What AI Insurance Exclusions Mean for Businesses
AI insurance exclusions are policy terms that limit or remove protection for losses caused by artificial intelligence systems. They matter because an AI tool can produce harmful output, make an expensive decision, expose personal data, or execute an unauthorized action without producing a traditional cyberattack. A policy may respond to the resulting business interruption or liability loss while excluding the AI component that allegedly caused it. The problem is that wording drafted before modern generative AI and autonomous agents often does not explain where that boundary sits.
Also worth reading: Are AI Insurance Exclusions Driving More Litigation in 2026, and What Should Technology Businesses Do? · How Are Insurance Policy Exclusions Interpreted in the Age of AI-Driven Underwriting and Emerging Risks? · What are asbestos removal insurance exclusions and how do they affect contractor liability coverage?
The direct answer is that ordinary cyber, technology errors and omissions, commercial general liability, or directors and officers cover may not automatically protect every AI-related loss. Protection depends on the insuring agreement, definitions, exclusions, conditions, endorsements, and the claims history of the specific policy. By September 25, 2026, businesses should assume that an AI exclusion is possible rather than unusual, particularly in liability and cyber policies. Insurers have increased scrutiny of AI because the technology is now used in customer service, hiring, credit, healthcare, software development, and physical operations. A broker can help identify these gaps, but the contract—not a sales presentation—controls the outcome.
Exclusions are not the same as a refusal to insure every AI system. They can be narrow, such as deliberate misuse of a model, or broad enough to capture a failure to verify an AI-generated decision. A carefully drafted policy may still provide meaningful protection, but businesses should not rely on the assumption that “cyber insurance” includes every autonomous-agent error. Reading the wording before deploying a higher-risk use case remains the most dependable approach.
Why Insurers Are Adding AI Exclusions
The main reason is accumulation of unfamiliar loss patterns. Generative AI can make a fraudulent claim appear credible, generate malicious code at scale, or allow a compromised model to propagate damaging content. Autonomous agents add another problem: they may take actions through software interfaces, creating a chain involving the model provider, cloud platform, developer, deploying company, and human approver. Insurers must decide which link in that chain they will indemnify and which risks they will exclude or subcontract.
Language and copyright questions add further uncertainty. Training data may contain material protected by copyright, while generated text or images may reproduce protected elements. A policy written primarily around conventional data breaches may not clearly classify an output dispute as a covered event. Regulators and courts are also still developing tests for duties associated with automated decisions, so insurers can manage uncertainty through broad exclusions and separate endorsements. The absence of a settled legal rule does not prevent an insurer from declining a claim under its contract.
Market forecasts should be treated cautiously. ScienceSoft has predicted that AI risks could enter 60%–80% of liability and cyber insurance underwriting by 2028. That is a forecast, not an observed market share, and other industry commentary suggests dedicated AI cover may remain a niche through 2028. The disagreement itself is informative: AI is becoming a standard underwriting question without necessarily becoming a separate, generously funded insurance category. Businesses may therefore receive AI protection through tailored endorsements rather than a product simply called “AI insurance.”
An exclusion can also compound other limits. Suppose a cyber policy covers unauthorized data access, but an autonomous agent sends confidential records because it was manipulated through poisoned instructions. The insurer might examine the definition of the event, the security warranty, the required controls, the exclusion for AI-related loss, and any sublimit for social engineering. Several restrictions could apply at once. This is why the wording must be assessed as a whole rather than searched for one familiar exclusion heading.
Where Coverage Usually Breaks Down
Cyber policies often focus on unauthorized access, accidental damage, ransomware, data restoration, business interruption, and incident response. Those provisions may apply when an AI system is attacked, but the wording may exclude loss arising from the model’s output, failure to correct a hallucination, or decisions made without human approval. The distinction can turn on whether the AI tool was the attacked asset, the means of attack, the cause of a consequential loss, or merely the background technology. Policies are not identical, and a single classification cannot answer every case.
Technology errors and omissions policies generally respond to a technology product failing to perform according to its specifications, subject to contractual warranties and service obligations. They may not cover liability for a model’s biased recommendation, an inaccurate safety assessment, or an agent that violates an instruction. Commercial general liability can respond to certain bodily injury or property damage, but an exclusion for the use or effect of AI could remove that response. Directors and officers policies may include an exclusion for a claim alleging a director relied improperly on AI, particularly where oversight duties are central to the allegations.
