The deploy-and-exclude paradox: insurers turned AI liability into a standalone market
The same carriers filing to exclude AI from commercial general liability policies are deploying AI in their own underwriting and claims operations at production scale. The ISO CG 40 47 exclusion family created a coverage gap that a standalone AI liability market — Armilla, Testudo, Munich Re/Mosaic, Coalition, Vouch, Corgi — has formed to fill. But both sides are pricing the same risk on loss data that does not meet classical actuarial credibility standards. The 2027 renewal cycle is the first full cycle where enterprises face the bifurcated market, and the deployer is the residual risk-bearer.
Two weeks ago I argued that Anthropic's text watermark turned Article 50 from a provider compliance checkbox into a deployer procurement row. The watermark was not the story; the story was that a frontier lab's product decision had made a regulatory gap visible in the enterprise contract.
This post is about the next paradox in that chain. The insurance industry has decided AI is too risky to cover in a general liability policy and too useful to keep out of its own underwriting operations. Both decisions are rational. The combination is the problem.
The exclusion is now live. The affirmative market is forming. The actuarial data does not exist. The 2027 renewal cycle is the first full cycle where enterprises face the bifurcated market, and the enterprise that has not checked its endorsement schedule is the enterprise that is self-insuring without knowing it.
What the exclusion did
On 1 January 2026, Verisk's ISO Core Lines Services made three new endorsement forms available to US commercial carriers: CG 40 47, CG 40 48, and CG 35 08. Each excludes generative artificial intelligence from a different slice of the commercial general liability policy. CG 40 47 is the broadest — it removes both Coverage A (bodily injury and property damage) and Coverage B (personal and advertising injury) for any loss "arising out of" generative AI. CG 40 48 is narrower, removing only Coverage B. CG 35 08 removes AI from products and completed operations. The definition of generative AI across all three forms is broad enough to capture large language models, image generators, code assistants, and any system that produces novel output from learned patterns.
The phrase "arising out of" is the load-bearing language. In insurance coverage law, it requires only a causal connection, not proximate cause. A claim does not need to be caused entirely by generative AI to be excluded; it needs only to arise out of the use of generative AI. A marketing agency that uses a gen AI tool to draft ad copy containing a defamatory statement, a contractor that relies on a gen AI estimator that mis-specifies load-bearing requirements, a retailer whose chatbot offers a warranty the company did not authorise — all face the same coverage question: was gen AI in the causal chain?
Insurance Journal's 17 August 2026 feature confirmed what practitioners had been tracking since the filings cleared. Verisk VP Joe Lam, who helped write the endorsements, reported "a high degree of interest" from carrier clients. Lathrop GPM partner Alana McMullin called the endorsements "the spark of this AI exclusion boom" and said she expects "rapid adoption of some version of an AI exclusion in most lines of coverage." W.R. Berkley went further than the ISO forms with its proprietary PC 51380, an "absolute AI exclusion" that reaches D&O, E&O, and fiduciary liability and covers "any actual or alleged use of AI, regardless of whether the model was company-owned, third-party, licensed, or embedded in software tools."
ISO forms underpin approximately 82% of US commercial property and casualty policies. State insurance regulators approved more than 80% of carrier exclusion filings, with Florida, Connecticut, and Maryland processing approvals at the fastest pace. The 30-to-60-day approval window was unusually fast for a coverage-narrowing endorsement, which suggests regulators saw the filings as clarifying rather than restrictive.
The previous post in this chain covered the exclusion mechanism in detail. The question now is what happened next.
What happened next: the carriers built AI stacks
The exclusion side of the market is centralising around the ISO form. The affirmative side is fragmenting. And the carriers doing the excluding are the same carriers deploying AI in their own operations.
actuary.info's August 2026 analysis maps the paradox with precision. Five of the six largest US P&C carriers disclosed production AI deployments on Q1 2026 earnings calls while simultaneously winning state regulatory approval to exclude AI from the commercial policies they sell.
