AI liability deserves its own line.
Auxilium SpecialtyOctober 20264 min read
Every new technology enters insurance the same way: first as risk nobody priced, then as risk everyone excludes, then as a line of its own. AI is in the middle of that path now. The real question is which AI risks will stay inside existing policies and which will need a policy of their own.
We've seen this before
Cyber followed four steps. First, the internet arrived and losses landed quietly in property, crime and general liability forms that never meant to cover them. That was "silent" cyber.
Next, carriers reacted. ISO introduced data breach exclusions for general liability in 2014, and by 2019 regulators and markets were requiring insurers to state whether cyber was covered or not. Endorsements filled the gaps for a while.
Finally, the risks that didn't fit anywhere else became a standalone line: breach response, ransomware, network interruption. Today cyber is a market of more than $15 billion a year.
AI is at the endorsement step. ISO's generative AI exclusions (CG 40 47, CG 40 48, CG 35 08) took effect in January 2026, with thousands of filed adoptions reported since. Carriers are drawing lines. Some risks will be written back into existing forms. Others won't be.
What existing lines will absorb
Most AI use is a person using a tool, and existing lines know how to cover a person's mistake. These scenarios will be clarified, not orphaned:
- A lawyer files a brief with a hallucinated citation from a copilot. That's professional negligence. E&O will cover it, with AI language added.
- A chatbot on a retail site defames someone. Personal and advertising injury already covers that. Expect affirmative buy-backs to CG 40 47.
- An AI-written phishing email tricks an employee into a wire transfer. That's social engineering, which crime and cyber already cover.
- An AI screening tool rejects job applicants unfairly. Employment practices liability will add AI endorsements.
- A generated marketing image infringes a copyright. Media liability already prices content risk.
The pattern is simple: when a person stays responsible for the output, the existing line can absorb it.
What won't be absorbed, line by line
The gap opens when software acts on its own, inside the access it was given:
- Crime needs a deceiving third party or a dishonest employee. An agent that refunds the wrong customers 4,000 times has neither.
- Cyber needs a security failure. An agent with valid credentials doing the wrong thing involves no breach.
- E&O covers claims against you for professional services. It doesn't pay your own loss, and it is now adding AI exclusions.
- CGL covers injury and property damage. Most agent losses are financial, and the new ISO forms exclude AI anyway.
- D&O covers management decisions, not an agent's operational error, and some forms now exclude AI outright.
- Property and business interruption need physical damage. A bad model update causes none.
Risks that will need their own line
First-party
- Execution loss: an agent makes payments, issues refunds or places orders correctly authorized but wrong.
- Runaway usage: an agent loops and runs up compute or API charges overnight.
- Destroyed data with no breach: an agent deletes production records using permissions it legitimately holds.
- Shutdown and rollback: the cost of stopping, investigating and restoring a malfunctioning agent.
Third-party
- Customer reliance: a support agent makes a commitment that customers act on, outside any professional service.
- Algorithmic discrimination: a pricing, credit or claims model treats customers or applicants unfairly.
- Regulatory proceedings: state AI laws and the EU AI Act create investigations and fines no current form was written for.
- Correlated failure: one model update causes losses at hundreds of companies at once. That's an accumulation problem general lines are built to avoid, not price.
These risks share three traits. The loss is caused by the software, not a person. It can be bounded in advance. And it moves together across insureds. Each of those calls for a dedicated underwriting method.
A note on the name
"AI liability" is the name the market has settled on, but it can mislead. It suggests the risk is the technology itself, and that every use of AI needs a new policy. As the sections above show, it doesn't: most AI use is a person using a tool, and existing lines will absorb it.
The risk that needs its own line is narrower. It is software acting on its own, inside the access it was given. Names like "agentic liability" or "autonomous execution loss" describe that more precisely. We use "AI liability" because it is the term buyers and brokers recognize, but the line we write is built for what software does when no person is in the loop.
Why our policy is built for that line
We split cover the way the risk splits. Section A covers your own loss from your scheduled agents, capped at what each agent can actually move before it is stopped. Section B covers liability from any use of AI that your other policies now exclude, including algorithmic discrimination and regulatory proceedings.
We don't price the model, which changes every few months. We price the limits that hold through any model update: payment caps, permissions, approval thresholds. Then we verify them every quarter, and within seven days of any change.
One model update is one event, and vendor concentration is capped. That's the correlation that keeps general lines out of this risk, and it's what makes it insurable as a line of its own.
Cyber took about twenty years to make this transition. AI is moving faster. The firms that build the method now will set the terms of the line.
