AI risk and insurance · Part 1 of 2

Before Your Next Renewal: What Insurers Are Now Asking About Your AI

AI exclusions are arriving policy by policy, at renewal. What changed, why insurers are moving, and what to expect in this year's renewal conversation.

Most organizations are deploying more AI this year than in any year before. Many will discover, at their next insurance renewal, that their coverage has been moving in the opposite direction.

If your commercial program renews on January 1, the quotes are being prepared now. This is the moment to understand what has changed, before the terms arrive.

This article is general commentary for business and risk leaders. It is not insurance or legal advice. Your broker and counsel should review your specific policies.

What changed

Since January 1, 2026, ISO, the Verisk unit whose standard forms underpin much of US commercial liability insurance, has made three generative AI exclusion endorsements available for general liability policies:

  • CG 40 47 excludes bodily injury, property damage, and personal and advertising injury arising out of generative AI.
  • CG 40 48 excludes personal and advertising injury only.
  • CG 35 08 excludes bodily injury and property damage from generative AI in products and completed operations.

These are optional endorsements. Each insurer decides whether to attach them, and to which policies. That is why many companies won't notice until renewal: the change arrives as an endorsement on next year's policy, not as an announcement.

Two details matter more than the form numbers. The exclusions use "arising out of" language, which courts in most US jurisdictions read more broadly than "caused by", so they can reach losses where AI was only one contributing factor. And commentators have noted they can apply whether AI was used by the insured directly or by its vendors and contractors.

Some carriers have gone further. W. R. Berkley introduced what it calls an "absolute" AI exclusion for directors and officers, errors and omissions, and fiduciary liability policies.

Why insurers are moving

Insurers price risk from loss history, and AI loss history is growing quickly. Gallagher Re has reported that generative-AI lawsuits in the US grew by 978% between 2021 and 2025.

In March 2026, Gallagher Re published a report with MIT and Testudo, Smart Systems, Blind Spots: Rethinking Insurance for the AI Era. Its central finding is that the main lines of coverage businesses rely on (cyber, technology errors and omissions, product liability and general liability) were not designed for the ways AI systems fail: fabricated outputs, biased decisions, models degrading over time, flawed training data.

When a risk doesn't fit existing models, insurers do two things at once. They exclude it from general policies, and a specialty market forms to price it on its own. Both are happening now. Standalone AI liability products have launched from specialty carriers and newer AI-focused insurers, with their own limits, pricing and underwriting questions.

Where that leaves the risk

The same Gallagher Re report makes an observation every CFO should read twice: liability is increasingly being assigned to the operators of AI systems rather than the technology providers, whose contracts frequently restrict their own exposure.

Put the pieces together:

  • The AI vendor's contract typically limits what it will pay.
  • General liability policies may increasingly exclude AI-related losses.
  • Responsibility for what the AI does is increasingly placed on the organization that deployed it.

What sits between those three is risk on your own balance sheet.

What to expect in the renewal conversation

Expect your broker to ask some version of these questions:

  1. Where are you using AI? Not just the sanctioned projects; the agents and tools in daily use across the organization.
  2. What does it touch? Customer data, financial records, regulated information, decisions about people, or internal drafting and search.
  3. What do your vendor contracts say? Liability limits, indemnities and who is responsible for what.
  4. Do you want AI-specific cover, and how much? It is becoming a separate line item, with separate limits.
  5. Can you show how your AI is governed? Not a policy document. Evidence.

The last question is where terms are won or lost. Specialty AI underwriters are asking for evidence of governance before they quote, and that evidence has a specific shape. We'll set out what it looks like, as eight questions you can put to any AI platform, in our next article.

Treat it as a risk program, not an insurance problem

It is tempting to hand this to the insurance team and move on. That would miss the bigger signal.

The insurance market moved first because it responds fastest to losses. Boards, auditors, regulators and customers are asking the same questions on their own timelines. Evidence that satisfies an underwriter will largely satisfy the others. Build it once and it serves all of them. Build it only when each one asks, and you'll build it several times, while paying a premium in the meantime.

The next renewal is a date on the calendar. The work to prepare for it can start today.

Bring one workflow. We'll show you where the evidence sits.

Schedule a 45-minute architecture review. We'll map where authority, enforcement and evidence sit today across the systems your agents touch, and show you the gaps either way.