it, but say which. The stated reason was the uncertainty surrounding silent coverage — cover nobody had priced, nobody had reserved for, and everybody would eventually claim on. The first move, overwhelmingly, was to exclude: the global insurance community moved to exclude cyber from all mainstream policy lines, which made a dedicated cyber policy unavoidable rather than optional. And then? Munich Re's data records an exceptionally steep rise in cyber premiums afterwards, to nearly $15bn globally by 2025 — a line its analysts still call one of the most rapidly growing sub-sectors of world insurance, even now the growth has cooled. The exclusion wasn't the end of coverage; it was the clearing of the ground.
Watch the same sequence starting now. Affirmative AI coverage — policies written on purpose, with real limits, for actual AI failures — is already being sold, and one of the first was underwritten at Lloyd's. Google Cloud now offers affirmative AI insurance coverage for its customers' AI workloads, through a partnership with insurers Beazley, Chubb, and Munich Re.
Read that carrier list again. Chubb. The same Chubb whose subsidiaries appear in the exclusion filings is helping build the product that covers the thing being excluded. It looks like hypocrisy for about four seconds, and then it looks like the actual story: the industry is not refusing this risk, it is moving it out of the cheap, silent, unpriced policy into an expensive, explicit, deliberately underwritten one.
The demand is certainly there. The Geneva Association surveyed 600 corporate insurance decision-makers across six countries last October and found nine in ten businesses want to buy it, two-thirds willing to pay at least 10% more in premium. Capacity is the harder problem — even the model builders are reportedly weighing investor money to settle lawsuits because of insurers who won't fully cover AI risks. But the industry's own research arm concluded that insuring these risks is possible, on condition the buyer can demonstrate human oversight, bias checks, cybersecurity controls and a contingency plan. Hold onto that condition; it becomes the most important sentence here.
Now imagine the renewal questionnaire in 2029
Let me extrapolate, because the direction of travel is not subtle.
Your company renews its liability cover. The broker sends the usual forms — revenue, headcount, claims history — and then a second document that didn't exist five years earlier. An AI schedule. Every model, every vendor, every agent with write-access to a system that touches money or people. Which decisions are automated, which have a human in the loop, and whether that human has ever actually overruled the machine or just clicked through. Whether you could reconstruct, six months later, why the system did what it did.
Answer well and you get cover, with a premium credit. Answer badly and you get the broad exclusion — and no other carrier will quote you either, because they're all reading the same schedule.
That is not a hypothetical regulatory regime. That is underwriting — and it would arrive faster, bind harder and reach further than any AI act any legislature has passed, because it doesn't need a majority. It needs an actuary. Push it one turn on: premiums start pricing the difference between a well-governed deployment and a reckless one, and "safety" stops being a conference panel and becomes a line item on a budget — the only place ideas ever really live.
And the next exposure is already visible over the ridge. Every one of these exclusions was drafted for generative AI — things that produce text and images. New research says the industry may not be equipped for agentic AI risks: software that doesn't write a paragraph but takes an action, books the flight, moves the money. Nobody has priced that yet. The forms filed this year won't be the last.
What the smart people are saying
The most interesting argument in this space is that insurers have quietly become AI's real regulator — and it is an argument, not a settled fact.
Writing in Lawfare, Cristian Trout makes the case that insurers do far more than pay claims: they monitor policyholders, identify cost-effective mitigations and end up enforcing private safety standards on companies no legislature ever reached — which makes a retreat from AI cover a governance problem, not just a commercial one. In fairness, Trout is a research fellow at a company that sells AI insurance, so read him as an interested expert. His remedies run from light-touch (transparency rules, clearer liability assignment) to muscular (insurance mandates, government backstops) — the latter being how nuclear power and terrorism cover both got built.
The scholarly version predates the panic. Anat Lior, who has spent her career on the seam between AI liability and liability insurance, argued in the Harvard Journal of Law & Technology in 2022 that insurance should be treated as a regulatory mechanism for AI — and, notably, that AI accidents are not similar enough to terror attacks to qualify as uninsurable events. Her "grace period" — when a technology causes harm tort law hasn't caught up to — describes 2026 uncomfortably well.
From the free-market right, the R Street Institute calls insurance and AI a double-edged sword and is the outfit that surfaced those D&O exclusions — hardly anti-industry, and still uneasy. From the consumer-protection left, the Consumer Federation of America is fighting the 2026 federal push to preempt state AI law because it would stop states addressing the harms they are actually experiencing. Different politics, same instinct: this is being decided where nobody is watching.
And from the defense bar, Wiley's survey of 2026 state legislation supplies the detail that makes this urgent: new bills creating private rights of action over AI companions and chatbot disclosure will reshape the liability landscape upward in the very year the policies stop responding. More ways to be sued; fewer policies that pay.
What does this mean for you?
If you don't run a business: not much yet, directly — personal lines haven't moved. But if you're a director, a founder or a partner, your personal exposure is in play.
If you run or advise a business, here is the checklist. None of it takes more than an afternoon:
Ask your broker one specific question: "Does our policy carry CG 40 47, CG 40 48 or CG 35 08, or any carrier-specific AI exclusion?" Ask about the last renewal and the next. Vague answers are answers.
Read the definition, not the heading. The heading may say "generative AI"; the definition may cover any system that infers an output from an input. The gap between them is your exposure.
Check the D&O policy separately. Different form, different carrier, increasingly a different answer.
Map where the gaps fall. They fragment across general liability, cyber, tech E&O, D&O and employment practices, so a single AI incident touches several lines and no single policy responds comprehensively.
Ask about affirmative cover. Standalone AI liability policies exist now. They cost money. So does an uninsured claim.
Fix your contracts. As Lathrop GPM's coverage team puts it, AI-related litigation and regulatory inquiries may become uninsured risks — so revisit indemnities with vendors and customers, and decide now who eats a loss nobody's policy will.
Start the paperwork underwriters will demand. Human oversight, bias testing, logging, an incident plan. Building it now beats retrofitting it during a claim.
And if you're on the receiving end of an automated decision, know that "the AI decided" now has a price attached for the company saying it. Ask who carries the risk; sometimes the question alone changes the behavior.
The lesson, as I see it
There is something almost clarifying about this. For three years we have argued about AI in the language of ethics panels and voluntary commitments, where everyone agrees in principle and nothing has a price. Insurance doesn't do principles. Insurance is what a society believes about a risk after it has been forced to put a number on it — and the number that came back, on the broadest and cheapest policies, was: not at this price, not on this form, not yet.
That is not a verdict that AI is too dangerous to use. It's a verdict that AI is too unmeasured to give away free inside a policy written before any of this existed. Different sentences — and the difference is the whole thing.
The exclusions page always was the honest part of the document: the only place an insurer says, without marketing, what it will not stand behind. That page now has AI on it, and the fastest route to getting it taken back off is to be the kind of organization that can prove how its systems behave.
My vote? Read the back of your policy this year. Not because the news is catastrophic, but because the market has finally written down, in plain form numbers, what it actually thinks of the technology we've all been told to adopt immediately and worry about later. That's worth ten minutes — and far cheaper than meeting the exclusions page the way I always assumed I eventually would. On the day I needed it.
If your company signed a renewal this year, someone in your building should read the back of that document — send them this. The HAIA Foundation spends its time on exactly this kind of quiet machinery: the paperwork, not the press release, that decides how we actually live alongside intelligent systems. If that's your sort of thing, come along for the rest.




