Does my business insurance cover AI errors? The 2026 policy-by-policy guide.
The question sounds simple. The answer requires going through every major policy type your business holds and checking what the current wording actually says, because the market shifted materially in January 2026 when new ISO exclusion endorsements took effect. This is the definitive reference for SME operators, operations leads, and their brokers. It covers seven policy types, two new exclusion forms, a decision table, named carriers on both sides of the market, real case precedent, and an eight-step renewal checklist. It will be updated as the specialist market develops.
Key takeaways
- From January 2026, Insurance Services Office (ISO, operated by Verisk) made three new AI exclusion endorsements available for Commercial General Liability policies: CG 40 47 (full AI exclusion), CG 40 48 (Coverage B only), and CG 35 08 (products and completed operations). Carriers can now exclude generative AI from CGL policies entirely using standardised forms.[1]
- Several management liability and professional lines carriers, W.R. Berkley among them, are reported to have filed absolute AI exclusions reaching D&O, E&O and fiduciary liability. We do not print those form numbers. None of the carriers publishes the form, and the published accounts contradict each other on what at least one of them is.[2]
- AIG, Great American and Philadelphia Indemnity have filed their own AI exclusion language with state regulators, independently of the ISO forms. Hamilton Insurance Group is reported to have done the same, in a form not confirmed at source.[3]
- The British Columbia Civil Resolution Tribunal ruled in Moffatt v. Air Canada (February 2024) that a business is liable for its AI agent's misrepresentations to customers. The airline's argument that its chatbot was a separate legal entity was rejected.[4]
- HSB, a Munich Re subsidiary, launched AI Liability Insurance for small and medium businesses on 18 March 2026, distributed through partner carriers rather than directly.[5]
- Armilla, a Lloyd's coverholder with capacity from Chaucer Group, launched affirmative AI liability insurance on 30 April 2025. It does not publish standard limits.[6]
- The precedents that already exist are small in money and large in principle. Moffatt v. Air Canada cost the airline CAD 812.02. The EEOC's iTutorGroup settlement cost $365,000 and covered more than 200 rejected applicants. Neither sum would trouble a balance sheet; both establish that the operator answers for the system.[4]
Section 1: The short answer
For most SMEs running AI agents in 2026: no, your existing business insurance is unlikely to cover AI errors cleanly, and the gap is growing. Your Commercial General Liability policy may have been updated with new ISO exclusion endorsements effective January 2026 that remove AI claims entirely. Your Errors and Omissions policy was almost certainly written before autonomous agents existed and its wording is ambiguous at best on AI-generated outputs. Your cyber policy is built around data breaches, not the consequences of an agent giving wrong advice. Your Directors and Officers policy may face new absolute AI exclusion language, which several management liability carriers are reported to have filed. The only exception is if your broker has specifically reviewed your AI exposure and confirmed coverage, or if you have obtained specialist AI liability coverage from one of the new entrants. The rest of this article explains exactly how each policy type works, what the current exclusion language says, and what to do about it.
Section 2: Seven policies your business probably holds, and how each treats AI in 2026
Commercial General Liability (CGL)
CGL policies are the baseline commercial coverage most businesses hold. They are designed to cover bodily injury, property damage, and personal and advertising injury claims from third parties, the standard scenarios being a customer slipping in your premises or your marketing making a defamatory claim about a competitor.
Until January 2026, AI claims under CGL were handled through general policy wording without specific AI provisions. That changed when Verisk (which operates Insurance Services Office, the body that produces the standardised policy forms most carriers use) made three new AI exclusion endorsements available for optional carrier adoption.[1]
The two main forms are CG 40 47 01 26, which removes both Coverage A and Coverage B for claims arising from generative AI, and CG 40 48 01 26, which removes only Coverage B. At least six major carriers filed to adopt these forms or equivalent proprietary language shortly after the forms were released.[1] If your carrier has adopted CG 40 47, the gap is substantial: bodily injury, property damage, and personal and advertising injury claims from AI outputs are all excluded.
Even without the new endorsements, CGL has significant limitations for AI scenarios. CGL does not respond well to pure economic loss claims, which is the most common category of AI agent harm. If your booking agent overcharges a customer, that is economic loss. If your advisory agent gives wrong investment guidance, that is economic loss. CGL was not designed for these cases, and adding AI exclusions makes the gap more explicit rather than creating a new problem.
The gap in plain terms: If your CGL carrier adopted CG 40 47, virtually no AI-related claim will be covered. If it has not yet adopted the new forms, your CGL still has limited value for the most common AI harm scenarios because they typically do not involve bodily injury or property damage.
Professional Liability (Errors and Omissions)
E&O policies are designed for businesses that provide professional services and can be held liable when those services are performed incorrectly. They are the most relevant existing policy type for businesses running AI agents that advise, recommend, book, communicate, or otherwise act on behalf of clients.
The challenge in 2026 is not a blanket exclusion, at least not yet for most carriers, but rather deep ambiguity. E&O policies were written before AI agents existed in their current form. The question of whether an AI agent's output constitutes a covered professional service has not been settled by a court in a case involving a standalone AI agent. The Air Canada chatbot case (Moffatt v. Air Canada, BC Civil Resolution Tribunal, 2024) established liability at the operator level but did not directly address insurance coverage allocation.[4]
W.R. Berkley is reported to have filed an absolute AI exclusion reaching professional lines including E&O, excluding any claim arising from the use, deployment or development of artificial intelligence.[2] We removed the form number and the detailed description of its wording from this article on 17 August 2026. The reporting is from serious law firms, but it is secondary, the accounts disagree on whether the instrument is an exclusion or an affirmative grant, and W.R. Berkley publishes no forms library. If W.R. Berkley paper sits on your programme, ask your broker for the endorsement itself.
