If your business builds, sells, or operates AI-driven products, your standard general liability policy almost certainly does not cover what you think it does. The gap between what traditional policies protect and what AI-specific claims actually look like is wide, and most businesses only discover it after a claim lands.
That gap is widening, not closing. As of January 2026, standardized generative-AI exclusions are being written into commercial general liability policies, carriers are adding AI carve-outs to E&O and D&O forms, and a handful of insurers have launched the first standalone AI liability products. The market is repricing AI risk in real time.
This guide breaks down what AI liability insurance actually is, which coverage lines apply to AI-driven products and services, where the gaps show up, what the new exclusions remove, how underwriters price the risk, and how to structure a program that keeps pace as your AI changes.
What Is AI Liability Insurance?
AI liability insurance is not a single standalone policy. It is a coordinated combination of commercial coverage lines - primarily technology errors and omissions (tech E&O), cyber liability, product liability, directors and officers (D&O), employment practices liability (EPLI), and media or intellectual property liability - structured to address the specific ways AI-driven products and services create legal and financial exposure.
When an AI system produces an incorrect output, makes a biased decision, causes a data breach, infringes a copyright, or fails to perform as contracted, the resulting claim can touch several of those lines at once. A policy built for a traditional software company or a physical-goods manufacturer does not map cleanly onto those scenarios.
A small but growing number of carriers now offer affirmative AI coverage, meaning policy language that explicitly names AI perils, either as an endorsement to an existing line or as a standalone AI liability policy. For a broader foundation, what AI insurance actually covers is worth understanding before you evaluate specific lines.
From Silent AI to Affirmative AI: Why Standard Policies Are Pulling Back
For years, AI losses were covered by accident. Legacy cyber, E&O, and general liability wordings never mentioned AI, so a claim involving an AI system often fell inside coverage simply because nothing excluded it. The industry calls this silent AI, by analogy to the silent cyber problem that forced cyber exclusions into property and casualty policies a decade ago.
That era is ending. In January 2026, the Insurance Services Office (ISO/Verisk) introduced standardized generative-AI exclusions for commercial general liability, filed as endorsements such as CG 40 47 and CG 40 48, with a companion form extending the exclusion to products and completed operations. Some carriers have gone further, filing near-absolute AI exclusions on D&O, E&O, and fiduciary forms unless affirmative coverage is bought back.
Not all of the erosion is loud. Some carriers are quietly revising base policy forms so that AI-related claims fall out of coverage without a separately labeled exclusion. This is why reading the current edition of your policy matters more than trusting last year's summary.
One principle runs through all of it: coverage usually turns on how a claim is framed, not on the underlying technology. The same AI failure can be pleaded as a professional error, a privacy violation, a discriminatory act, or a defamation, and each framing points at a different policy. That is exactly why gaps open up between lines.
The Coverage Lines That Actually Apply to AI
Technology Errors and Omissions (Tech E&O)
Tech E&O is the anchor line for most AI product companies. It covers claims arising from errors, omissions, or failures in your technology product or service, including failure to perform as promised. If your AI model produces a flawed recommendation that causes a client financial harm, tech E&O is typically the first line of defense.
Policy language matters enormously here. You want coverage that explicitly addresses AI-generated outputs, model failures, hallucinations, and automated decision errors, not just software bugs in the traditional sense. Carrier appetite and wording vary widely, which is why tech E&O insurance deserves its own evaluation if you build or sell AI-driven products.
Cyber Liability
AI products are data-intensive by nature. Training data, inference data, user inputs, and outputs frequently include sensitive personal or business information. A breach, unauthorized access, prompt-injection attack, or regulatory violation tied to that data creates real cyber liability exposure.
Modern cyber policies increasingly respond to AI-specific events. Coalition's affirmative AI endorsement, added to its cyber policies in 2024, treats an AI-caused security failure as a covered event and extends coverage to funds-transfer fraud carried out with deepfakes. If your AI product processes health records, financial data, or personal information at scale, cyber coverage is not optional.
Product Liability and General Liability
If your AI system has a physical component or controls a physical process - robotics, autonomous vehicles, medical devices, industrial automation - product liability and CGL become directly relevant, because claims involving bodily injury or property damage can arise quickly. This is also precisely the territory the 2026 ISO generative-AI exclusions target, so the interplay between what CGL still covers and what it now excludes needs careful review.
For pure software AI products, product liability plays a smaller role, but it should not be ignored if your system influences real-world physical outcomes.
