The question is not whether you are covered. It is which policy answers.
An operator commissions a system to do a specific piece of work. It quotes, or it drafts, or it routes, or it reads documents and tells somebody what is in them. It works. Twelve months later it produces an output that is wrong in a way that costs somebody money, and the somebody is a customer or a client rather than the operator. At that point a fairly ordinary commercial question arrives: whose problem is this, and is it insured?
The reflexive answer in most mid-market businesses is cyber, because cyber is the policy people associate with computers. The second answer, usually offered by somebody who has read a vendor blog, is technology errors and omissions. Both are wrong, and they are wrong for reasons you can establish yourself in an afternoon by reading documents that are free and public. We spent this week reading them: a real cyber policy and its endorsements, a real carrier's technology E&O application, the industry body's description of the new general liability exclusions, and the market association's own note on how AI got into cyber wordings in the first place.
What comes out of that reading is a clean division that almost nobody states plainly. Cyber answers when AI is the attacker or the door. General liability is where the retreat is happening. Technology E&O answers for the person who sold the technology, which is your vendor and not you. And your own professional liability policy, the one that covers the work your firm is actually paid for, is the policy most likely to respond when your firm delivers a bad answer, regardless of what helped produce it. That holds whether the firm in question is one of the insurance agencies, CPA firms or manufacturers this site is written for. That last policy is where your attention belongs, and it is the one that gets checked last because it does not sound like an AI policy.
Cyber is being extended to cover AI as a weapon, not as a mistake.
The document worth reading here is a real policy rather than a summary of one. We read a US cyber policy issued to a public agency for the period beginning 1 July 2025, base form SP 14 798 0419, published openly by the buyer along with its full endorsement schedule. Endorsement CYUSP-50EN-000039-0324-01 adds a new defined term. In the endorsement's own words, an AI security event means the failure of security of computer systems caused by any artificial intelligence technology, including through the use of machine learning or prompt injection exploits.
That is an affirmation, and it is worth pausing on how much of an affirmation it is. The same endorsement then folds the new term into two existing definitions. Data breach is amended to include unauthorised acquisition, access, theft or disclosure of personally identifiable information or third party corporate information resulting from an AI security event. Funds transfer fraud is amended so that a fraudulent instruction transmitted by electronic means includes one transmitted through the use of deepfakes or any other artificial intelligence technology. A carrier writing that language is not running away from AI. It is naming two specific AI-shaped attacks and saying yes to both.
Now read it against the definition it depends on. In the same policy, security failure means the failure of security of computer systems which results in one of five things: unauthorised acquisition, access, theft or disclosure of personally identifiable information or third party corporate information in your care, custody or control; loss, alteration, corruption or damage to software, applications or electronic data existing in computer systems; transmission of malicious code to third party computer systems; a denial of service attack on your systems; or access to or use of computer systems in a manner that is not authorised by you, including when resulting from the theft of a password.
Five limbs, and every one of them is a security limb. Somebody got in, something was taken, something was corrupted, something was knocked over. None of them describes a system that is perfectly secure, running exactly as its designers intended, and confidently wrong. The AI endorsement does not widen this, because it defines an AI security event as a failure of security caused by AI. The security requirement survives the amendment. So the practical reading of a well-endorsed 2026 cyber policy is that it covers your AI when your AI is the weapon or the target, and has nothing to say about your AI being mistaken.
This is not a criticism of the wording. It is the correct scope for a cyber policy and the carrier has drafted it well. It is a problem only for the operator who assumed cyber was the answer and stopped looking.
You cannot buy technology E&O for a system you did not sell.
The second reflex is technology errors and omissions, and it fails for a reason that becomes obvious the moment you look at an actual application rather than a product page. We read Chubb's DigiTech ERM new business application for small business, form PF-48204 (10/16), issued by ACE American Insurance Company.
Its technology E&O section asks for: the size of the applicant's largest active customer contract by annual revenue; the average contract value; the average contract length in months; the percentage of customers from whom the applicant obtains written contracts, purchase orders or user acceptance agreements; whether qualified legal counsel reviews boilerplate standard customer contracts and any substantially customised ones; what percentage of customer agreements contain a disclaimer of consequential damages, a limitation of liability to the cost of products or services, or a warranty disclaimer; whether the applicant has formal customer acceptance, milestone management and customer signoff procedures; and whether subcontractors are required to carry their own technology E&O at limits of at least one million dollars.
Read that list as a description of the risk being insured and the answer falls out. Every question is about customers you sold technology to. The policy exists to answer for the gap between what you promised a buyer and what your software did. A specialty manufacturer, a CPA firm or an insurance agency running a commissioned system for its own operations has no customer for that system, no acceptance milestone, no warranty and no contract. The underwriter has nothing to underwrite.
The same application makes the point from the other side in its eligibility screen, which asks whether the applicant derives more than fifty percent of its revenue from non-technology products and services. For the operators this site is written for, the honest answer is yes, comfortably. That is not a technicality to be argued around. It is the product telling you it was built for somebody else.