On the other side, Counterpart added affirmative AI coverage and a technology errors and omissions insuring agreement across its miscellaneous professional liability and allied health products, announced 24 November 2025.[9] Embroker attached an AI coverage endorsement to eligible technology E&O and cyber quotes with effect from 5 August 2025. Hiscox has been reported as revising its technology professional liability wording for AI; hiscox.com publishes nothing about AI cover or AI exclusions in that product, so we state the report and not the coverage.
The gap in plain terms: If your E&O policy has been updated with W.R. Berkley-style absolute AI exclusion language, professional liability from AI agents is uninsured. If the wording is older and ambiguous, coverage at claim time depends on how your insurer interprets language written before your agent existed. Neither position is comfortable.
Technology E&O
Tech E&O is the professional liability product most often held by technology companies and software businesses. It extends E&O coverage to technology products and services, including claims arising from software failures, data processing errors, and system downtime.
Tech E&O is in some ways a better fit for AI agent claims than general E&O because it is already designed for technology-enabled service delivery. However, the same ambiguity problem applies. Tech E&O wordings typically cover technology services delivered by the insured, and whether a third-party AI model accessed via API constitutes the insured's own service has not been settled.
The vendor liability gap is particularly acute here. If you deploy a third-party AI model, any claim against you that exceeds the vendor's contractual liability cap falls to your Tech E&O. Carriers have reportedly been denying these claims when the insured lacks independent validation or supervision of the AI model it deployed.[3] The practical implication is that governance documentation is not just regulatory good practice but a direct condition of coverage response in contested claims.
Corgi is a full-stack AI-native carrier writing technology and AI liability for technology companies, alongside D&O, E&O, cyber and general liability.[10] It is built for venture-backed software businesses rather than for a general SME, and it publishes no rate information.
The gap in plain terms: Tech E&O is the most likely of the traditional policy types to respond to AI agent claims, but the wording was not written for autonomous agents and the vendor liability gap is real. If you are deploying a third-party model without documentation of independent oversight, a claim could be denied on that basis.
Cyber Liability
Cyber policies were built to cover data breaches, network failures, ransomware, and related first-party and third-party losses. They were not built for AI agent errors. The distinction matters because AI-generated harm is categorically different from cyber harm: it typically does not involve a breach of security, an attack by a third party, or an unauthorized access event.
An AI agent that gives a customer incorrect medical information is not a cyber event. An AI agent that books the wrong flights is not a cyber event. An AI agent that generates content that defames a third party is not a cyber event. These are liability events of a different kind, and cyber policy triggers simply do not reach them.
That said, the cyber market is moving. Some carriers are adding AI-specific riders that cover first-party and third-party losses from AI-driven actions including prompt injection, model manipulation, and automated decision errors. These riders introduce definitions of terms like machine learning, data poisoning, and hallucinations, and extend coverage to AI-related incidents that fall outside traditional cyber scope. The specific coverage depends entirely on the wording of the rider, and sub-limits are typical.
QBE North America has published AI-focused cyber endorsements running the other way: one for AI regulatory compliance exposure, meaning fines, penalties and defence costs under emerging AI regulation, and one for LLMjacking, where an attacker uses stolen credentials to run up compute on your cloud-hosted model.[8] QBE does not publish a limit or a sublimit for either. An earlier version of this article carried percentage and monetary figures for AI sublimits at two named London cyber carriers. Those came from trade summaries rather than from either carrier, and we removed them on 17 August 2026 rather than restate them here. Neither carrier publishes a sublimit. The withdrawn wording is recorded in the corrections log. The pattern that holds is that cyber carriers are managing AI exposure deliberately rather than leaving it silent, and a managed grant usually means a sublimit, so ask what yours is.
The gap in plain terms: Standard cyber does not cover AI agent output errors. If your cyber carrier has added an AI rider, read the specific trigger carefully. It will not cover most of what an AI agent does when it makes a mistake.
Directors and Officers (D&O)
D&O policies protect directors and senior officers against personal liability arising from decisions made in that capacity. As AI deployment becomes a board-level strategic decision rather than a purely operational one, D&O exposure to AI-related claims is growing.
The exposure has two primary forms. First, shareholder or investor claims arising from inadequate board oversight of AI risk, including failure to disclose AI exposure in a prospectus or misrepresenting the company's AI governance posture. Second, regulatory claims arising from board-level failures to comply with AI-specific obligations, particularly as the EU AI Act assigns governance duties to deployers.
The most significant development in the D&O space is that absolute AI exclusions are being drafted for management liability rather than only for general liability. W.R. Berkley is the carrier most often named.[2] Where such an exclusion is attached, board-level AI liability is uninsured, and the reach can extend past AI-caused loss to the governance of an AI programme and to what the company has said publicly about it. That is why the definition of artificial intelligence in the endorsement matters more than the heading: a broad definition catches predictive scoring and automated decisioning as well as generative tools. Ask for the endorsement.
