Affirmative vs Silent AI Coverage in Commercial Policies
Silent AI coverage leaves companies exposed the moment a claim is filed.

A company renews its commercial policy, files no claims, and changes nothing about its operations, yet its AI coverage can still shrink without a single word of notice. That is the condition the industry calls "silent AI," and it is the subject of this piece: most commercial policies today neither confirm nor deny that AI-related losses are covered, and that silence is a liability that resolves against the policyholder the moment a claim is filed.
Why "silent AI" is not the same as covered
Silent AI describes a policy that never mentions artificial intelligence. The exposure sits inside a cyber policy or a Tech E&O policy, covered only by accident, because the carrier never wrote language that excluded it either. Nobody decided to include it. Nobody decided to exclude it. It simply rode along inside definitions that were built for a different kind of risk.
The trouble appears at the worst possible moment: when a loss occurs. If a system hallucinates and causes a customer financial harm, it does not file itself neatly under one coverage line. An adjuster can treat it as a professional error, a cyber incident, a product defect, or a general liability claim, and the carrier that wrote the policy did so with none of those categories built for an AI-caused loss in mind. Two companies can run the same AI system, buy similar-looking policies from two different carriers, and land in opposite places when a claim comes in, with the outcome turning on how one underwriter's legal team reads a definition written years before the technology existed. The ambiguity itself is why any company deploying autonomous systems needs a broker to read the actual policy language before renewal, before a claim is filed. Brokers who work exclusively with frontier hardware operators, Risklytics among them, treat that pre-loss review as the point where you can still fix silent AI exposure.
ISO's January 2026 endorsements and the end of the silent era for CGL
The Insurance Services Office closed part of that ambiguity in January 2026, when it introduced three generative AI exclusion endorsements for commercial general liability policies. ISO's standardized forms underlie the large majority of property and casualty policies written in the country where it operates, so wherever a carrier adopts these endorsements, the effect reaches deep into the market. Not every carrier adopts every form on the same timeline, and some have not adopted them at all, but the direction of the market is now set.
The three forms differ in what they take away. CG 40 47 is the broad version: it bars bodily injury, property damage, and personal and advertising injury arising out of or attributable to generative AI, and it reaches both Coverage A and Coverage B of the policy. So in practical terms, it can eliminate coverage for AI-generated defamation, intellectual property disputes, and third-party harm tied to an AI system's inaccurate output. CG 40 48 is narrower: it removes only the Coverage B grant, the personal and advertising injury coverage that handles defamation and copyright claims. CG 35 08 works on a different part of the policy altogether, addressing the Products and Completed Operations exposure, so that bodily injury or property damage tied to generative AI loses coverage under that specific coverage part as well.
The operative phrase in each form, "arising out of, or attributable to," sets a low bar for denial. AI does not need to be the sole cause of a loss for a carrier to invoke the exclusion. If AI touched the process anywhere along the chain that produced the harm, the carrier has grounds to deny the claim.
None of this arrived without warning. The RAND Corporation's 2026 report on the insurability of artificial intelligence found that exclusion activity had already begun surging the previous summer, concentrated in commercial umbrella and CGL policies starting in summer 2025. ISO's January 2026 endorsements formalized a trend that the filing data had already shown building for months. Some carriers moved faster and further than ISO's standard language, filing near-absolute AI exclusions across directors and officers, errors and omissions, and fiduciary lines, broad enough to bar any claim arising out of AI use, output, training, or decision-making, regardless of how far removed the AI was from the actual harm.
Quiet coverage erosion beyond labeled exclusions
A labeled exclusion is the easy case, because at least it tells a policyholder directly what has changed. The harder case is the one where nothing on the declarations page announces any change, yet the architecture of the policy underneath it has moved. Insuring agreements get redrafted, definitions get narrowed, carve-backs disappear from renewal forms, and none of it needs a new exclusion endorsement to accomplish the same result: coverage that existed last year is gone this year, and the renewal document looks the same at a glance.
Reading a policy for AI risk now means reading the whole structure together, the insuring agreement, the definitions section, the exclusions, and any carve-backs, rather than scanning for a line that says "artificial intelligence" and stopping there. A company can pass that scan and still have lost ground.
