Something changed in commercial insurance on 1 January 2026, and most of the writing about it is wrong in both directions. One set of commentary treats the new AI exclusions as an industry-wide withdrawal from AI risk. Another treats them as a non-event. Neither reading survives the forms themselves.
This note sets out what the endorsements say, where the carrier-specific wording goes considerably further, what is genuinely unknown about how often any of it is being applied, and which widely circulated statistics we could not trace to a primary source. The corrections matter as much as the findings. A buyer acting on the alarmed version of this story will make different decisions than a buyer acting on the accurate one.
The three forms
ISO, part of Verisk, publishes the standard policy language that most US commercial insurers build their forms from. In July 2025 it made a multistate general liability filing with a proposed effective date of 1 January 2026. That filing contained three optional generative-AI exclusions.
- CG 40 47 01 26Exclusion – Generative Artificial Intelligence. Attaches to the CGL coverage part and removes both Coverage A (bodily injury and property damage) and Coverage B (personal and advertising injury). The full shutoff.
- CG 40 48 01 26The same exclusion for Coverage B only, leaving bodily injury and property damage intact. Coverage B is where AI-generated content bites hardest: defamation, copyright infringement in advertising, misappropriation of advertising ideas. Sources differ on whether the printed title reads “(Coverage B)” or “(Coverage B Only)”; we could not resolve it without the filed form.
- CG 35 08 01 26 Attaches to the separate Products/Completed Operations Liability coverage part. This is the vendor-facing form: it follows the exposure into a delivered product with AI embedded.
The operative language of CG 40 47 reads:
This insurance does not apply to: “Bodily injury” or “property damage” arising out of “generative artificial intelligence”.
The forms are notably short. There is no schedule, no carve-back, no exception for third-party or embedded AI, and no exception for incidental use. Courts read “arising out of” broadly, requiring only a causal connection rather than direct causation.
One drafting detail deserves attention. The word “use” does not appear in the operative sentence. The trigger is injury arising out of generative AI, not the insured's use of it. On its face that reaches a loss caused by AI inside a vendor's product, which is precisely the exposure an internal user of enterprise software is least likely to know it has.
Two pieces of context are routinely omitted. First, these endorsements are optional. Verisk has been explicit that adoption “is at the discretion of each insurer, depending on their underwriting guidelines and risk appetite.” The base CGL form is unchanged, and an insurer that does nothing continues to write coverage that is silent on AI. Second, the AI exclusions arrived inside a routine emerging-issues package that also carried assault-or-battery endorsements, a human trafficking exclusion, a new punitive damages exclusion and an updated war exclusion. This was ISO doing what ISO does annually, not an industry declaration.
Looking forward, the most consequential public statement on the subject came from Verisk in July 2026: it is “evaluating additional options to address AI-related exposures, including agentic AI.” No such form exists yet. The standard-form apparatus for agents that act rather than generate has not been written.
The definition, and the limit inside it
All three forms add the same definition:
“Generative artificial intelligence” means a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code.
Verisk states the definition was based on existing government and NAIC definitions. It is narrower than most commentary assumes, and the whole question sits in one phrase: the system must have the ability to create content or responses.
That phrase is doing two different jobs, and only one of them is precise. “Content” suggests a generative limitation, and the enumerated examples that follow — text, images, audio, video, code — reinforce it. “Responses” is looser. An insurer could argue that a fraud score, a credit decision, a triage classification, or a routing instruction is a response to an input, in which case the definition reaches predictive and classification-only systems too.
So the proposition that a model emitting only a label, a score, or a prediction falls outside these forms is a policyholder argument, not a settled reading. It is a good argument, and the drafting history supports it — had Verisk wanted to capture any inference system it could have said so, as at least one carrier expressly did. But it is untested, and an insured should not plan on the narrow reading prevailing. Either way, it is the point at which the standard form and the broadest carrier forms clearly diverge.
How widely are they actually being used?