A wider point matters more than any single carrier name. The scenarios most likely to generate significant D&O or E&O exposure are systemic ones, where a single model failure reaches many customers at once, and systemic exposure is exactly what carriers manage hardest because it defeats the diversification insurance depends on. Where a carrier grants AI cover, read the wording for an aggregation or widespread-event carve-out before you read the limit. We have removed a previous description of one named carrier's carve-out because we could not confirm it in that carrier's own documentation.
The gap in plain terms: Traditional D&O may respond to isolated AI governance failures, but absolute AI exclusion language is entering the market. Systemic failures and regulatory investigations linked to AI are increasingly being carved out. Board-level AI liability without specialist D&O coverage is materially underinsured.
Media Liability
Media liability policies protect businesses that create and publish content against defamation, copyright infringement, misappropriation, and invasion of privacy claims. They are most commonly held by publishers, agencies, marketing firms, and media companies.
AI content generation creates a direct and acute media liability problem. An AI model can generate defamatory claims without the publisher knowing, reproduce copyrighted material without attribution, or create content that invades privacy by combining publicly available information in ways the subject has not consented to. The frequency of these outputs is far higher with AI than with human content production.
The new ISO CG 40 48 01 26 exclusion specifically removes Coverage B (personal and advertising injury) from the CGL policy for claims arising from generative AI. For businesses that held the view their CGL would respond to defamation from AI-generated marketing copy, CG 40 48 removes that assumption.[1]
Media liability policies may still respond, depending on wording, because they are built specifically for content liability rather than as catch-all commercial policies. However, these policies are seeing increased scrutiny from carriers regarding AI-generated content, and the exclusion trajectory from the CGL market is likely to influence media liability renewals.
The gap in plain terms: CGL coverage for AI-generated defamation and advertising injury is being removed by the new ISO endorsements. If you produce content with AI tools, your media liability policy needs to explicitly address AI-generated content, and this is worth confirming with your broker at renewal.
Employment Practices Liability (EPL)
EPL policies cover claims of wrongful termination, discrimination, harassment, and related employment-related allegations. They are the policy type most directly implicated by AI use in HR processes: hiring screening, performance review, scheduling, and workforce reduction decisions.
EPL policies generally respond to employment wrongful act claims regardless of whether the act was performed by a person or an algorithm, because the claim is framed around the protected characteristic and the harm rather than the decision mechanism. This means EPLI remains one of the more reliable existing policies for AI-related exposure.[12]
However, the exposure is growing in scale. In 2023 the US Equal Employment Opportunity Commission settled its first AI hiring discrimination suit, against iTutorGroup, for $365,000. The company's tutor application software was programmed to reject female applicants aged 55 or older and male applicants aged 60 or older automatically, and the EEOC alleged more than 200 qualified US-based applicants were rejected on that basis. The Commission's then chair put the principle plainly: even when technology automates the discrimination, the employer is still responsible.[12] AI-driven decisions operate at a scale that human HR decisions rarely reach. A biased algorithm can discriminate against thousands of candidates before anyone notices. The class exposure created by a single biased AI model is orders of magnitude larger than the equivalent human error.
New York City's law requiring annual bias audits of automated employment decision-making tools, and similar legislation in California and Colorado, is creating a compliance obligation that will increasingly be tested against EPL coverage at claim time.[12]
The gap in plain terms: EPLI is the most likely of the traditional lines to respond to AI-related employment claims, but the scale of exposure from AI-driven HR tools is significantly larger than legacy EPL was designed to handle. Class exposure from a biased algorithm is categorically different from individual human discrimination claims.
Section 3: The named AI exclusion endorsements
The most significant structural change to the traditional insurance market in 2026 is the introduction of ISO's standardised AI exclusion endorsements. These were released by Verisk's ISO Core Lines Services in January 2026 as part of a multistate CGL filing.[1] They are optional, meaning carriers choose whether to adopt them, but the carrier interest was strong from the start.
CG 40 47 01 26: Exclusion for Generative Artificial Intelligence
This is the broad form. It applies to the entire ISO Commercial General Liability Coverage Part and excludes claims under both Coverage A (bodily injury and property damage) and Coverage B (personal and advertising injury) where the claim arises from generative artificial intelligence.
The definition of generative artificial intelligence in the form reads: "a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code."[1]
The trigger language is "arising out of," which is significant. In insurance law, "arising out of" is interpreted broadly to require only a causal connection rather than direct causation. A claim does not need to be directly about an AI output; it only needs to have a causal link to one. For businesses that use generative AI in any customer-facing capacity, this is a wide exclusion.
A parallel form, CG 35 08, applies the same logic to the products and completed operations coverage extension, ensuring that AI-related claims arising from products the business sells are also excluded under the same terms.
CG 40 48 01 26: Exclusion for Generative Artificial Intelligence (Coverage B Only)
This is the narrower form. It removes only Coverage B, which covers personal and advertising injury including defamation, privacy invasion, and advertising-related claims. Coverage A (bodily injury and property damage) is preserved.
The Coverage B exclusion uses the same definition of generative AI and the same "arising out of" trigger language as CG 40 47. For businesses primarily concerned about defamation, misrepresentation, or copyright claims from AI-generated content, CG 40 48 removes their most likely coverage pathway. For businesses deploying AI in physical settings where bodily injury remains a realistic scenario, Coverage A survival under CG 40 48 may be meaningful.
