Est.

Denied AI Claims and the Policy Language That Enabled the Denial

Staff Writer, AI Ethics & Policy · · 10 min read
Cover illustration for “Denied AI Claims and the Policy Language That Enabled the Denial”
AI Harm and Claims · October 7, 2026 · 10 min read · 2,276 words

Denied AI claims rarely trace back to bad luck. They trace back to specific clauses, definitions, and endorsements that standard commercial policies now carry, often invisibly, and that most operators never read until a loss has already occurred. Understanding the exact mechanisms that produce these denials is the only reliable way to know whether a policy's AI coverage is real or illusory before that moment arrives.

The end of silent AI coverage

Before 2025, professional liability, commercial general liability, and errors and omissions policies were silent on artificial intelligence. They neither named it as a covered exposure nor carved it out as an excluded one. Insurance practitioners came to call this the "silent AI" period: coverage existed by default, because the policy language was ambiguous and ambiguity, under longstanding contract law, tends to favor the party that did not draft the document. Courts applying the doctrine of contra proferentem construed unclear policy terms against the insurer, which meant that a policyholder whose claim touched an AI system often won coverage simply because the policy never said no.

Most commercial policies written today no longer have that judicial backstop to fall back on. Carriers have replaced the ambiguity that once worked in policyholders' favor with express exclusion language, which eliminates the interpretive question that contra proferentem depended on. A court cannot construe language in a policyholder's favor when the exclusion states its scope directly. The shift did not arrive as a public product announcement that policyholders could track and respond to. It moved through endorsement schedules attached at renewal, through disclosure questionnaires asking about AI use that began appearing broadly across the 2025 to 2026 renewal cycle, and through underwriting memoranda that stayed internal to the carrier. Transitional exclusions took effect in January 2026, and by the time most organizations received their renewal paperwork, the exclusion language was already a standard modification rather than a negotiated change requiring their sign-off. An organization whose broker did not specifically flag the new language at renewal may still believe its coverage looks the same as it did the year before, while the contract itself has already changed underneath it.

The ISO forms that changed the baseline for most commercial policies

The scale of this shift did not come from individual carriers making independent underwriting decisions. It came from a major policy-rating organization, known throughout the industry by its standardized filings, and it files standardized policy forms used by property and casualty insurers across the United States. Because so much of the commercial insurance market is built on these standardized forms rather than bespoke carrier language, a change filed at the rating organization's level touches a large share of commercial policies simultaneously, across many carriers' books of business at once. ISO filed three generative AI exclusion endorsements for commercial general liability policies, effective January 2026, numbered CG 40 47, CG 40 48, and CG 35 08, and each one does a slightly different job. CG 40 47 is the broadest of the three, excluding bodily injury, property damage, and personal and advertising injury arising out of generative AI under both Coverage A and Coverage B of a standard CGL policy. CG 40 48 is narrower: it limits its reach to Coverage B, so it applies only to personal and advertising injury claims. CG 35 08 extends the same generative AI exclusion to products and completed operations coverage, so it matters directly to any company whose AI-enabled product, or whose completed service involving AI, causes harm after it has left the company's direct control.

Because these forms are filed at the ISO level, a policyholder cannot assume that an AI exclusion appearing in a renewed policy reflects a deliberate choice by that policyholder's specific carrier. The exclusion may simply be the new baseline that ships with the form, and removing it requires the policyholder or its broker to negotiate an affirmative carve-back. State insurance regulators approved more than four in five of the carrier requests to add explicit AI exclusions to general liability, D&O, and E&O policies, so these exclusions cleared the public regulatory approval process in large volume without generating the kind of scrutiny or press attention that might have put policyholders on notice. If a company renewed a standard general liability policy any time after January 2026 without specifically interrogating its endorsement schedule line by line, it may be carrying coverage assumptions that no longer match the contract it signed.