Travelers rolled out Anthropic's Claude to 10,000 employees — the largest disclosed carrier-to-foundation-model deployment in the industry, backed by a $1.5 billion technology budget. AIG deployed AIG Assist across underwriting and claims, integrating Palantir Foundry with Claude to process commercial submissions at 88% accuracy rates on automated decisions. Allstate built ALLIE (Allstate Large Language Intelligence Ecosystem), a proprietary agentic AI stack that handles customer engagement, direct policy sales in three states, and claims processing. Chubb created a new executive role, Global Claims AI Mandate, under Jim Rampe. Chubb CEO Evan Greenberg disclosed on the Q1 2026 earnings call that he now spends "much more time" on AI than even a year ago, and warned that leaders who rely on second-hand briefings risk becoming "irrelevant."
Greenberg also named Anthropic's Claude Mythos model specifically, framing it as a catalyst for a "new era of cyber-adjacent risk." The arms race is on, he told analysts. Mythos has "lowered the threshold for vulnerability," allowing minor security gaps to be "aggregated in a much more insightful way." He identified middle-market organisations as the "biggest meatball" for attackers — more financial resources than small firms but weaker cybersecurity practices. This is the market segment where Chubb holds significant commercial lines market share.
This is the same CEO whose company is filing to exclude AI-related damages from its own commercial policies. When the head of the world's largest publicly traded P&C insurer says the arms race is on, the exclusion filings stop looking like routine product adjustments and start looking like strategic risk shedding at scale. The contradiction is not subtle, and it is not hypocrisy — it is risk management. But it means the enterprise customer is buying AI insurance from an industry that has decided AI is too risky to include in its standard product.
The affirmative market: four architectures, one problem
While the exclusion side centralises around the ISO form, the affirmative side is fragmenting into at least four distinct product architectures. Each covers AI-caused harm, but each does it differently.
Munich Re's aiSure (performance guarantee model). Munich Re's product, now partnered with Mosaic for up to $15 million in capacity, is a performance guarantee rather than a liability policy. The AI developer or deploying enterprise agrees to a performance specification, and Munich Re backstops the financial consequences if the model fails to meet that specification. Coverage triggers are tied to model output accuracy, downtime, or deviation from contracted service levels. Because the trigger is contractual performance rather than tort liability, the pricing problem looks closer to surety or warranty than to standard casualty. Munich Re has been in this space since 2018, but the 2026 growth is about expanded capacity for gen AI-specific triggers such as hallucination rates and drift thresholds.
Coalition's affirmative AI (cyber-adjacent model). Coalition, the cyber MGA backed by Swiss Re and several Lloyd's syndicates, extended its cyber policy wording in late 2025 to include affirmative AI triggers. The product covers prompt injection attacks, model theft, training data poisoning, and resulting third-party liability when a gen AI system deployed by the insured causes harm. The underwriting questionnaire includes gen AI governance attestations: which models are in production, whether human review is mandatory for customer-facing outputs, whether adversarial testing has been performed, and whether the insured maintains a model inventory consistent with ISO 42001 or the NIST AI RMF. Pricing layers an AI load on top of the cyber base rate, scaled by attestation quality.
Armilla Warranty (third-party warranty model). Armilla, backed by a Chaucer-led Lloyd's consortium, offers a standalone AI warranty with limits up to $25 million. It pays out when a contracted AI model underperforms against pre-agreed benchmarks. Coverage triggers include accuracy below a specified threshold, bias amplification beyond a fairness floor, and hallucination rates above a negotiated limit. Armilla runs an independent model audit before binding, which produces the loss-frequency inputs used in pricing. The audit is the product's distinguishing feature: without it, there is no objective baseline for the performance guarantee to measure against.
