The Short Answer: AI Is Not Automatically Covered or Automatically Excluded
AI insurance exclusions do not have one universal legal meaning. A policy may cover a loss caused by an AI-assisted employee, while excluding loss caused by the AI model itself, autonomous decision-making, training-data infringement, or a failure to disclose the system’s limitations. The result depends on the wording, the insurance class, the date of the event or claim, and the specific controls used by the insured. As of 24 September 2026, the central problem is not that every insurer has banned AI, but that AI is being used in businesses faster than policy forms and underwriting questions can describe it. Bloomberg Law, Dentons, Jones Day, Pillsbury, Honigman, and other commentators have reported growing insurer interest in narrowing or clarifying AI-related exposure. That does not mean every policy excludes every AI loss, and it does not mean that a business can safely assume its existing policy responds.
Also worth reading: How Do AI Liability Insurance Solutions Work for Businesses Using Generative AI? · How Are Insurance Policy Exclusions Interpreted in the Age of AI-Driven Underwriting and Emerging Risks? · How Should Consumers and Businesses Evaluate an AI Insurance Broker Comparison Guide in 2026?
A useful starting point is to separate three questions: whether the underlying event falls within the insured activity, whether a particular AI-related cause is excluded, and whether contractual liability is accepted. The same company may have cyber insurance for a data breach, technology errors and omissions coverage for a failed service, and commercial general liability coverage for physical injury, yet receive no payment for a defective automated decision, a third-party claim over training data, or a regulatory penalty. An AI Insurance Broker should compare the policy wording with the actual AI workflow rather than search only for the words “artificial intelligence.” The insurance market is still developing, so the wording and the evidence supplied at underwriting are often more important than the label attached to the product.
Why Insurers Are Adding or Clarifying AI Exclusions
Insurers are responding to a mixture of new technology, older legal categories, and higher uncertainty. Cyber policies already address unauthorized access, ransomware, data compromise, and business interruption, but an AI system can cause harm without a conventional hacker or malware event. A model may misclassify a claim, a trading system may execute an unwanted transaction, or an agent may send inaccurate information to customers at scale. Traditional liability forms may cover resulting bodily injury or property damage while leaving the model’s intellectual-property, discrimination, privacy, and contractual risks outside the policy wording. Underwriters are therefore trying to define which losses arise from the insured’s business activity and which arise from a third-party technology component.
Regulatory pressure adds another reason. The EU AI Act entered into force on 1 August 2024, with provisions on prohibited practices and AI literacy applying from 2 February 2025 and broader obligations for general-purpose AI systems scheduled from 2 August 2025. Some high-risk obligations were scheduled to apply from 2 August 2026, although implementation details and political changes can affect the timetable. A company operating across borders may face exposure under privacy, consumer-protection, product-safety, employment, discrimination, or sector-specific rules. A penalty imposed by a regulator is not automatically a covered loss; some policies exclude fines, penalties, punitive damages, or amounts that cannot be insured by law. The regulatory event may be the visible failure, while the insured event is a failure of governance, testing, or contractual performance.
The market’s direction is becoming more explicit. A widely circulated ScienceSoft estimate, reported by TradingView, predicted that AI risks could enter 60–80% of liability and cyber underwriting by 2028. This is a forecast, not an observed underwriting statistic, and it should not be presented as proof that coverage will disappear. It does show why insurers are asking about models, autonomous agents, training data, and the proportion of decisions made without human review. The trend is toward closer classification and documentation, not necessarily a simple refusal to insure AI businesses.
Which Insurance Policies May Be Affected?
Cyber insurance is commonly the first policy a business reviews, but it is not a general guarantee against AI failure. A cyber policy may respond to a breach involving AI infrastructure, an incident affecting model training data, or business interruption caused by a covered cyber event. It may exclude loss arising solely from an AI model’s output, an undisclosed autonomous decision, or an obligation assumed in a technology contract. Some forms also contain sublimits for social engineering, contingent business interruption, cloud-service failure, and third-party dependencies. Those sublimits can apply even when the event is described as an AI incident. The policy’s definition of “computer system,” “data,” and “security incident” therefore needs to be read alongside any AI-specific exclusion.
Technology errors and omissions, or technology E&O, may be more relevant than cyber insurance when a customer alleges that a software product or AI-enabled service failed to perform. The policy may respond to a claim for negligent advice, incorrect processing, failed integration, or breach of contract, but the wording may exclude the use of generative AI, autonomous decision-making, or the use of third-party models. Professional indemnity and management liability policies face similar questions when a professional judgment is made or approved with limited human involvement. D&O policies may respond to a securities claim alleging misleading disclosure about an AI strategy, but they may exclude deliberate misstatement, undisclosed material weaknesses, or regulatory penalties. Product liability, general liability, intellectual-property, and cyber policies can all be involved, and the correct answer often requires more than one policy review.
