Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Which Liability Policy Covers Your AI Incident?Policy Structure & Terms
5 min readFor Enterprise Risk Managers

Which Liability Policy Covers Your AI Incident?

You're facing a decision that didn't exist three years ago: where does liability for AI-related harm actually sit in your insurance program?

The answer isn't straightforward anymore. The same market forces that eliminated silent cyber coverage from general liability policies are now carving out AI exposures. If you're still assuming your GL policy will respond when an AI system causes third-party harm, you're operating on outdated assumptions.

Here's how to choose between traditional coverage, standalone products, and strategic gaps you might need to accept.

The Decision You're Facing

You need to determine which insurance will respond when your AI tools cause:

  • Financial loss from AI-generated errors or misrepresentations
  • Defamation or reputational harm from AI outputs
  • Intellectual property infringement claims
  • Unauthorized disclosure of third-party data
  • Bodily injury or property damage from AI inaccuracies

Your GL policy once provided ambiguous coverage for some of these scenarios. That's changing. ISO introduced three new exclusionary endorsements in 2026 (CG 40 47 01 26, CG 40 48 01 26, and CG 35 08 01 26) that remove AI-related liabilities from standard GL forms. The broadest form, CG 40 47, excludes coverage across both Coverage A (Bodily Injury and Property Damage) and Coverage B (Personal and Advertising Injury) for any claim arising from artificial intelligence, generative AI, or large language models.

The question isn't whether these exclusions will appear in your policy. It's when, and what you'll do about it.

Key Factors That Affect Your Choice

Your industry profile determines adoption speed. Underwriters are prioritizing these endorsements for technology companies, media outlets, marketing and advertising firms, software developers, and app publishers. If you're in one of these sectors, expect the exclusions at your next renewal. Other industries will follow.

Your AI integration depth matters. If AI tools are embedded in finished products or completed work, you're exposed under the Products-Completed Operations exclusion (CG 35 08 01 26). If you use AI for content generation, customer service, or decision support, you face Coverage B exposure under the narrower endorsement (CG 40 48 01 26).

Your existing cyber policy doesn't fill this gap. Stand-Alone Cyber Policies typically cover first-party response costs and some third-party privacy liabilities. They weren't designed to respond to defamation claims, IP infringement, or bodily injury caused by AI errors.

The standalone AI liability market is immature. New products are emerging to cover third-party AI claims, but they're not yet standardized. Coverage terms, capacity, and pricing vary significantly across carriers.

Path A: Rely on Modified GL Coverage (Declining Viability)

Choose this path if:

  • Your renewal is imminent and the AI exclusions haven't appeared yet
  • You operate in a low-exposure sector where underwriters aren't prioritizing these forms
  • Your AI use is minimal and purely internal

Understand the limitations:

Even if your current GL policy doesn't include the new AI exclusions, it likely already contains the Cyber Incident exclusion (CG 40 35 12 23). Since 2014, the market has systematically eliminated silent cyber coverage. That 2023 endorsement doesn't just exclude data breach costs. It excludes all Bodily Injury, Property Damage, and Personal and Advertising Injury resulting from a "Cyber Incident," defined broadly to include unauthorized access, viruses, or denial-of-service attacks.

If an AI system is compromised or manipulated through a cyber event, you're dealing with overlapping exclusions. The GL policy won't respond.

Action steps:

  • Document your current GL policy forms and endorsements
  • Identify which AI exclusions, if any, are already attached
  • Prepare for these exclusions at your next renewal
  • Don't mistake temporary coverage for a long-term solution

This path buys you time, not protection.

Path B: Secure Standalone AI Liability Coverage (Emerging Standard)

Choose this path if:

  • You develop, deploy, or integrate AI tools that interact with third parties
  • Your GL policy already includes AI exclusions
  • You face material exposure to AI-generated defamation, IP claims, or financial loss
  • You can articulate specific AI risk scenarios to underwriters

How to implement:

Work with your broker to identify carriers entering the AI liability market. These products are designed to respond directly to the unique exposures the GL exclusions eliminate: financial loss from AI errors, defamation and reputational harm, IP infringement, unauthorized data disclosure, and bodily injury or property damage.

What to negotiate:

  • Scope of "AI" definition (does it cover all algorithmic decision-making or just generative models?)
  • Coverage for both pre-deployment and post-deployment incidents
  • Limits adequate for your third-party exposure profile
  • Sublimits for specific claim types (IP vs. defamation vs. bodily injury)
  • Insurer Consent Requirements for incident response decisions

Expect market friction:

These products are new. Underwriters are still calibrating risk. You'll face detailed Underwriting Questionnaires about your AI governance, testing protocols, human oversight mechanisms, and disclosure practices. If you can't answer those questions specifically, expect limited capacity or declined coverage.

Path C: Strategic Self-Insurance with Targeted Mitigation (Controlled Exposure)

Choose this path if:

  • Your AI use is limited to internal operations with minimal third-party exposure
  • Standalone AI coverage is unavailable or prohibitively expensive for your risk profile
  • You can implement controls that materially reduce the likelihood of third-party harm

What this requires:

You're accepting the coverage gap and managing the risk through operational controls instead of insurance transfer. This isn't a passive choice. It demands:

  • Documented AI governance frameworks with clear approval workflows
  • Human review requirements for AI outputs that affect third parties
  • Contractual limitations of liability in customer agreements
  • Segregated reserves for potential AI-related claims

When this makes sense:

If you use AI for internal process automation, data analysis, or decision support where outputs don't directly reach customers or the public, your third-party exposure is limited. The cost of standalone coverage may exceed the risk.

When it doesn't:

If your AI tools generate customer-facing content, make decisions that affect third parties, or integrate into products you sell, you're retaining exposure that insurance markets are actively excluding. That's a board-level risk acceptance decision, not an operational one.

Summary Matrix

Coverage Path Best For Key Limitation Immediate Action
Modified GL Low AI exposure, exclusions not yet applied Temporary only; exclusions coming at renewal Document current forms; prepare for transition
Standalone AI Liability Material third-party AI exposure, high-risk sectors Immature market; limited capacity Engage broker; complete detailed risk assessment
Strategic Self-Insurance Internal AI use; minimal third-party interaction Retains all uninsured exposure Implement governance controls; document risk acceptance

The market has made its position clear: GL policies won't carry unpriced AI risk. The same exclusionary logic that eliminated silent cyber coverage is now being applied to AI exposures. If you're waiting for clarity, you've already received it. The exclusions are here.

Your decision isn't whether to address this gap. It's which combination of coverage, controls, and retained risk makes sense for your specific exposure profile. Start by reviewing your GL policy for CG 40 47, CG 40 48, and CG 35 08. If they're not there yet, they're coming.

Then decide where the risk actually sits.

Promotional banner for the Pentest Readiness checklist download

You Might Also Like