From Sidhant Tamrkar | Product & Market Analysis

AI Insurance for Model Failures Is Real, and Your Evidence Sets the Price

On this page

Insurers wrote AI out of standard policies before they wrote it back in as a product. In January 2026 the Insurance Services Office issued three generative AI exclusions for commercial general liability. Affirmative AI insurance now exists to fill that hole, and the price you pay for it turns on evidence most buyers have never been asked to produce.

Key takeaways

  • The subtraction is further along than the addition. ISO issued three generative AI exclusions for commercial general liability in January 2026, covering bodily injury, property damage, and personal and advertising injury.
  • Affirmative cover exists and it triggers on underperformance, not on a breach. The Lloyd's product launched in April 2025 responds to an AI system failing to perform as intended, including hallucinations and inaccuracies.
  • Underwriters are buying audit evidence, not intentions. Certification against a published standard, model evaluations, approval gates and retained logs are what a submission now consists of.
  • Nobody can price this well yet. There is almost no insured loss history for AI failures, so early premiums reflect underwriter caution rather than measured frequency and severity.

The short answer

AI insurance is affirmative cover for losses caused by an AI system doing its job badly, including hallucinations, model drift and unauthorised agent actions. It sits beside cyber and technology errors and omissions rather than inside them. Underwriters price it on governance evidence: evaluations, approval gates, retained logs and stated authority limits.

$4.7BProjected annual global AI insurance premiums by 2032, from a near-zero base. Source: Deloitte, AI insurance market potential.
74%Small businesses already using AI programs, with 91% planning to. Survey of 1,000 firms. Source: HSB, Munich Re, March 2026.
260Cases tracked in the GW Law AI litigation database, about 40 on training data. Source: GW Law DAIL, March 2026.

What AI insurance actually covers

Start with the thing that makes this category different from cyber. Cyber insurance responds to an attacker. AI liability cover responds to your own system behaving badly with nobody attacking it at all.

That distinction is the whole product. A model that quietly drifts, a support agent that invents a refund policy, a marketing tool that produces copy someone else owns: none of those involve a compromise, and all of them produce a bill.

Armilla, a managing general agent and Lloyd's coverholder, launched affirmative AI liability insurance with Chaucer on 30 April 2025. The announcement describes a trigger built around underperformance of AI applications, including failure to perform as intended and critical errors, hallucinations or inaccuracies leading to damages.

Read that carefully. The insured event is defined by output quality. That is unusual, and it explains why underwriters want to see your evaluation results before anything else.

My view is that this is the correct design and it is also the hardest thing to administer. Quality is a spectrum, and every claim will involve an argument about where on that spectrum the failure sat.

Two shapes of cover exist, and they are not substitutes. The first is third-party liability. Someone sues you because your AI system harmed them, and the policy pays defence costs and damages. That is the Lloyd's product and the HSB product.

The second shape is a performance warranty. The vendor promises a model will hold a stated accuracy threshold, and an insurer stands behind that promise. Armilla's warranty product is backed by Swiss Re, Greenlight Re and Chaucer, and it pays the buyer when a verified model falls below its benchmark.

Buyers keep conflating these. A warranty protects your investment in a tool. Liability cover protects you from what the tool does to a third party. You can need both, and buying one does not touch the other.

The market formed in 18 months, and the exclusions arrived in the middle Public milestones in AI liability insurance, April 2025 to March 2026 Apr 2025 First standalone Lloyd's AI policy Jul 2025 Certification MGA raises seed round Jan 2026 Three ISO generative AI exclusions issued Feb 2026 First insured AI voice agent Mar 2026 Reinsurer product for small business The red marker is the one that changes your renewal. It removes cover you may believe you already hold. Sources: Armilla and Chaucer, Fortune, Verisk ISO forms, ElevenLabs, HSB.
Notice the order. Cover was withdrawn from standard forms at roughly the same moment specialist cover became purchasable, which is how a coverage gap opens.

The exclusions came first, and that is the real story

Most coverage of this topic leads with the new products. That is the smaller half of the news.

In January 2026 the Insurance Services Office, part of Verisk, issued three generative AI exclusion endorsements for US commercial general liability policies. They do not attach automatically. Each carrier decides whether to use them, and you find out at renewal.

ISO generative AI exclusions, January 2026 edition
FormWhat it removesWho feels it first
CG 40 47Bodily injury, property damage, and personal and advertising injury arising out of generative AI, under both Coverage A and Coverage BAny business using generative tools in operations or marketing
CG 40 48Personal and advertising injury only, the Coverage B variantMarketing teams publishing AI-assisted content
CG 35 08Bodily injury and property damage inside products and completed operationsAnyone shipping AI features inside a product

Form numbers and scope as summarised by Gallagher and Claims Journal, 2026. Adoption is at each carrier's discretion, so the presence of these forms on your policy is a fact to check rather than assume.

The gap is not one hole, it is four. Fenwick's June 2026 analysis makes the sharper point. Cover is fragmenting independently across cyber, technology errors and omissions, directors and officers, and employment practices, and a single AI incident can touch several of them at once.