The practical choice between the two forms reflects a carrier's overall risk appetite for AI exposure. Carriers adopting CG 40 47 are leaving the AI segment of CGL entirely to the specialist market. Carriers adopting CG 40 48 are managing their most contentious AI exposure while retaining some market relevance for AI-adjacent physical risk.
Carrier adoption
Several carriers are reported to have filed proprietary AI exclusion language with state regulators independently of the ISO forms, AIG, Great American, Philadelphia Indemnity, Cincinnati Financial and Frederick Mutual among them, and W.R. Berkley to have gone furthest by extending beyond general liability to D&O, E&O and fiduciary lines.[2] All of that reaches us through law-firm and trade analysis rather than through the carriers, none of whom publishes the forms. Treat the names as a prompt for a question to your broker, not as a finding about your policy.
These are not the only carriers moving in this direction. The trajectory from Verisk's filing and the rapid carrier adoption confirms that AI exclusions in traditional commercial lines are not an experiment. They are the default position of a significant portion of the market.
Section 4: A decision table
| Policy type | AI coverage status (April 2026) | Exclusion risk | Operator action |
|---|---|---|---|
| CGL (Coverage A + B) | Potentially eliminated if CG 40 47 adopted | High | Confirm with carrier whether CG 40 47, CG 40 48, or CG 35 08 have been attached. Do not assume. |
| CGL (Coverage B only) | Excluded if CG 40 47 or CG 40 48 adopted | High | Defamation and advertising injury from AI-generated content is the first claim type to be cut. Confirm with broker. |
| E&O / Professional Liability | Ambiguous; exclusion entering from W.R. Berkley-style forms | Medium-High | Request a written review of AI treatment in current E&O wording. Ask whether any carrier AI exclusion is attached, and for the endorsement itself. |
| Tech E&O | Best fit of traditional lines; still ambiguous on third-party AI | Medium | Document governance and oversight of all AI models in use. Vendor liability gap is real if you deploy without independent validation. |
| Cyber Liability | Does not cover AI output errors by design; AI riders narrow and sub-limited | High (for output errors) | Do not rely on cyber for AI agent output errors. Check if rider exists and read its trigger language carefully. |
| D&O | Carrier-drafted absolute AI exclusions entering the market; systemic-event carve-outs appearing in AI grants | High for AI-related board liability | Check D&O policy for AI exclusion endorsements. Confirm with broker whether board-level AI governance failures are covered. |
| Media Liability | CGL Coverage B removed by CG 40 48; dedicated media liability ambiguous on AI | Medium-High | If you use AI for content production, confirm with your media liability carrier how it treats AI-generated defamation and copyright claims. |
| Employment Practices (EPL) | Most likely traditional line to respond; scale exposure is the risk | Lower for individual claims | Confirm EPL covers automated decision-making. Run bias audits on AI hiring tools. Scale exposure may exceed traditional EPL limits. |
| Standalone AI Liability | Available from HSB, Armilla, Testudo, Counterpart (limited, SME and enterprise focus) | Purpose-built for this risk | Engage broker to obtain indications. Requires governance evidence. Start Agent Certified self-assessment at agentcertified.eu. |
Section 5: How carriers are responding, the bifurcation
The insurance market's response to AI risk in 2026 has split into two distinct movements running in parallel. On one side, traditional carriers are tightening policy language and introducing exclusions. On the other, a set of specialist programmes has entered the market to fill the gaps those exclusions create.
Carriers tightening language
W.R. Berkley is the carrier most often named as moving first on an absolute AI exclusion across D&O, E&O and fiduciary liability.[2] We no longer print the form number or describe its wording. See the sourcing note at the top of this article.
AIG, Great American and Philadelphia Indemnity filed proprietary AI exclusion language with state regulators for management liability policies.[3] Cincinnati Financial and Frederick Mutual filed exclusion language in parallel with the ISO forms.[1]
Systemic-event carve-outs are appearing in AI grants across the market, limiting or removing cover where one model failure affects many insureds at once. We previously attributed a specific carve-out to a named carrier on the strength of a secondary summary and removed that attribution on 17 August 2026. Read your own grant for aggregation and widespread-event language.
QBE North America has published affirmative AI-focused cyber endorsements for AI regulatory compliance and for LLMjacking rather than an AI exclusion.[8] It publishes no sublimit for either.
Specialist carriers building dedicated AI coverage
HSB (Hartford Steam Boiler), a Munich Re subsidiary and specialty insurer, launched AI Liability Insurance for small and medium businesses in March 2026.[5] The product covers bodily injury, property damage, and advertising injury from AI-generated content including advertising, marketing, blogs, and social media. It is designed to fill the gap left by CGL exclusions. Distribution is through partner insurance carriers rather than direct to businesses, meaning access comes through existing broker relationships with HSB's carrier partners.
Armilla, the first Managing General Agent dedicated exclusively to AI liability, launched as a Lloyd's of London coverholder underwritten by Chaucer in April 2025.[6] Its policy provides affirmative coverage for AI application failures including critical errors, hallucinations, and inaccuracies causing damages. Armilla does not publish standard limits for its standalone AI Liability Policy; limits are agreed per submission. Coverage includes AI regulatory violations, non-breach privacy incidents, data leakage, AI model error liability, harmful outputs, AI agent failures, AI-driven property damage, and defence costs under new AI regulations including the EU AI Act and Colorado AI Act.
