The Problem: You May Be More Exposed Than Your Policies Suggest
When leaders ask "are we protected?", they often mean their security controls. A second, quieter question sits with the CFO and general counsel: if an AI system causes a loss, does the insurance actually respond? For many organizations, the honest answer today is that nobody has checked.
According to the law firm Fenwick's analysis of emerging AI exclusions, the Insurance Services Office (ISO) introduced a generative AI exclusion for commercial general liability (CGL) policies in January 2026, covering bodily injury, property damage and personal or advertising injury "arising out of, or attributable to, generative AI". Fenwick also reports that individual insurers are narrowing AI coverage ahead of 2026 renewals: some management liability forms (D&O, employment practices, fiduciary) carry "absolute" exclusions for "any use, development, or deployment of artificial intelligence", and technology E&O policies increasingly exclude AI-related errors.
Fenwick's central warning is that the narrowing is often "quiet". Coverage may be carved out through revised definitions, sublimits and underwriting changes in the base form rather than one conspicuous exclusion, so the surprise arrives at claim time. AI exposures also span several policies (cyber, tech E&O, D&O, EPLI), each with its own exclusions that may stack, and coverage can depend on how a claim is legally characterized, not on the technology involved.
A caution on where this comes from: ISO forms and much of Fenwick's commentary are US-focused. We have not found comparable analysis of how Swiss or wider European insurers are treating AI in their policy wordings, so we cannot tell you that the same exclusions apply to your program. That is exactly why it needs checking.
The Solution: Treat Insurance as One More AI Control to Verify
Aon, a global insurance broker, describes three market responses: selective exclusions added case by case (some creating "silent limitations"), affirmative AI coverage added through endorsements to cyber, E&O, EPLI and D&O policies, and standalone AI insurance products from carriers including Armilla, Munich Re and AXA XL, which it says have limited capacity and narrow scope. Aon's practical advice is to verify whether existing policies affirmatively cover AI-specific losses or leave them in "silent" ambiguity. Aon reports that 88% of organizations deployed AI in 2025, up from 78%, and that more than 90% of insurance decision-makers expect AI-specific products to appear.
Gallagher, another broker, adds that in its 2026 AI survey most policies "don't explicitly address AI-related risks", that 55% of respondents cited data protection and privacy violations as a top threat, and that fewer than half have developed AI-specific incident response plans. Both firms sell insurance and advice, so read the urgency with that in mind. But the underlying question, which policy responds to which AI loss, is one you can answer without buying anything.
There is a second link between insurance and governance. Underwriters increasingly want to see evidence of controls. An organization that can show an AI inventory, access controls on agents, data-handling rules and a tested incident response plan is in a better position at renewal than one that cannot. That is our inference, not a finding from the sources above, but it follows from how underwriting generally works.
The Approach: Four Steps Before Your Next Renewal
1. Build the AI exposure picture. List where AI is used, what data it touches and what decisions or outputs could cause harm to third parties, employees or customers. Include AI embedded in products you sell, not just tools you use.
2. Map exposures to policies. For each exposure, identify which policy might respond: cyber, tech E&O, CGL, D&O, EPLI, professional liability. Read the exclusions and definitions, not just the schedule.
3. Put specific questions to your broker in writing. For example:
- Do any of our policies contain a generative AI exclusion or an AI-related sublimit, and where?
- If an AI agent takes an action that causes a loss, which policy responds?
- Do our D&O and employment practices forms exclude "use or deployment of AI" broadly?
- What evidence of AI controls will underwriters ask for at renewal?
- Would an affirmative endorsement or a standalone AI product be available, and at what cost and capacity?
4. Decide what to accept, reduce or transfer. Some gaps will be closed by endorsement, some by controls that reduce the exposure, and some accepted deliberately by the board with the decision recorded.
The worst time to learn that a policy excludes AI is after the claim. The best time is a few months before renewal, with the evidence already assembled.
How ANG Associates Can Help
ANG Associates supports an AI coverage gap review, run alongside your broker and legal counsel. We build the AI inventory and exposure map, document the controls you already have, translate that into the evidence pack and question set your broker and underwriters need, and give your CFO and general counsel a clear view of the gaps between your AI exposures and the policies currently in place. Where controls could reduce exposure, we prioritize them.
To be clear about scope: ANG is not an insurance broker, does not sell or place insurance, and does not give coverage or legal opinions. Those stay with your broker and counsel. We provide the operational picture and control evidence that make their advice sharper, and because we earn nothing from placing a policy, our view of your controls is independent of any product.
This is one of six services in our ANG AI Trust Compass offering.
Sources
- Fenwick, publication on emerging AI exclusions, coverage fragmentation and practical implications (law firm; US-focused)
- Aon, AI risk 2026: a practical agenda (Aon is an insurance broker with an interest in insurance placement and risk consulting)
- Gallagher, 2026 AI adoption and risk benchmarking survey (Gallagher is an insurance broker; sample size not specified on the page)