Contract terms can create a separate layer of risk. A customer may allege breach of warranty, breach of contract, negligence, discrimination, or statutory violation regardless of what the insurance policy says. An exclusion prevents insurance recovery; it does not prevent the underlying lawsuit. Vendors may also limit liability for model performance, shift responsibility to the customer, or require the customer to provide its own indemnities. Those contractual allocations do not automatically defeat a claim against the customer’s insurer, but they can expose a balance to the business.
| Feature | Standard cyber cover | Tailored AI or agent cover | Technology E&O and liability cover |
|---|---|---|---|
| Primary trigger | Unauthorized access, data loss, ransomware, or covered network compromise | Defined AI or autonomous-agent event, depending on wording | Failure to provide a technology service or legally covered liability |
| Main weakness | AI output and consequential error may fall outside the trigger | Exclusions may be narrow, and available terms can be limited | AI exclusions, warranties, sublimits, and contract alignment may control the response |
| Claims support | Restoration, response, and sometimes business interruption | May include model-specific incident costs or agreed services | Defense, correction, and settlement subject to policy limits |
| Best use | Conventional cyber risk plus some AI-related incidents | Higher-risk, clearly defined deployments | Products and services sold to third parties |
| Evidence needed | Controls, incident chronology, logs, and loss calculation | System scope, autonomy level, testing, and human oversight | Contract, specifications, code, warranties, and causal chain |
A Practical Four-Part Coverage Review
The first step is to create an accurate inventory of AI use. For each system, record the vendor, model, business purpose, deployment date, data accessed, users, downstream providers, and whether a person must approve consequential actions. Agents should be distinguished from ordinary assistants, because an agent may call tools, initiate transactions, change records, or communicate with customers without manual intervention. A review covering only chatbots can miss the systems with greater operational exposure. Even an inventory of 20 tools can be misleading if a forgotten internal model remains in production.
The second step is to gather every policy, endorsement, application, and renewal document. Search for “artificial intelligence,” “machine learning,” “algorithm,” “model,” “automated,” “software,” “data,” and “electronic,” then examine broad phrases such as failure to maintain accuracy. A cyber policy, cloud-services contract, professional indemnity policy, and commercial general liability policy must be read together because exclusions may apply across different contracts. Brokers should be asked whether the answers came from the wording or from general market experience.
The third step is to map each plausible claim to its contractual trigger. For an incorrect credit decision, document the decision maker, the applicable regulation, the policy wording, the warranty, the expected performance, and the resulting financial loss. For an AI-generated security flaw, preserve prompt histories, model versions, tool-call records, access logs, detection times, and remediation evidence. For a bodily injury claim, establish whether the system was part of a product, whether a warranty described safe operation, and whether a product-completed operations exclusion may apply. The causal chain must be supported, not reconstructed from memory after a dispute begins.
The fourth step is to compare the gap with practical alternatives. Self-insured retentions may be appropriate, but they must be affordable and should not be mistaken for full insurance. Security controls can reduce frequency without guaranteeing contractual coverage. A capped professional indemnity policy, a separate agent policy, or a negotiated customer indemnity may fit some risks better than a single policy with a broad AI exclusion. A useful review should produce decisions, owners, and dates—not merely a general recommendation to “buy AI insurance.”
Common Mistakes in AI Risk Management
A frequent mistake is treating model accuracy as the only insurance issue. Accuracy matters, but the record needed to settle a claim also includes design governance, instructions, monitoring, human review, data provenance, and the contractual description supplied to customers. A model can pass ordinary testing and still cause a loss through an unusual prompt, changing data distribution, poisoned retrieval data, or an integration error. Insurance review asks whether the system was managed reasonably and whether the claim falls within the promised service.
Another mistake is assuming that specialist insurance automatically provides broader protection. A product described as cover for AI agents may exclude certain high-impact decisions, regulated activities, pre-existing vulnerabilities, or losses known before inception. The policy can also cap coverage through sublimits, require prior consent before notification, or define “agent” more narrowly than the business does. Marketing language should never substitute for the definitions and conditions in the policy. Prospective buyers should ask for the full wording and sample limits rather than rely on a broker’s summary.
