The Vanishing Safety Net
Businesses now deploy AI at scale. Law firms draft with it. Hospitals triage with it. Retailers set prices with it. Manufacturers route logistics with it. Banks screen applications with it. In under three years, AI has become invisible infrastructure inside ordinary businesses, assumed and embedded in the daily work.
The insurance behind that work is moving the other way. Over the past 18 months, the largest commercial carriers have started rewriting their policies to strip AI-related liability out of coverages and lines that businesses already pay for. The change rarely comes with an announcement. It arrives as a new endorsement buried in a renewal packet, a paragraph most policyholders never read, sitting inside the forms they rely on when something goes wrong.
The shift became standard in January 2026, when the industry's main form-setter, Verisk's ISO published ready-made exclusion language that any carrier can drop into a GL policy. What used to be a few custom endorsements from a handful of insurers turned into a market-wide tool almost overnight. Since then the same posture has spread across E&O, D&O, EPL, fiduciary, and cyber.
That leaves a growing gap between how companies actually operate and what their policies actually cover. AI is now intertwined through every aspect of day-to-day work, and the protection for when that work causes harm is being pulled back. More weight is landing on the safety net just as it thins.
What follows is a map of that shift: which carriers are excluding what, in what form, and where it leaves the businesses now running on AI.
Why Now: The Cyber Playbook, Again
Every new category of risk moves through the same four stages inside the insurance market, and AI is walking that path faster than anything before it.

It begins silent. The risk is simply absent from the policy language. Nobody wrote AI in or out, so coverage exists by accident, if it exists at all. That is where AI sat until recently, a real exposure hiding inside forms drafted for a world that predated it.
Then comes excluded. Carriers resolve the ambiguity in their own favor and carve the risk out. That is the stage the market is in now. The exposure is new, the loss history is thin, and one widely used model failing across thousands of businesses at once looks less like ordinary claims and more like a catastrophe. Faced with that uncertainty, insurers do what they always do. They remove the risk and wait. Standardized exclusion language, now available to every carrier, turned that retreat from a slow drift into a market-wide default almost overnight.
Next is affirmative coverage. Once carriers can actually price the risk, they start writing it back in on purpose, usually as endorsements added on top of existing policies. A few large carriers have already begun.
Last is standalone. The risk grows into its own dedicated line, underwritten and priced on its own terms. Cyber reached this stage and became one of the fastest-growing products in commercial insurance. AI is moving the same way, and the only real question is how fast.
3. The Five Shapes of an AI Exclusion
Not all AI exclusions are equal. They range from total bars to modest caps, and the shape matters as much as the label. Five forms now dominate.
Absolute. The broadest version bars any claim connected to AI in any way, with no carve-outs for ordinary or good-faith use. If AI touched the loss, coverage is gone.
Targeted. A narrower version excludes specific categories, most often generative AI, and sometimes names the common tools directly. It leaves some AI exposure intact while removing the part carriers worry about most.
Conditional. Some carriers keep coverage for isolated incidents but exclude systemic ones, where a single model failure hits many insureds at the same time. Coverage survives for the one-off, not the correlated event.
Market-standard. This is not one carrier but a shared instrument: standardized exclusion forms any insurer can attach to a policy. Its power is reach. It lets the whole market adopt the same language at once.
Sublimit. The softest form does not exclude at all. It caps AI-related payouts at a fraction of the policy limit, often around five to ten percent. The coverage still exists, but at a size unlikely to match the loss.
Read together, these five describe a market deciding, form by form, how much AI risk it is willing to hold.
4. The Landscape
Here is where the exclusions sit today, by carrier and line. The pattern is consistent. Management liability and general liability are moving fastest, professional liability is close behind, and cyber is being capped rather than cut.
Carrier | Lines affected | Shape | What it removes |
|---|---|---|---|
W.R. Berkley | D&O, E&O, Fiduciary | Absolute | Any claim arising from the use, development, or deployment of AI. The broadest language in the market. |
Hamilton | E&O | Targeted | Claims arising from generative AI use, referencing common tools by name. |
Philadelphia Indemnity | E&O | Targeted | Content created with generative AI in the course of the insured's services. |
Cincinnati | D&O | Targeted | Governance and oversight claims tied to developing, deploying, or using AI. |
Berkshire Hathaway | CGL, D&O | Conditional / State-approved | AI-driven discrimination, IP infringement from AI content, and damage from autonomous systems. |
Chubb | CGL, D&O, E&O | Conditional | Systemic events where one model failure affects many insureds at once. Isolated failures may remain covered. |
Travelers | CGL, D&O | Conditional | AI-driven discrimination, IP infringement from AI marketing content, and harm from autonomous or robotic systems. |
AIG | E&O | Market-standard | AI-related professional liability for design professionals and other classes, following the standardized forms. |
Great American | Professional liability | Market-standard | AI-related professional liability, adopting the standardized forms. |
Verisk / ISO | CGL | Market-standard | Bodily injury, property damage, and personal and advertising injury from generative AI. Ready-made language for every carrier, effective January 2026. |
Beazley | Cyber | Sublimit | AI-related cyber losses capped near ten percent of the policy limit. |
QBE | Cyber | Sublimit | AI-related cyber losses capped in the five to ten percent range. |
AXA XL | Cyber | Clarifying | Not excluding yet. Adding explicit AI wording to remove silent exposure. |
Two things stand out. First, the exclusions cluster in E&O, D&O, EPL, and fiduciary, the lines that respond when a business is blamed for a decision or a work product. Those are exactly the places AI now sits in the workflow. Second, cyber, long treated as the natural home for anything digital, is not expanding to absorb AI. It is being fenced off with sublimits instead.
5. Why It Matters: The Deployer's Gap
The exclusions would matter less if AI risk were rare or exotic. It is neither. The most common AI loss is also the most ordinary. A person or a system relies on an AI output that turns out to be wrong, and someone is harmed.
Courts have already decided who is responsible, and the answer is the business that deployed the AI, not the model that produced it. When a law firm filed a brief built on citations a chatbot had fabricated, the sanctions fell on the firm. When an airline's support chatbot invented a refund policy, the airline was held to it. The principle is settled. You own your AI's output the moment you put it to work, and human oversight is not a duty you can outsource.
That is the exact exposure now being written out of policies. The claim that used to land in E&O or D&O, an employee acting on an AI answer without checking it, or a decision shaped by a model that got it wrong, is the claim carriers are moving to exclude. The businesses most exposed are the ones that adopted AI fastest and trust it most.
The gap is not theoretical, and it is not shrinking. As AI spreads deeper into everyday operations, the share of claims with an AI fingerprint climbs, while the coverage for those claims is pulled the other way.
6. What Comes Next
The cyber story did not end with exclusions. It began there. Once carriers had carved the risk out, a purpose-built market grew up to put it back, on terms that fit the actual exposure. Standalone cyber cover is now one of the fastest-growing lines in commercial insurance. AI sits at the same starting point.
The early signs of that second act are already here. A few large carriers and cloud providers have begun writing affirmative AI coverage rather than only excluding it, a sign that the risk is insurable when it is underwritten on purpose instead of inherited by accident. Exclusion is the first move, not the last.
What the market needs now is coverage built for the deployer from the start. Affirmative, standalone, and mapped to the way AI actually creates liability across professional, management, employment, and general liability exposures, rather than bolted onto forms written for a world before AI. No business should have to choose between using AI and being covered for it.
That is the gap worth closing, and it is the reason Axiom exists.