Directors and Officers (D&O)
AI governance is now a board-level issue. Regulatory scrutiny of AI systems, particularly in financial services, healthcare, and hiring, creates exposure for executives who decide how AI is deployed, disclosed, or governed. A distinct and growing D&O risk is AI-washing: overstating AI capabilities to investors, which can trigger securities claims.
If your company faces regulatory action or shareholder claims tied to AI decisions, D&O coverage protects the individuals who made those calls. This matters most for companies that have raised institutional capital and face investor expectations around AI risk management.
Employment Practices Liability (EPLI)
If you use AI in hiring, promotion, or workforce management, algorithmic bias is an employment exposure. EPLI responds to discrimination claims, and AI-driven hiring tools have already produced real ones. In 2023, iTutorGroup paid $365,000 to settle the EEOC's first AI hiring discrimination case, after its software automatically rejected older applicants.
Media and Intellectual Property Liability
Generative AI has created an entire category of exposure that most standard policies never contemplated. Outputs can infringe copyright or trademark, and AI-generated marketing can create advertising-injury claims. The active copyright suits over training data, including The New York Times against OpenAI and Getty Images against Stability AI, are the reason underwriters now scrutinize how your models are trained and what they produce. Some carriers address this through media liability; most standard policies do not address it at all.
General Liability and Umbrella
General liability remains relevant for physical harm or property damage tied to AI systems, subject to the new exclusions above. An umbrella policy sits above your primary lines and extends limits when a single large claim exhausts the underlying coverage, which is useful when AI-related claims involve multiple parties or prolonged litigation.
Which Policy Responds to Which AI Failure
Because AI claims rarely fit one box, it helps to map common failure scenarios to the line most likely to respond. The exact answer always depends on your policy wording, but the pattern looks like this:
| AI failure scenario | Coverage line that usually responds |
|---|---|
| AI output is wrong and a client relies on it and loses money | Tech E&O / professional liability |
| A chatbot gives a customer false information the business is bound to | Tech E&O, sometimes media liability |
| Training or inference data is breached or exposed | Cyber liability |
| A deepfake or AI-enabled scam triggers a fraudulent transfer | Cyber (crime / social engineering) |
| A hiring or lending model produces discriminatory outcomes | EPLI and tech E&O, sometimes D&O |
| Generative output infringes a copyright or trademark | Media / IP liability, sometimes tech E&O |
| An AI-controlled machine causes injury or property damage | Product liability and CGL |
| A regulator or shareholder challenges how the board governed AI | D&O |
What AI Liability Insurance Does Not Cover
Even a well-built AI insurance program has edges. The most common carve-outs and limitations in 2026 include:
- Generative-AI CGL exclusions. The 2026 ISO endorsements remove bodily injury, property damage, and personal and advertising injury arising out of generative AI from many general liability policies.
- Absolute AI exclusions on management and professional lines. Some carriers exclude AI-related claims entirely from D&O, E&O, or fiduciary coverage unless you buy affirmative coverage back.
- First-party losses. Most standalone AI liability products cover third-party claims only. Your own cost to retrain a failed model or rebuild a corrupted dataset is usually not covered.
- Restricted-appetite use cases. Carriers frequently exclude or decline facial recognition, law-enforcement surveillance, fully autonomous vehicles, political advertising, gambling, and some healthcare and mental-health applications.
- Uninsurable regulatory fines. Even when a policy contemplates regulatory response, fines and penalties may be uninsurable as a matter of law in a given state.
- Intentional or reckless conduct. Knowingly shipping a model you understood to be unsafe is not an insurable accident.
Standalone AI Policy vs. Endorsement: Which Do You Need?
The practical decision is usually this: when AI is a feature inside a broader product, an endorsement to your existing tech E&O or cyber policy is often enough. When the AI output is the product, meaning the thing your customers pay for and rely on, a standalone AI liability policy or an affirmative AI endorsement with real limits becomes worth the cost.
The market that supports this choice is young but real. Named programs as of 2026 include:
- Armilla, a standalone third-party AI liability policy underwritten by Lloyd's insurers including Chaucer, covering hallucinations, model drift, and performance falling below agreed thresholds, with reported limits up to $25 million.
- Munich Re aiSure, a performance guarantee that pays when an AI model underperforms a defined accuracy benchmark. It is first-party performance cover rather than third-party liability, and is now offered with limits reported up to $15 million through Mosaic.
