Updated 17 August 2026.
This article names ISO endorsement form numbers. Two of the three, CG 40 48 01 26 and CG 35 08 01 26, we have read from specimens of the forms themselves, each marked SAMPLE and footed "© Insurance Services Office, Inc., 2025". Each is one page: a single sentence of exclusion and a single sentence defining "generative artificial intelligence" as a machine-based learning system or model trained on data with the ability to create content or responses. We have not read CG 40 47 01 26. Its existence, edition date and scope are reported consistently by brokers, law firms and the insurance trade press, but no specimen was publicly obtainable on 17 August 2026, so treat it as reported rather than read. Carrier-drafted AI exclusions, as distinct from the ISO forms, are not named here by form number at all: the carriers do not publish them and the published accounts contradict each other.
Whatever a form number says here, the endorsement schedule attached to your own policy is the record. Ask your broker for the endorsement itself, and note that a search engine confirming these numbers may be drawing on pages published by this network, including this one.
AI agent insurance covers the losses traditional E&O and cyber policies now exclude. Typical cover includes third-party claims when an agent harms a customer (a hallucination the customer relied on, a wrongful commitment, exposure of personal data) and the operator's own first-party losses (corrupted records, unauthorised transactions, investigation costs). It usually requires the agent to be assessed against a published framework first. The first live example is ElevenLabs, which secured an AIUC-1-backed policy in February 2026, underwritten through Lloyd's of London. Purpose-built providers including Klaimee now cover the same gap for other deployers. European SME availability is limited as of mid-2026.
- AI liability policies respond to five distinct categories of loss: third-party bodily injury or property damage, financial harm from incorrect AI output (errors and omissions), regulatory defence costs, data incident notification costs, and intellectual property claims from AI-generated content. Not all five are included in every policy form.
- The most important exclusion is the one most operators overlook: if you were warned about a failure mode and deployed anyway, the resulting loss is typically uninsurable. That comes from the ordinary expected-or-intended injury exclusion in commercial general liability and from the knowing-misuse exclusions in specialist AI wordings. It does not come from the ISO generative AI endorsements, which are simple "arising out of" exclusions with no state-of-mind test at all.
- Your existing general liability policy almost certainly does not cover AI agent failures. If your insurer did not ask about your AI deployments at renewal, they did not price for them and will not welcome a claim from them.
- The Air Canada chatbot case (Moffatt v. Air Canada, 2024) would have been a covered loss under a properly structured AI errors and omissions policy. The damages were small but the reputational and legal costs of the event were not.
- Prompt notification to your carrier is not optional. Delayed notification is the single most common ground for coverage denial in AI-related claims. If you become aware of an incident, notify your carrier the same day, not after you have investigated.
- Documented governance is the lever you hold on both your premium and your exclusion exposure. Written deployment policies, human oversight logs, and incident procedures give an underwriter something to price; whether that improves your terms is the insurer's decision, and no provider publishes what it is worth.
Why this question matters more than operators realise
The AI insurance market is expanding fast and in several directions at once. HSB (a Munich Re subsidiary) introduced SME AI liability insurance in the United States in March 2026, added to partner carriers' business policies rather than sold direct. Armilla operates as a Lloyd's coverholder with capacity from Chaucer Group, Axis Capital and Convex. Testudo entered the market in January 2026. At the same time, standard general liability policies are adding AI exclusion endorsements at renewal, narrowing the coverage that SMEs previously assumed they had.[1]
The result is a market where operators face mounting pressure to buy dedicated AI coverage while having limited visibility into what that coverage actually delivers. Most insurance brokers are themselves working through this in real time. This guide is a starting point for the conversation you need to have with yours, with specific enough language to help you evaluate what you are being offered.
The five payout categories
1. Third-party bodily injury and property damage
The most straightforward category covers physical harm or property loss caused by an AI system operated by the insured. This is primarily relevant to operators of AI in physical contexts: AI-controlled industrial equipment, autonomous navigation systems, AI-assisted medical devices, or AI systems directing physical actions. The trigger is an AI agent taking or recommending an action that results in a person being injured or property being damaged.