Honestly: nobody knows, and the people closest to the market say so. This is the single largest gap between what is being written about AI exclusions and what can be established.
John Farley, managing director of Gallagher's cyber practice, in July 2026: “There are a few carriers that are starting to adopt those exclusions. […] We're just at the very beginning and we have to watch this very closely.” Greg Eskins, global cyber product leader at Marsh: the market “has been restrained in taking any drastic actions with either affirmative or exclusionary language, though both exist.” Kara Higginbotham, head of professional liability and cyber at Zurich North America: “In most cases, amending policy language to address AI exposures is unnecessary.”
Joe Lam, the Verisk vice-president of liability who helped write the endorsements, said he did not know how many insurers had adopted them. He also offered the clearest available explanation of why exclusions exist at all: “Without exclusions to allow underwriters a level of stability or to accept a risk, you run into a situation where they might just walk away from the risk.”
What can be verified comes from The Insurer's review of product filings to US state regulators: at least half a dozen insurers have filed to adopt Verisk's wordings. The same review carries the caveat that matters, and it is usually dropped when the figure is repeated — because the exclusions are optional and the filing bundled several other emerging risks, a filing does not establish that those insurers will use the AI exclusions at all.
So the defensible statement is narrow: the tools now exist, they are beginning to appear, adoption is early and unmeasured, and the only reliable way to know your own position is to read your own forms.
Where the severity actually is
The standard forms are the visible story. The proprietary carrier wording is broader and matters more.
In November 2025 the Financial Times reported that AIG, Great American and W.R. Berkley had sought permission from US regulators to offer policies excluding liabilities tied to businesses deploying AI. Separately, an analysis of state filings identified W.R. Berkley, Cincinnati Financial, Frederick Mutual and Philadelphia Insurance as having filed their own restrictive AI wording.
The detail almost every downstream account drops: AIG told the Financial Times that although it had filed generative AI exclusions, it “has no plans to implement them at this time.” Great American and W.R. Berkley declined to comment. Filing is not approval, and approval is not deployment. Any account that reports the three carriers as excluding AI has overstated its own source.
The most consequential wording found is W.R. Berkley's, intended for directors and officers, errors and omissions, and fiduciary liability rather than general liability. It defines artificial intelligence as:
any machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments…
That tracks the OECD and EU AI Act formulation and is not limited to generative AI. It reaches predictions, recommendations and decisions — which is to say, almost any inference system. The same exclusion also expressly captures “statements, disclosures or representations concerning AI,” which is drafted to catch the AI-washing securities claims now being filed at pace.
So two very different exclusions circulate under one label. The standard form covers systems that create content. The broadest carrier form covers systems that infer anything, plus what you said about them. An insured told it has “the AI exclusion” has been told almost nothing.
A note of proportion on directors and officers exposure, since it is frequently overstated. WTW's March 2026 analysis finds that almost all AI-related securities class actions involve AI-washing allegations that “typically fall within the scope of D&O coverage, subject to customary policy terms,” and that AI-specific exclusions “remain uncommon but have begun appearing in some private-company policies.” The larger practical risk is that existingexclusions — bodily injury, professional services, privacy — get triggered by AI allegations.
The trigger ladder
A fast way to rank severity when reading any AI exclusion is to look at the trigger phrase rather than the heading. Three tiers are in circulation:
- “arising out of” The ISO forms. Broad, but the narrowest of the three.
- “based upon, arising out of, or attributable to” W.R. Berkley.
- “based upon, arising out of, or in any way involving” Hamilton's professional liability wording and at least one unnamed manuscript endorsement. Broadest.
One correction for anyone analysing the standard forms: at least one secondary source describes the ISO endorsements as excluding injury “arising out of, or attributable to” generative AI. The verbatim ISO text contains only “arising out of.” The stronger triple trigger belongs to the proprietary forms.
A drafting curiosity worth noting in the same vein. Hamilton's definition enumerates specific products — “including but not limited to ChatGPT, Bard, Midjourney, or Dall-E.” Bard was retired as a brand in 2024, so the wording was already stale when filed, and an insured could argue the enumeration constrains the general words that precede it.
