The question is not whether AI creates new risks – it does – but whether current policy language was designed to respond. In most cases, that answer is still unclear.
That is not necessarily a bad thing for policyholders. Standard executive risk insurance policies, including Tech E&O, Cyber, Professional Liability, D&O and EPL, are not listed-peril policies. If an AI-related loss is not explicitly excluded, the default presumption generally favors coverage. The challenge is that this landscape is changing, and policyholders who are not actively engaged may not know where they stand until an AI-related claim tests their current policy language.
How Insurers Are Responding
In the commercial property and casualty market, insurers have already started to respond. In January 2026, ISO introduced standard CGL exclusion forms (CG 40 47, CG 40 48, and CG 35 08) that broadly exclude bodily injury, property damage, and personal injury arising from generative AI. Adoption varies by carrier, but the direction is clear: where AI losses are identifiable, insurers will act to manage their exposure.1
For executive risk lines, the market has not responded as decisively. Broad AI exclusions are not yet a standard feature of these policies. Instead, some carriers are looking to introduce what they describe as affirmative AI coverage grants. In their view, this is clarifying language that explains how AI-related losses are treated under the policy.
A recent Beazley announcement illustrates how quickly this issue is moving from an abstract coverage question to express policy language. Beazley has introduced affirmative AI wording for its cyber and technology E&O policies, while stating that the endorsement addresses AI-related risks already within the scope of the policy.2
That distinction is important: AI wording may clarify existing protection, but it can also define the circumstances in which coverage will apply. Language that covers AI-related losses only under specified conditions may, by implication, narrow the coverage available outside those conditions. Any proposed wording should be compared with the current policy to determine what it adds, clarifies, or potentially restricts.
How Current Policies May Respond
Technology E&O / Professional Liability
Tech E&O / Professional Liability policies are the most likely coverage home for AI-related failures. If a platform’s AI feature produced an incorrect output that causes client loss, there is a plausible claim under most current forms, provided AI has not been specifically excluded.
Does a probabilistic model output constitute a failure to perform when the model did exactly what it was designed to do? Is an AI-assisted recommendation gone wrong a technology failure or a professional error?
This is predominantly unsettled precedent. Courts have generally applied the principle that ambiguous policy language is construed in favor of the insured (contra proferentem), though how that principle applies to AI-related losses has not been tested.
Cyber
Cyber policies typically cover system failures, data breaches, and privacy liability. AI introduces new vectors for each – including model poisoning, prompt injection, and training data exposure – that existing cyber forms did not explicitly contemplate. Where those events result in a network security failure or privacy liability, current policy language may still respond.
Some cyber forms already include widespread event provisions designed to limit insurer exposure when a single event affects many policyholders simultaneously. These provisions were written for infrastructure attacks, not AI model failures. Whether they also apply to a downstream AI vendor outage affecting thousands of clients is an open question that buyers should confirm in their current forms.
Directors & Officers / Employment Practices
AI governance is becoming a board-level issue. SEC guidance on AI-related disclosures, FTC enforcement in AI product contexts, and EEOC guidance on AI-assisted hiring tools that produce discriminatory outcomes all create potential claims where current D&O and EPL policies may be called upon to respond.3
A securities claim arising from an AI disclosure failure is still a securities claim. An employment practices claim arising from an AI hiring tool is still an employment practices claim. The AI context adds factual complexity that carriers may use to contest coverage on the margins, which is precisely why active broker engagement at renewal matters.
Where the Coverage Questions Linger
- Deployer vs. Developer Liability: Coverage follows the named insured, not the model’s creator. A company that uses a third-party AI tool and assumes indemnification obligations in its vendor contracts may be taking on exposure its own policy was not designed to cover, regardless of whether the policy addresses AI explicitly.
- AI outputs in professional advice contexts: When a model produces a confident but incorrect output that forms the basis of professional advice, the question becomes whether the resulting loss is a technology failure or a professional error. Until policy language clearly draws that distinction, professional liability may have a plausible basis to respond.
- Autonomous agents: AI systems that can execute transactions, access third-party systems, or use credentials without real-time human approval do not fit neatly within existing coverage lines. The July cyberattack against Hugging Face involving OpenAI agents illustrates the issue. Standard cyber wording was not drafted with this fact pattern in mind.
What Buyers Should Be Doing Now
- Audit current policy language before accepting any AI-specific endorsement. Any proposed wording should be compared with the existing form.
- Confirm that material AI adoption has been accurately disclosed in any submission materials or correspondence with carriers. AI use discovered during a claim, when it was not disclosed where requested, could give carriers a material misrepresentation argument, regardless of whether the loss would otherwise be covered.
- Map AI indemnification obligations in vendor contracts against policy coverage. MSAs with AI vendors may shift liability to the buyer through indemnification clauses that were negotiated before the current insurance program was in place.
A Look Ahead
Cyber insurance was not always a standalone coverage line. Through the early 2000s, cyber losses sat ambiguously within standard policies, sometimes covered and sometimes not.
ISO introduced electronic data exclusions to CGL forms in 2001 and 2004, and in May 2014 published CG 21 06, the form that broadly removed access-and-disclosure liability from standard CGL policies and effectively created the demand for standalone cyber products.4
U.S. domiciled insurers reported approximately $483 million in standalone cyber premium in 2015, rising to approximately $1.1 billion by 2018.5 One important driver of that growth was the steady narrowing of standard policy treatment for electronic data and privacy liabilities, which created demand for purpose-built cyber coverage for losses that had previously sat in a gray area within traditional forms. AI may be at an earlier point on that same trajectory.
For now, policyholders still benefit from ambiguity. Where policies do not explicitly exclude AI as a loss trigger, there may still be room to argue for coverage – room that won’t exist once exclusions standardize. Current softer market conditions across executive risk lines create an opportunity to engage carriers proactively, while that window remains open. But it will not stay open forever. The time to understand your coverage position is before you need it.
Sources
- ISO, Commercial Lines Program Filing (January 2026). Forms CG 40 47, CG 40 48, and CG 35 08.
- Beazley, “Beazley confirms affirmative AI cyber cover”
- U.S. Securities and Exchange Commission, Staff Guidance on AI-Related Disclosures (2024-2025).
- FTC, Enforcement Policy Statement on AI (2024).
- EEOC, Technical Assistance Guidance on AI and the ADA/Title VII (2023).
- California Consumer Privacy Act (CCPA); Illinois Biometric Information Privacy Act (BIPA).
- ISO CG 21 06 05 14 (May 2014); ISO Circular LI-CF-2013-175.
- National Association of Insurance Commissioners advisory to the Cybersecurity (EX) Task Force (2016).
- Federal Reserve Bank of Chicago, “The Growth and Challenges of Cyber Insurance” (2019).
Contributors
Ryan Flink, RPLU
Executive Risk Advisors

