The Short Answer: What Cyber Policy AI Exclusions Are

AI exclusions are policy wordings that strip out or limit coverage for losses connected to artificial intelligence systems — whether the AI caused the loss, failed to prevent it, or was itself the subject of the claim. As of August 2026, these exclusions have become one of the most contested topics in commercial insurance. Insurers including several Lloyd's syndicates and large US carriers have begun inserting standalone AI exclusions or AI-specific endorsements into cyber, tech E&O, media liability, and even D&O policies. The stated rationale is actuarial: underwriters say they cannot yet price AI-related losses because there is too little loss history, so they would rather exclude the exposure than guess at a premium.

Also worth reading: How can businesses effectively approach negotiating algorithmic insurance policy exclusions in the current AI-driven market? · What are the specific credit card rental insurance exclusions I need to watch out for in 2026? · What are AI errors and omissions exclusions and how do they affect my professional liability insurance?

The important nuance for buyers is that cyber policies are not yet the primary battleground. Reporting from Insurance Business and commentary from the International Underwriting Association (IUA) both note that cyber wordings have, ironically, the potential to provide unintended AI cover — meaning some insurers worry their existing cyber forms may already respond to AI incidents without having priced for them. The exclusion push is currently more aggressive in professional indemnity, media liability, and general liability lines. But that is changing quickly, and any business renewing a cyber policy in 2026 should assume an AI endorsement will appear on the quote.

Why Insurers Are Adding These Exclusions Now

Three forces converged between 2023 and 2026. First, AI adoption became ubiquitous: surveys of US and UK enterprises consistently show 70–80% of organizations using generative AI in at least one function by 2025, which means nearly every insured now has an AI exposure whether they bought 'AI insurance' or not. Second, early test cases emerged. Industry press covered incidents such as an AI agent that autonomously took actions against a gym's systems — raising the question of whether a cyber policy responds when software, not a human hacker, causes the damage. Third, underwriters watched the silent-AI problem unfold exactly as it did with cyber 20 years ago and pandemic exclusions more recently: broad wordings written before a new peril existed can accidentally cover it.

Bloomberg Law reported growing policyholder alarm that these exclusions create coverage gaps precisely where businesses assumed they were protected. Law firms such as Honigman and Jones Day have published analyses warning technology companies that AI exclusions interact badly with contractual indemnities — a vendor may contractually promise to cover AI-related damages while its insurer simultaneously excludes them, leaving the vendor personally exposed. That mismatch between contract language and policy language is now the single biggest source of disputes in this area.

How AI Exclusions Actually Work in Policy Wordings

An AI exclusion is typically an endorsement that removes coverage for claims 'arising out of' the use, operation, development, or output of artificial intelligence. The critical words are the trigger phrases, and they vary enormously:

  • Narrow versions exclude only losses caused by the insured's own development or training of AI models. If you merely use third-party tools like ChatGPT or Copilot, you may still be covered.
  • Broad versions exclude anything 'arising out of or relating to' AI in any form — including claims where AI was only incidentally involved, such as a deepfake-enabled social engineering attack.
  • Carve-back endorsements remove the exclusion but add sub-limits (commonly $250,000 to $1 million), higher retentions (often $50,000–$100,000 specific to AI claims), and coinsurance clauses requiring the insured to bear 10–20% of AI-related losses.

Some carriers instead offer affirmative AI coverage extensions — standalone grants of cover for algorithmic discrimination, IP infringement from model outputs, or AI system failure. Cowbell's published analysis ('AI and Insurance: Vector, Peril, and Promise') frames this as insurers choosing between treating AI as a vector (a way losses arrive), a peril (the cause itself), or a promise (an insurable product line). Most 2025–2026 wordings treat it as a vector first and a peril second.

Comparison: Exclusion vs Carve-Back vs Affirmative Cover

FeatureBlanket AI ExclusionExclusion + Buy-Back EndorsementAffirmative AI Coverage Extension
Coverage for AI-caused lossesNoneSub-limited ($250K–$1M typical)Full limit up to policy cap
Retention impactN/A — no cover at allSeparate AI retention ($50K–$100K)Standard policy retention
CoinsuranceN/AOften 10–20% co-pay on AI claimsRarely applied
Premium effectMay reduce premium slightlyNeutral to modest increaseAdds 5–15% to premium typically
Deepfake/social engineering claimsUsually excluded if 'relating to' AICovered up to sub-limit if endorsedCovered if wording includes it
Contractual indemnity alignmentFrequently misalignedPartially alignedBest aligned
Availability in 2026 marketCommon in PI/media linesGrowing in cyber and tech E&OLimited to specialist markets
The practical takeaway is that a blanket exclusion is rarely acceptable for any business that uses AI daily, and even carve-backs deserve scrutiny — a $500,000 sub-limit sounds generous until a single deepfake fraud event or algorithmic discrimination class action exceeds it within weeks.