There is a version of this that is worth doing, and it is the mirror image: make sure the vendor who built your system carries technology E&O, and read their liability cap, because the cap in your agreement will usually bind long before their limits do. That is a contract exercise rather than an insurance one, and we work through the clauses in what belongs in an AI vendor contract, where indemnity scope is one of five clauses that decide an engagement.
General liability moved first, and it moved in January.
If there is a retreat happening, this is where it is visible. The Independent Insurance Agents and Brokers of America publishes technical bulletins through its Virtual University, and on 21 October 2025 it described the Verisk and ISO rollout of three generative AI exclusions for commercial general liability, effective January 2026.
CG 40 47 removes bodily injury, property damage and personal or advertising injury arising out of generative artificial intelligence, under both Coverage A and Coverage B. CG 40 48 does the narrower version, removing personal and advertising injury under Coverage B alone. CG 35 08 does the same job inside products and completed operations liability. The definition the forms use, as reproduced by the Big I, is a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code.
That definition deserves a second read, because it is not narrow. It does not say large language model. It does not say chatbot. Trained on data, able to create content or responses covers a forecasting tool, a routing engine, a document classifier and a quoting assistant. An exclusion written that broadly, sitting on a general liability policy, is a large and vaguely bounded hole for anyone who has one of those systems in production.
Two things keep this from being a five-alarm fire, and both are worth saying plainly. ISO circulating an endorsement is not the same as your carrier attaching it, and many will not, or will attach the narrower Coverage B version. And general liability was never the policy that answered for a bad commercial decision anyway; its job is bodily injury and property damage. For most mid-market operators the practical impact of CG 40 47 is smaller than the headline suggests. The reason to care is directional. The forms exist, they are broad, and the same drafting instinct is now loose in a market that also writes your professional liability cover.
Silent AI, and how a software definition ends up deciding an AI question.
The market has a name for this whole situation, and the name carries a warning about how expensive it got last time. Silent cyber described the long period in which ordinary property and casualty policies neither affirmed nor excluded cyber losses. Nobody had decided anything. Coverage existed by omission, and what it actually amounted to was settled years later in litigation, at considerable cost to both sides.
Silent AI is the same shape, and the Lloyd's Market Association showed exactly how it happens in a note published on 13 April 2025. Discussing AI in the context of contractual language, the LMA observes that most of its model cyber clauses use defined terms, and that its definition of computer system includes software, which by extension already includes AI systems.
Read that sentence as an operator rather than as an underwriter. Nobody sat down and decided that AI belonged inside a cyber clause. It arrived there because AI is software and the definition said software, in wordings drafted before anyone was asking the question. Whatever your policy says about computer systems is already saying something about your AI, and it is saying it by accident.
The LMA is candid about the unfinished state of this. It goes on to say that if the deployment of AI does change risk profiles, it may be necessary to amend the definition of computer system in future, to develop model definitions of AI systems, facilitating more nuanced coverage, limitations or exclusions as required by the market. That is a market body saying the wordings are still moving. For a buyer, the operational consequence is simple: what your policy says about AI this year is not a stable fact, and the endorsement schedule is the part of the renewal to actually read. The same instinct applies one layer down, in the security questions worth asking before a build, where the copies of your data nobody counts are the thing that decides the answer.
The regulation you will find if you go looking is aimed at your carrier.
An operator who searches for AI insurance regulation lands on state bulletins, and the bulletins look important, and they are, to somebody else. The National Association of Insurance Commissioners adopted a Model Bulletin on the Use of Artificial Intelligence Systems by Insurers on 4 December 2023. Its addressee line reads: to all insurers licensed to do business in the jurisdiction. It sets out how insurers are expected to govern the development, acquisition and use of AI systems, and what documentation a department may request during an investigation or examination.
It regulates the company that issues your policy. It imposes nothing on the company that buys one. The NAIC's own implementation map, carrying a status date of 6 August 2026, lists twenty-five adopting jurisdictions. Massachusetts is among them, by Bulletin No. 2024-10, adopted 9 December 2024.
One honest limitation, stated rather than glossed. The Massachusetts bulletin's own text sits behind a mass.gov endpoint that returned HTTP 403 to every client we tried on 26 August 2026, so we make no claim about what it says beyond the fact of its existence, number and date, which come from the NAIC map we did read. If you are a carrier or an MGA, go read it properly. If you are an agency, a firm or a manufacturer, it is background.
The distinction matters because it changes where an operator should spend attention. There is no compliance obligation here to discharge. There is a commercial exposure to place, and it gets placed by reading your own policies and asking your own broker, not by tracking a regulatory calendar that was never about you.
There is affirmative cover now, which is mostly useful as evidence.
The gap described above is real enough that somebody is writing paper against it. Armilla, a Lloyd's coverholder, offers an AI liability product underwritten by certain underwriters at Lloyd's, with backing its own site names as Chaucer, Axis Capital and Convex. The distinguishing feature is the trigger. It responds to AI underperformance, the system failing to perform as intended, rather than to a security failure.