- Coalition's affirmative AI endorsement, which builds AI security events and deepfake-enabled fraud into its cyber policies.
- Munich Re's HSB small-business product, which covers bodily injury, property damage, and advertising injury arising from AI-generated content.
- Insurtech brokers such as Vouch and Embroker, which package tech E&O, cyber, and D&O for AI startups and negotiate AI-specific enhancements.
There is no reliable public figure for the size of the standalone AI liability market yet, and capacity is still limited. Be careful with the large market-size numbers that circulate online: most of them measure insurers' use of AI, not the market for insuring AI.
Who Is Liable When AI Goes Wrong?
Buyers ask this constantly, and the answer shapes which business needs which coverage. Liability generally follows control and reliance. The developer who trains and ships a model, the deployer who integrates it into a service, and the enterprise that relies on its output can each carry exposure, and a single incident can name more than one of them.
Two cases anchor the point. In Moffatt v. Air Canada (2024), a tribunal held the airline responsible for false information its website chatbot gave a customer, rejecting the argument that the chatbot was a separate entity. The lesson: you own what your AI says. And in the ongoing Mobley v. Workday litigation, an AI hiring vendor, not just the employer, is being pursued for alleged discrimination by its screening tools, a signal that AI developers can be dragged directly into claims once thought to belong to their customers.
Where the Gaps Actually Appear
Most AI liability claims do not fit neatly into one box. Here is where businesses get caught:
- Algorithmic bias claims. A hiring or lending AI that produces discriminatory outcomes can trigger EPLI, regulatory action, and third-party claims at once. New York City's Local Law 144 already requires annual bias audits of automated hiring tools, with penalties per violation, so the compliance and liability exposures compound.
- Model failure after deployment. AI models degrade. If your model performs well at launch but drifts over time and harms a client months later, the claim arrives mid-policy-year. A broker who only reviews coverage at renewal will not have flagged the exposure that emerged when the model was retrained or the data pipeline changed.
- Third-party and training-data liability. If your AI ingests third-party data or content and that data is misused, breached, or infringed, liability can extend beyond your own clients to the original data owners. Standard cyber policies often carry sublimits or exclusions for this.
- Regulatory fines and penalties. AI regulation is moving fast, and not all cyber or tech E&O policies cover regulatory defense or fines. You have to read the policy language.
- IP and copyright claims. Generative AI faces an emerging wave of training-data and output-ownership claims. Most standard policies do not address it, and only some carriers offer media or IP endorsements that do.
How Underwriters Evaluate AI Risk
AI underwriting is governance-based. Carriers are less interested in the model architecture than in whether you can show the model is controlled. Expect questions along these lines:
- A current inventory of the AI models you build, deploy, or rely on
- Whether a human reviews or can override high-stakes automated decisions
- How you test for accuracy, bias, and drift, and how often
- What you log, and whether you can reconstruct why a model produced a given output
- How your customer contracts allocate AI risk and limit liability
- Your data provenance and your rights to the data used for training
- Any prior AI-related incidents or complaints
Emerging certification standards, such as AIUC-1, are starting to formalize this by testing AI systems against thousands of adversarial cases. The stronger your governance evidence, the broader and cheaper your coverage, because affirmative AI coverage is increasingly conditioned on it.
What AI Liability Insurance Costs
Pricing depends on your revenue, how critical your AI's decisions are, your data exposure, your governance maturity, and your claims history. As rough, illustrative anchors reported across the early market, seed-stage AI companies often see combined tech E&O and cyber premiums in the low thousands of dollars per year, while growth-stage companies with material AI exposure can run into the low tens of thousands or more. Healthcare, autonomous systems, and financial decision-making price higher, and early-stage companies often carry higher retentions.
Treat any single number with caution. AI premiums are being repriced quickly as carriers gather loss experience, and the strength of your governance can move your premium more than your revenue does.
The Regulation Driving AI Insurance Demand in 2026
Regulatory exposure is now one of the biggest reasons AI companies buy specialized coverage. The landscape as of 2026:
The EU AI Act
The EU AI Act (Regulation 2024/1689) entered into force in August 2024 and applies extraterritorially: a US company is in scope whenever its AI system's output is used in the EU. Penalties are severe, reaching up to 35 million euros or 7 percent of global annual turnover for prohibited practices, and up to 15 million euros or 3 percent for other high-risk violations. A 2026 simplification package known as the Digital Omnibus pushed the compliance deadline for most stand-alone high-risk systems to December 2027, but the transparency duties, including disclosing that users are interacting with AI and labeling AI-generated content, remain on the August 2026 timeline.
