AI Liability · Standalone · Ten insuring agreements

    AI Liability

    Standalone cover for the AI your organization actually uses: a person working with a model, an automated decision system, and an agent that acts on its own.

    Section A · First party · Pays on discovery. No claim required.

    Your own loss

    Seven agreements that respond to your own loss the moment you find it. No claimant, no lawsuit, no duty to defend. One trigger runs through the whole section: a declared agent acted outside its authority, or inside it but against the instruction it was given. Each agreement then measures a different consequence of that same act, from money moved to data destroyed to a process you had to stop.

    IA-1

    Autonomous Execution Loss

    The financial consequence when an agent departs its authority: what it moved, committed, or lost, net of what you kept or recovered.

    Triggers when

    A declared agent acts outside its authority, against its instruction, or through manipulation. Departure, not outcome.

    Where your tower stops

    Crime needs a dishonest person; cyber needs a breach. The agent is authorized and the instruction is yours.

    Planned
    IA-2

    Model and Data Restoration

    Putting back data, code, weights, or configuration the agent deleted or corrupted.

    Triggers when

    The same three-limb agent trigger as IA-1, discovered by you.

    Where your tower stops

    Cyber restoration needs a security failure. Data is not tangible property, and vendors cap at fees paid.

    Planned
    IA-3

    Resource Overrun

    Compute and inference spend a declared agent ran past a limit you set.

    Triggers when

    Consumption past the limit you configured, or through manipulation. With no limit configured, a reduced recovery applies.

    Where your tower stops

    Nothing answers. The bill is a real, metered charge from your own vendor.

    IA-4

    Event Response Costs

    Finding out what happened and correcting wrong output, before anyone claims.

    Triggers when

    Your awareness of an event, with our prior consent. Carried on every policy.

    Where your tower stops

    A liability form defends a claim, and there is no claim yet. Cyber response needs a security incident.

    Planned
    IA-5

    Contingent AI Supply Failure

    Lost profit and extra expense when a declared vendor fails you, plus migration.

    Triggers when

    A provider event: a withdrawn or changed model, a ceased service, or a lost license.

    Where your tower stops

    Cyber contingent interruption needs a breach or outage; a model deprecated on notice is neither.

    Planned
    IA-6

    Autonomous Operations Interruption

    Lost profit and extra expense while a declared agent is switched off, or while your own systems are down because of what it did.

    Triggers when

    You suspend the agent after a covered act, a regulator or court requires it, we direct it, or a covered act leaves your systems inoperable.

    Where your tower stops

    Cyber and property interruption need an unplanned outage. A deliberate suspension is the opposite.

    Planned
    IA-7

    Wrongful Decision Remediation

    The scheduled cost of re-determining a population of decisions you must redo.

    Triggers when

    Discovery of the obligation to re-determine, from a statute, regulator, court, or your own policy.

    Where your tower stops

    Nothing does. Liability forms pay the individual, not the cost of redoing the population.

    Agreements marked Planned are not available at launch. What is shown for them describes the intended cover, and the policy wording governs in every respect.

    Section B · Third party · Claims made and reported.

    Third-party claims

    Two third-party agreements, with a duty to defend and defense costs inside the limit.

    IA-8

    Wrongful Disclosure through Output

    Damages and defense when your system discloses protected information through its output.

    Triggers when

    A claim, whether or not any access was unauthorized or the system held valid credentials.

    Where your tower stops

    Cyber privacy needs unauthorized access or a security failure. An over-permissioned system breached nothing.

    IA-9

    AI Regulatory Proceedings

    Defense, insurable fines, and consumer-complaint response, under a listed AI statute.

    Triggers when

    A formal investigation or enforcement action under a scheduled statute.

    Where your tower stops

    A regulatory proceeding is not a claim for damages. Employment practices reaches an employment charge, not this.

    Section C · Difference in conditions · Claims made, attached head by head.

    AI Liability, attached head by head

    IA-10 carries five heads, each separately purchased and attached. A head sits in front of your expiring policy as primary where that policy carries an AI exclusion, and behind it as difference in conditions where it does not. You pay for the gap you actually have.

    IA-10(a)

    Professional and Operational Error

    Third-party loss from wrong output or an autonomous act relied on in your business.

    Triggers when

    A claim. No requirement that anyone failed to check, or that anything was breached.

    Where your tower stops

    Professional liability, but only with a client claimant, the insured activity, and no AI exclusion.

    IA-10(b)

    Automated Decision Liability

    Discrimination and employment or consumer wrongs from a system's part in a decision, ML or generative.

    Triggers when

    Participation in the decision, not authorship. A model that narrows a shortlist has participated.

    Where your tower stops

    Employment practices reaches the employee only, never the consumer, tenant, or credit applicant.

    IA-10(c)

    Content and Publication

    IP infringement, defamation, and publicity or privacy, from your output or how you trained.

    Triggers when

    A claim, from what you published or what you did to build the system.

    Where your tower stops

    GL advertising injury now carries the ISO exclusions. A vendor indemnity moves money, not the duty.

    IA-10(d)

    Bodily Injury and Property Damage

    Third-party injury or damage from reliance on output or an autonomous act. On the ordinary submission.