Four exclusion patterns that appear in 2026 policies

Diagram: Four Exclusion Patterns That Can Void AI Coverage. Visualizes: Visualize four distinct exclusion patterns found in 2026 commercial policies, arranged as a ranked or stepped list showing each pattern's name, its key trigger phrase, and the…

Knowing that "an AI exclusion exists" in a given policy tells an operator almost nothing useful, because four distinct exclusion patterns have emerged across 2026 policies, each built on different definitions and different triggers. The scope of each pattern decides which operations lose coverage and which stay protected, and a sophisticated buyer may find several of these patterns stacked into one endorsement.

The first pattern is the output exclusion. It excludes any loss arising out of content that an AI tool generated, and its danger sits in a specific phrase: "in whole or in part." Sample language reads: "The insurer shall not be liable for any Loss arising out of, based upon, or attributable to the use of any artificial intelligence system, including but not limited to losses arising from output, content, or recommendations generated in whole or in part by such system." Because the exclusion applies to output generated in whole or in part by an AI system, a carrier can argue that any AI-touched material triggers the exclusion no matter how extensively a human later reviewed, edited, or approved it. The human-editing defense that most operators assume will preserve their coverage simply does not survive contact with this language.

The second pattern is the vendor exclusion, which excludes losses caused by third-party AI tools that the insured used but did not build or control. Its sample language states: "This policy does not cover Loss arising from any third-party artificial intelligence product, service, model, or API used by the Insured." If a company embeds an external AI API, including enterprise-licensed products purchased under a formal contract, it inherits the exclusion attached to that underlying provider's technology under this pattern. One negotiating point has proven defensible in practice: carriers have accepted carve-outs for enterprise-licensed AI products governed by a business associate agreement or a data processing agreement, which gives policyholders a concrete basis for pushing back against the vendor exclusion.

The third pattern, the decision exclusion, deserves the closest attention because it is the least intuitive of the four and the one most likely to surprise an operator who assumes that keeping a human in the loop protects their coverage. It excludes losses from business decisions "substantially informed by" an AI system, even when a human made the final call. The sample language reads: "The insurer shall not be liable for any Loss arising from any decision, determination, or recommendation made by, or substantially informed by, an automated decision-making system or artificial intelligence model." The phrase "substantially informed by" does the damage here. It allows a carrier to argue that a human-in-the-loop workflow remains excluded, because the human's final decision was itself shaped by AI input, regardless of whether a person technically pulled the trigger. For an operator running an autonomous vehicle's routing logic, a robot's path-planning output, or an AI-driven medical triage recommendation, this pattern may apply even when a human explicitly approved the resulting action, because the decision exclusion asks only whether AI substantially informed the outcome, not whether a human retained final authority. Operators negotiating these endorsements have one meaningful lever: pushing carriers toward "sole decision-making" language in place of "substantially informed by" is the specific change that preserves coverage for genuine human-in-the-loop workflows.

The fourth pattern is the hallucination exclusion, and it appears mainly in professional liability contexts. It excludes losses stemming from AI that generates false, fabricated, or misleading content in legal, accounting, medical, financial, and comparable professional service settings. Its sample language reads: "This policy does not cover Loss arising from any inaccurate, fabricated, false, or hallucinated content generated by an artificial intelligence system, including but not limited to false citations, fabricated case law, inaccurate medical recommendations, or erroneous financial advice." This exclusion began in professional liability forms but is spreading into E&O policies for any service provider whose deliverables incorporate AI-assisted analysis or recommendations, which broadens its reach well beyond the law firms and accounting practices where hallucination risk first drew attention.

Why autonomous and physical AI systems face the sharpest exclusions

Autonomous and physical AI systems absorb the sharpest version of all four patterns, because these systems act on sensor input and model output without waiting for a human to start them, and standard policy language treats that very feature as the trigger for exclusion. A warehouse robot, a delivery drone, or an autonomous vehicle is built to use sensors, software, and AI models to adjust its behavior as conditions change in real time. That adaptive capacity is the entire value proposition of the technology, and it breaks the liability framework that standard commercial policies were built around, a framework that generally assumes a human actor made the proximate decision that led to a loss.