Cyber and professional lines move the other way
The most commercially important asymmetry in this topic, and the fact that most undermines a simple withdrawal narrative: while general liability moves toward exclusion, cyber and professional lines are moving toward affirmative language.
Coalition added an Affirmative AI Endorsement in March 2024, expanding the definition of a security failure to include an AI security event and expanding funds-transfer-fraud to cover fraudulent instruction delivered by deepfake; a Deepfake Response Endorsement followed in December 2025. AXA XL added a generative AI endorsement covering data poisoning, usage-rights infringement and regulatory violations including under the EU AI Act. In June 2026 CFC embedded affirmative AI language across seven products at once, with its chief underwriting officer noting that while “parts of the market are understandably focused on how to manage uncertainty, including through exclusions,” CFC had instead “reflected that explicitly in our coverage.”
Coalition's framing of the distinction is the clearest available: a silent policy says nothing about AI, leaving the language open to interpretation and dispute; an affirmative policy states how coverage responds.
Exclusions are nonetheless present in cyber at material frequency. A 2025 survey of more than 750 security leaders found 42% reported an AI misuse and liability exclusion in their cyber policy, with the most common exclusionary events being AI model error or failure, third-party AI service issues, and prompt injection. The same survey found 86% had been offered premium credits for using AI in security controls. The same technology is being rewarded and excluded simultaneously.
QBE illustrates how capacity actually behaves better than any single carrier. It has applied sublimits to certain AI-related cyber losses, told the Financial Times it is “not retreating” from AI risk, and separately provides capacity to a standalone generative-AI liability product written through a delegated-authority MGA. That is not inconsistency. Priced, bounded, monoline AI risk with a dedicated aggregate is a fundamentally different proposition from unpriced AI accretion inside a cyber tower. It is also the best available answer to whether anyone will write this: yes, when it is bounded, evidenced, and separately aggregated.
There is one further threat to professional liability cover that requires no exclusion at all. As coverage counsel Anthony Crawford puts it, an insurer may argue that a professional who relied on unverified AI output without exercising supervision “never rendered a ‘professional service’ within the terms of the policy.” That attacks the coverage grant rather than carving an exception into it. If it holds, documented human oversight is not merely good governance. It is part of what preserves the insuring agreement.
Why the deployer is holding the risk
The exclusions land on companies that are already the least protected party in the chain, for two independent reasons.
Vendor contracts have capped vendor exposure. Analysis by Gallagher Re, MIT and Testudo found that AI vendor terms typically cap liability at twelve months of fees and offer no performance warranties, with indemnity “almost always limited to third-party intellectual property infringement claims arising from the services themselves.” That is corroborated by what the large providers actually publish: the Microsoft Copilot Copyright Commitment, Google Cloud's generative AI indemnification, OpenAI's Copyright Shield and IBM's watsonx indemnity all cover intellectual property infringement only, and several are conditional on the customer using built-in guardrails. None responds to a hallucination that causes financial loss, a discriminatory output, an unauthorised agent action, model drift, or a regulatory fine.
Courts are treating the deploying company as responsible. In Moffatt v. Air Canada, the airline was held liable for negligent misrepresentation by its own website chatbot, which invented a bereavement fare policy. Air Canada's argument that it was not responsible for its chatbot failed, and the chatbot vendor was not a defendant.
That case should be cited for what it is. It was decided by British Columbia's Civil Resolution Tribunal, a small-claims forum; the award was a few hundred dollars; and CRT decisions are not binding precedent. Its value is as an early, concrete illustration of an adjudicator rejecting “the AI did it” — not as authority a US court is obliged to follow.