For most SMEs, this category has limited immediate relevance unless the AI system interacts with the physical world. A customer service chatbot, a content generation tool, or an AI assistant for internal use does not typically create bodily injury or property damage exposure. The coverage matters most for operators in logistics, construction, healthcare support, and any sector where AI recommendations translate into physical actions.[2]
Coverage note: most policies require that the bodily injury or property damage was unintended and unexpected. An operator who deploys an AI system in a context where physical harm is a foreseeable and unaddressed risk will find this coverage harder to access at claim time.
2. Errors and omissions: financial harm from incorrect AI output
This is the category most directly relevant to SMEs. It covers financial loss suffered by a third party because an AI system operated by the insured provided incorrect information, made an incorrect recommendation, or failed to perform a task accurately, and the third party relied on that output to their detriment.
The Air Canada chatbot case is the clearest illustration of this category in practice. Jake Moffatt contacted Air Canada's chatbot and received information about a bereavement discount policy that turned out to be incorrect. He purchased flights in reliance on the chatbot's statement and was then refused the discount. The BC Civil Resolution Tribunal awarded him CAD 812.02 in damages plus additional compensation.[3] Under an AI errors and omissions policy with a third-party financial harm trigger, the defence costs and the damages award would both have responded.
For an SME deploying an AI agent to answer customer questions, process orders, provide product recommendations, or give guidance on anything from tax treatment to medical protocols, this coverage category is the most important one on the policy. The trigger is: a customer suffered financial harm because they relied on your agent's output and the output was wrong.
The exclusions in this category are also the ones operators most commonly fail to read. Most policies exclude: losses where the operator was aware of the failure mode before deployment; losses from AI systems operating outside the scope defined at underwriting; and losses from professional services in regulated categories such as legal advice or medical treatment unless the operator holds the required professional licence and the policy is specifically structured for that sector.[4]
3. Regulatory defence costs and civil fines
As AI regulation has developed, so have the regulatory risks operators face. The EU AI Act (Regulation 2024/1689) creates a penalty regime of up to EUR 35 million or 7% of global annual turnover for the most serious violations, and up to EUR 15 million or 3% of turnover for deployer non-compliance with Article 26 obligations.[5] Colorado's AI Act (C.R.S. section 6-1-1701 et seq.), in force from 30 June 2026 (postponed from 1 February 2026), gives the state attorney general enforcement authority over algorithmic discrimination claims.
AI liability policies can cover the legal defence costs incurred in responding to a regulatory investigation, even where no fine ultimately results. Defence costs coverage is often the most valuable element for SMEs, where the cost of legal representation in a regulatory enquiry can exceed the eventual penalty.
An important limitation: most jurisdictions prohibit insuring against the fines themselves in certain categories, particularly criminal penalties and fines specifically excluded by statute from being the subject of insurance contracts. Your policy wording will specify whether civil regulatory penalties are covered, defence costs only, or both. Read this clause before the investigation begins, not after.[6]
4. Data incident notification and crisis management costs
Where an AI system processes personal data and a data incident occurs, costs accumulate fast: forensic investigation, regulatory notification requirements under the GDPR's 72-hour supervisory authority notification obligation (Article 33 of Regulation 2016/679), individual notification where required, credit monitoring services, and public relations management. AI-specific policies increasingly include a data incident response cost trigger that does not require a formal third-party claim before coverage responds.
