The most honest assessment of artificial intelligence risk is not found in any regulator's speech. It is found in insurance policy language, where opinions are backed by capital. By that measure, 2026 marks a turning point: carriers are actively weighing new ISO exclusions targeting generative AI risks in commercial general liability policies, responding to litigation that has grown roughly tenfold since 2021, led by patent, copyright, and privacy claims.
An exclusion is not a prediction that AI is dangerous everywhere. It is a statement that the risk can no longer ride along silently inside policies priced before the risk existed. Until now, many traditional policies arguably covered AI-related losses by accident, simply because nothing in the wording carved them out. That era of inadvertent coverage is ending — and both sides of the market need to respond deliberately.
The carrier's dilemma Insurers face a genuine strategic fork. Exclude broadly, and you shrink exposure but also relevance — pushing clients toward competitors willing to underwrite the risk, and toward a growing specialty market in AI liability. Underwrite and price the risk, and you need something the industry mostly lacks: underwriting insight into how a policyholder governs its AI. Which models does the insured deploy? What testing, human oversight, and vendor controls exist? A carrier that cannot ask those questions cannot price the answer, and will default to exclusion by necessity rather than strategy.
This is where insurance and AI governance converge in a way few have noticed: the underwriting questionnaire is becoming a de facto governance audit. Policyholders with documented AI inventories, testing regimes, and incident processes will increasingly buy coverage that poorly governed competitors cannot obtain at any price. Insurance is about to do for AI governance what it did for fire codes and cybersecurity — make it a condition of doing business.
What each side should do now Risk managers and brokers should read renewal terms with fresh eyes: inventory where the business uses AI, map those uses against current wordings, and negotiate explicitly — silence in a policy is no longer a coverage strategy. Where exclusions appear, ask what affirmative AI coverage exists and what governance evidence would improve terms. General counsel should treat the litigation statistics as a leading indicator: the claim mix arriving at insurers today is the lawsuit mix arriving at companies tomorrow.
Carriers, for their part, should resist the comfort of the broadest exclusion. The insurers that build genuine AI underwriting capability — the ability to distinguish a well-governed deployment from a reckless one — will own a profitable specialty line while the rest of the market cedes it. Excluding a risk you do not understand is prudence; still not understanding it three years later is strategy failure.
Related reading - [From principle to proof: bias testing in AI underwriting and claims](/insights/ai-bias-testing-underwriting-claims-jonas-osman-abdelghafour) - [You didn't build it, but you own it: third-party AI risk comes of age](/insights/third-party-ai-vendor-risk-financial-services-jonas-osman-abdelghafour) - [The NAIC's AI evaluation pilot is the new exam playbook](/insights/naic-ai-evaluation-pilot-insurers-jonas-osman-abdelghafour)
See also Insurance Risk, Enterprise Risk and Model Risk.
About the author Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.
Frequently asked questions
What should risk leaders know about the carrier's dilemma?
Insurers face a genuine strategic fork. Exclude broadly, and you shrink exposure but also relevance — pushing clients toward competitors willing to underwrite the risk, and toward a growing specialty market in AI liability. Underwrite and price the risk, and you need something the industry mostly lacks: underwriting insight into how a policyholder governs its AI. Which models does the insured deploy? What testing, human oversight, and vendor controls exist? A carrier that cannot ask those que...
What each side should do now?
Risk managers and brokers should read renewal terms with fresh eyes: inventory where the business uses AI, map those uses against current wordings, and negotiate explicitly — silence in a policy is no longer a coverage strategy. Where exclusions appear, ask what affirmative AI coverage exists and what governance evidence would improve terms. General counsel should treat the litigation statistics as a leading indicator: the claim mix arriving at insurers today is the lawsuit mix arriving at co...
What should risk leaders know about related reading?
See also [Insurance Risk](/expertise/insurance-risk), [Enterprise Risk](/expertise/enterprise-risk) and [Model Risk](/expertise/model-risk).
What should risk leaders know about about the author?
Jonas Osman Abdelghafour writes about AI governance, risk management, and regulation in insurance and banking. Follow Jonas Osman Abdelghafour for analysis of how supervisors, carriers, and banks are adapting to artificial intelligence.