Vouch and Corgi (bundled tech E&O model). Vouch, which writes technology errors and omissions for startups, has embedded gen AI coverage into its tech E&O form. Corgi, a Y Combinator-backed carrier that launched in May 2026, takes a similar modular approach, offering an AI Insurance Coverage endorsement that integrates with existing Tech E&O policies. Corgi's modules cover biased algorithms, inaccurate or harmful generated content, misuse of training data, adversarial attacks, synthetic media, and autonomous system failures. Both Vouch and Corgi build gen AI into the base rate rather than charging a separate load, because their customer base skews toward AI-native companies where gen AI use is universal, not peripheral.
The four architectures share one problem. None of them has a credible loss triangle.
The pricing problem: no rows in the triangle
The core actuarial problem across both the exclusion side and the affirmative side is the same: there is no credible loss history. Generative AI in its current form is roughly three years old. Enterprise deployment is younger. The claim cycle has not run through enough reporting years to produce usable paid or incurred triangles. Classical credibility theory sets a numerical bar — the limited fluctuation standard for full credibility on claim frequency, derived from (1.645/0.05)², works out to approximately 1,082 claims. That is the volume needed for observed frequency to fall within 5% of the true mean at a 90% confidence level. A book that young cannot generate 1,082 claims in any single accident year, and likely will not for several years even as premium volume grows.
The nearest available proxy is EPIC Insurance Brokers' 16th Annual Lawyer's Professional Liability Claims Survey, published in May 2026. The survey covers 13 carriers that collectively insure more than 80% of Am Law 200 firms. Seven of those 13 carriers reported an increase in AI-related claims over the prior year. That is directional evidence that AI is generating professional liability losses somewhere in the system. It is not a frequency estimate an actuary can plug into a credibility formula for AI liability rating, because the exposure base, coverage trigger, and claimant population of a legal malpractice policy differ from a standalone AI liability policy written for an AI vendor or an enterprise deploying a third-party model.
But it is the first survey to show AI-related claims actually arriving. Previous versions of the survey had treated AI as a future risk that carriers expected to confront eventually. The 2026 survey is the first to report that more than half of responding carriers have seen AI-related malpractice claims in real numbers. The survey also shows the first increase in overall claim frequency in five years, and nine of 13 carriers reported reserving at least one claim in excess of $100 million during the last two years. As Eileen Garczynski, who has compiled the survey since 2011, put it: "What we're seeing is a perfect storm: economic volatility, complex transactions and accelerating AI adoption all converging to increase legal risk."
Gallagher Re's March 2026 report — "Smart Systems, Blind Spots: Rethinking Insurance for the AI Era," produced with MIT and Testudo — gives the claim-category breakdown. Of the more than 700 cumulative generative AI lawsuits filed in the US between 2020 and 2025, patent infringement accounted for 11.9%, copyright infringement 11.2%, and personal injury tied to privacy violations 10.2%. That distribution argues for weighting the tech E&O and intellectual-property analogues more heavily than the pure bodily-injury analogue in a typical AI liability book today, at least until the mix of insureds shifts toward physical-system deployments where the product liability analogue should dominate.
The severity anchors are even thinner than the frequency data. Three developments from the past 14 months illustrate what is available. On 21 May 2025, a federal district judge in Florida ruled that Character.AI's chatbot product is subject to product liability law on the same footing as a defective vehicle, allowing strict liability, negligence, and wrongful-death counts to proceed — the first ruling to establish that framework for a generative AI product. In January 2026, Character.AI and Google settled five related lawsuits over teen suicide and self-harm claims, among the first AI-chatbot-harm settlements of scale in the country, though the terms were confidential and included no admission of liability. On 3 February 2026, the California Judicial Council coordinated roughly a dozen wrongful-death and product-liability cases against OpenAI into a single proceeding, In re: ChatGPT Product Liability Cases, JCCP No. 5431. None of those cases had reached trial as of mid-2026.