This category overlaps significantly with cyber insurance. Operators who already hold a cyber policy should review it alongside any AI-specific coverage to identify both gaps and duplication. The risk of a coverage gap is typically in the AI-specific failure mode, where an AI system's error caused the data incident rather than a conventional network intrusion. Some cyber policies exclude losses arising from AI system failures that were not caused by an external threat actor.[7]
5. Intellectual property claims from AI-generated content
Where an AI system generates content that infringes a third party's copyright, trademark, or other intellectual property right, the resulting claim falls on the operator, not the model provider. Model providers including Microsoft (via its Azure OpenAI Copilot Copyright Commitment), Google, and Amazon Bedrock have each committed to defend customers against copyright infringement claims arising directly from the model's training data, subject to usage policy compliance. However, these commitments have limits and do not cover operators who have modified outputs, combined them with other content, or used them outside the terms of the provider's commitment.[8]
An AI liability policy with an IP infringement endorsement covers the defence costs and damages from a copyright or trademark claim where your AI agent produced the infringing content. This is particularly relevant for operators using AI to generate marketing copy, code, images, or other creative output that is published externally.
The three exclusions that end most claims
Understanding what a policy covers is only half the analysis. The exclusions are where most AI-related claims encounter resistance. Three exclusions account for the majority of denied AI claims at SME scale.
Exclusion 1: Expected or intended outcomes
A correction first, because an earlier version of this section attributed this exclusion to the wrong forms. The expected-or-intended test does not come from the ISO generative AI endorsements. Those are one-page forms with a single "arising out of" trigger and no state-of-mind element. It comes from two other places: the standard commercial general liability wording, which has always excluded bodily injury and property damage expected or intended from the standpoint of the insured, and the knowing-misuse and deliberate-act exclusions carried by specialist AI liability wordings.[9]
The effect for an operator is the same, and it is the reason the correction is worth making rather than deleting. If you reviewed your AI system before deployment, identified a category of error, and deployed anyway, you have created a record that the outcome was foreseen. An insurer reading that record has an argument that the loss was expected.
The practical implication is significant. An operator who runs careful pre-deployment testing, identifies a failure pattern, documents it, and then deploys anyway has created a record that the outcome was expected. The solution is not to skip testing. It is to fix the identified failure patterns before deployment and document that you did so. A clean pre-deployment audit, properly documented, is both a risk management tool and an insurance document.
Exclusion 2: Systems outside the scope disclosed at underwriting
Insurers price AI liability coverage based on what the operator disclosed at underwriting: the types of AI systems in use, the categories of decision they support, the sectors they operate in, and the volume of interactions they handle. If a claim arises from an AI system or deployment category that was not disclosed, or that has materially changed since disclosure, the claim may be denied on the basis of material misrepresentation or non-disclosure.
This exclusion catches operators who add AI tools during the policy period without notifying their carrier, deploy an existing AI tool in a new higher-risk category (for example, moving from internal use to customer-facing use), or exceed the deployment volumes or geographic scope disclosed at underwriting. Most AI policies include a mid-term notification obligation for material changes to the AI systems they cover. Treat this obligation seriously.[4]
Exclusion 3: Regulatory categories where coverage is prohibited
Certain categories of AI deployment attract regulatory restrictions that also affect insurability. An operator who deploys AI in a regulated professional context without the required authorisation (medical diagnosis without regulatory clearance, legal advice without a practising certificate, financial advice without FCA or equivalent authorisation) will find that claims arising from that deployment fall outside coverage, both because the activity itself was prohibited and because the insurer did not price for a regulated professional liability risk.
The EU AI Act's Article 5 prohibited practices are a particularly important boundary. Any AI system that falls within the Article 5 prohibitions (subliminal manipulation, social scoring, real-time biometric surveillance in public spaces except in defined law enforcement contexts) cannot be deployed legally, and claims arising from it will not be covered by any legitimate insurer.[5]
Three realistic claim scenarios
Scenario A: Customer service agent gives wrong pricing. Coverage responds.
A retail SME deploys an AI customer service agent that has access to a product database. The database contains a pricing error for a limited period. The agent quotes 200 customers the incorrect price during that window. Thirty customers place orders at the quoted price and then receive invoices at the correct (higher) price. Twenty of the thirty dispute the charge or request refunds. The SME incurs legal review costs for five formal complaints and refunds eight customers totalling EUR 3,400.
