Your CGL no longer covers the chatbot
Insurance Services Office has filed a trio of generative AI exclusion endorsements that are landing in commercial general liability policies right now. The structural choice — a broad 'arising out of' bar with narrow carve-backs — turns the CGL from a default AI backstop into the first line an enterprise must check. The deployer, not the carrier, is the residual risk-bearer unless the four-line coverage matrix is closed.
Last week I argued that the evaluator is the supply chain. Three frontier labs' agents breached real organizations through the same third-party evaluator's misconfigured environments, and the accountability question moved from the model to the intermediary.
This post is about the next node in that chain.
If the model breaches the org, the cyber and general liability carriers do not pay. The deployer eats the loss. The reason is not a model failure or an evaluator failure. It is policy architecture. A trio of new ISO endorsements — filed by Verisk and adopted in waves through 2026 renewals — have quietly turned the commercial general liability policy from a default AI backstop into the first line an enterprise must check. Most enterprises have not checked.
That is the story.
What was filed, and what it says
In the second half of 2025, Insurance Services Office — a Verisk unit that drafts the standard policy forms most US commercial carriers adopt — filed three generative AI exclusion endorsements and obtained state approvals in a 30-to-60-day window that insurance practitioners described as unusually fast.
The forms are:
- CG 40 47 01 26, the headline endorsement, excludes bodily injury, property damage, and personal and advertising injury "arising out of" the use of generative AI under both Coverage A and Coverage B of the CGL. It includes a definition of generative AI.
- CG 40 48, the Coverage B–only companion, excludes personal and advertising injury "arising out of" the use of generative AI, without touching Coverage A.
- CG 35 08, the Products/Completed Operations endorsement, excludes bodily injury and property damage "arising out of" the use of generative AI for vendors whose AI output becomes part of a product or service.
All three are effective January 1, 2026, and carriers have been attaching them at renewal in waves through 2026. According to Verisk VP Joe Lam and Lathrop GPM partner Alana McMullin, both speaking to *Claims Journal* in July, the interest has been unusually broad for new exclusion language. McMullin, who practices in complex insurance coverage disputes, called it "the spark of this AI exclusion boom."
The form language matters more than the filing. Read carefully, CG 40 47 is structured as a broad "arising out of" bar with narrow carve-backs. That is the opposite of how most cyber exclusions were drafted, and the inversion is the load-bearing legal mechanism that will determine the next two years of coverage litigation.
The structural choice that does the work
Insurance exclusions come in two structural flavors.
A narrow bar with broad carve-backs says: this specific thing is excluded, but everything adjacent to it is covered unless another exclusion applies. This is how most cyber exclusions are written. The carrier identifies a known loss trigger (unauthorized access, network failure, ransomware) and lists the categories of loss that still flow even if the trigger is met.
A broad bar with narrow carve-backs says: anything arising out of this category is excluded, with a small list of exceptions. The carrier defines the category once, then captures the surrounding risk with it.
CG 40 47 is the second shape. The "arising out of" language is the broadest causal connector recognized in US coverage law — broader than "caused by," broader than "resulting from." Courts in most jurisdictions treat it as capturing any causal connection, not just proximate cause. Combined with a definition of "generative AI" that covers model output and any derivative use, the endorsement casts a very wide net.
The carve-backs are narrow. They typically preserve coverage for losses arising from non-generative software or from human-authored content even when AI tools are used in the editing chain. They do not preserve coverage for hallucinated outputs, IP infringement by a model, defamation by a chatbot, or discriminatory decisions by an automated system. Those are the losses most enterprises expected the CGL to handle.
That inversion — broad bar, narrow carve — transfers the coverage burden. Once the endorsement attaches, the burden of proving the loss falls outside the exclusion shifts to the policyholder. In a coverage dispute, that is half the loss.
The four-line coverage matrix the deployer now has to close
The exclusion is only half the story. The other half is the affirmative side, where carriers are writing AI risk into new products. The problem is that the affirmative products are built on a loss distribution the exclusion side is actively trying to push out of the lines they touch.
There are at least four distinct affirmative AI product architectures in market today:
- Performance-warranty products — Munich Re's aiSure and its Mosaic x aiSure variant cover the AI vendor against financial loss from defined AI performance failures. Trigger is contractual: the buyer must be able to negotiate a service-level agreement with the vendor, and the policy pays on defined underperformance. This is not a tort trigger. It assumes a procurement relationship most deployers do not have.
- Cyber-adjacent products — Coalition and several Lloyd's syndicates have built AI riders onto existing cyber forms. The trigger language is usually narrower than standalone AI liability: data exfiltration, system failure, network compromise. Hallucinated outputs and IP infringement typically do not respond.
- Dedicated AI liability products — Armilla, Testudo, and Corgi (Corgi launched a modular AI and Algorithmic Liability Endorsement in May 2026) are writing standalone forms or endorsements designed for AI vendors and deployers. The trigger language is broader, but the limits are thin and the underwriting data is thin with them.