A contract can create coverage even when the policy does not obviously name AI. For example, a supplier may promise that an AI-enabled platform will meet accuracy, uptime, or compliance requirements, while the supplier’s insurance excludes contractually assumed liability. A customer may also require the supplier to name the customer as an additional insured, provide primary and non-contributory wording, or waive subrogation against the customer. Those contract terms do not expand the policy beyond its terms, but they can transfer risk back to the supplier and create a claim that is difficult to resolve. Contractual language should therefore be compared with the actual exclusions, limits, deductibles, and notice conditions.
Comparing the Main Coverage Approaches
The main choice is not simply “insurance” versus “no insurance.” It is whether to rely on a legacy policy, add an AI-specific endorsement, or negotiate a bespoke technology and liability solution. The following comparison is a practical guide, not a substitute for reading the wording of a particular policy.
| Feature | Legacy policy with broad wording | AI-aware endorsement | Bespoke AI liability and cyber solution |
|---|---|---|---|
| Main scope | May respond to a traditional cyber, E&O, or liability event if the trigger is described | Adds explicit treatment of model errors, agents, data, and AI-specific exclusions | Tailors coverage to the company’s actual AI use, sector, contracts, and risk profile |
| Typical AI treatment | May be silent, ambiguous, or subject to an exclusion added at renewal | Usually states what is covered, limited, sublimited, or excluded | Can address specialized exposures such as third-party model failure, bias, or autonomous actions |
| Evidence needed | Standard application, loss history, and security controls | AI inventory, model documentation, human-review processes, and data provenance | Detailed underwriting file, use cases, testing records, vendor terms, and incident procedures |
| Cost approach | Premium may be based mainly on revenue, industry, limits, and claims | May add an endorsement premium or require a higher limit structure | Usually negotiated; price depends on risk, exclusions, limits, and control evidence |
| Best fit | Businesses with limited or conventional AI use | Companies already using AI and needing clearer boundaries | Regulated, high-revenue, or agentic businesses with complex third-party exposure |
How to Read an AI Exclusion Properly
The first step is to identify whether the clause is a true exclusion, a limitation, a sublimit, an exception, or a definition. An exclusion generally removes coverage for a described loss or cause. A limitation may cap the amount payable for a covered event. A sublimit can apply only to part of the loss, such as third-party data-privacy claims or dependent-business interruption. Definitions may place a system inside or outside a policy section, and endorsements can override parts of the base wording. A clause stating that “the insured is responsible for the design, development, or use of artificial intelligence” is different from one stating that all loss arising from an AI system is excluded. The first may address control or contractual responsibility, while the second may attempt to remove the entire loss category.
The second step is to locate the relevant date. A policy may be written before the AI system existed but still respond to an occurrence-based event if the period and trigger are met. A claims-made policy usually depends on when the claim is made and reported, while an occurrence policy usually depends on when the event happened. Retroactive changes, prior-knowledge language, notice requirements, and the policy period can therefore be decisive. A claim arising from a system deployed in 2024 may be evaluated under a 2024 policy, a 2025 renewal, or a 2026 endorsement, depending on the governing document. The insured should preserve the policy versions, applications, broker communications, renewal papers, and incident records rather than relying on a current certificate of insurance.
The third step is to test the exclusion against a concrete scenario. Imagine that an AI agent incorrectly approves a customer refund, a model generates discriminatory employment rankings, an image generator produces copyrighted material, or a cyberattack compromises a training dataset. For each scenario, ask what caused the loss, whether there was a security event, whether the system was autonomous, whether a third party supplied the model, and whether the loss was a penalty, third-party claim, or interruption expense. This exercise exposes gaps that a general statement such as “the policy covers cyber risk” cannot resolve. It also helps a broker ask the insurer precise questions instead of receiving a generic assurance that AI is covered.
Practical Steps for an Insured Business
The most effective review begins with an inventory of every AI system, vendor, model, and agent used by the company. The inventory should identify the business purpose, data inputs, model provider, decision rights, human review, deployment date, customer impact, and whether the system can take action without an employee’s approval. A spreadsheet or risk register is enough for a small business, while regulated or larger organizations may need a formal system of record. The purpose is not to collect information for its own sake. It is to show the insurer what exists and to identify risks that the current wording does not address. A company that cannot say whether a vendor’s model is being used for a consequential decision may also struggle to quantify its own exposure.
The next step is to read the declarations, application, exclusions, endorsements, definitions, and renewal documents together. The broker should ask the insurer, in writing, whether coverage responds to the company’s specific use case, and should identify any endorsements needed to remove ambiguity. Answers such as “AI is covered if it causes a cyber incident” are useful but not complete. The written response should identify the relevant policy section, limits, deductibles, sublimits, exclusions, and notification requirements. A material change in the use of AI should be disclosed during renewal or mid-term, because silence on the application can create a separate basis for dispute even when the event is otherwise covered.