The fragmentation compounds because no single regulator or standards body controls the whole market at once. Cyber carriers, Tech E&O carriers, D&O carriers, and EPLI carriers are each narrowing their own AI-related language on their own schedule, with no coordination between them. A single AI-related incident can fall into the space between several policies that each assumed another line would pick it up, a condition the industry calls gap risk.
RAND's report also named five mechanisms by which AI losses can cluster across many policyholders at once rather than striking one company in isolation: a universal attack that exploits a vulnerability shared across many AI deployments, common dependence on the same underlying models or infrastructure, AI acting as a force multiplier for cyberattacks generally, a legal or regulatory shock that makes a widespread AI practice suddenly actionable across the market, and slow degradation in model performance that produces claims across multiple policy lines before anyone recognizes the pattern. For autonomous and physical AI systems, this compounding effect is sharper still. A single incident involving a robot can read simultaneously as a cyber incident, a professional error, and a product defect, and that ambiguity generates disputes over which policy is supposed to respond before any claim gets settled.
The structurally worse problem for physical and autonomous AI systems
Physical AI, meaning robots, autonomous vehicles, and industrial automation systems that use sensors and models to decide how to act as conditions change, produces losses that do not sort cleanly into any one policy line. The same adaptability that makes these systems useful is what breaks the liability framework that traditional insurance was built around, because that framework assumes a human somewhere in the decision chain whose action or omission can be pinned down as the cause of harm.
A single incident involving a warehouse robot or an autonomous vehicle can involve a defective component, a flawed AI decision, a cyber event that altered the system's behavior, and a calibration error, all at once. That one claim touches product liability, CGL, cyber, and Tech E&O simultaneously, and each carrier on each of those policies has an incentive to argue that the loss belongs to one of the others.
Agentic AI sharpens the problem further. These are systems that take actions in the world rather than only generating text or recommendations, and when an agentic system causes physical or financial harm without a human directly intervening in that specific action, the loss may fall outside a CGL policy's insuring agreement. CGL was built on the premise of human-caused bodily injury and property damage, and an autonomous decision chain does not fit that premise cleanly. California has already moved to close one escape route: AB 316, effective January 1, 2026, bars AI companies from using the AI's autonomy as a legal defense, so a company cannot argue that harm resulted from the system acting independently rather than from the company's own design or deployment choices. That one change raises the stakes for every AI company operating in the state, because it removes a defense that might otherwise have shifted responsibility away from the manufacturer.
Because a single incident involving a robot can resemble a cyber event, a professional error, and a product defect all at the same time, operators running autonomous hardware in the field benefit from brokers who read the cyber, product liability, Tech E&O, and CGL lines together as one submission. Risklytics positions itself in that space, working to make sure the full scope of a physical AI deployment is visible to carriers up front, so that pricing and coverage reflect the actual risk rather than getting discovered as a gap only after an incident occurs.
What each coverage line does and does not cover for AI deployments
AI liability is handled, or mishandled, by a stack of lines that each cover a piece of the exposure and leave gaps where they meet.
Tech E&O is the anchor line for most AI product companies, covering claims arising from errors, omissions, or failures in a technology product or service. Standard E&O language, written before generative AI existed, may not respond to a hallucination, model drift, or algorithmic bias, because none of those look like the traditional software bugs the policy was drafted to cover. So the fix is policy language that names AI-generated outputs and automated decision errors explicitly. A small but growing number of carriers now offer affirmative AI insurance as a specialized form of Tech E&O, with explicit coverage for hallucinations, algorithmic bias, intellectual property disputes, and regulatory investigations, sold either as an endorsement to an existing policy or as a standalone product.
Cyber is currently the most adaptive line in the market. Coalition added an affirmative AI endorsement to its cyber policies in 2024 that treats an AI-caused security failure as a covered event and extends coverage to funds-transfer fraud carried out using deepfakes. AXA XL's GenAI endorsement to its CyberRiskConnect product covers data poisoning, usage-rights infringement, and violations tied to the EU AI Act.