The US litigation to watch instead is Estate of Gene B. Lokken v. UnitedHealth Group, in the District of Minnesota, over the nH Predict tool used in post-acute care coverage decisions. Two features of it are instructive. First, the named defendants include both the insurers and naviHealth, the entity that developed the algorithm — and naviHealth has been a UnitedHealth subsidiary since 2020. Where the deployer owns the developer there is no arm's-length vendor to point at, and the corporate group holds the entire exposure. Second, and more useful for anyone thinking about oversight: the claims that survived a motion to dismiss in February 2025 were breach of contract and breach of the implied covenant, and they turn on policy language promising that coverage decisions would be made by clinical staff and physicians. The alleged wrong is not that the algorithm was inaccurate. It is that a human judgment the insured had been promised was delegated to software. UnitedHealth disputes that nH Predict was used to make coverage determinations.
California codified the direction of travel. From 1 January 2026, Civil Code §1714.46 provides that a defendant who developed, modified, or used an AI system may not assert that the AI autonomously caused the harm. It does not create strict liability — causation, foreseeability and comparative fault are expressly preserved — and Moffatt shows adjudicators reaching the same place without a statute. The statute is a signal, not the engine.
The scale of the untracked exposure is the part worth sitting with. A July 2026 paper co-authored by researchers at Anthropic, OpenAI and Aon found that more than 90% of insurers' AI-agent exposure sat as silent coverage as of March 2026, concentrated in cyber, directors and officers, general liability and technology errors and omissions. And Gallagher's 2026 research found that one in five surveyed insurance professionals had an insured suffer economic loss or make a claim from AI-related risk in the past year — of which just over half were covered in full and 44% only partially.
The case that silent coverage still responds
This argument deserves to be made properly, because it is strong and because almost nobody selling into this market makes it.
Start with the decisive fact: no court anywhere has yet construed an AI exclusion. Every interpretation in this note, and every interpretation in every vendor's marketing, is untested.
Policyholder counsel at Hunton Andrews Kurth advance four arguments that an insured should not concede:
- Narrow construction.Coverage grants are construed broadly and exclusions narrowly against the insurer. Courts “have rejected insurer attempts to apply [broad trigger language] as automatic bars to any claim with a remote connection to excluded conduct.”
- Mixed claims preserve the defence obligation. Where a suit alleges both AI-related and non-AI wrongful acts, an AI exclusion “may not eliminate the insurer's defense obligation,” because the test is whether the claim plainly and clearly falls within the exclusion.
- Illusory coverage.If the broadest reading were adopted, then as AI becomes embedded in everything almost any claim would be connected to it, which “could eliminate coverage for most or all of the insured's operations.” Courts have held that exclusions may not swallow the coverage promised. Notably, this argument is strongestfor the AI-native companies most exposed to the exclusion — a genuine inversion.
- Prior policy years are an asset. If an AI exclusion was necessary in 2026, that suggests a 2022 or 2023 policy lacking the language did not already exclude AI-related claims.
That last point has independent support from a neutral source. FC&S, ISO's own forms analysis service, states that because the coverage was not previously specifically excluded, attaching any of these endorsements “will generally result in a reduction of coverage.” That concedes the coverage was there. Crawford reaches the same conclusion: “the introduction of new AI exclusions is a strong indicator that the insurance industry recognizes that insurance policies currently provide that coverage.”
There is also a market argument. Alana McMullin of Lathrop GPM, who works both sides of coverage disputes, notes that “aggressive exclusions may make their policies less attractive, especially given the pervasive nature of AI in today's business environment,” and that some insurers will choose “to underwrite and price the risks probably for an additional premium rather than exclude them.” She adds that policyholders “may have the most influence over how many carriers adopt the AI exclusions through policy buying and in negotiations during renewals.”
The honest conclusion is that an exclusion changes an insured's negotiating position and evidence burden. It does not automatically mean the insured is uncovered.
Claims that do not survive a primary source
We set out to build a defensible position on this subject and found that several of its most-repeated statistics could not be traced. These are published in the same spirit as the findings.