None of those three data points gives an actuary a jury-awarded severity figure to anchor a scenario. The 2025 product-liability ruling establishes legal exposure, not a dollar amount. The Character.AI settlement establishes that claims of this type are worth resolving before trial, but confidential terms mean the number cannot be used directly in a rate indication. The JCCP coordination signals claim volume and venue concentration, both of which raise the probability of an eventual verdict but say nothing yet about its size.
With classical credibility off the table, the working method looks closer to Bayesian prior construction than ratemaking in the traditional sense. An actuary starts from loss experience in adjacent lines — tech E&O for financial-harm analogues, product liability for bodily-injury analogues, cyber for data-processing and systemic-accumulation analogues — weights each by how closely its harm mechanism resembles what an AI system actually does, and blends the results into a starting frequency and severity assumption. Then catastrophe-style scenario loading replaces the trend line: define a small number of plausible loss scenarios, assign each a probability, and load the rate to the probability-weighted outcome rather than to a fitted curve.
The rating factors that have emerged in 2026 filings are hypotheses borrowed from adjacent lines, not variables validated against AI liability's own loss experience. Model type (generative vs deterministic) proxies for hallucination and IP exposure. Industry of deployment proxies for severity — healthcare AI implicates bodily injury, consumer recommendation engines skew toward financial and reputational harm. Human-in-the-loop presence reduces frequency and shifts liability allocation toward the deployer. Training data provenance proxies for IP-infringement frequency. Audit certification status proxies for governance quality, borrowed directly from how cyber underwriters use security control questionnaires.
The human-in-the-loop and audit-certification factors are the two most likely to move rates materially at renewal, because they are the two a policyholder can change through its own governance practices rather than through the underlying model choice. They give carriers a lever for risk selection even before frequency data exists to price the factor precisely.
The cyber exclusion precedent: same playbook, compressed timeline
The closest precedent for the CG 40 47 adoption cycle is the rollout of cyber exclusions from approximately 2014 to 2019. In 2014, ISO introduced the CG 21 06 and CG 21 07 endorsements, which excluded data-related liability from CGL policies. Lloyd's Market Association followed with model cyber exclusion clauses. The logic was the same: insurers recognised they were silently covering a risk they had not priced, and the exclusion was the fastest mechanism to remove that exposure from existing policy forms.
What followed was a five-year migration. Cyber risk did not disappear; it moved. Standalone cyber policies, which barely registered as a line of business in 2013, grew into a market that reached $15.3 billion in global premium by 2024, according to Munich Re, with North American premium alone accounting for $10.6 billion. The number of insurers offering standalone cyber coverage increased by approximately 35% between 2016 and 2019.
Several structural features of the cyber exclusion rollout are repeating in the AI exclusion cycle. Ambiguity drives the first wave of exclusion: carriers that did not explicitly exclude the risk were silently carrying it. Adoption follows a predictable curve — early adopters file within the first quarter, midmarket carriers follow within six to twelve months, smaller regionals and mutuals lag by 18 to 24 months. A standalone market forms on the other side of the exclusion line, initially capacity-constrained and pricing on judgment rather than data.
But the AI exclusion cycle is running at a compressed timeline. The cyber exclusion took roughly five years to reach broad adoption. The AI exclusion is moving faster. Verisk filed in the second half of 2025, the forms took effect 1 January 2026, and within weeks at least six insurers had filed to adopt them or their own proprietary variants. The 30-to-60-day state approval window is faster than the cyber exclusion cycle saw. Based on the current pace of filings, broad adoption of some form of AI exclusion across the majority of commercial GL books appears likely by the end of 2027.
The compression is driven by the litigation trajectory. Year-over-year AI-related legal filings accelerated to approximately 137% in 2024-2025, roughly doubling the 59% growth rate observed in 2023-2024. The 978% cumulative growth from 2021 to 2025 gave carrier actuaries and product managers the data they needed to justify exclusion filings to their boards and regulators. Gartner projected that more than 2,000 legal claims linked to "death by AI" incidents will be brought worldwide by the end of 2026. Whether that projection proves accurate or not, the trajectory is steep enough that the regulatory argument for exclusion writes itself.