Testudo launched in January 2026 as a claims-made product targeting middle to large enterprises deploying generative AI.[13] The company uses proprietary litigation data and risk signals to assess generative AI liability exposure. Testudo does not publish its capacity. Testudo UK Limited is an Appointed Representative of Pro MGA Solutions Ltd and is regulated by the Financial Conduct Authority.
Munich Re aiSure is a performance guarantee for AI systems, settling on measurable performance data covering proven AI errors, and is a named AI risk product from a tier-one reinsurer.[14] It settles on measurable performance data rather than through loss adjustment, making it better suited to AI vendors and corporate AI developers than to SMEs deploying third-party models. The February 2026 partnership with Mosaic extended initial coverage to EUR/USD/CAD 15 million for AI developers and vendors worldwide.
AIUC (Artificial Intelligence Underwriting Company) emerged from stealth in July 2025 with a $15 million seed round led by Nat Friedman, with participation from Emergence, Terrain, and angel investors including Anthropic cofounder Ben Mann.[15] AIUC's model combines independent audits that test real-world performance with insurance coverage, pricing the policy to reflect how safe the audited system is. The AIUC-1 standard is the first certification standard designed specifically to underwrite AI agent deployments.
Counterpart expanded affirmative AI coverage in November 2025, adding a Technology E&O Insuring Agreement to its Miscellaneous Professional Liability products.[9] This makes Counterpart one of the few carriers in the professional liability segment explicitly affirming AI coverage rather than introducing exclusions.
Corgi is a full-stack AI-native carrier writing technology and AI liability for technology companies alongside D&O, E&O, cyber and general liability.[10] It targets venture-backed and high-growth software businesses, and publishes no rate information.
Section 6: What to do at your next renewal
The eight steps below are written for an SME operator or operations lead managing an insurance renewal without specialist AI insurance knowledge. Complete them in order. Each one is contingent on the previous.
Step 1: Catalogue every AI agent or automated system in production. List each one by name, describe what it does, what outputs it generates, what systems it interacts with, and which customers or third parties it reaches. This list is the foundation of every conversation that follows and is also what a specialist underwriter will ask for at the start of an application.
Step 2: Request your full policy schedules and endorsement lists. Ask your broker for the complete wording of every endorsement attached to your CGL, E&O, cyber, and D&O policies. The declarations page alone is not enough. The exclusions that matter are in the endorsements, not in the base policy form.
Step 3: Check your CGL for ISO AI exclusion endorsements. Look for CG 40 47, CG 40 48, or CG 35 08 in the endorsement schedule. If any of these are attached, note whether the carrier is using the ISO form or proprietary equivalent language. Confirm the effective date. If your renewal was after January 2026, assume these forms may have been added and verify.
Step 4: Send a written AI coverage request to your broker on each policy. Frame each request as follows: "Given that our business operates [name of agent], which [describe what it does], please confirm in writing how our [policy type] responds to a claim arising from that agent's outputs. Reference any exclusions by endorsement number and section." Do not accept a verbal answer. Do not proceed until you have written confirmation on each policy.
Step 5: Map the coverage responses against your agent catalogue. For each agent, determine whether a claim arising from its actions would be covered, excluded, or ambiguous. This produces a gap map. Any agent in the excluded or ambiguous column is your priority for the next steps.
Step 6: Approach specialist AI liability carriers for indications. Ask your broker to obtain preliminary indications from HSB (for SME coverage), Armilla (Lloyd's-backed), Testudo (enterprise focus), and Counterpart (professional liability with AI affirmation). The suitability depends on your sector, agent type, and scale.
Step 7: Start the Agent Certified evidence file. Specialist AI underwriters require documented evidence of governance, oversight, and scope before they will quote. The Agent Certified self-assessment at agentcertified.eu is structured around the seven dimensions underwriters ask about. Starting this process before you approach carriers, rather than during the application, gives you a stronger submission and a faster path to a binding indication.
Step 8: Document the outcome and set a review cadence. Record the coverage position for each agent, note any gaps you have accepted and why, and schedule the next review before your next renewal date or whenever a new agent goes into production. The AI insurance market is changing quarterly. A review you completed in January 2026 may be materially out of date by July 2026.
Section 7: Real incidents and what they cost
Moffatt v. Air Canada (BC Civil Resolution Tribunal, 2024)
On 14 February 2024, the British Columbia Civil Resolution Tribunal issued its decision in Moffatt v. Air Canada, a case that has become the most cited precedent in discussions of AI agent operator liability.[4]
The facts are straightforward. Jake Moffatt, travelling to Ontario following the death of a family member, consulted Air Canada's customer service chatbot to ask about bereavement fares. The chatbot stated that bereavement fare refunds could be claimed retroactively after travel was completed. That was incorrect. The airline's actual policy required the request before travel. When Moffatt claimed the refund and was refused, he brought a claim to the tribunal.
Air Canada argued it could not be held liable for information provided by the chatbot, positioning the chatbot as a separate legal entity from the airline itself. The tribunal rejected this argument directly. Member Christopher Rivers wrote that it was unclear why Air Canada would suggest that the chatbot is a separate legal entity that is responsible for its own actions. Air Canada cannot deny responsibility for information provided by one of its agents.
The award was modest by any corporate standard: the tribunal ordered Air Canada to pay CAD 812.02 in damages plus filing fees, representing the difference between the bereavement fare Moffatt should have paid and the price he actually paid, plus the additional amount he paid to request the reduced fare after the fact.