- “ISO forms underpin 70–82% of US property and casualty policies.” We could not source this. Verisk's own March 2026 Investor Day presentation uses 82% and 18% as its domestic and international revenue split, and 71% and 29% as its segment split. The statistic appears to be a misreading. What Verisk does verifiably state is that its clients include the top 100 US property and casualty insurers, that it processes around 2,000 regulatory filings annually across 32 lines, and that it maintains 16,000 active policy forms. Those support “ISO language is the industry baseline” as a qualitative claim. They do not support a percentage.
- “CG 40 35 is an AI exclusion.” It is not. CG 40 35 is ISO's Exclusion – Cyber Incident, edition 12 23. Any analysis repeating this should be discounted.
- “AI hallucinations are driving the litigation wave.” The opposite, on the best available data. The most-cited dataset is Testudo's, and Testudo sells standalone generative-AI liability insurance, so read it accordingly. It puts hallucination claims at 4.9% of AI suits, with patent infringement at 11.9% and copyright at 11.2%. The wave that has arrived is intellectual property and privacy, not autonomous error. This cuts against the coverage-gap thesis and we would rather say so. Note also that we cannot fully audit the figure: the underlying State of Play report is gated, the inclusion criteria are not published, and the same body of work is the source of the widely repeated litigation-growth percentages whose base year secondary accounts disagree about. The Gallagher Re report listed in our sources is co-authored with Testudo and is the accessible route to its framing.
- “AI agents have already caused large enterprise losses.” We could not verify a single instance of a large, unrecovered loss caused by an autonomous agent. The most-circulated incident, an agent deleting a production database, ended with the data fully restored. The best-documented agentic financial incident we could confirm was a transfer of roughly $1,400 between two accounts belonging to the same user. The case for insuring agents currently rests on mechanism and deployment growth, not on loss experience — which is itself the underwriting problem.
- Market-size figures for AI liability insurance. Four syndicated research reports give a fifteen-fold spread for the same base year, which makes all of them unusable. The only estimate we would cite is Deloitte's projection of roughly $4.8bn in global AI insurance premium by 2032 at around 80% compound growth — which implies a 2025 base of perhaps $60–70m, consistent with a market where the largest single product offers $25m of limit per risk.
- “AI insurance will follow the cyber growth curve.” Swiss Re has explicitly documented that the market over-extrapolated cyber's own growth after 2022, warning that 20% annual growth “keeps being mentioned, almost as if this was a law of nature.” The analogy is sound methodologically — cyber matured through scenario analysis, exposure assessment and accumulation management before claims data existed — and unsound numerically.
- Regulatory timelines published before late July 2026. Regulation (EU) 2026/1744 entered into force on 27 July 2026, moving the EU AI Act's high-risk obligations from 2 August 2026 to December 2027 and August 2028 — while Article 50 transparency obligations still commence on 2 August 2026. Separately, Colorado's AI Act never took effect: it was repealed and reenacted in May 2026 before its commencement date, and enforcement had already been stayed in litigation. Much published material is now wrong in both directions.
What to check
None of the following requires buying anything, and all of it is better done before a renewal than after a claim.
- Whether the general liability policy carries CG 40 47, CG 40 48, or CG 35 08, or any manuscript AI exclusion — and which, because CG 40 48 leaves Coverage A intact and CG 35 08 only reaches products and completed operations.
- Whether directors and officers, errors and omissions, fiduciary, employment practices or crime policies carry proprietary AI wording — and what its definition covers. Content and responses, or predictions, recommendations and decisions?
- The trigger phrase on every AI clause found, ranked against the ladder above.
- Whether cyber contains affirmative AI language, silence, an exclusion, or a sublimit. Sublimits are easy to miss and can be a small fraction of the policy limit.
- Whether any clause carves out widespread or systemic AI events, as distinct from individual ones.
- Copies of prior-year policies and endorsement schedules, stored permanently. If an exclusion was added at this renewal, the prior form matters.
- Whether AI is the product or a tool in use. The forms, the market and the available solutions all segment on this axis.
