The AI insurance exclusion wave
Starting in January 2026, more than sixty P&C carriers began filing explicit AI exclusions into their general liability, E&O, and D&O policies. Three new ISO endorsement forms now exist specifically to carve AI-related claims out of standard coverage. If your company deploys AI in production and something goes wrong, there's a real chance nothing in your current policy stack pays for it.
This isn't a fringe concern from a handful of cautious carriers. It's a structural response to a real spike in claims: incorrect AI-generated outputs used in professional contexts, model behavior that diverges from what was represented to customers or regulators, and liability arising from systems nobody inside the company fully understands anymore. The new ISO forms — CG 40 47, CG 40 48, and CG 35 08 — exist because underwriters need a standard way to say "not this" without rewriting every policy from scratch.
The gap underneath the exclusion
Exclusions solve the carrier's problem, not the insured's. Companies that depend on AI internally — for code generation, customer-facing tools, decision support, anything with real operational weight — are left with a widening coverage gap and no systematic way to close it. Specialty and E&S carriers want to fill that gap, because underwriting a genuinely new risk category well, early, is how insurers build durable books of business. But right now they're doing it the same way early cyber insurers did in the mid-2000s: long self-assessment questionnaires, underwriter judgment calls, and very little that resembles evidence.
AI is at the 2005–2010 stage now — first-mover advantage exists for whoever builds real assessment tooling first.
Cyber insurance didn't mature because carriers got better at asking questions. It matured because the industry built tooling that could actually verify what companies claimed — scans, telemetry, audits that replaced self-attestation with evidence. AI liability insurance hasn't had that moment yet. Nobody has published a systematic, technical assessment methodology for it.
What "systematic" has to mean here
Not a questionnaire with better wording. A methodology that looks at whether a company has actually implemented and maintained technical defenses against the specific, well-understood ways AI systems fail in production — and that can tell the difference between a control that exists on paper and one that's actually running. That's the premise the rest of this project is built on, and it's the subject of the next two pieces: the architecture that keeps the assessment from becoming its own liability, and the scoring methodology that defines what "evidence" actually means.