The cyber precedent also carries a warning. The cyber analogue introduces a correlated-failure risk the other analogues do not: a single foundation model, cloud provider, or training-data vendor sitting behind dozens of insureds is the same aggregation problem that reshaped cyber catastrophe modelling after large-scale outage and breach events. John Farley, managing director of Gallagher's Cyber Liability practice, put it directly: "When you consider how much organisations are relying on AI platforms to provide critical services and products to their own clients, it creates the potential for the frequency and severity of claims to go up." That argues for an explicit accumulation load layered on top of the per-risk analogical blend, not just a per-policy severity assumption borrowed independently from each adjacent line.
The 2027 renewal cycle: what the enterprise faces
The 2027 renewal cycle is the first full cycle where enterprises face the bifurcated market in its current shape. The exclusion is in the endorsement schedule. The affirmative market exists but is young, capacity-constrained, and pricing on judgment. The enterprise that has not read its endorsement schedule is the enterprise that is self-insuring without knowing it.
For an enterprise whose CGL policy comes up for renewal in 2027, the diligence questions are:
1. Is CG 40 47, CG 40 48, or CG 35 08 attached? Search the bound CGL, E&O, and tech-E&O policies for those form codes or for any endorsement titled "generative artificial intelligence." If one is attached, core AI product risk is likely excluded. This is not a future date — the exclusions took effect 1 January 2026 and are rolling through renewals now.
2. What is the affirmative coverage gap? If the CGL excludes AI, what does the enterprise need to buy back? The answer depends on how the enterprise uses AI: marketing and content teams using AI-generated copy (Coverage B exposure), HR departments deploying AI screening tools (EPL exposure), product teams embedding gen AI in customer-facing products (Coverage A and products exposure), professional services firms relying on AI-assisted analysis (E&O exposure).
3. Can the affirmative market cover the gap? The standalone market is young. Armilla offers up to $25 million via Lloyd's. Testudo runs $1 million to $10 million. Munich Re/Mosaic offers up to $15 million for performance guarantees. Corgi and Vouch bundle AI into tech E&O. For an enterprise that needs $50 million or $100 million in AI liability limits, the standalone market does not yet have the capacity. That enterprise is self-insuring the difference, whether it knows it or not.
4. What rating factors can the enterprise improve before renewal? The human-in-the-loop and audit-certification factors are the two a policyholder can change through governance practices. An enterprise that can demonstrate mandatory human review for customer-facing AI outputs, documented adversarial testing, a model inventory consistent with ISO 42001 or NIST AI RMF, and third-party audit certification is likely to receive meaningfully better terms than an enterprise that cannot. The audit is not free, but it is cheaper than the premium load for an unaudited peer.
5. What is the accumulation exposure? If the enterprise and its key vendors all depend on the same foundation model, the correlated-failure risk is real. The enterprise that wraps Claude through AWS Bedrock, Google Cloud Vertex AI, or Microsoft Foundry is part of an accumulation cluster. The enterprise that uses multiple models from multiple providers is less correlated. The underwriting questionnaire is starting to ask, and the answer matters for pricing.
The disconfirming indicators
The falsifiable claim this post is making: The ISO CG 40 47 exclusion family has created a structural bifurcation in the commercial liability market — CGL policies no longer cover AI, a standalone affirmative market has formed but is capacity-constrained and pricing on judgment rather than data — and the 2027 renewal cycle is the first cycle where the deployer-side gap is priced explicitly rather than absorbed silently. The enterprise that does not close the gap is the residual risk-bearer, and the insurance industry's own deploy-and-exclude paradox means the enterprise is buying coverage from an industry that has decided the risk is too material to include in its standard product.