- Which enterprise tools in the stack now embed generative AI — remembering that the standard trigger does not require the AI to have been the insured's own.
- What each agent may decide, spend, promise, publish, change, deploy or transact without human approval; the maximum plausible loss from one action; and whether the human oversight that exists can be evidenced afterwards.
- What customer contracts promise about AI performance, compared with what the insurance programme actually covers. A warranty given to a customer that the insurance would not respond to is a direct balance-sheet exposure.
One further question, for anyone being asked to produce evidence of AI insurance. More than ten products now target this gap, and the paper behind them is not equivalent. Four distinct structures are in the market, named so the point can be checked:
- Lloyd's syndicated capacity.Armilla writes as a Lloyd's coverholder on a binder led by Chaucer; Testudo writes on a panel led by Apollo with Atrium and QBE. Lloyd's paper carries an A+ (Superior) AM Best rating.
- A non-US carrier behind US fronting paper. Relm is Bermuda-domiciled and reaches US insureds through a fronting agreement with Trisura Specialty, an A− rated surplus lines company.
- A risk retention group. Corgi writes liability through an RRG organised under the federal Liability Risk Retention Act. RRGs pool member resources to self-insure and are not backed by state guaranty funds, so if the pool cannot pay, members bear the loss. Corgi says it uses different structures for different lines, and that some policies sit with state-regulated carriers instead — so the answer depends on the specific policy, not the brand.
- No publicly disclosed carrier.Neither AIUC nor Klaimee names the insurer behind its offering. In AIUC's case that includes its flagship ElevenLabs policy, where the widely repeated “$50m, backed by Lloyd's” figure appears in secondary write-ups but in neither party's own announcement.
If a counterparty is relying on that certificate as its route to recovery, those are different promises. Ask who the carrier is, what its financial strength rating is, whether it is admitted, surplus lines, an RRG, or a fronted programme, and whether a guaranty fund stands behind it. We have not found another public source drawing this distinction across the AI market, though the underlying structural questions are ordinary ones any broker asks.
Clara's approach
Clara is building a specialist risk practice for companies that give AI the authority to act — to decide, spend, promise, publish, change, deploy, or transact — and researching how insurance markets should respond to that authority.
This note is the current state of one part of that work. The reason the exclusions matter to us is not that they create a product opportunity. It is that they are the first place the insurance market has committed language to paper about AI, and the language reveals what the market thinks it is insuring. A definition that stops at systems which “create content or responses” is a definition written for generative AI, not for agents that take actions. Verisk saying it is now evaluating agentic-AI exclusions is an acknowledgement that the second problem is different from the first.
That gap is where our research sits. It connects directly to work we have already published: our note on the tail risk static insurance cannot see examines why point-in-time underwriting struggles when models, tools, permissions and goals change at machine speed, and our note on Klaimee examines the first commercial interface being built for insuring individual agents.
There is one question we cannot answer from outside, and it is the one the entire affirmative market rests on: whether enterprise procurement actually requires AI-specific insurance or certification from its vendors. Nearly every claim that it does comes from a company selling the remedy, and no independent survey exists. We are researching it by asking buyers rather than vendors. If you have been asked for AI-specific insurance in a procurement process, or have asked an AI vendor for it, we would like to hear from you.
Sources and scope
This is an independent research note based on public information, current as at 29 July 2026. It is not insurance, legal, or coverage advice, and it is not a substitute for reading your own policy. Clara is not currently placing insurance.
Form wording quoted here was obtained from third parties reproducing the ISO forms, including FC&S and practising coverage counsel; we have not inspected a Verisk-issued document, and ISO circulars are subscriber-only. Statements attributed to carriers, brokers, or vendors are their claims, not our verification. No court has construed any AI exclusion, so all interpretation here is untested. Statistics produced by parties who sell AI insurance are identified as such wherever cited.
Where we could not verify a claim we have said so rather than omitting it. We would rather be corrected than confident.