The amount is not the point. The principle established is. Any business operating a customer-facing AI agent is bound by the representations that agent makes. The disclaimers that many businesses attach to their chatbot interfaces (stating that the AI may produce incorrect information and that customers should verify) do not dissolve the liability. The operator is responsible.
For insurance purposes, the Moffatt decision is relevant because it confirms that AI agent output creates real legal obligations. The coverage question that follows is whether the policy that responds to a human employee's negligent misrepresentation also responds to an AI agent's negligent misrepresentation. Under traditional E&O wordings, the answer is genuinely uncertain.
Mata v. Avianca, Inc. (S.D.N.Y., 2023)
On 22 June 2023, Judge P. Kevin Castel of the US District Court for the Southern District of New York sanctioned attorneys Peter LoDuca and Steven A. Schwartz of Levidow, Levidow and Oberman, imposing a $5,000 fine jointly and ordering that their clients be notified.[16]
The case arose from a 2022 personal injury claim by Roberto Mata against Avianca. Counsel Schwartz used ChatGPT to research and draft a legal motion. The motion contained six judicial decisions that did not exist. They had been fabricated by the AI tool. When Avianca's attorneys reported that they could not locate the cited cases, the court ordered the plaintiffs' attorneys to provide copies. None could be produced, because none existed.
Schwartz testified at the sanctions hearing that he had operated under the belief that the AI tool could not possibly be fabricating cases on its own. Judge Castel described one of the AI-generated legal analyses as gibberish.
The professional responsibility principle the case establishes extends well beyond legal practice. Every profession that relies on AI-generated information for client deliverables carries equivalent exposure. A financial adviser whose AI tool fabricates market data, an accountant whose AI tool generates incorrect regulatory references, a medical practice whose AI tool describes incorrect dosages: the Mata principle is that the AI tool is not a defence. The professional's standard of care does not lower because AI was involved in producing the output.
For operators thinking about E&O coverage: the Mata case supports the argument that E&O should respond to AI-related professional failures on the same basis as human failures, because the professional standard of care is unchanged. However, if an E&O carrier has adopted AI exclusion language that removes coverage for claims arising from the use of AI tools, the Mata principle reinforces operator liability while the exclusion simultaneously removes the coverage intended to protect against it.
EEOC AI Hiring Discrimination Settlement (2023)
In 2023, the US Equal Employment Opportunity Commission settled its first enforcement action involving AI-powered hiring discrimination. The company's AI tool had automatically rejected job applicants above a certain age, affecting more than 200 candidates. The settlement was $365,000.[12]
The case illustrates the scale multiplier that AI introduces to employment discrimination liability. A human recruiter with an age bias might affect dozens of applications over a career. An AI system with an equivalent bias can affect thousands of applications in a single recruitment cycle. The EPL exposure from AI-driven HR is not categorically different from traditional employment discrimination, but the scale of the exposure is.
Section 8: The move from generalist to specialist coverage
The structural shift described above, with traditional carriers narrowing their AI exposure and specialist carriers building new products to fill those gaps, is not a temporary market dislocation. It reflects a genuine underwriting logic. Traditional policy forms were built around risks that are relatively well-modelled: slips and falls, professional mistakes by named individuals, data breaches from external attackers. AI agents introduce a risk profile that does not map cleanly onto those models.
Specialist AI carriers approach the problem differently. Rather than retrofitting traditional wording, they are building underwriting criteria around AI-specific risk indicators: the governance structure around the agent, the oversight mechanisms in place, the quality of the training data, the documentation of scope and constraints, and the track record of the model in production.
The table below summarises the specialist carriers currently active in this space and the coverage profiles they offer.
| Carrier | Launched | Limits | Target market | Key coverage |
|---|---|---|---|---|
| HSB (Munich Re subsidiary) | March 2026 | Via partner carriers | SMEs; distributed through partner insurers | Bodily injury, property damage, advertising injury from AI-generated content; fills CGL exclusion gap |
| Armilla (Lloyd's coverholder with Chaucer) | April 2025 | Set per submission | Enterprises deploying custom AI models; organisations lacking E&O AI coverage | Hallucinations, model error liability, harmful outputs, AI agent failures, regulatory violations, AI-driven property damage, EU AI Act defence costs |
| Testudo (underwritten at Lloyd's) | January 2026 | Set per submission | Mid-to-large enterprises deploying generative AI | Third-party claims from AI-generated outputs; specific coverage for CGL GenAI exclusion gap; claims-made basis |
| Munich Re aiSure | 26 February 2026 (Mosaic partnership) | Up to EUR/USD/CAD 15 million initial capacity | AI vendors and corporate developers deploying named AI models | Parametric performance insurance triggered by measurable AI model failures; prediction errors, calibration drift, fraud detection failures |
| AIUC | July 2025 (stealth exit) | Varies by audit outcome | AI agent deployers; pricing based on audit results | Coverage tied to AIUC-1 certification standard; priced to reflect assessed safety of the specific system |
| Counterpart | November 2025 (expansion) | By programme | Professional services; allied health; technology companies | Affirmative AI coverage in MPL and Tech E&O; one of few carriers explicitly affirming rather than excluding |
| Corgi Insurance | July 2025 (regulatory approval) | By programme | Venture-backed and high-growth technology companies | AI liability as named category alongside D&O, E&O, cyber, CGL in bundled programme |
The practical implication for operators is that the path to coverage now requires two conversations instead of one. The first is with your existing broker to understand what your current policies cover and exclude. The second is with the specialist market to understand what is available to fill the gaps. Both conversations need to happen before your next renewal, not during it.