US state AI laws
US regulation is a patchwork moving quickly. Texas's Responsible AI Governance Act took effect in January 2026. Colorado passed the first comprehensive state AI discrimination law but replaced it before it took effect, with the successor now scheduled for January 2027. California's frontier-model transparency law (SB 53) and training-data disclosure law (AB 2013) took effect in January 2026, and Illinois began regulating AI in employment decisions the same month. New York City's Local Law 144 has required bias audits of automated hiring tools since 2023.
Insurance-specific and federal oversight
The NAIC Model Bulletin on the use of AI by insurers, adopted in 2023, has now been taken up by roughly half the states, requiring insurers to run formal AI governance programs. At the federal level, the FTC and CFPB have signaled they will use existing authority, including the FTC Act, ECOA, and FCRA, against algorithmic discrimination and deceptive AI claims rather than waiting for new AI statutes.
How to Structure Coverage for an AI Business
The right structure depends on your product, your clients, and your regulatory footprint, but the general framework looks like this:
| Coverage line | What it does for an AI business |
|---|---|
| Tech E&O | AI output errors, model failures, failure to perform as contracted |
| Cyber liability | Data breaches, AI security events, deepfake fraud, privacy violations |
| Product liability + CGL | Bodily injury or property damage from AI-embedded or AI-controlled products |
| D&O | Board and executive exposure from AI governance, disclosure, and AI-washing claims |
| EPLI | Algorithmic bias claims in hiring and employment decisions |
| Media / IP liability | Copyright, trademark, and advertising-injury claims from AI content or training data |
| GL + umbrella | Broad liability floor and excess limits above the primary lines |
No single policy covers all of these. The goal is a coordinated stack where the policies are written to work together, so that a claim does not fall through a seam between exclusions.
Why Your Risk Profile Changes When Your AI Does
This is the part most businesses miss. Your insurance risk profile is not static. When you retrain a model, add a data source, ship a new use case, or deploy into a new vertical, your exposure changes materially, and it can change the day the model does, not the day your policy renews.
A traditional broker reviews your coverage once a year. If you retrained your model in March, expanded into healthcare in June, and your policy renews in December, you may have spent months underinsured for risks nobody flagged. Worse, if a carrier quietly added an AI exclusion at your last renewal, you may be carrying a gap you never agreed to.
This is why continuous monitoring matters for AI businesses specifically. At Aiden, an AI built for commercial insurance analyzes 140+ signals year-round, including changes in your tech stack, industry posture, and the external threat and regulatory environment, and flags exposure changes between renewals. A licensed specialist then reviews those flags and acts on the ones that need a professional, before a claim forces the conversation.
The intake takes about 5 minutes, against the 40-page application and multi-week wait of a traditional broker. Understanding how AI-assisted underwriting differs from the traditional process also helps explain why the resulting risk profile reflects what your business looks like today, not what it looked like at your last renewal.
Key Takeaways
- AI liability insurance is not one policy. It is a coordinated stack of tech E&O, cyber, product liability, D&O, EPLI, and media or IP coverage, structured to your specific exposure.
- The market is moving from silent AI to affirmative AI. As of 2026, new ISO exclusions and carrier carve-outs remove AI claims from standard policies unless you buy coverage that names AI explicitly.
- Coverage usually turns on how a claim is framed, not on the technology, which is why claims fall into the gaps between lines.
- The biggest gaps appear in algorithmic bias, model drift after deployment, third-party and training-data liability, regulatory fines, and IP claims.
- Standalone AI liability products now exist (Armilla, Munich Re aiSure, Coalition, and others), but capacity is limited and coverage is conditioned on governance.
- Your AI risk profile changes every time your model, data, or deployment scope changes. Annual renewals alone will not keep pace.
FAQs
What is AI liability insurance?
AI liability insurance is a coordinated set of commercial coverage lines, typically tech E&O, cyber, product liability, D&O, EPLI, and media or IP liability, structured to respond to the specific ways AI-driven products and services cause harm. It is not a single off-the-shelf policy, although a few standalone AI liability products have recently entered the market.
Is there a standalone AI liability insurance policy?
Yes, but the market is young. Insurers such as Armilla, through Lloyd's, now offer standalone third-party AI liability policies, and Munich Re's aiSure offers a first-party performance guarantee. For most businesses, though, coverage is still assembled across several commercial lines rather than bought as one dedicated AI policy.