Businesses also make the mistake of reviewing policies after deployment. A late amendment may cost more, carry stricter terms, or leave prior exclusions unresolved. Action is particularly important before a system handles protected information, makes decisions about employment, credit, housing, healthcare, safety, or access to essential services. It is also sensible before a customer requests contractual evidence of insurance and before a financing, audit, or acquisition review raises questions. Waiting for a cyber incident to clarify coverage converts a planning exercise into a dispute over notice, causation, and records.
The final error is buying several overlapping policies without assigning responsibility. A claims-handling rule should identify the broker, legal counsel, security team, business owner, and insurer contacts, with a target of immediate notice and no later than 30 days where the policy or applicable law requires it. Internal reporting within 10 business days can be an operational control, not a substitute for meeting a shorter contractual deadline. Responsibility must be clear because missed notice can jeopardize coverage even when the underlying loss would otherwise be covered.
When to Act and What Pricing to Expect
A coverage review should occur before the next material AI deployment, contract renewal, change in model provider, or launch in another jurisdiction. Organizations should also act promptly if policies were recently renewed without AI wording, a model begins accessing sensitive data, or an agent can execute financial or physical actions. Changes in autonomy can alter the risk materially: recommending a product differs from transferring money, closing an account, controlling equipment, or approving a regulated decision. A system that changes without a new approval process should be treated as a changed exposure, not as the same product with new features.
There is no reliable universal price for “AI insurance.” Premiums depend on revenue, industry, limits, deductibles, geographic reach, model size, deployment method, data sensitivity, autonomy, control maturity, and claims history. A tailored endorsement on an existing policy may cost less than a standalone program, while a heavily regulated deployment may require specialist underwriting and higher limits. ScienceSoft’s 60%–80% projection concerns the share of underwriting in which AI risks may enter, not a premium rate or a promise of coverage. Quotes should therefore be compared on limits, sublimits, exclusions, warranties, and services, rather than on the headline premium alone.
A broker offering AI-related products should explain capacity, commission arrangements, coverage limits, exclusions, and the claims-handling process in writing. Ask which insurer issues the policy, whether the wording is standard or negotiated, what loss figures inform the price, and what changes would trigger endorsement or re-underwriting. Uncertain answers are a reason to request the actual policy. Independent review may be worthwhile for a high-limit or complex deployment, but it should be proportionate to the potential loss rather than treated as an automatic expense.
If coverage is declined or restricted, the next step is risk selection. Limit the system’s permissions, require human approval for high-impact actions, separate production and testing data, log every tool call, and define an incident response for model failure. These measures can reduce exposure, but they do not create insurance coverage. They should be documented because insurers may examine control evidence when setting terms or investigating a claim.
What Good Coverage Should State Explicitly
A useful policy should state whether AI and machine-learning systems are included within an existing definition or covered only by endorsement. It should explain which losses are covered, such as restoration costs, business interruption, liability, defense, correction, third-party service interruption, or incident response. The wording should also state which costs are excluded, including unauthorized use, intentional deployment, failure of the customer to follow instructions, known defects, and output generated without required human review. Silence on these points leaves avoidable interpretation risk.
The definitions must match the business’s architecture. A policy written for machine learning may not address a large language model that interacts with other software. A cyber endorsement may protect an agent while excluding the regulated decision it recommends. An E&O extension may cover the technology supplier while leaving the customer responsible for configuration. For agentic systems, the contract should address tool calls, permissions, unauthorized transactions, third-party APIs, propagation, and the point at which human approval is required. Terms such as “AI-related loss” should not be left to an undefined dispute.
Financial terms deserve equal attention. Confirm aggregate limits, per-event limits, sublimits, deductibles, coinsurance if any, and whether defense costs erode the limit. Establish whether the insurer pays first-party restoration and interruption, third-party liability, both, or selected combinations. Also check the claims-reporting period, prior-knowledge treatment, consent-to-settle terms, and dispute-resolution provisions. These details often matter more than the product’s name.
The best outcome is not a policy with zero AI exclusions. It is a contract whose accepted risks, excluded risks, financial ceiling, and claims process fit the organization’s actual use of the technology. AI-related exclusions are manageable when identified before deployment and matched to specific controls or alternative contracts. The governing principle is simple: treat the wording as a technical and financial control, then test it against real system behavior and plausible loss scenarios.