Under an AI errors and omissions policy with a third-party financial harm trigger: the defence costs and the refunds respond, subject to the policy's retention (excess). The trigger is met: the AI system provided incorrect information and customers suffered financial harm by relying on it. The exclusions are not engaged: the pricing error was not a known failure mode at deployment, the system was operating within the scope disclosed at underwriting, and the activity is not in a prohibited category. This is the scenario AI E&O coverage is designed for.
Scenario B: AI hiring screener applies discriminatory criteria. Partially covered.
An SME uses a third-party AI hiring tool to screen applications for a customer service role. The tool, without the operator's explicit instruction, ranks candidates below 25 and above 55 lower than others in the same qualification bracket. Three rejected applicants file age discrimination complaints with the national equality body. The SME incurs legal representation costs of EUR 18,000 over nine months before the complaints are resolved with a finding of no deliberate discrimination but inadequate oversight.
Coverage position: the defence costs are likely covered under a policy with a regulatory defence cost endorsement, because the trigger is a regulatory investigation rather than a direct civil claim. The outcome (no discrimination finding) does not negate the defence cost claim. However, if the insurer can demonstrate that the operator had access to the tool's demographic performance data and failed to review it before deployment, the expected or intended outcome exclusion may partially apply. The lesson for SMEs: review the bias and fairness performance documentation for any AI tool you use in employment decisions before deploying it, and keep a record of having done so.[10]
Scenario C: AI content tool generates copyright-infringing marketing copy. Coverage depends on disclosure.
A marketing agency uses an AI writing tool to generate social media content for clients. A client campaign uses generated copy that closely resembles a competitor's branded slogan. The competitor issues a cease and desist and then files a trademark infringement claim seeking EUR 50,000. The agency's legal costs in responding are EUR 12,000 before a settlement of EUR 8,000 is reached.
Coverage position: if the agency disclosed its use of AI content generation tools at underwriting and the policy includes an IP endorsement, the legal costs and the settlement may both respond subject to the retention. If the AI tool was added after the policy was bound and the carrier was not notified, the claim may fail on the non-disclosure exclusion. This scenario illustrates why the mid-term notification obligation for new AI tools is not administrative overhead. It is a precondition to coverage.[8]
What documentation strengthens a claim
The practical outcome of an AI insurance claim depends significantly on the documentation an operator can produce. Insurers examining AI-related claims look for four categories of evidence that were assembled before the incident occurred, not afterwards.
First, system documentation: a written description of what the AI agent is designed to do, what it is designed not to do, the data sources it accesses, and the constraints applied at deployment. This is the baseline document that establishes what the operator intended the system to do and what the operator considered to be outside scope.
Second, pre-deployment review: records of any testing conducted before deployment, the results of that testing, the failure modes identified, the steps taken to address them, and the sign-off process before go-live. This documentation directly addresses the expected or intended outcome exclusion: it demonstrates that the failure that caused the claim was not identified in pre-deployment testing and was therefore not expected.
Third, oversight and monitoring: records of how the AI system was monitored after deployment, what review process was applied to its outputs, and whether any anomalies were escalated. Regular human review of AI outputs is both a risk management measure and a coverage documentation tool.
Fourth, the incident record: a contemporaneous log of when the operator became aware of the incident, what steps were taken, and when the carrier was notified. The timestamp on carrier notification is often the first document an insurer reviews when a claim is filed. Late notification that cannot be explained will typically result in a coverage dispute.[6]
The structured framework for building this documentation before any claim arises is available at agentcertified.eu, where the seven-dimension AI agent certification methodology maps directly to the evidence categories insurers examine at claim time.
How to read your policy before a claim happens
Three clauses determine most AI-related claim outcomes. Read them before you need them.
The insuring agreement defines the trigger. Look for whether the policy requires a formal claim to be made against you during the policy period (claims-made) or whether it requires only that the incident occurred during the period (occurrence). Most professional liability and E&O policies are claims-made, which means the policy in force when the claim is first made against you is the one that responds, regardless of when the incident occurred. If you change carriers, maintain tail coverage for incidents that may emerge from prior deployment periods.
