If your business deploys autonomous AI agents — whether for customer service, coding, ERP transactions, or content generation — the single most important document you will review this year is the exclusions section of your AI liability policy. The market has shifted dramatically since early 2025, and by August 2026 the exclusions buried on pages 12 through 20 of a policy form matter more than the headline coverage limit. Berkshire Hathaway and Chubb both won regulatory approval during 2025 and 2026 to drop or narrow AI coverage in certain lines, and insurers across the board are pulling back from broad AI liability promises. That means the policy you are quoted today is almost certainly narrower than the one a competitor bought eighteen months ago. This checklist walks through every exclusion category you should verify before signing, why each one exists, and what language to push back on.
Why AI Agent Exclusions Have Exploded Since 2024
Also worth reading: What are the most common AI insurance policy exclusions and how can businesses avoid coverage gaps? · What is the definitive AI liability insurance policy checklist for enterprises deploying generative AI in 2026? · What are real-world AI agent liability coverage examples for businesses using autonomous software?
The insurance industry's retreat from broad AI coverage is a direct response to loss experience and regulatory uncertainty. Insurers discovered that traditional professional liability and cyber forms were silently absorbing AI-related claims — hallucinated advice, unauthorized agent actions, biased outputs — without ever having priced for that risk. Rather than reprice everything, carriers responded surgically: they added AI-specific exclusions to general liability, cyber, E&O, and D&O forms, then sold standalone AI liability endorsements at premiums reflecting actual model risk.
Three events accelerated this. First, the March 2026 Wikipedia incident, in which an autonomous editing agent operating under the account TomWikiAssist made unsupervised changes at scale, demonstrated how quickly an agent can create reputational and legal exposure without any human in the loop. Second, regulators issued model risk guidance — particularly in banking, where American Banker reported that supervisory expectations left many questions unanswered — which insurers read as a signal that liability standards were still moving. Third, claims data began arriving: Insurance Business reported that insurers face hidden AI liability as agent risks multiply, because agents act, transact, and communicate in ways that fall outside legacy definitions of 'professional services.'
The practical consequence for buyers: roughly 60 to 70 percent of the AI policies marketed in 2026 contain at least one exclusion that would have surprised the buyer had they read it before binding. Some of those exclusions are reasonable risk transfer; others quietly gut the coverage you thought you purchased. The checklist below exists to tell the difference.
Exclusion Category 1: Known Defects and Prior Knowledge
Nearly every AI liability form now excludes claims arising from defects, errors, or model behaviors that the insured knew about before the policy period or before a specific retroactive date. On its face this mirrors standard 'known loss' doctrine, but AI makes it far more dangerous. If your engineering team logged a known hallucination rate, a bias finding in a fairness audit, or an open ticket about an agent's tendency to exceed transaction limits, the insurer can argue that any related claim stems from a pre-existing defect.
When reviewing this exclusion, look for three things. Check whether the trigger is 'knew or reasonably should have known' — the latter phrase converts ordinary negligence in monitoring into a coverage denial. Check whether the knowledge must be documented and communicated to leadership, or whether a junior engineer's Slack message counts. And check whether there is a carve-back for claims arising from defects the insured disclosed to the insurer at underwriting. A well-negotiated version requires formal documentation and executive awareness; a poorly negotiated version lets the insurer mine your issue tracker after a claim to find any ticket that resembles the loss.
Exclusion Category 2: Unapproved Model Changes and Fine-Tuning
This exclusion denies coverage when the insured modifies a model — through fine-tuning, retrieval augmentation changes, prompt engineering at scale, or swapping underlying foundation models — without following a change-management process the policy specifies. Insurers justify it by pointing to model risk management guidance: if you cannot demonstrate control over what changed and when, underwriting assumptions collapse.
The trap here is definitional drift. Some policies define a 'model change' narrowly as retraining weights; others sweep in prompt template updates, tool configuration changes, or even third-party API version updates from your cloud provider. Given how frequently vendors like AWS update agent frameworks — ERP Today noted AWS issuing rulebooks governing SAP agent exceptions precisely because agent behavior shifts with platform updates — a broad definition means routine vendor-side changes could technically void your coverage. Negotiate for a definition limited to material changes initiated by you, with a safe harbor for vendor-initiated updates, and confirm the required change-management process matches what your organization actually does rather than an idealized ITIL framework no team follows perfectly.
Exclusion Category 3: Autonomous Action Without Human Oversight
Several 2026 forms exclude bodily injury, property damage, or financial loss caused by an agent acting autonomously beyond defined thresholds — for example, transactions above a dollar cap, actions outside a whitelisted system, or decisions made without human approval. This exclusion directly targets agentic deployments: agents that book purchases, edit systems of record, send communications, or execute code.
Read the thresholds carefully. A policy might cover agent actions up to $10,000 per transaction but exclude anything above, leaving a single large erroneous trade uninsured. Others exclude all actions in designated 'high-risk systems' such as ERP, payments, or HR platforms — which is exactly where many companies deploy agents first. If your roadmap includes autonomous agents in transactional systems, either negotiate the threshold upward, buy a specific endorsement for high-risk-system deployment, or accept that those use cases are self-insured. Do not assume the broker's summary reflects the endorsement's actual scope; request the endorsement wording itself.
Exclusion Category 4: Intellectual Property and Training Data Claims
IP exclusions remain the most litigated area of AI insurance. Standard forms exclude claims arising from copyright infringement in training data, output that substantially reproduces copyrighted works, or patent claims related to model architecture. Some policies offer a sub-limit — commonly $250,000 to $1 million — for third-party IP claims arising from model outputs, while excluding training-data claims entirely.