Section 9: Frequently asked questions
Will my cyber policy cover an AI hallucination that causes financial loss?
In most cases, no. Standard cyber policies are designed around data breaches and network failures. An AI hallucination that causes a customer financial loss, for example by quoting the wrong price or giving incorrect advice, falls into professional liability territory, not cyber. Some carriers are adding AI-specific riders to cyber policies that extend cover to certain AI-driven outputs, but these carry sub-limits and vary significantly by wording. Check whether your cyber policy includes an AI or automated decision extension and what the specific trigger conditions are.
Does the ISO CG 40 47 exclusion apply to my E&O policy?
No. ISO CG 40 47 and CG 40 48 are Commercial General Liability endorsements. They apply to CGL policies, not to professional liability or Errors and Omissions policies. However, E&O carriers are introducing their own AI exclusion language independently. W.R. Berkley, for example, is reported to have filed a standalone absolute AI exclusion covering D&O, E&O and fiduciary liability policies. Check your E&O renewal for any AI exclusion language, which will typically appear as an endorsement or schedule item, not under the CGL endorsement numbering.
Is Munich Re aiSure available for SMEs?
Munich Re aiSure is an AI performance insurance product designed primarily for AI vendors and corporate adopters deploying AI at scale. It is not a retail SME product. The related SME product is from Munich Re's subsidiary HSB, which launched an AI Liability Insurance product in March 2026 distributed through partner carriers rather than directly to businesses. If you are an SME, HSB's product is the more relevant Munich Re offering. aiSure is aimed at AI model developers who need to back the performance of a specific model with financial coverage.
What happens if my AI agent gives wrong advice to a customer?
You are likely liable for that advice. The British Columbia Civil Resolution Tribunal ruled in Moffatt v. Air Canada (February 2024) that a business cannot disclaim what its AI agent says to a customer. The tribunal rejected Air Canada's argument that the chatbot was a separate legal entity. Under this precedent, incorrect advice from a customer-facing AI agent binds the business in the same way as advice from a human employee. Whether your insurance responds depends on the specific wording of your E&O or professional liability policy and whether it has been endorsed to cover AI-generated outputs.
What is the difference between CG 40 47 and CG 40 48?
Both are ISO standard endorsements introduced effective January 2026 for Commercial General Liability policies. CG 40 47 is the broader exclusion: it removes coverage under both Coverage A (bodily injury and property damage) and Coverage B (personal and advertising injury) for claims arising from generative artificial intelligence. CG 40 48 is narrower: it removes only Coverage B, preserving some potential for bodily injury and property damage claims to be considered under Coverage A. Carriers adopting CG 40 47 are eliminating substantially all AI-related CGL coverage. Carriers adopting CG 40 48 are taking a more targeted approach.
Does my D&O policy cover claims from AI deployment decisions?
Traditional D&O policies may respond to shareholder or investor claims arising from board decisions about AI, such as failing to disclose AI risks or deploying AI without adequate governance. However, W.R. Berkley and other management liability carriers are reported to have filed absolute AI exclusions for D&O, which eliminate coverage for any claim arising from the use, deployment or development of AI. We do not print those carrier form numbers: none of the carriers publishes the form and the published accounts disagree on what at least one of them is. If your D&O carrier has adopted this type of exclusion, AI-related board liability is uninsured under that policy. Request a copy of all endorsements at your next renewal.
Which carriers are currently writing standalone AI liability insurance?
As of April 2026, the main carriers writing standalone AI liability include Armilla (Lloyd's coverholder with Chaucer Group capacity, affirmative AI liability), Testudo (generative AI liability underwritten at Lloyd's, targeting enterprises), and HSB (Munich Re subsidiary, launched March 2026, distributed through partner carriers, designed for SMEs). Counterpart has also expanded affirmative AI coverage in its professional liability and Tech E&O products. AIUC combines certification, auditing, and insurance in a single framework.
Can I rely on my existing E&O policy to cover claims from AI-generated professional advice?
Not reliably. Many E&O policies were written before AI agents existed and their wording is ambiguous on AI-generated outputs. The key questions to answer are whether your policy covers professional services delivered by automated systems, whether there is an AI exclusion in the current endorsement schedule, and how the policy defines a covered professional act. Some carriers are adding affirmative AI language that explicitly covers AI-assisted professional services. Others are adding exclusions. Without reviewing the current wording, you cannot know which side of that divide your policy sits on.
Does my employment practices liability policy cover AI hiring discrimination claims?
Employment practices liability policies generally cover discrimination claims regardless of whether the decision was made by a person or an automated system, because the claim is framed around the employment wrongful act rather than the technology used. The EEOC's first AI-related discrimination settlement in 2023, worth $365,000, involved an AI hiring tool that rejected candidates based on age. The risk for EPLI holders using AI in hiring is that AI can replicate bias at scale, creating larger class exposure than equivalent human decisions would. Check that your EPLI policy covers algorithmic and automated decision-making as well as direct human discrimination.
What should I do before my next renewal if I am running AI agents in my business?
