Two weeks ago I wrote that the industry which prices every risk on earth had refused to price this one. I finished that piece with a small piece of homework — go read the back of your policy — and then I went and did something quietly embarrassing.
I read mine. And I filed the whole thing under not my problem.
Because I am not an AI company. I write, I invoice, I keep a laptop and an accountant and a professional liability policy I have renewed for years without ceremony. Whatever the underwriters have gotten frightened of, I told myself, is happening to somebody else — to the model builders, the agent startups, the people whose actual product is the machine.
Then I stopped reading the commentary about the form and went and read the form.
It never asks whether you are an AI company. There is no box for that. It asks one question about the injury, and if the answer comes back wrong the coverage is gone — and the answer can come back wrong because of software you never bought, running quietly inside a service you did.
The whole endorsement is one page. That is the entire trick.
Start with the plumbing, because the plumbing is the story.
Almost no commercial insurance policy in the United States is written from scratch. It is assembled — a base coverage form plus a stack of endorsements, drafted not by your insurer but by ISO, the standard-forms arm of the analytics company Verisk, and bolted onto thousands of carriers' own paper. One drafting decision therefore propagates at renewal speed: ISO forms underpin approximately 82% of U.S. property and casualty insurance policies, by one law firm's count.
This year, three of them are new, and the distinctions matter: CG 40 47, the broad one, knocking out bodily injury, property damage and personal and advertising injury; CG 40 48, hitting only personal and advertising injury — the coverage that answers a defamation or copyright claim; and CG 35 08, aimed at products and completed operations, the things you already shipped.
Those trailing digits on the printed form — 01 26 — are the edition code. January 2026. Verisk's own description of the filing that produced them is admirably undramatic: a suite of new, optional and mandatory endorsements addressing generative AI, human trafficking, social inflation and cyber warfare, with a proposed effective date of January 1, 2026. That is the quiet half of the story: not a press release, just a number in the corner of a page.
Here is what is on that page. I am quoting the middle one of the three in full, because its brevity is the point — the operative provision is one sentence:
This insurance does not apply to: "Personal and advertising injury" arising out of "generative artificial intelligence".
And, because policies define their own terms:
"Generative artificial intelligence" means a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code.
Read that again and notice what it does not contain. Not your industry. Not who built the system, bought it or profits from it. It describes a category of software — anything trained on data that can produce content — and hangs the exclusion on injury "arising out of" it.
"Arising out of" is one of the broadest causal phrases in insurance drafting, and it is doing enormous work. It does not require that you used the tool, or that the tool was central. So the question is no longer "are we an AI company?" It is "was there, anywhere behind this claim, a machine trained on data that produced content?" In 2026 that is hard to answer no to.
Coverage lawyers have said so for months: reliance on third-party AI tools may not avoid the exclusion, and even incidental use may trigger it. At a captive conference in Vermont last week, a Fenwick & West lawyer put it the other way: AI is already embedded in many companies, even when they have not formally adopted the technology.
That is the article, really. You did not adopt AI. Your scheduling vendor did. Your payroll platform did. Your helpdesk widget did, in a release note that said "improved responses."
And ISO's version is the restrained one. It stops at "generative." Carrier-drafted wording goes further — one insurer's absolute exclusion reaches any actual or alleged use, deployment, or development of artificial intelligence, across directors and officers, errors and omissions, and fiduciary lines. Stack that against a vendor contract with a liability cap and you get the line that belongs on every renewal packet: if the vendor disclaims and the insurer excludes, the business may be left holding the bag.
Now let me argue against myself, because this is not a verdict
Here is the honest other side, and it is stronger than the alarm.
First, these endorsements are optional. ISO drafts; carriers choose. A form existing is not a form attached, and interest growing is not adoption completed. It happens policy by policy, as renewals come round — which is why the useful response is to look.
Second, the underwriters have a real argument — with precedent. Verisk's vice president of liability put it plainly: without exclusions that let underwriters accept a risk with some stability, "they might just walk away from the risk" altogether. An insurer that cannot carve out the part it cannot price does not write a broader policy. It writes no policy. Every line these exclusions touch was priced on loss data containing none of this, and insurers do not have reliable data on these incidents with which to predict it.
The industry has run this play before, defensibly. NotPetya and WannaCry in 2017 together produced insured losses estimated at USD 3.6 billion on both affirmative and non-affirmative (silent) covers globally — some of it under policies nobody had underwritten for a cyberattack. The answer was to kill off "silent cyber." Lloyd's, warning that such losses "have the potential to greatly exceed what the insurance market is able to absorb," required its syndicates' standalone cyber policies to carry a state-backed-attack exclusion from March 2023, arguing that robust wordings mean "risks can be properly priced." ISO did the paperwork version: two mandatory cyber endorsements in 2020. Nobody calls that a conspiracy; it was hygiene. Read the AI forms as the same housekeeping one technology later, and most of the alarm drains out.
