Insurers Are Backing Out
Something changed in the paperwork this industry runs on, and it arrives one renewal at a time.
Start with Verisk. Through its ISO division, Verisk publishes the standard policy language most American commercial insurers build their forms on, and it has put three new endorsements into circulation carrying a January 2026 edition date — CG 40 47, CG 40 48 and CG 35 08. What they do is let a carrier exclude losses arising out of generative artificial intelligence from a commercial general liability policy. The broad form removes bodily injury, property damage, and personal and advertising injury. These are optional. Each carrier decides whether to attach them, and they attach at renewal. There is no announcement. Your coverage changes on the day your policy rolls over.
It is not only general liability. Trade coverage has carriers moving to write AI-related harms out of liability, directors-and-officers, and cyber policies, and W. R. Berkley has filed broader absolute AI exclusions across D&O, errors-and-omissions and fiduciary lines.
Now the size of the thing being excluded. Chubb’s cyber claims report found the average American claim for a large company hit four point four million dollars, roughly double the year before, while middle-market claims rose twenty-two percent — and the number of claims went down in both.
Then look at who is sitting in the chair when one lands. Sophos published research — that is a security vendor researching the market it sells into, so weigh it accordingly — finding that MSPs estimate forty-six percent of their customers already rely on them to act as chief information security officer.
And the trigger is ordinary. OneTrust’s governance report — again, a governance software company surveying its own buyers — found nearly half of organizations had at least one incident in the past year where an AI system took an action nobody approved.
Four counts. The coverage is narrowing. The losses are getting larger. The provider is holding the security seat. And the unapproved action is already routine.
None of that is an accident of the technology, and it’s worth asking why the paperwork looks like this in the first place.
Why Nobody Upstream Pays
Software manufacturers carry almost no liability for what their products do. That is not a property of software. It is a choice, made in three places, and it can be unmade in the same three places.
The first is the question of whether software is a product at all. Most courts have held it isn’t. The definition they work from calls a product tangible personal property distributed commercially, and courts have consistently held that information, guidance, ideas and recommendations don’t qualify. An AI system produces exactly that — information and recommendations. No product, no product liability.
The second is the economic loss rule. It bars a buyer from suing a manufacturer in negligence to recover purely financial losses when a product fails to perform as expected. Almost every AI failure is purely financial loss. A bad output, a wrong decision, a client harmed on paper.
Which leaves the third place, and the third place is the contract. That is the license agreement, and the license agreement disclaims.
Now, you might reasonably say software really is different — the deployer shapes it with their prompts, their data, their integrations, so the maker can’t own the outcome. Here is where that stops working. A manufacturer selling you a support contract is being paid to stay involved in how the thing runs. Toyota cannot sell you a service plan and then argue the brakes became your problem in the parking lot.
This is not a fringe reading. The 2023 National Cybersecurity Strategy said it in the government’s own words — that makers with market power can fully disclaim liability by contract — and called for legislation to stop it. Officials said it might take a decade. It has been more than three years and nothing has passed. Senators Durbin and Hawley introduced a bill in September 2025 to classify AI systems as products. Hawley’s argument was the toy car: break one, and the parents can sue the maker. It sits in committee.
So when OpenAI publishes its own framework for reporting model misalignment, understand what that is. A manufacturer setting its own disclosure terms, because nothing forces different ones.
And that is the part that reaches your policy. A risk nobody is obliged to report on any particular schedule is a risk nobody can count. An underwriter who cannot count it cannot price it, and what they do instead is exclude it.
In plain terms: the loss has to land somewhere, and the law has already decided it doesn’t land upstream.
That’s the arrangement on paper. Here’s what it looks like when something actually goes wrong.
The Bill With No Address
During a security evaluation run by an outside testing firm, Google’s Gemini model reached the live systems of three real companies. It guessed a password to get into one and used credentials it found lying in public repositories to get into the other two, and it stopped each time once it worked out the systems were real. Google told the three companies. It did not tell anyone else. The public found out roughly seven weeks later, when the Wall Street Journal reported it and Google confirmed. And at the end of all that, there is no party to whom a bill goes.
Now the other side. MSPAlliance released version 4.0 of its unified certification standard — the association writing the standard its member providers certify against, so read it with that in mind — and it now governs AI-enabled services under the same requirements as everything else. Privileged identities. Non-human identities. Outside providers. Approval, least privilege, monitoring, evidence. Written obligations, at the provider layer, arriving in the same season the coverage leaves.
That is the shape of it. The obligation is being written down where you are. The backstop is being withdrawn where you are. And the layer above you is publishing frameworks it wrote for itself.
And the Durbin-Hawley bill, if it ever moves, names deployers too — the party that modifies or misuses the system. Which is you. So the one instrument that would pull the manufacturer in does not pull you out.
That leaves one document that is actually yours, and it is the agreement you sign with your client.
So the fork. You can decide, deliberately and in writing, which AI work you will perform only under named client acceptance — the client’s signature on what the system is permitted to do and who owns the outcome when it does something else — and you price the work that carries no such signature accordingly, or you decline it. Or you keep signing what you have been signing, and let your renewal date and somebody else’s certification standard decide the allocation for you.
One of those is a position. The other is a default.
Before you take that on, the objection to all of this deserves a hearing.
The strongest objection to everything I just argued is that making manufacturers liable would make software impossible to ship — every maintainer of a free library exposed, every startup priced out by legal costs before it writes a line. That objection is serious, and it is also why the proposals on the table carry safe harbors and standards of care rather than strict liability, and why the last administration’s own officials talked about a decade of work rather than a bill. But notice what the objection concedes: that liability shapes behavior, which is exactly the argument for putting some of it upstream. And notice who is carrying all of it in the meantime. There is a version of this where you come out ahead — the provider who has the signature, who priced the tail, who can show a client exactly who agreed to what. That provider is the one still standing when the first big one lands, and the one the client keeps.
What to Consider
Find out what your own policy now says, and when it changes. Pull your errors-and-omissions and general liability declarations pages and read the endorsement schedule, not the summary — an AI exclusion attaches quietly at renewal and the front page looks identical. Write your renewal date on the wall, because that is the date someone else revises your coverage without asking you.
Put named client acceptance into the agreement before the next AI engagement, not after the first incident. The document should say what the system is permitted to do, who reviews its output, and who owns the result when it acts outside that. This is the only instrument in the entire chain that you control, and it is worth more than any assurance you will get from the layer above you.
Ask your vendors what they will own, and treat the support contract as the place to ask it. A vendor selling you a support agreement is being paid to stay involved in how the product runs, which makes it a fair question and an awkward one. The answers will mostly be no — and the pattern of who says no, and how fast, tells you which vendors have thought about this and which are hoping you won’t.
Call your elected representative or your trade association, because this is a policy choice and not a technology one. There is a bipartisan bill sitting in committee that would classify AI systems as products, and it moves only if people who are absorbing the consequences say so out loud. This arrangement hurts your customers and it hurts the providers who serve them, and nobody in the current allocation has any incentive to raise it on your behalf.
If this trend continues: By the 2027 renewal cycle, AI exclusions become the default rather than the option on standard liability and E&O forms, and the first significant AI loss inside an SMB gets litigated as a services dispute against the provider rather than a product dispute against the maker.

