Insurers are carving out a variety of new exclusions for AI risk from corporate liability coverage.
This article appears in the October issue of Global Finance Magazine.
C-suite executives have a new headache when it comes to AI-generated risks. Their insurers may be getting ready to exclude AI-related claims from the range of liability policies available to them.
As corporate risk managers drop into negotiations with their insurers for the upcoming January 1 renewals, they will find out just how widely—and deeply—the exclusions will be applied.
“The mechanism is real and dated,” said Michel Léonard, chief economist and data scientist at The Insurance Information Institute, pointing to the generative AI-exclusion endorsements for general liability introduced last January by the Insurance Services Office (ISO), a subsidiary of Verisk Analytics. “More than 60 property and casualty carrier groups have filed to adopt some form of AI exclusion. But even industry analysts say it’s too early to know real-world renewal impact.
“We won’t know until renewals start coming in.”
C-suite execs and board members may bear the brunt of the AI exclusions, which are hitting hardest in the management and professional liability lines. Directors and officers (D&O), errors and omissions (E&O), employment practices liability insurance (EPLI), and fiduciary liability are the areas where “broad absolute” exclusions are most common, Léonard said.
Commercial general liability coverage, meanwhile, is being narrowed via the ISO endorsements, he added, although cyber cover remains comparatively more stable, with many carriers still affirmatively covering AI-enabled threats like deepfake fraud.
The practical fallout is that a wide range of claims where an AI system plays a role in generating harm have crossed into a no-coverage zone: employees alleging AI-driven discrimination; intellectual property violations, such as AI using copyrighted material without a company’s knowledge; and property damage caused by autonomous or robotic systems.
Governance on the Hook
The consequences can be even more severe under the “absolute AI exclusion” shift. For example, under a ban issued last year by Berkley Insurance Co., which removed all D&O coverage touching AI use, deployment, or development, a director is no longer covered if a shareholder alleges harm due to inadequate AI governance. The exclusion also applies to Berkley’s E&O and fiduciary liability coverage.
But with the rapid pace of the exclusions’ roll-out and limited publicity surrounding them, many managers and board members will be in for a surprise this renewal season, industry observers say.
“This change has happened relatively quickly, so the knowledge gap is quite large at this point,” said Erike Young, deputy executive director of the California Intergovernmental Risk Authority. “Most organizations that have deployed AI at scale, most likely did so through their technology/operations teams, not through a risk management process.”
The insurance market has not yet issued public guidance around AI risks, as it did around Covid-19 exclusions, said Young, who is also founder of the Risk Management Study Group, an online educational platform. Adding to the murkiness, AI exclusions are not always labeled as such; some are included in extensions to existing cyber exclusions. Or they are issued as new endorsements within renewal documents and not specifically called out on a declarations page.
“Most [executives] would only know about the changes if their broker told them about them,” Young said. “Board members are further removed from the review process and even less likely to be aware of the changes.”

CIRA
The AI exclusion is a textbook example of a risk identification failure, Young said. Many organizations have deployed AI at scale without assessing how it will change their insurance risk profile: “The exposure existed before the exclusion; the exclusion simply made it visible.”
Many risk managers depend on their brokers to vet such issues, said Manny Padilla, president of the Risk and Insurance Management Society, adding that he has not yet heard of an insurance carrier excluding or denying coverage because of an AI risk exclusion on its policy.
“I think that’s relatively new,” he said, noting that as coverage and exclusions around AI risks evolve, some corporations may turn to captive insurers and other types of risk transfer mechanism.
The crisis is compounded by the ongoing rollout of the EU Artificial Intelligence Act. For any organization with operations, customers, or data subjects in the EU, the act creates legal compliance obligations that intersect directly with the insurance gap. An AI system that violates the act’s requirements and produces a harm is not just an uninsured risk, Young said, it is an uninsured risk with a regulatory penalty on top of it.
Same Playbook as Cyber Risk
All is not lost, industry observers added.
Insurers’ treatment of AI risk is following an arc similar to the one it took with cyber risks in the 1990s, when internet-related losses initially fell under standard general liability and E&O policies. These so-called “silent coverages,” not specifically excluded, were unintended and became increasingly expensive for insurers. As their losses mounted along with cyber breaches in the following decade, they began excluding cyber risk from policies. Then as now, executives may have assumed their claims would be covered.
“Cyber took roughly 20 years to mature from silent coverage to a defined market,” said Aman Gour, co-founder and CEO of FurtherAI, a San Francisco-based AI developer that helps insurers automate their underwriting processes. “AI may do it in 10 to 12 years.“
Another AI risk, shadow AI, is also being excluded from liability coverage. This corporate risk occurs when employees use unapproved AI tools without the knowledge or control of the IT and security teams.
Carriers are now weaving AI exclusion language into existing policies and pricing AI risk as a distinct exposure in professional lines like D&O and E&O, Gour said, while gathering claims data to price dedicated coverage.

FurtherAI
“By 2029,” he added, “AI liability will likely be a core product category for leading carriers, not a pilot or add-on.”
Even as exclusions expand, Gour said, a standalone AI liability market is forming, with carriers including Armilla, Mayflower Specialty, Embroker, and Corgi Insurance writing coverage today. Limits are already reaching $2 million to $50 million, he added. In February, Munich Re began offering aiSure, a suite of coverage that addresses multiple AI-related risks for AI providers and corporate adopters.
Cyber insurance demonstrates how the insurance market can handle a risk it does not yet know how to quantify, said Ashu Savani, co-founder of TryHackMe, an enterprise cybersecurity training platform based in London. AI-related liability in D&O, E&O, and fiduciary lines is similar to the evolution of cyber risks, he added.
“It’s a risk moving faster than a stable loss history can form,” said Savani, “yet it might even be harder to price than traditional, pre-AI cyber risk was. Cyber attackers’ behavior had some consistency to study over time, whereas with AI, the risk is embedded in the model itself, which continues to change faster than claims data can accumulate.
“Insuring a risk without understanding the field it sits in will typically end badly, regardless of how confident the pricing model looks on paper.”

Paula L. Green is a contributing writer based in the U.S.