There is a technical version, too. A preprint mapping AI threats against insurance products argues the novel problem is concentration: "upstream model failure can correlate losses across many cedents at once." Insurance works by pooling risks that fail independently. A few million businesses on the same handful of models is not that.
Third: an exclusion is not a court ruling. Merck's insurers spent years arguing a hostile-and-warlike-action clause swallowed a $1.4 billion NotPetya claim; an appeals panel found they had not shown the attack was hostile or warlike, so the exclusion could not be used — the language is meant to apply to armed conflict. The case settled. And the policyholder bar has spotted the reductio here: if the broadest reading of "arising out of AI" won, almost any claim could be connected, however indirectly, to AI — making the coverage illusory. Courts dislike readings that turn a paid-for policy into a decoration.
Not a locked door, then. But an argument you can only have if somebody in your building knows the endorsement is there.
Brussels answered the same question, and it did not reach for a form
Here is where the comparison gets uncomfortable. The United States is settling "who pays when the machine gets it wrong" through private contract. A drafting committee writes an endorsement, carriers file it with fifty state regulators, brokers attach it at renewal, and one day a claim gets denied. Nobody voted. There was no debate. The most consequential liability decision of the decade is being made in the endorsement schedule.
And it is not that American insurance regulators ignored AI. They have been busy — with the other half of the problem. The model bulletin state commissioners adopted in December 2023 reminds insurers that decisions made or supported by AI systems must comply with all applicable insurance laws and regulations, including the ones on unfair trade practices and unfair discrimination. By the NAIC's own implementation map, two dozen states plus the District of Columbia had adopted it as of April 1, 2026; Delaware's commissioner issued his in February 2025. Every one of those documents governs how an insurer may use AI — underwriting, pricing, marketing, claims decisions — and not one governs what an insurer may refuse to cover. The rulebook points at the machine inside the insurance company; the exclusion travels as a form.
The European Union took the same question and answered it with a statute. The revised Product Liability Directive — the first rewrite of Europe's regime since 1985 — counts software, including AI systems, as a product, carrying the strict liability that has attached to toasters and tires for forty years. Its recitals call liability without fault on the part of economic operators "the sole means of adequately addressing the problem of fair apportionment of risk inherent in modern technological production," and treat an AI developer as a manufacturer. Member States must have it in force by December 9, 2026.
In practice the injured person does not have to prove fault — only defect, damage and the link between them — and, because proving a defect inside a model is near-impossible for an ordinary claimant, the directive adds rebuttable presumptions that lower what an injured person has to prove when a defendant withholds evidence.
To be clear about what this is not. The directive does not touch a word of anybody's insurance policy; a European business can still be handed an AI exclusion at renewal. And strict liability has real costs, landing hardest on small producers.
But notice the difference in venue. In one system, the answer to "who carries this risk" is a public instrument with a number, a debate, an implementation date and a parliament that can amend it. In the other, it is a one-page endorsement in an email attachment. I am not claiming Europe got the substance right. I am pointing out that Europe got to argue about it.
Run the clock forward three renewals
Every one of these forms says generative. Hold that word up to the light, because the technology has already walked past it.
NYU engineer Quanyan Zhu's June 2026 paper on insuring agentic AI draws the line precisely: agentic systems go beyond generating information to multi-step reasoning, invoking external tools and producing persistent changes in the world. The consequence for insurance is brutal — losses may occur independently of traditional cyber compromise. No breach. No hacker. Just a competent system doing a wrong thing quickly, at scale, with your credentials.
So picture 2029.
A three-person dental practice renews its liability cover, as it has every year since 1998. Nobody there has ever typed a prompt. But the scheduling software shipped an assistant in a routine update, and it drafts the recall reminders. A recall is missed. There is a lawsuit. And a coverage attorney asks one question: did any part of this involve a machine-based system, trained on data, that produced content or a response?
The answer is buried in a vendor changelog nobody in that building has read.
And the exit ramp is unevenly distributed. Large companies have one: form a captive, retain the risk, self-insure the gap. At that Vermont conference the actuarial view was that captives are close to a perfect solution for this problem — for organizations big enough to have one. Which is why the researcher who has thought hardest about insurance as governance proposes a mandate that "bars pure captives": once the biggest players leave the pool, so does whatever discipline it imposed. The dental practice does not get a captive. It gets an exclusion.