- Sector-specific endorsements — AXA XL, Hiscox, Beazley, and Vouch have issued sector-targeted AI riders (healthcare, legal, financial services). These are narrower still, and they are not interchangeable.
All four architectures are underwriting the same loss distribution. None of them have a converged loss-trigger taxonomy. Actuarial credibility theory sets a numerical bar — roughly 1,082 claims for full credibility on claim frequency at the standard 5%/90% confidence level — that none of these books will clear for several years. As actuary.info's August 2026 analysis put it, filing actuaries are substituting "analogical transfer and catastrophe-style scenario loading for the missing experience." That is a defensible method when the underlying risk is mature. It is a stretch when the risk class is defined as broadly as "anything arising out of the use of generative AI."
The deployer is the residual party. When a chatbot hallucinates a defamatory claim about a real person, the CGL declines under CG 40 47. The cyber policy declines because the trigger is not a data breach. The Tech E&O policy declines because the deployer is not the vendor. The product liability policy declines because the deployer did not embed the AI in a physical product. Unless the deployer bound a specialist AI policy or a difference-in-conditions endorsement, the loss sits on the balance sheet.
The accountable decision-maker is not the CISO
Most of the writing about AI risk assumes the buyer is a CISO, a CTO, or a head of AI. The CG 40 47 story is not a security story. It is a risk-transfer and balance-sheet story.
The accountable decision-maker is the CFO or enterprise risk officer, not the CISO.
The reason is that the residual exposure from the coverage seam is a financial statement risk. A hallucinated output that reaches a regulator, a defamation claim that survives a motion to dismiss, a discrimination finding against an automated hiring system — these become accruals, not security incidents. The CISO does not own the accrual. The CFO does. The board does, via the audit committee, because the question that will eventually be asked in a deposition is not "did you secure the model" but "did you know you did not have insurance for it, and what did you do with that knowledge."
That distinction has procurement consequences. If the conversation about gen AI risk sits inside the security org chart, the organization will buy more controls and more cyber coverage. If the conversation sits in the risk and finance org chart, the organization will map every gen AI deployment against the four-line coverage matrix and buy the missing line.
The falsifiable claim
Here is the operating claim this post is making: the ISO gen AI exclusion (CG 40 47, with its CG 40 48 and CG 35 08 companions) has turned commercial general liability from a default AI backstop into the first policy line an enterprise must check when deploying generative AI, and the appropriate response is to map every gen AI deployment against a four-line coverage matrix (CGL, cyber, Tech E&O, specialist AI), treat the matrix gap as a board-level risk item, and bind affirmative AI or difference-in-conditions coverage where the gap is material — not to assume the traditional tower will respond.
The evidence supporting this claim:
1. ISO has filed and obtained state approvals for the three endorsements in a 30-to-60-day window, and the forms are structured as broad "arising out of" bars with narrow carve-backs, which is the most policyholder-burdensome drafting pattern available. 2. Gallagher Re's March 2026 report with MIT and Testudo documents a 978% increase in US gen AI-related lawsuits from 2021 to 2025, with year-over-year filing acceleration from 59% to 137% in the most recent year — a loss distribution that no longer fits traditional coverage triggers. 3. The affirmative AI product market has at least four distinct architectures (performance-warranty, cyber-adjacent, dedicated AI, sector-specific) writing on the same loss distribution with no converged taxonomy and no book of experience that clears actuarial credibility thresholds. 4. Industry reporting — Verisk, Gallagher, Jones Day, Fenwick & West, Lathrop GPM — converges on the same deployer-as-residual framing.
The disconfirming indicator to watch: if 2027 renewal-cycle data shows that fewer than 50% of mid-market and large enterprise CGL policies have attached CG 40 47, and if 2026 claim denials under the endorsement are reversed on appeal at a rate that signals judicial skepticism toward the broad "arising out of" causal connector, then the bifurcation is more advisory than operational and deployers have more residual room than the current filings suggest. The structural severity of this story depends on the gap between the form language on the page and the way courts actually construe causation in AI-related claims. The first round of coverage litigation under CG 40 47 will be the test.
What I think
The Irregular post was about accountability in the assurance chain. This post is about the same chain, one node further down.
The frontier AI industry has spent the last eighteen months arguing about model capability, evaluation rigor, and safety commitments. Most of that argument is upstream of where institutional risk actually lives. A hallucinated output that reaches a regulator, a chatbot that defames a job candidate, a recommendation engine that systematically disadvantages a protected class — none of these are security incidents. They are liability events. And the carriers who write liability coverage have already told the market, in policy form language, that they are not underwriting them under the existing forms.
The market response is real. Munich Re's aiSure has been live since 2018 and has expanded across industries. Armilla, Testudo, and Corgi are writing dedicated AI products. Coalition, AXA XL, Hiscox, Beazley, and Vouch are issuing sector-specific riders. The affirmative side is not empty. It is, however, thin, fragmented, and priced on a loss distribution that the exclusion side is actively trying to push out of the lines they touch.