Corrections, 29 July 2026. This note was revised on the day of publication after review. The first version stated that in the US litigation over algorithmic post-acute care denials, the vendor that built the tool was not a defendant. That was wrong: naviHealth, which developed nH Predict, is a named defendant in Lokken, and has been a UnitedHealth subsidiary since 2020. The passage has been rewritten and the docket sources added. We also softened the standfirst, which described the endorsements as removing generative AI from general liability rather than as optional forms available to insurers across general liability and products/completed operations; reconsidered the claim that predictive-only models fall outside the ISO definition, which we now present as a policyholder argument rather than a reading; qualified the authority of Moffatt; named Testudo as the source of the litigation dataset rather than describing it anonymously; named the carriers and structures behind the counterparty-strength comparison; and added eleven sources that supported claims in the body but had been omitted from the source list.
- Big “I” Virtual University: Verisk to roll out new general liability exclusions for generative AI exposures (21 Oct 2025)
- PropertyCasualty360 / FC&S: General liability endorsements — assault or battery, generative AI, human trafficking (6 Oct 2025)
- Claims Journal: Insurer interest in AI exclusions growing (20 Jul 2026)
- The Insurer: Verisk weighs new exclusions for agentic AI risks (10 Jul 2026)
- Business Insurance: Insurers, brokers adjust as AI exclusions emerge
- Financial Times: Insurers retreat from AI cover as risk of multibillion-dollar claims mounts (23 Nov 2025)
- Hunton Andrews Kurth, Policyholder Pulse: AI exclusions in insurance policies — broad language, uncertain impact (13 Apr 2026)
- Olshan Frome Wolosky / The Legal Intelligencer: The continued rise of generative AI exclusions (15 May 2026)
- Zelle LLP: The growing trend of AI-related insurance policy exclusions (31 Oct 2025)
- WTW: Sarbanes-Oxley and the AI governance gap — D&O insurance considerations (Mar 2026)
- Coalition: Affirmative AI endorsement added to cyber policies (26 Mar 2024)
- CFC: Affirmative AI cover across seven products (Jun 2026)
- Gallagher Re, MIT and Testudo: Smart systems, blind spots — rethinking insurance for the AI era (Mar 2026)
- Gallagher: Not so silent — tackling the complexities of AI liability (May 2026)
- The Insurer: US liability insurers explore AI exclusions — review of state product filings
- Lathrop GPM: The AI coverage gap — what new insurance exclusions mean for your business
- Bloomberg Law: Insurer AI exclusions spark policyholder alarm on coverage gaps
- Delinea / Censuswide: 2025 Cyber Insurance Research Report (survey of 750+ security leaders)
- Deloitte Center for Financial Services: AI insurance could be a $4.8B market by 2032 (Aug 2025)
- Swiss Re: Reality check on the future of the cyber insurance market
- AIUC et al.: Underwriting the Agent Economy (Jul 2026) — source of the >90% silent-coverage finding; co-authors include Anthropic, OpenAI and Aon, and AIUC sells AI insurance
- Chaucer: Chaucer and Armilla AI launch Vanguard AI (10 Feb 2026)
- Relm Insurance: fronting partnership with Trisura Specialty Insurance Company
- TechCrunch: Corgi reportedly raised more money at $4B — on its risk retention group structure and the absence of guaranty fund backing (23 Jul 2026)
- AIUC: ElevenLabs secures first-of-its-kind AI agent insurance (11 Feb 2026)
- Moffatt v. Air Canada, 2024 BCCRT 149
- Estate of Gene B. Lokken v. UnitedHealth Group, No. 0:23-cv-03514 (D. Minn.) — complaint
- Estate of Gene B. Lokken v. UnitedHealth Group — memorandum opinion and order on motion to dismiss (13 Feb 2025)
- California AB 316: Civil Code §1714.46 (effective 1 Jan 2026)
- Verisk Investor Day presentation (5 Mar 2026)
- Clara: Klaimee and the emerging shape of agent insurance
- Clara: The tail risk static insurance can't see