Who is arguing what — and it isn't the fight you'd expect
This is where it gets genuinely interesting, because the usual teams have swapped jerseys.
From the free-market right, a shrug. The American Enterprise Institute's Daniel Lyons argues against AI-specific liability rules altogether; better, he writes, "to apply existing legal principles consistently," since fear-driven bespoke rules "tilt those benefits toward society's largest and wealthiest players." His colleague Bronwyn Howell treats this machinery as the good outcome: insurance arrangements for managing outcome uncertainties, she writes, "provide a more constructive way forward than do risk management regimes." On that reading an exclusion is not a failure of governance. It is governance — priced, revisable, made by people with money at stake.
From the policyholder side, the opposite reading of the same page. The consumer advocacy group United Policyholders told businesses last December that "sweeping AI exclusions threaten to eviscerate all types of insurance coverage," and that the answer is to "push for clearer definitions, narrower lead-in language, and targeted carve-backs." Their worked example: wording barring anything "in any way connected to" AI could let an insurer deny a professional-services claim because the insured used AI to write marketing copy. Brookings saw it coming — in 2019 it argued insurance can be part of the way we mitigate AI risks while noting AI risk was "not mentioned as an explicit cover in most insurance policies today." Now it is. As an exclusion.
From the AI-governance world, a worry neither side raises. Writing in Lawfare, Cristian Trout argues carriers do more than pay claims — they monitor policyholders and enforce private safety standards on companies no legislature reached; when firms retreat into captives instead, it eliminates nearly all potential for private governance. (Trout is a research fellow at a company that sells AI insurance — an interested expert, not a wrong one.)
And from two academics who have watched this movie before, a flat no. Daniel Schwarcz and Josephine Wolff, drawing on the history of cyber insurance, conclude that liability insurers are unlikely to price coverage for AI safety risks in ways that encourage firms to reduce those risks; they fall back on crude measures such as firm size, revenue and industry sector, signaling that safety spending will not lower the premium. Only ex ante regulation, they write, is likely to motivate significant shifts in how firms audit and test their systems.
Four camps, almost no overlap in politics, and one point of complete agreement: the decision is being made somewhere no citizen is watching.
What does this mean for you?
If you are an employee with no policy in your name: not much yet. Personal lines have not moved. But if you run a business, advise one, sit on a board, or carry professional liability cover as a freelancer or consultant — that is a commercial policy, and this is your paperwork.
None of this takes more than one afternoon:
Open the PDF and search it. Look for
CG 40 47,CG 40 48,CG 35 08, then simply forartificial intelligence. The endorsement schedule sits near the front; the forms are stacked at the back.Ask the supplier question, not the identity question. Not "are we an AI company" — nobody's exclusion cares. Ask which vendors have shipped a model inside their product: payroll, scheduling, CRM, helpdesk, transcription, résumé screening. Ask in writing.
Treat the wording as negotiable, because it is. Insurance policies are contractual and negotiable, and renewal is when your broker has leverage. Narrower wording is a thing you can ask for.
Fix the contracts while you are in there. Require vendors to show cover for AI output and infringement, and demand IP indemnification outside general liability caps rather than inside a sub-cap that evaporates on first contact.
If a claim is denied on one of these, treat it as an opening argument. New, untested and broadly drafted is not a settled answer; it is the start of a negotiation.
The lesson, as I see it
The loud half of this story was a refusal, and refusals make headlines. The quiet half is a definition, and definitions travel.
A refusal is visible; somebody can be asked about it in a hearing. But a definition sitting in a one-page endorsement, tied to nothing more specific than "a machine-based learning system or model that is trained on data," does not need anybody's attention to work. It waits at the back of a document until the day it is the only thing that matters — and it reaches everyone who ever bought software from someone who bought software.
That pattern runs well beyond insurance. The consequential decisions about how we live with these systems will not arrive as legislation you recognize. They will arrive as edition codes, schedule entries and terms-of-service revisions — the boring, load-bearing paperwork nobody reads and everybody signs.
My vote? Go find out whether the answer to a question you were certain did not apply to you is already printed at the back of a document you signed. It takes an afternoon and one text search. The alternative is to find out the way I always assumed I would — on the day it counts, when the arguing is over.
If somebody you know signed a renewal this year and has never once opened the endorsement schedule, forward this to them — the whole check costs four minutes and one text search, and the alternative costs considerably more. The HAIA Foundation spends its time on this sort of thing: the quiet machinery, not the loud announcement. The rest of it is over here.