    Triggers when

    A claim. A clinical claim needs a licensed person's review before the output is relied on.

    Where your tower stops

    General liability, now the widest US gap after the ISO exclusions took effect 1 January 2026.

    IA-10(e)

    Management and Fiduciary

    Claims against an insured person for AI oversight, disclosures, or benefit-plan administration.

    Triggers when

    A claim against a person in that capacity, excess of your D&O and fiduciary policies.

    Where your tower stops

    D&O and fiduciary, where no AI exclusion is attached. Filed forms now exclude all three together.

    Who buys this

    Illustrative buyers, and what they take

    Hypothetical profiles, not customers. Every agreement is optional, and many buyers take the whole policy. Premiums and estimated exposures are illustrative, within the worked-scenario range on the form.

    BuyerUses AI toAgreementsPremiumEst. exposure
    Law firm
    Associates draft and research with models.
    IA-10(a)IA-8IA-4
    USD 14,200USD 1.2M
    Staffing platform
    A model screens and ranks applicants.
    IA-10(b)IA-7IA-9
    USD 28,500USD 2.5M
    Consumer lender
    Automated models decide credit.
    Whole policy
    USD 34,800USD 3.5M
    Health system
    Clinical decision support triages and doses.
    Whole policy
    USD 41,200USD 4M
    Logistics operator
    An agent books carriers and commits rates.
    Whole policy
    USD 22,600USD 1.8M
    Finance team
    An agent reconciles and pays invoices.
    IA-1IA-2IA-4
    USD 18,400USD 1.5M
    Insurance MGA
    An agent triages and adjudicates claims.
    Whole policy
    USD 24,900USD 2M
    Property manager
    A model screens prospective tenants.
    IA-10(b)IA-9
    USD 12,700USD 900K
    Marketing agency
    Generative tools produce campaigns.
    IA-10(c)IA-4
    USD 11,300USD 750K
    Retailer
    A pricing agent sets prices in real time.
    IA-1IA-10(b)IA-3
    USD 16,800USD 1.1M
    Accounting firm
    AI drafts filings and reconciles books.
    IA-10(a)IA-8
    USD 13,500USD 1M
    Engineering firm
    AI generates specifications and drawings.
    IA-10(d)IA-10(a)
    USD 26,300USD 2.2M
    Wealth advisor
    AI drafts advice and plan allocations.
    IA-10(a)IA-10(e)IA-9
    USD 19,700USD 1.6M
    Publisher
    AI writes and edits published articles.
    IA-10(c)IA-8
    USD 15,400USD 1M
    Manufacturer
    A vendor model runs quality inspection on the line.
    IA-10(d)IA-5IA-6
    USD 29,600USD 2.8M

    Shaded agreements are available at launch. "Whole policy" marks buyers who take the form as a standalone.

    Underwriting

    Application and a public-record check

    An Application and a public-record check. No audit, no penetration test, no model evaluation, and nothing installed in your environment to price the risk. Four conditions precedent and no others, and failing one affects only the claim it relates to.

    Through your broker

    Placed through appointed surplus lines brokers. Your broker brings the Application; there is no self-serve gate and no pre-bind audit.

    Declare, and evidence

    You select the categories of use you want covered and schedule only the systems that can do real damage. For each agent, first-party cover attaches once the three governance controls are evidenced, from your own configuration and logs, a supplier attestation, or an accreditation.

    A fast, plain answer

    An indication within five business days of a complete submission. A hard decline within one business day, with the reason.

    Axiom Governance · included free

    Three controls, required for agents. The software is free.

    For any agent you run, qualifying governance is a condition of coverage: a documented authorization scope enforced in configuration, timestamped logging, and a person other than the agent who can halt it. Every policy includes Axiom Governance at no cost to put all three in place and keep the evidence, so the AI is governed from the day it is deployed.

    Three controls, and that is the list

    Authority the agent cannot exceed, a log of what it did, and a person who can stop it. Nothing else is required, and none of it applies if you do not run agents.

    Evidence it however you like

    Your own configuration and logs, a written attestation from the supplier of the agent, or an accreditation. The free software is simply the easiest way to produce that evidence and keep it current.

    Free, and it earns a credit

    You never pay for it. It reports factual observations only, it never scores or certifies your systems, and staying connected through a policy year earns the retention credit in your Declarations at renewal.

    Regulatory backdrop

    The rules are catching up fast

    Traditional insurance was not written with any of these in mind. This form is.

    ISO GenAI exclusions

    CG 40 47, CG 40 48 and CG 35 08, effective 1 January 2026, on the general liability line every commercial buyer holds.

    EU AI Act

    High-risk obligations phasing in, with fines up to EUR 35M or 7% of global turnover.

    US state AI statutes

    Automated-decision and AI-transparency laws, tracked on the AI Statute Schedule attached to each policy and maintained quarterly.

    SEC AI disclosure scrutiny

    AI-disclosure securities actions were pleaded in the first half of 2026, reaching directors and officers cover.

    FTC enforcement

    Action against deceptive or harmful AI practices under existing consumer-protection authority.

    ABA Formal Opinion 512

    Professional-responsibility duties for AI use by lawyers.

    AI Liability FAQ

    Questions about the coverage