Practical Steps Before Your Next Renewal

Start with an internal AI inventory. You cannot negotiate what you cannot describe. Document every AI system your organization uses or builds: customer-facing chatbots, code-generation tools, automated underwriting or hiring algorithms, marketing content generators, and agentic systems that take autonomous actions. For each, record who built it, what data trained it, and what decisions it makes without human review. Brokers report that underwriters in 2026 increasingly ask for exactly this information at renewal, and vague answers tend to produce the broadest exclusions.

Second, read the exclusion's trigger language against your actual use cases. If the exclusion applies only to AI you 'develop, train, or fine-tune,' a company using off-the-shelf tools has less exposure than one running custom models. If it sweeps in anything 'arising out of or relating to' AI, almost every modern cyber incident arguably qualifies, since attackers routinely use AI-generated phishing and deepfakes. Third, quantify the gap: estimate your realistic maximum AI-related loss — a regulatory action, an IP claim over model outputs, a deepfake payment fraud — and compare it to whatever sub-limit the buy-back offers. Fourth, put AI risk allocation into your vendor contracts deliberately, matching indemnities to actual insurance capacity rather than promising coverage your policy excludes.

Common Mistakes Buyers Make

The most expensive mistake is assuming your existing cyber policy covers AI incidents by default. The IUA has explicitly warned that cyber wordings carry potential for unintended AI cover — which cuts both ways. It may help you today, but it also means insurers will close that opening, and a claim filed during the transition period could face aggressive reservation-of-rights letters. Do not build a risk management strategy on accidental coverage.

Second, buyers often accept exclusions without negotiating. Market conditions matter: carriers competing for a $50,000-premium account will frequently soften wording, add carve-backs, or raise sub-limits rather than lose the renewal. A blanket exclusion accepted without comment signals to the underwriter that the buyer does not care about AI exposure. Third, companies conflate AI exclusions across different policies. An exclusion in your media liability policy does not necessarily appear in your cyber policy, and vice versa; each form must be reviewed separately. Fourth, many organizations forget that first-party and third-party exposures differ. A deepfake CEO-fraud loss is largely first-party (your money gone); an algorithmic discrimination claim is third-party (someone sues you). Some endorsements address only one side.

Finally, do not rely solely on 'standalone AI insurance.' A handful of MGAs and specialty carriers now offer dedicated AI liability products, and Marketplace reported in late 2025 that new products covering AI-caused damages were reaching the market. These can be useful supplements, but they are young products with untested wordings, limited capacity, and no track record of paying claims. Treat them as part of a stack, never as a replacement for clean primary wordings.

When to Act and What It Costs

Act at renewal, not after a claim. Once an exclusion is on your policy and an incident occurs, your negotiation leverage drops to near zero. Businesses with 2026 renewals should begin the AI inventory and broker discussion 90–120 days before expiry. Companies developing their own models, operating in regulated sectors (hiring, lending, healthcare), or handling customer data through AI pipelines should move faster — these profiles attract the strictest exclusions first.

On cost: adding an affirmative AI extension typically adds roughly 5–15% to a cyber or tech E&O premium, according to broker market reports through mid-2026. Buy-back endorsements range from neutral pricing to a 5–10% uplift depending on sub-limit size. Standalone AI liability policies currently start around $5,000–$15,000 annually for small limits ($1M) and scale sharply for larger risks. Compare that against the cost of an uninsured event: average deepfake-enabled fraud losses reported to insurers in 2025 clustered in the six-to-seven-figure range per incident, and algorithmic discrimination settlements have reached eight figures. The pricing asymmetry favors buying cover — provided the wording actually delivers what it promises.

There is also a counterargument worth stating plainly: some exclusions are reasonable. If your business touches AI only marginally, accepting a narrow exclusion in exchange for premium stability may be rational. The problem is not exclusions per se; it is broad, ambiguous ones applied uniformly to businesses with wildly different exposures.

How This Evolves Through 2026 and Beyond

Expect three developments. First, standardization: bodies like the IUA and Lloyd's market associations are working toward model AI exclusion and endorsement clauses, similar to what happened with cyber war exclusions in 2022–2023. Standardized LMA-style clauses will make comparison easier but will also spread the stricter wordings faster. Second, litigation will define the boundaries. The National Law Review has tracked early denied claims involving AI exclusions, and the first wave of coverage lawsuits — likely arriving in 2026–2027 — will test how courts interpret 'arising out of' triggers when AI is one contributing factor among several. Third, affirmative AI cover will mature from novelty to expectation, much as cyber endorsements did between 2015 and 2020. Buyers who understand the mechanics now will negotiate from strength; those who discover the gaps at claim time will fund their losses themselves.