Insurers Pursue Generative AI Liability Exclusions

As generative AI enters products, workflows, and customer-facing systems, insurance wording can become a material operational risk for AI teams because a claim may span general liability, errors and omissions, cyber, employment, and directors and officers coverage. Claims Journal reports growing carrier interest in three ISO endorsements that exclude specified generative AI-related liabilities from commercial general liability policies. The reported forms cover bodily injury, property damage, and personal or advertising injury in different coverage parts. Fenwick reports that AI-related coverage is becoming fragmented as insurers revise cyber, technology E&O, D&O, and employment-practices policies. For practitioners, the development raises the importance of documenting model governance, vendor responsibilities, human review, and incident-response ownership alongside technical controls.
Insurance language is becoming an AI governance concern
What the ISO endorsements cover
According to Claims Journal's paraphrase of descriptions supplied by ISO parent Verisk, the three forms are:
- •CG 40 47, a Generative Artificial Intelligence Endorsement excluding bodily injury, property damage, and personal and advertising injury arising from generative AI under the Commercial General Liability Coverage Part.
- •CG 40 48, a Coverage B-only version excluding personal and advertising injury arising from generative AI.
- •CG 35 08, a form for Products/Completed Operations coverage excluding bodily injury and property damage arising from generative AI.
These endorsements address commercial general liability lines, not a universal AI insurance regime. Still, Fenwick reports a broader transition away from "silent AI" coverage, where AI-related losses could have been implicitly covered because policies did not expressly mention AI. Its June analysis describes insurers as using endorsements, revised forms, exclusions, and underwriting changes across cyber, technology E&O, D&O, and employment practices liability insurance.
Coverage fragmentation across AI use cases
Practical implications for AI teams
For practitioners
Technical documentation increasingly has value beyond internal model governance. Companies in comparable situations commonly need a traceable record of where AI is used, which vendor or internal model supports a workflow, what human-review controls exist, what data flows into the system, and who owns incident escalation. Those artifacts can support risk assessment, procurement review, legal review, and insurance-renewal discussions without assuming that a particular claim is covered.
UPHelp's guidance has focused on reviewing insuring agreements, exclusions, definitions, endorsements, and carve-backs together rather than treating a policy's AI label as dispositive. Fenwick recommends mapping potential claims to individual coverage lines and considering negotiated endorsements or other structures where gaps emerge. UPHelp similarly advises policyholders to scrutinize broad "arising out of" language and seek narrower definitions or targeted carve-backs during renewal negotiations.
Industry context
AI risk management is often framed as a model-quality, security, privacy, and compliance problem. Emerging insurance exclusions add a commercial control point: organizations using or supplying AI may need to determine whether a loss involving generated content, automated decisions, or AI-enabled services is covered under any relevant policy.
Claims Journal reports that carriers have shown increased interest in three Insurance Services Office, or ISO, endorsements for commercial general liability coverage. Alana McMullin, a partner at Lathrop GPM, told Claims Journal there has been a "major shift" in insurers' treatment of AI-related risk and that carriers are moving quickly to limit exposure. The publication reports she has seen more carrier filings with state insurance regulators seeking approval to use the endorsements.
A single AI-enabled business process can create several legally distinct loss scenarios. An incorrect generated answer may raise professional-liability questions; a discriminatory automated hiring outcome may raise employment claims; a data exposure involving a model or vendor may implicate cyber coverage; and public statements about AI capabilities can create corporate-governance exposure. The relevant policy and exclusions can differ by scenario.
Hub International identifies examples across those lines, including alleged AI-related hallucinations in professional work, discrimination claims involving AI-powered hiring systems, AI-washing-related securities and regulatory exposure, and cyber risks involving AI systems. Rough Notes reports that AIG, Berkley, Chubb, Great American, and QBE have developed endorsements or provisions restricting coverage for AI claims. These reports do not establish that every insurer uses the same wording or that all AI-related claims are excluded.
Fenwick warns that coverage erosion can occur through narrower definitions and carve-backs, rather than one highly visible exclusion. It characterizes the resulting issue as "gap risk," where no single policy clearly responds to a claim spanning traditional insurance lines.
Broad exclusions can make the distinction between an AI feature and an AI-dependent service commercially significant. Teams building generative AI into customer-facing or high-consequence workflows may therefore benefit from involving risk, legal, security, and procurement stakeholders early, particularly when third-party model providers, agents, or automated decision systems are part of the architecture.
Key Points
- 1ISO-related exclusions could limit commercial general liability coverage for specified generative AI harms, making policy wording relevant to deployed AI workflows.
- 2Fenwick reports coverage fragmentation across cyber, E&O, D&O, and employment policies, increasing the chance that multi-part AI claims face gaps.
- 3Industry context: AI inventories, vendor records, human-review logs, and incident ownership can support governance and insurance-risk assessments across comparable organizations.
Scoring Rationale
The reported interest in ISO generative AI exclusions is notable for organizations operationalizing AI in customer-facing, professional, and automated-decision workflows. It does not change model capabilities, but it can alter the financial-risk assumptions surrounding AI deployment, vendor contracts, and governance documentation.
Sources
Public references used for this report.
Practice with real Health & Insurance data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Health & Insurance problems