Before your next renewal, take these steps. Request a written summary from your broker on how each of your current policies (CGL, E&O, cyber, D&O) responds to a claim arising from an AI agent. Ask specifically whether any AI exclusion endorsements have been added since your last renewal. Document what your AI agents do, what outputs they generate, and what human oversight exists. If you find uninsured gaps, ask your broker to approach specialist AI liability carriers including HSB, Armilla, and Testudo. Start the Agent Certified process at agentcertified.eu, which is the evidence framework underwriters are beginning to require.
Section 10: Related reading
On this site:
- AI policy exclusions: what SME operators must review before their next renewal, a focused guide to the four exclusion types that are most likely to affect your current coverage.
- Five questions to ask before deploying an AI agent in your business, the pre-deployment checklist that matches what insurers and certification bodies will ask for.
- The Air Canada chatbot case: what SME operators should learn, the full story of Moffatt v. Air Canada and its implications for operators running customer-facing agents.
- Mata v. Avianca: what AI hallucination in legal proceedings teaches every operator, the sanctions case and the professional responsibility principle it establishes.
Across the network:
- agentliability.eu, the regulatory desk for the EU AI Act, Product Liability Directive, and operator-level compliance obligations coming into force in August and December 2026.
- agentinsured.eu, the coverage platform where operators can join the waitlist for the first wave of European AI agent insurance.
- agentcertified.eu, the Agent Certified methodology: the seven-dimension framework underwriters are beginning to use to assess AI agent deployments before quoting coverage.
References
- Verisk / Insurance Services Office. "Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures." Released January 2026. Forms CG 40 47 01 26, CG 40 48 01 26, CG 35 08. Effective date January 1, 2026. Available via IndependentAgent.com and Verisk Core Insights.
- W.R. Berkley's absolute AI exclusion for D&O, E&O and fiduciary liability is reported in National Law Review and Hunton Andrews Kurth. Both are secondary. Checked 17 August 2026: berkley.com publishes no forms library, no forms list and no statement on AI underwriting. The form number and the wording description previously carried here were removed for that reason, and because this site had described the same form in two places as opposite instruments.
- Swept AI. "AI Insurance Liability: New CGL Exclusions, Silent AI Coverage, and What Every Enterprise Should Know." 2026. Reports AIG, Great American and Philadelphia Indemnity filing proprietary AI exclusions. Available at swept.ai.
- British Columbia Civil Resolution Tribunal. Moffatt v. Air Canada. Decision issued 14 February 2024. Tribunal member Christopher Rivers. Award: CAD 812.02 plus filing fees. Available via McCarthy Tetrault and ABA Business Law Today.
- HSB (Hartford Steam Boiler, a Munich Re company). Press release: "HSB Introduces AI Liability Insurance for Small Businesses." 18 March 2026. Available at munichre.com/hsb and BusinessWire.
- Armilla. "Armilla Launches Affirmative AI Liability Insurance with Lloyd's Underwriter, Chaucer." 30 April 2025. Available at armilla.ai. Capacity providers listed at armilla.ai/ai-insurance.
- Removed 17 August 2026. This note supported a growth figure for generative AI litigation in the United States that came from a market update published by a carrier selling into that market. We do not publish a market-size or growth statistic on the strength of a vendor's own marketing.
- QBE North America, "QBE North America Introduces AI-Focused Cyber Insurance Coverages to Address Emerging Risks," qbe.com, and QBE Cyber Services, "Understanding LLMjacking: An AI Security Threat", qbe.com (both read 17 August 2026). Neither states a sublimit. The payout-cap figures previously carried here for two named London cyber carriers came from trade summaries of newspaper reporting, are stated nowhere on either carrier's own site, and were removed on 17 August 2026.
- Counterpart. "Leading Insurtech, Counterpart, Addresses Critical Coverage Gap With Affirmative AI Coverage." November 2025. Available via IIReporter and Yahoo Finance.
- Read 17 August 2026: Corgi, product page at corgi.insure/ai. The regulatory approval date and the annual recurring revenue figure previously carried here came from a magazine summary and a startup directory profile, are not stated by the company, and were removed in this revision.
- US Equal Employment Opportunity Commission, "iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit," eeoc.gov (read 17 August 2026). The age thresholds, the applicant count, the settlement sum and the quoted principle are read off the Commission's own release.
- Testudo. Generative AI liability insurance, underwritten at Lloyd's. Testudo UK Limited is an Appointed Representative of Pro MGA Solutions Ltd, regulated by the Financial Conduct Authority. Available at testudo.co.
- Munich Re. "aiSure: More AI Opportunity, Less AI Risk." Product page at munichre.com. Mosaic partnership announced February 2026: initial coverage to EUR/USD/CAD 15 million. Computer Weekly, "Munich Re sees strong growth in AI insurance," 2026.
- Fortune. "AIUC, a startup creating insurance for AI agents, emerges from stealth with $15 million seed." 23 July 2025. Investors: Nat Friedman, Emergence, Terrain, Ben Mann. Available at fortune.com. Also Reinsurance News, "Artificial Intelligence Underwriting Company launches with $15m seed round."
- US District Court, Southern District of New York. Mata v. Avianca, Inc., No. 1:2022cv01461. Opinion and order on sanctions by Judge P. Kevin Castel, 22 June 2023. $5,000 sanction against attorneys Schwartz and LoDuca of Levidow, Levidow and Oberman. Available at Justia and summarised at Wikipedia.