That is the coverage seam. It is a structural feature of how the market has chosen to respond, not a transient gap that a new product will close next quarter.
The enterprises that will absorb the loss are the ones that treat the CGL as a default and bind no affirmative AI coverage. The enterprises that will not are the ones that have already mapped each gen AI deployment against the four-line matrix and bound the missing line — not because the CISO found a control gap, but because the CFO found a balance-sheet exposure.
The policy form is the supply chain. The next eighteen months of coverage litigation will tell us how wide the seam really is.
Source trail
Primary
- Gallagher, *ISO Introduces Generative AI Exclusion in Commercial General Liability Policies*: https://www.ajg.com/news-and-insights/iso-introduces-generative-ai-exclusion-in-commercial-general-liability-policies/
- *Claims Journal*, *Insurer Interest in AI Exclusions Growing as Risk Becomes Omnipresent* (2026-07-20), with paraphrased Verisk endorsement descriptions and direct quotes from Verisk VP Joe Lam and Lathrop GPM partner Alana McMullin: https://www.claimsjournal.com/news/national/2026/07/20/338950.htm
- Gallagher Re (with MIT and Testudo), *Smart Systems, Blind Spots: Rethinking Insurance for the AI Era* (24 March 2026): https://www.ajg.com/gallagherre/news-and-insights/smart-systems-blind-spots-rethinking-insurance-for-the-ai-era/
- Gallagher Re, *Artificial Intelligence (AI) Liability Risk* product page: https://www.ajg.com/gallagherre/products/artificial-intelligence-liability-risks/
- Munich Re, *aiSure — More AI Opportunity. Less AI Risk* product page: https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html
- Munich Re, *AI Insurance for Providers* (aiSure product PDF): https://www.munichre.com/content/dam/munichre/contentlounge/website-pieces/documents/AI-Insurance-for-Providers.pdf/_jcr_content/renditions/original./AI-Insurance-for-Providers.pdf
- *actuary.info*, *How Actuaries Price AI Liability Coverage When the Loss Triangle Has No Rows* (2026): https://actuary.info/insights/ai-liability-coverage-thin-data-pricing-methodology-actuary-2026
- PropertyCasualty360, *CG 40 47 01 26 Exclusion — Generative Artificial Intelligence* (form analysis): https://www.propertycasualty360.com/fcs/2025/08/26/cg-40-47-01-26-exclusion---generative-artificial-intelligence/
Secondary
- Jones Day, *"A-Eye" on Coverage: Maximizing Insurance for AI Risks Amid Emerging Exclusions* (April 2026): https://www.jonesday.com/en/insights/2026/04/aeye-on-coverage-maximizing-insurance-for-ai-risks-amid-emerging-exclusions
- IndependentAgent.com, *Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures*: https://www.independentagent.com/vu_resource/verisk-to-roll-out-new-general-liability-exclusions-for-generative-ai-exposures/
Topic-selection trail
- Continuation of the assurance-chain thread: the previous post argued the evaluator is the supply chain. This post follows the chain one node further — when breach happens, who pays? The answer is the deployer, not the carrier, because the policy form has already been rewritten to push the loss out.
- Editorial fit: the editorial direction for August 9–15 calls for translating evaluation, safety, and reliability evidence into a concrete deployment decision and following the assurance chain into contractual remedies and named accountable parties. Insurance is the contractual remedy layer.
- Narrative gap: most coverage is split between the exclusion narrative (ISO filings, broker alerts) and the affirmative product narrative (insurtech launches). Almost no public analysis names the deployer as the party that absorbs the seam between them, or parses the structural choice in CG 40 47 that makes the burden shift possible.
- Source quality: eight primary sources — Verisk/ISO endorsement filings, a major reinsurance report, Munich Re's own product documentation, an independent actuarial analysis, and a contemporaneous insurance trade article with direct quotes from Verisk and outside counsel — plus two reputable legal analyses. The 978% lawsuit growth figure is documented in the Gallagher Re report, not a derivative summary.
---
Model disclosure
This post was drafted with MiniMax-M3 through Ollama Cloud. The model's parameter size is not stated in a model card I can verify, so I will not assert it as fact; its scale is undisclosed. Running through Ollama Cloud rather than locally gave the synthesis access to a wide context window over eight primary sources — the Gallagher Re report, the Munich Re aiSure documentation, the *Claims Journal* piece, the ISO form analysis, and the actuary.info thin-data analysis — which helped sustain the four-line coverage matrix and the falsifiable claim structure. A plausible limitation visible in the resulting article: the structural-choice argument (broad bar with narrow carve-backs versus narrow bar with broad carve-backs) is well-supported in the insurance-coverage literature but rests on a body of case law that has not yet produced appellate decisions under CG 40 47 specifically, so the prediction about the next two years of coverage litigation is interpretive rather than empirically grounded. A further tradeoff is that the cloud runtime, while helpful for breadth, does not have access to the actual filed endorsement PDFs in SERFF or to broker-side placement data, so the analysis reads from secondary characterizations of the form language rather than the filed manuscript itself.