Finally, the business should align contracts, controls, and coverage. High-risk deployments should have documented testing, access controls, logging, human escalation, data-retention rules, and an incident response process. Contracts with AI vendors should address uptime, data use, security, model changes, intellectual property, indemnities, audit rights, and responsibility for consequential decisions. Where appropriate, the company should require evidence of vendor insurance, additional-insured status, or a contractual risk-allocation structure. Insurance is one layer in this process. It cannot replace good governance, and a compliant control record does not by itself guarantee a claim will be paid.
Common Mistakes That Create Coverage Disputes
One common mistake is assuming that a cyber policy covers every technology malfunction. A model’s incorrect output may be a liability or contract issue rather than a security breach, and the same policy may treat a covered intrusion and an excluded failure differently. Another mistake is treating AI vendors’ marketing language as a coverage description. A product may be described as “secure,” “responsible,” or “compliant,” but the insurance wording can still exclude the precise event. Businesses should distinguish assurance about the software from the financial protection supplied by the policy. A vendor’s compliance statement may help an insurer assess risk, but it does not interpret the policy.
A second error is reviewing insurance only after an AI-related complaint arrives. Once notice deadlines, forensic work, and customer communications are underway, options may narrow. Another is relying on a general indemnity without checking the legal definition of consequential loss, limitation of liability, data ownership, and excluded practices. Contractual promises can exceed what the supplier’s policy will fund. A third error is assuming that regulatory investigations are automatically covered. Investigations, defense costs, settlements, fines, and corrective-action costs may be treated differently, and some categories cannot be insured. An organisation should obtain advice on the jurisdiction and the particular enforcement action rather than extrapolating from an unrelated cyber claim.
The final error is confusing an AI exclusion with a ban on AI businesses. Insurers are not necessarily refusing the entire sector. They are pricing, limiting, and defining the risk according to the underlying activity, control environment, and claims history. A software company, hospital, manufacturer, bank, and retailer can all use AI while presenting very different exposures. The absence of an AI label from a policy does not guarantee coverage, and the presence of an AI label does not prove exclusion. The correct conclusion comes from matching the wording to the activity and the loss.
When to Act and How Pricing Is Determined
A business should act before a major AI deployment, a new customer contract, a material product change, or a policy renewal. That timing gives the broker and insurer an opportunity to amend wording or pricing before the company relies on the system at scale. A review is also sensible when an AI vendor changes the model, the system gains authority to approve or execute transactions, sensitive data is used for training, or the company enters a new jurisdiction. If the business is already investigating a complaint, the priority is to notify the insurer according to the policy and preserve evidence rather than waiting for a complete root-cause report. Early notice can preserve coverage options, although it may trigger a reservation of rights.
There is no defensible universal price for AI insurance. Premiums are usually quoted per $1 million of limit and depend on industry, revenue, geographic exposure, claims history, limits, deductibles, security controls, data sensitivity, and the proportion of decisions delegated to AI. An endorsement may cost little when it clarifies a limited use, while a bespoke policy can cost substantially more because it accepts a new or hard-to-price exposure. A high limit does not solve a narrow exclusion, and a low premium may be achieved by restricting coverage. Brokers should therefore compare written scope, not only the quoted premium. The market may charge more for AI because the loss distribution is uncertain, not because every AI user is inherently high risk.
As of 24 September 2026, the practical deadline is not a public ban date. It is the next renewal, major deployment, or contract negotiation. Businesses using AI should not wait for a headline about insurer exclusions to decide whether their wording still fits. The market is moving toward explicit AI definitions, sublimits, and exclusions, and that change is likely to continue. A clear application, a maintained AI inventory, and a broker capable of comparing policy wording with operational reality can make the difference between a known risk and an expensive dispute.
Bottom Line for Technology and Insurance Buyers
AI-related losses can be covered, partially covered, limited, or excluded depending on the policy and the facts. The most reliable answer is obtained by reviewing the exact wording, the date of the event or claim, the system’s role, and the customer’s contractual expectations. A policy without an AI clause may still respond to a covered cyber or E&O event, but silence is not a promise of universal coverage. A policy with an AI exclusion may still contain exceptions, sublimits, or a path to endorsement, and the exception’s scope may be more important than the headline wording.
For an AI Insurance Broker, the value is not simply finding a product labelled “AI insurance.” It is mapping the company’s actual AI risks, identifying the gaps across cyber, E&O, liability, D&O, product, and contract documents, and negotiating wording that the insurer can administer. Businesses with autonomous agents, high-impact decisions, sensitive training data, or strict customer contracts should obtain a written review before deployment. Companies with limited AI use may need only a targeted confirmation, but they should still verify limits, exclusions, and notification rules. In this evolving area, documentation and scenario testing are as important as the policy name.