The decision exclusion's "substantially informed by" language is specifically hostile to this category of operation. An autonomous system's entire purpose is to make decisions, so a carrier has a strong argument that every outcome the system produces was substantially informed by the AI, regardless of whatever human review happened afterward. The output exclusion compounds this problem: it applies to any AI-generated recommendation or instruction, which covers the routing outputs, path-planning decisions, and sensor-fusion conclusions that an autonomous system produces continuously during normal operation, including during routine use. Beneath both exclusions lies a further structural problem: standard business insurance responds only to a loss that fits the policy's definition of an "accident," and an autonomous system acting on its own decision-making can be characterized as intentional deployment. So coverage could disappear before anyone even reaches the AI exclusion itself.

Physical AI incidents also tend to generate losses that cross multiple policy lines at once, and coverage gaps open at each boundary where those lines meet. A standard general liability or products liability policy might cover the physical damage a robot causes in a collision, but if the production line shuts down afterward, that business interruption is typically excluded or sharply sublimited under that same policy. A third-party logistics operator running autonomous mobile robots in a shared warehouse carries contractual liability to the facility owner and to workers on site, and this sits entirely apart from whatever product liability attaches to the robot's manufacturer, so the policy covering one party's exposure does not automatically extend to the other. Workers' compensation carriers have begun requiring documented risk assessments against the ANSI/RIA R15.06 standard before they will bind coverage for collaborative robot environments, and an employer that deploys a cobot without that documentation risks a workers' comp carrier declining to cover an injury claim on the basis that the required safety standard was never met.

Absolute" exclusions in D&O and E&O policies

W. R. Berkley has introduced an "absolute" AI exclusion across directors and officers, errors and omissions, and fiduciary liability lines that goes further than any of the four patterns described above, because it does not confine itself to AI outputs or AI-informed decisions. It excludes the entire claim if AI was involved anywhere in the chain of events, including cases where the insured's failure was simply not detecting that someone else had used AI. The endorsement excludes any claim "based upon, arising out of, or attributable to" the "actual or alleged use, deployment, or development of Artificial Intelligence." It extends further still, excluding claims tied to an insured's "failure to identify or detect content or communications created through a third party's use of Artificial Intelligence," which means a company that relied on a vendor's AI-generated output without ever knowing it was AI-generated can still have a resulting claim denied. The endorsement also excludes "inadequate or deficient policies, practices, procedures, or training relating to Artificial Intelligence," so a governance failure at the board level falls outside D&O coverage even when no AI system had any direct hand in causing the loss itself. The phrase "arising out of" has long been understood in insurance contracts as deliberately broad: a carrier invoking it does not need to prove that AI was the sole cause of a loss, only that it was connected closely enough to the alleged harm, and that breadth gives carriers considerable room to deny a claim that an operator might reasonably have expected to be covered.

The D&O dimension of this exposure creates personal liability risk for individual directors and officers, and it exists apart from the company's own operational insurance program. A Harvard Law School Corporate Governance Forum analysis described this as "the hidden C-suite risk of AI failures," pointing to directors who assume their D&O policies cover AI-related governance claims without realizing that exclusion language added at a recent renewal has quietly withdrawn that protection. The Caremark doctrine, which establishes that directors can face personal liability for failing to adequately monitor the risks a company faces, has already been applied to AI governance failures, and under an absolute exclusion, the D&O policy simply does not respond to a claim built on that theory. For companies operating autonomous systems, this exposure is especially acute. A physical incident involving an autonomous system will draw board-level scrutiny of the company's governance and oversight practices almost automatically, and if the company's D&O policy carries an absolute AI exclusion, its directors and officers have no personal coverage waiting for them when that scrutiny arrives.