CGL is now the line that has changed the most structurally. The ISO endorsements eliminate coverage for claims arising out of or attributable to generative AI use, development, or deployment, regardless of whether the AI involved is company-owned, licensed from a third party, or simply embedded inside another software tool the company uses.
A newer specialty tier has emerged around standalone AI and performance warranty products. Munich Re's aiSure functions as a performance guarantee, paying out when an AI model underperforms defined specifications, including accuracy, hallucination rate, or uptime thresholds, using a parametric-like structure, and it has been offered with limits reported up to $15 million through Mosaic. Chaucer, together with Armilla, offers Vanguard AI, which combines Chaucer's cyber and Tech E&O coverage with standalone AI liability under predefined allocation rules, built around a separate AI aggregate limit and predetermined rules for splitting a loss across cyber, tech failure, and AI behavior.
For autonomous robotics specifically, the practical stack usually needs four lines working together: Tech E&O, Cyber Liability, Product Liability, and technology-driven Business Interruption, structured to address AI errors, system failures, cyber-physical incidents, and the production losses that follow when a robot failure shuts down a line.
The underwriting submission as a governance audit
The market has split in two. Companies that can document an AI governance framework can now negotiate affirmative coverage. Companies that cannot are declined or face absolute exclusions.
The submission is now treated as evidence of how maturely the business manages the risk it is asking to insure, rather than merely a description of what the business does.
That shift changes what the submission is worth. A submission that documents testing protocols, model versioning, and an incident response plan produces a different quote, and often a different coverage outcome, than a generic application that describes an AI company as though it were a conventional software business. The gap between those two submissions is often the gap between an affirmative AI endorsement and a flat decline.
A common objection from smaller teams is that they lack a formal AI governance program to point to. Carriers are looking for evidence that risk is being managed on purpose rather than left to chance, and at an early-stage company that evidence can take modest forms: a documented testing procedure, a record of which model version is running in production, a written plan for what happens in the first hours after an incident. Even at a ten-person company with no formal risk office, each of those can serve as proof of governance maturity. The quality of the broker matters as much as the quality of the underlying business. A specialist broker working carrier relationships focused on autonomy can confirm what language is being bound and flag an exclusion that a generalist broker, filling out a standard form, might miss. Verifying affirmative coverage explicitly, rather than assuming last year's renewal language still applies, matters more now that ISO's exclusion language reaches most of the commercial market and the "arising out of or attributable to" standard does not require AI to be the sole cause of a loss.
Enterprise and government contracts enforcing coverage requirements
Insurance coverage has become a condition of doing business before it ever becomes a question of claims. Enterprise buyers and government agencies are now independently requiring AI-specific coverage as a prerequisite to signing a contract, and a company without affirmative coverage can lose the deal before any incident ever occurs.
Enterprise buyers increasingly set minimum limits on CGL, Tech E&O, and Cyber as a condition of vendor onboarding. Buyers in healthcare, finance, or government tend to ask for higher Tech E&O limits specifically, and some add a D&O requirement on top.
Government contracts layer a compliance structure on top of those same four lines, General Liability, Cyber, Tech E&O, and D&O, with regulation-driven terms that typically call for higher limits, additional insured status, and a waiver of subrogation. The GSA has moved to tighten that structure further. Its proposed clause GSAR 552.239-7001 imposes a 72-hour incident reporting requirement and requires prime contractors to flow compliance obligations down to their AI service providers, making commercial efforts to ensure those providers adhere to them. Earlier drafts of the clause included "Unbiased AI Principles," but the final rule, effective October 19, 2026, replaced that framework with a reasonable-efforts standard, while still giving the government authority to suspend use of an AI system and recover decommissioning costs where a contractor falls out of compliance. Defense contractors carry an additional layer under the FY2026 NDAA, which sets affirmative AI-specific requirements covering policy and governance, the defense supply chain, and protection against adversary-linked technology, moving well past the generic, software-era safeguards that older contracts relied on.
The practical risk this creates is straightforward: a company that has been operating under silent AI coverage can win a contract on the strength of its product, only to discover at execution that its policy language does not satisfy the customer's certificate of insurance requirements. By that point, fixing the gap takes time the contract timeline may not allow.