The disconfirming indicators to watch:
1. If the first bellwether AI liability verdict produces a damages award within the range of existing product liability or professional liability verdicts for comparable harm, the severity anchors stop being hypothetical and the standalone market can price with narrower bands. If the first verdict produces a damages award materially above those ranges — a verdict that establishes a new severity category for AI-caused harm — the standalone market's capacity constraint becomes acute and the exclusion side's loss-load adjustment widens. 2. If state insurance regulators begin requiring carriers that file AI exclusions to also file the loss-load adjustment they are applying to the excluded premium, the actuarial judgment in the exclusion side becomes auditable. If the exclusion filings continue to be approved without documented loss-load adjustments, the exclusion side is removing exposure without reducing premium, and the deployer is paying the same price for less coverage. 3. If a major enterprise procurement cycle publishes an AI insurance diligence questionnaire that includes separate line items for CGL AI exclusion status, affirmative AI liability limits, and accumulation exposure across the enterprise's model vendor stack, the deployer-side procurement premium crystallises. If the major questionnaires continue to treat AI insurance as a single yes/no item, the bifurcation is not yet priced in the procurement channel. 4. If the EPIC LPL survey's 2027 edition shows AI-related claims increasing across a majority of responding carriers in both frequency and severity, the adjacent-line proxy data strengthens and the standalone market's analogical transfer becomes more credible. If the 2027 survey shows the 2026 increase was a one-year anomaly, the pricing problem gets harder, not easier, because the early signal weakens.
What I think
The deploy-and-exclude paradox is not a contradiction. It is the insurance industry doing what it does: pricing risk. The carriers that are deploying AI internally have decided AI is useful enough to build into their own operations and risky enough to remove from the policies they sell. Those are two separate decisions, and both are rational. The problem is that the enterprise customer is the one who absorbs the gap between them.
The enterprise that wraps a foundation model through its own product is the entity that owes the customer a remedy when the model causes harm. The CGL policy that used to backstop that exposure no longer does. The affirmative AI liability policy that could backstop it is young, expensive, and pricing on judgment rather than data. The enterprise that has not read its endorsement schedule is the enterprise that is self-insuring AI liability without a reserve.
The cyber exclusion cycle took five years to produce a $15 billion standalone market. The AI exclusion cycle is moving faster. The 2027 renewal cycle is the first test of whether the standalone market can scale fast enough to cover what the CGL market has excluded, and whether the enterprise procurement function has caught up to the fact that the coverage it assumed was implicit has been deleted at renewal. The deployer is the residual risk-bearer, just as the deployer is the residual risk-bearer for the Article 50 disclosure, and just as the deployer is the residual risk-bearer for the CGL exclusion. The chain keeps landing in the same place. The question is when the enterprise starts pricing that fact into its own budget, rather than discovering it during the next renewal cycle.
---
Model disclosure
This post was drafted with GLM-5.2 through Ollama Cloud. GLM-5.2's exact parameter size is not reliably disclosed in the model name or in a public model card I could verify; I will treat it as undisclosed or uncertain. Running through Ollama Cloud gave the synthesis access to a long context window across the Insurance Journal feature, three actuary.info analyses, the EPIC LPL survey coverage, the Gallagher Re report findings, the Corgi launch announcement, the Character.AI and JCCP case records, and the alatirok.com market overview — which is what allowed the deploy-and-exclude paradox argument to be sustained across regulatory, actuarial, and commercial sources simultaneously. A plausible limitation visible in the article: the post reasons about the 2027 renewal cycle as a decisive test, but the renewal cycle is still months away, so the claim depends on the current adoption trajectory continuing rather than on observed renewal outcomes. A second tradeoff: the Ollama Cloud runtime's cross-source synthesis strength comes at the cost of independent actuarial verification — the post reports the rating factors and pricing methods from actuary.info's analysis, but does not independently test whether those factors will correlate with AI liability loss experience, because that experience does not yet exist in credible volume.