The definition of AI systems tells you what is covered. Some policies cover only AI systems specifically listed at underwriting. Others use broader language covering any automated decision-making or machine learning system. If the definition is narrow, an AI tool you deploy after binding that was not listed at underwriting is likely outside coverage. If the definition is broad, ensure you understand what it includes because broad coverage may come with broader exclusion language.
The notification condition sets the clock. Most claims-made policies require prompt written notice to the carrier upon becoming aware of any claim or circumstance that could give rise to a claim. Some policies specify a number of days, typically 30 to 60. Others use broader language. In either case, the standard advice applies: notify your carrier on the day you become aware of an incident, in writing, with a brief factual summary. A detailed investigation is not required for notification. The notification can precede the investigation.
For more detail on how policy language maps to specific AI failure scenarios, see the SME policy exclusions guide and the European market coverage analysis at agentinsured.eu, which tracks how European insurers are structuring AI liability products in 2026.
Questions
What does AI insurance actually pay out for?
AI liability policies typically respond to five categories of loss: third-party bodily injury or property damage caused by an AI system, financial harm to a customer from an incorrect AI output (errors and omissions), regulatory fines and defence costs where coverage is permitted by law, crisis management and notification costs after a data incident involving AI-processed personal data, and intellectual property claims including copyright infringement by AI-generated content. The exact scope depends on the policy form and whether your insurer uses an affirmative AI endorsement or a general technology professional liability framework.
What is excluded from most AI insurance policies?
Common exclusions include: losses from deliberate or knowing misuse of the AI system by the operator; claims arising from AI systems deployed in excluded high-risk categories such as autonomous weapons or clinical treatment without regulatory approval; bodily injury to employees; losses from system unavailability where no third-party harm occurred; and fines uninsurable under applicable law. Separately, if your commercial general liability policy carries an ISO generative AI exclusion endorsement, AI-related general liability claims are removed from that policy altogether, which is a different mechanism from an exclusion inside an AI policy.
Does my existing business insurance cover AI agent mistakes?
Usually not. Standard general liability policies were written before AI agents existed and contain exclusions for professional services, expected outcomes, and technology errors that typically apply to AI-related failures. Professional indemnity policies may provide some cover for errors where an AI tool contributed, but most insurers are adding AI exclusion endorsements at renewals. The clearest signal: if your insurer did not ask about your AI deployments at renewal, they did not price for them and will not welcome a claim.
How much does AI liability insurance cost for a small business?
No provider in this market publishes a premium or a rate card. HSB is the exception on limits: its release gives standard limits of USD 25,000 or USD 50,000 with a USD 500 deductible, higher limits available. It published no premium. A broker submission is the only way to obtain a real figure. Documented governance is the lever you hold on premium: written deployment policies and incident logs give the underwriter something to price and your broker a case on terms, though no provider publishes what they are worth.
What triggers a valid AI insurance claim?
A valid AI insurance claim typically requires: an AI system operated by the insured was the proximate cause of a covered loss; the loss falls within a covered category; the claim is first made during the policy period; and the insured notified the carrier promptly. The most common reasons claims fail: delayed carrier notification, the loss arose from a system category not disclosed at underwriting, or the loss was classified as a business performance failure rather than an AI agent failure.
What happened in the Air Canada chatbot case and what would insurance have covered?
In Moffatt v. Air Canada (BC Civil Resolution Tribunal, 2024), the tribunal awarded CAD 812.02 to a passenger who relied on Air Canada's chatbot stating he could claim a bereavement fare retrospectively. Under a properly structured AI errors and omissions policy, the defence costs and the damages award would likely have been covered. The AI error (incorrect policy information) is precisely the trigger AI E&O policies are designed to respond to. The more important lesson: the reputational and legal costs of the event far exceeded the CAD 812 damages award.
Related reading
Run the Coverage Audit
Before you talk to a broker, use the Coverage Audit tool to map your current policies against your AI agent exposure. It takes ten minutes and produces the document your broker needs to review your position.
Start the Coverage Audit