Your AI Was Wrong. Now Find Out Which Policy Was Supposed to Pay.
Cyber covers breaches. Tech E&O covers negligent services. General liability covers bodily injury and property damage. A model that produced a confident, wrong, expensive answer sits in the seam between all three — and carriers have spent the last two renewal cycles deciding that seam with endorsements.
Why the Existing Wordings Do Not Fit
Every major line of business insurance was drafted around a mental model of how loss happens. Cyber assumes an intruder. Technology errors and omissions assumes a professional who performed a service below the standard of care. Media liability assumes a publisher who published something actionable. Each has a trigger, and the trigger is what an adjuster reads first.
An AI failure frequently satisfies none of them cleanly. Nobody broke in. The service performed exactly as designed — it generated a plausible answer, which is its whole function. Whether anything was published depends on where the output went. The result is not that you have no cover; it is that you have an argument, and arguments are expensive at precisely the moment you can least afford one.
The Claim Shapes, and Where Each One Usually Lands
The exclusion arrives at renewal, not at claim time. AI exclusions are being added to schedules as standard endorsements across cyber, tech E&O and professional lines. They do not require your consent beyond accepting the renewal terms, and they are easy to miss in a schedule of thirty endorsements. The single highest-value hour in this whole exercise is diffing this year's endorsement list against last year's before you bind.
Reading the Endorsement You Were Just Sent
Start with the definition. An exclusion is only as broad as its definition of artificial intelligence, and those definitions vary enormously — some are confined to generative systems producing content, others reach any system that makes or supports a decision using statistical inference, which on a literal reading captures a spam filter and a recommendation widget. If the definition is broad and the operative clause says arising out of, assume the exclusion reaches most of your product.
Then look for carve-backs. The negotiable middle ground is an exclusion that does not apply where a documented human review preceded the output reaching a third party, or where the use case appears on a disclosed schedule. That is a workable trade: you get cover for the systems you have governed, and you accept the exposure on the ones you have not. It also gives your governance programme a price tag your finance team can read, which is usually the argument that gets it funded.
What to Do Before Your Next Renewal
- Diff the endorsement schedule. This year against last year, every policy. New AI exclusions are the most common silent change on the schedule right now.
- Read the definition before the exclusion. The operative clause is meaningless without knowing what the policy calls AI. Broad definition plus "arising out of" equals a much bigger hole than it appears.
- Inventory the systems and the decisions. Not a list of tools — a list of decisions each tool influences and who reviews the output. This is the document underwriters ask for and the one that supports a carve-back.
- Price the affirmative endorsement and its sublimit. Ask specifically what the sublimit is, whether defence costs erode it, and whether regulatory proceedings are inside or outside it.
- Reconcile your MSAs against the policy. Any accuracy warranty or uncapped indemnity you have signed is probably outside cover. Either change the contract template or accept the retained risk explicitly.
- Read your vendor's indemnity for its conditions. Most are conditioned on unmodified safety settings and limited to IP claims. Confirm you are actually operating inside the conditions you are relying on.
- Answer the supplemental application carefully. Narrowly and accurately, and keep the submitted copy. An overstated oversight control is a rescission argument later.
Frequently Asked Questions
We are a small SaaS company. Is this worth the effort at our size?
The effort scales down but the exposure does not, because the loss is driven by your customers' reliance rather than your headcount. A ten-person company whose product produces a number a customer acts on has the same claim shape as a large one, with less runway to fund a defence. The proportionate version for a small team is three things rather than a programme: diff your endorsements at renewal, know whether your tech E&O has an AI exclusion, and make sure your MSA does not promise accuracy your policy will not stand behind. That is an afternoon, once a year.
Does general liability help if an AI decision caused physical harm?
Sometimes, and this is the one place the older wordings work in your favour, because general liability responds to bodily injury and property damage regardless of how the negligence arose. The complications are the professional services exclusion, which pushes advisory failures back out to E&O, and the newer AI exclusions now appearing on general liability schedules too. If your system touches anything physical — logistics, clinical support, building systems, vehicle routing — this is the line to have specifically reviewed rather than assumed.
Is standalone AI liability insurance available yet?
Products marketed as AI-specific cover exist, largely as endorsements to existing towers rather than as a mature standalone market. Read them the way you would read any new product: what is the trigger, what is the sublimit, do defence costs erode the limit, what conditions precedent apply, and what does the exclusions list still remove. A grant-back of an exposure your base policy never clearly excluded is worth less than it sounds, and a small sublimit on a novel trigger is often worse value than negotiating the exclusion narrower on the policy you already hold.
Our model comes from a major provider. Does that reduce our exposure?
It changes who you can pursue afterwards, not who your customer sues first. You deployed the system, you chose the use case, and you are the counterparty on the contract, so the claim lands on you regardless of whose weights produced the output. The provider relationship matters at the recovery stage, and only to the extent the indemnity's conditions were met — which typically means you did not modify the safety configuration, you used the documented interfaces, and the claim is an IP claim rather than a reliance claim. Verify that before you treat it as risk transfer.
What single artefact most improves how we are underwritten?
A short, honest register of AI use cases with the decision each supports, the human-review step, and the date it was last reviewed. It is unglamorous and it does more work than anything else, because it lets an underwriter price a specific exposure instead of a category. It also supports the carve-back you want in the exclusion, gives your broker something concrete to market, and is the first document a regulator or a plaintiff will ask for. If you build only one governance artefact this year, build that one and keep it current.
The Policy Is Decided Before the Claim
Nobody negotiates an exclusion after a loss. The whole of this exercise happens in the four weeks before a renewal, and it consists of reading a schedule, knowing which of your systems make decisions customers rely on, and asking for a carve-back you can evidence.
Start with the inventory. It is the input to the underwriting conversation, the support for the carve-back, and the document you would otherwise have to assemble under deadline while a claim is open.