That is the affirmative version of exactly the hole the cyber wording leaves. It is worth knowing about and, for most operators in the eight to fifty million range, it is not a first purchase. The site publishes no limits and no price, states that certain exclusions apply, and points buyers to full policy documentation, so nothing beyond the shape of the product can responsibly be said from the outside.
Its real value to a reader of this page is evidentiary. A Lloyd's syndicate has looked at the space between what cyber covers and what professional liability covers, decided there is something there worth pricing, and built a product to sit in it. That is a stronger argument that the gap exists than anything we could assert.
The honest counter-case, because most of this is smaller than it sounds.
A page like this one has an obvious failure mode, which is to frighten an operator out of a good decision using documents they will never read. So here is the case against the alarm, made properly.
The default is still that you are covered for the work you do. A professional liability policy responds to claims arising from the professional services your firm renders. A CPA firm that files a wrong return is exposed for filing a wrong return; whether a spreadsheet, a junior, or a commissioned model helped produce it is not usually the question the policy asks. The tool is upstream of the claim, and the claim is about your service. That has not changed, and no document we read this week suggests it has. The one vertical where this has already been examined against real claims data and a real application question is law, and that sits in our note on law firm AI governance, bar rules and the malpractice carrier.
Cyber is arguably the most stable line here rather than the shakiest. The endorsement we read affirms rather than excludes. It is the general liability side, a policy that was never answering this question anyway, where the clean exclusions have landed.
And the biggest exposure in this whole area is not exotic. It is an application question answered carelessly. An application is a representation the insurer prices and issues on, and a material inaccuracy is the sort of thing that gets argued about after a claim rather than before. If a renewal form asks whether the firm uses artificial intelligence and the person signing it does not know what was commissioned two floors away, that is a live problem, and it costs nothing to fix. It is an inventory and a conversation, not a new policy.
None of this is a reason to delay a build. It is a reason to spend one hour on the paperwork the same quarter you spend six figures on the system.
What an operator can do this week, with no broker in the room.
Four things, in order, and all of them are free.
Inventory what you actually run. One page. Every AI system in the business, what it does, what data it touches, whether it writes anything into a system of record, and who owns it. Include the commissioned systems and the subscriptions your staff bought on a card. Most operators cannot produce this list today, and its absence is what makes an application question dangerous.
Pull your endorsement schedules. Not the summary of insurance your broker sends, which will not show you this. The actual schedule of forms on each policy. Search it for artificial intelligence, for generative, and for the form numbers CG 40 47, CG 40 48 and CG 35 08. You are looking for what has quietly attached at the last renewal.
Read the definition your cyber policy depends on. Find security failure, or whatever your policy calls the trigger, and read the limbs. If they all describe attacks and unauthorised access, you now know what your cyber policy does and does not answer for, which is more than most buyers of that policy know.
Send one email. Ask your broker, in writing: which policy on our programme responds if a system we commissioned produces a wrong output that reaches a client and causes them a financial loss, and under which insuring agreement. Then ask whether any AI or generative AI exclusion has attached anywhere on the programme, with form numbers. The written answer is the deliverable. A verbal reassurance is worth nothing at claim time, and the act of writing it down is what surfaces the gap.
What we look at when an owner asks who carries the risk.
This comes up in diagnosis calls more often than it used to, usually phrased as a worry rather than a question. Three things get looked at, and none of them is the model. This is the same ground the AI Maturity Index covers from the readiness side, and it runs inside the diagnosis described on our process page.
The failure mode, priced, before the coverage conversation.
There is no useful coverage question until you can say what the worst plausible wrong output costs and who it reaches. A system that drafts an internal summary a human then rewrites has almost no exposure worth insuring. A system that issues something to a client under your firm's name has real exposure, and it is exposure of a shape your existing professional liability cover already contemplates. The design decision and the insurance question are the same decision, which is why we would rather narrow the system than buy a product.
Whether a human decision sits between the output and the client.
This is the single highest-leverage design choice available and it is architectural rather than procedural. Everyone says a person reviews the output. What matters is whether the system is built so that it cannot reach a client without a named person approving it, and whether that approval is logged. A reviewed-in-practice system and a review-gated system look identical on a good day and completely different in a dispute.
The record, because every version of this question is answered by one.
A bar investigator, an underwriter at renewal and a client's counsel all ask the same thing in different words: what happened on this specific matter, which system ran, on what input, who approved the output and when. A system that can answer that from its own logs converts an investigation into an afternoon. A system that cannot converts it into an estimate, and estimates are expensive. This is the same architecture that answers the governance question, which is why we treat the two as one piece of work rather than two.
Where the site line is, stated plainly.
We are an AI consulting firm, not a broker, not an insurance agency and not your counsel. Nothing here is legal or insurance advice, and none of it is a substitute for reading your own policy with somebody licensed to interpret it. Every document cited on this page is listed below with the date we read it, so you can check the reading rather than take it.
One further note, since this page argues from documents rather than from experience. We name no client and assert no client outcome anywhere on this site, because our engagement terms grant no publicity rights. Where you see a claim here, it comes from a public document you can open yourself.