The distinction matters enormously depending on your role in the AI supply chain. A company fine-tuning open-weight models on proprietary data faces different exposure than a company merely calling a commercial API. Ask whether the exclusion distinguishes between inputs (training data), processing (the model itself), and outputs (generated content). Also verify whether contractual liability is excluded separately — many enterprise customer contracts now include IP indemnities for AI outputs, and if your policy excludes assumed contractual liability, your indemnity commitments are uninsured promises. As The Actuary observed regarding proof burdens in AI-enabled policies, expect the insurer to demand evidence about data provenance during underwriting; failing to produce it can result in rescission later.
Exclusion Category 5: Cyber, Security, and Adversarial Attack Overlap
Security researchers have documented attackers targeting AI systems directly — prompt injection, model extraction, data poisoning, adversarial inputs — rather than the surrounding network. Business attorneys advising on liability note that these attacks blur the line between cyber insurance and AI liability insurance, and insurers have responded with anti-stacking exclusions: the AI policy excludes anything that could arguably be covered by cyber, and vice versa.
Dark Reading reported that while cyber insurance rates dropped through 2025 and into 2026, exclusions widened — a classic soft-market pattern where price falls as terms deteriorate. For AI agent owners, the dangerous gap is an attack that manipulates an agent into harmful action via prompt injection. Is that a cyber event (compromise of a system) or an AI event (agent misbehavior)? Policies disagree. Before binding, run a joint review of your cyber and AI forms side by side and identify, in writing, which policy responds to: prompt injection causing data exfiltration, model theft, poisoned retrieval corpora, and agent-driven fraudulent transactions. If neither policy clearly responds, you have a gap regardless of how much coverage you bought.
Comparing Standalone AI Liability Policies Against Endorsements and Self-Insurance
Buyers in 2026 generally face three structures, each with different exclusion profiles. Understanding the trade-offs prevents overpaying for paper coverage or underinsuring real exposure.
| Feature | Standalone AI Policy | AI Endorsement on Existing E&O/Cyber | Self-Insurance / Captive |
|---|---|---|---|
| Typical annual premium | $25,000–$150,000 for mid-market | $10,000–$40,000 add-on | Variable; fund reserves instead |
| Coverage limits | $1M–$10M common | Usually capped at 10–25% of base limit | Unlimited up to reserves |
| Exclusion breadth | Moderate; negotiable | Broad; inherits base-form exclusions plus AI-specific ones | You set terms, but bear full loss |
| Regulatory approval risk | Lower; purpose-built forms | Higher; several carriers (e.g., Chubb, Berkshire units) won approval to narrow AI terms in existing lines | None externally, but solvency rules apply to captives |
| Best fit | Companies with material agent deployment | Companies testing limited AI use cases | Large enterprises with mature risk teams |
Common Mistakes Buyers Make With AI Exclusions
The most frequent error is reading the insuring agreement and stopping there. In 2026 AI policies, the exclusions, definitions, and endorsements collectively determine maybe 80 percent of real value. Buyers who compare two policies by premium and limit alone routinely choose the cheaper form whose exclusions eliminate their primary exposure.
Second, buyers conflate 'AI is not excluded' with 'AI is covered.' An absence of an AI exclusion is not affirmative coverage; if the loss does not fit an enumerated insuring agreement — professional services, wrongful acts, network security failure — it may fall between categories entirely. Third, teams underestimate the warranty problem. Many applications now include warranties about governance: human review requirements, logging retention periods (often 12 months minimum), incident reporting within 48 to 72 hours, and model inventory maintenance. Breaching a warranty can reduce or void recovery even for unrelated claims. Fourth, buyers ignore the notice-and-cooperation conditions specific to AI incidents, where identifying that an agent caused harm may take weeks; late notice disputes are already appearing in claims. Finally, some buyers rely on vendor indemnities from model providers as a substitute for insurance. Vendor indemnities are contractually capped, conditioned on your compliance with usage policies, and unenforceable against the vendor's own insolvency — treat them as partial mitigation, never as coverage.
When to Act and What It Costs
Act before your next renewal, not after an incident. Underwriters are tightening terms quarterly; a risk profile presented proactively with documentation — model inventories, evaluation results, human-oversight logs, incident response plans — earns materially better terms than the same profile presented reactively. NBC News reported that insurers are explicitly using pricing and coverage terms to push customers toward safer AI practices, meaning demonstrable controls translate directly into narrower exclusions and lower premiums.
On pricing: standalone AI liability for a mid-market company deploying agents in customer-facing functions typically runs $25,000 to $150,000 annually for $1 million to $5 million in limits, with deductibles of $25,000 to $100,000 per claim. High-risk deployments — autonomous financial transactions, healthcare adjacent uses, agents acting on regulated data — can double those figures. Endorsements add $10,000 to $40,000 to an existing program. Budget also for the indirect costs: legal review of policy wording ($5,000–$15,000), broker fees (often 10–15% of premium), and internal time building the governance artifacts underwriters now demand. If a quote seems cheap relative to peers, assume the exclusions are doing the work the premium is not.
Your Working Checklist, Condensed
Before binding any AI agent liability policy in 2026, confirm in writing: the prior-knowledge exclusion requires documented executive awareness; model-change definitions exclude vendor-initiated updates; autonomous-action thresholds match your actual transaction caps; IP exclusions distinguish training data from outputs and preserve room for customer indemnities; the cyber interaction clause names which policy responds to prompt injection and agent manipulation; warranties reflect processes your teams genuinely follow; notice periods accommodate slow-to-detect agent incidents; and any sub-limits for regulatory proceedings, IP claims, or bodily injury are sized to your real exposure. Get the endorsement wording, not summaries. Have counsel who has read AI forms before mark up the exclusions — this is negotiable more often than carriers admit, particularly at renewal when they fear losing the account. The market is hardening in substance even where prices soften; the buyer who reads page 20 wins.