Is AI liability insurance the same as tech E&O?
No, though tech E&O is usually the core of it. Tech E&O covers errors and failures in your technology service, which captures many AI output problems. But AI exposure also spans cyber, product liability, D&O, EPLI, and IP, so tech E&O alone leaves gaps.
Does my existing E&O or cyber policy already cover AI?
Maybe, and maybe less than it used to. Older policies often covered AI by silence, because nothing excluded it. As of 2026, carriers are adding AI exclusions and endorsements, so you need to read the current edition of your policy language rather than assume last year's coverage still applies.
Does general liability cover AI product failures?
Generally no, and increasingly not by design. General liability is built for bodily injury and property damage. Financial harm from an AI output or a model error typically falls outside GL, and new 2026 ISO endorsements explicitly exclude generative-AI-related claims from many general liability policies.
Do I need AI insurance if I only use AI internally and not in my product?
Often yes. Internal use of AI in hiring, credit, or operational decisions can still create employment, privacy, and regulatory exposure. The coverage emphasis shifts toward EPLI, cyber, and D&O rather than product-focused tech E&O, but the risk does not disappear because the AI is internal.
What does AI liability insurance not cover?
Common exclusions include first-party costs to fix your own model or data, restricted use cases such as facial recognition and autonomous vehicles, uninsurable regulatory fines, intentional or reckless conduct, and, under the 2026 ISO endorsements, generative-AI claims on general liability policies.
What is silent AI?
Silent AI refers to AI-related losses that fall inside a policy simply because the wording never mentioned AI and never excluded it. It mirrors the earlier silent cyber problem. The industry is now replacing silent AI with affirmative AI, meaning explicit language that either covers or excludes AI perils on purpose.
What coverage applies if my AI model produces a biased or discriminatory output?
Depending on the context, it can implicate EPLI if the bias affects employment decisions, tech E&O for failure to perform as contracted, and sometimes D&O if executives face regulatory scrutiny. Because these claims often span multiple lines, the policies need to be structured to work together.
Does AI insurance cover hallucinations?
It can, but only if the policy language contemplates it. Standalone AI policies and modern affirmative AI endorsements increasingly name hallucinations and incorrect outputs as covered perils. Older tech E&O wordings that only reference software errors may not respond clearly, which is why wording review matters.
Does AI insurance cover copyright claims from generative AI?
Usually only through media or IP liability, and often not at all under standard policies. The active training-data copyright suits have made carriers cautious, so intellectual property coverage for generative AI outputs typically requires a specific endorsement or a specialized policy.
Who is liable when AI causes harm, the developer or the business using it?
Often both. Liability tends to follow control and reliance, so the developer, the deployer, and the end business can each be named. Courts have already held companies responsible for their own AI chatbots, and AI vendors are now being pursued directly in discrimination litigation.
How much does AI liability insurance cost?
It varies widely with revenue, how critical your AI's decisions are, your data exposure, and your governance maturity. Illustratively, early-stage AI companies often see combined tech E&O and cyber premiums in the low thousands of dollars per year, while higher-risk sectors such as healthcare and autonomous systems price materially higher. Strong governance can lower your premium more than almost anything else.
How does AI regulation affect my insurance needs?
Regulation is now a primary driver of demand. The EU AI Act reaches US companies whose AI output is used in the EU and carries penalties up to 7 percent of global turnover, and US state laws in Texas, California, Colorado, Illinois, and New York City add more. Not all policies cover regulatory defense and fines, so you have to confirm it in the wording.
When should I update my AI liability coverage?
Any time your AI changes materially - new training data, new use cases, new verticals, or significant retraining. Waiting for annual renewal can leave you underinsured for months after a meaningful change to your product or model.
How do I know if my current coverage has gaps for AI risks?
The most reliable way is a coverage gap analysis by a broker who understands both your tech stack and the current carrier market, reading your actual policy editions for new AI exclusions. A reviewer who does not understand how your AI works cannot accurately assess where your policies fall short.
AI liability risk is specific, fast-moving, and easy to underestimate until a claim arrives. If your business builds or operates AI-driven products, get a risk profile that reflects what you actually do. An AI risk engine maps your exposure, a licensed specialist places and adjusts the coverage, and your risk is watched year-round instead of once at renewal. Get a quote at aidenrisk.com.