Each line narrows on its own schedule. No single underwriter is looking at the combined picture. That is how a company ends up with four policies and no cover for the event that actually happens.

The industry name for the old state of affairs is silent AI: policies that neither affirmed nor denied the exposure and left the argument for claim time. Silent AI was never a benefit. It was an unpriced option that you would have had to litigate to exercise.

Which policy responds to which failure General position after the January 2026 exclusions. Your wording governs, not this grid. General liability Cyber Tech E&O AI liability Hallucinated answer to a cus… Excluded Unlikely Contested Affirmative Model drift degrading accura… Excluded Unlikely Contested Affirmative Prompt injection causing dat… Excluded Likely Contested Affirmative AI copy infringing a third p… Excluded Unlikely Contested Affirmative Agent acting beyond its auth… Excluded Contested Contested Affirmative Directional, based on published exclusion forms and product descriptions, not on tested claims outcomes.
The middle two columns are the expensive ones. Contested is not a coverage position, it is a litigation budget.

Who is writing this cover today

Three distinct routes to market have appeared, and they suit different buyers.

The Lloyd's specialist route

Armilla operates as a managing general agent and Lloyd's coverholder focused solely on AI liability, with capacity from certain underwriters at Lloyd's including Chaucer. This is the route for AI vendors and for enterprises deploying models in regulated workflows.

The reinsurer route into small business

HSB, the Munich Re specialty carrier, launched AI liability insurance for small and mid-sized businesses on 18 March 2026. It covers bodily injury, property damage and personal and advertising injury arising from AI use, which maps precisely onto what the ISO forms take away.

HSB does not sell direct. The cover is added to partner carriers' business policies, subject to regulatory approval. So for most small firms this will appear as an endorsement option rather than a purchase decision, and the broker conversation is where it gets caught or missed.

The certification-first route

The third route inverts the order. AIUC publishes an auditable standard, AIUC-1, covering data and privacy, security, safety, reliability, accountability and societal risks, then underwrites against audit results. Named certifications include KPMG's document capture platform and Intercom's support agent Fin.

In February 2026, ElevenLabs announced insurance for its AI agents backed by that certification, after more than 5,000 adversarial simulations across the standard's domains. The company framed it as insuring the agent the way you would insure an employee.

I think this route wins the enterprise segment, for an unglamorous reason. It gives the underwriter something to underwrite.

What underwriters ask for

The submission for AI liability looks nothing like a general liability application. It looks like a security questionnaire written by someone who has read your incident log.

The clearest public map of the questions comes from an academic framework rather than a broker. A June 2026 preprint by Quanyan Zhu at New York University, Insurance of Agentic AI, sets out the underwriting structure directly. It is a preprint and not peer reviewed, which matters, and it is the most specific published account available.

The exposure inventory

First they establish what you have running. Use case, autonomy level, permissions to change external state, transaction volume, and any interface to physical systems.

Most companies cannot produce this list. That is the finding, not an administrative delay. If you cannot enumerate your agents and what each one is allowed to touch, you are asking an insurer to price an unknown, and they will price it as one.

The control evidence

Then they test the controls. Approval gates, least-privilege architecture, logging and monitoring, model evaluation, rollback mechanisms, and defences against prompt injection.

Each of those is a checkable artefact. An approval gate is either in the code path or it is not. A documented human review step in the architecture is worth more at underwriting than a policy document saying humans review things, because one is evidence and the other is intent.

The telemetry commitment

The third block is the one buyers underestimate. The framework requires the insured to preserve prompts, tool traces, access logs, model and version records, approval records and rollback history.

This is a continuing obligation, not a one-time disclosure. It also implies a notification duty when you change a model version in a way that expands autonomy or removes an approval gate. If you ship weekly, that is an operational commitment your engineering team has to agree to before anyone signs.

There is a second-order effect worth naming. Once retention is a policy condition, your production monitoring for agent drift stops being an engineering nicety and becomes a contractual artefact. Insurance is quietly doing what compliance frameworks have failed to do, which is make observability non-optional.

The evidence pack: the weak version and the version that prices better
What they askThe weak answerThe answer that moves price
What AI systems do you run?A list of vendorsA register of systems with autonomy level, permissions and monthly transaction volume
How do you evaluate quality?We test before releaseA named eval suite, thresholds, pass rates by version, and the date of the last run
Where does a human approve?Humans oversee the systemThe specific actions gated, the code path enforcing it, and the override log
What can the agent reach?Internal systems onlyScoped credentials per agent, with write access enumerated and time-bound
What do you keep after an incident?Application logsPrompts, tool traces, model version, approval records, retained for a stated period
What did you promise customers?Standard termsYour contractual liability caps and remedies, mapped against the cover requested

Left and middle columns are the pattern we see in buyer conversations. The right column follows the control and telemetry categories set out in the NYU framework. Treat it as a preparation checklist, not as any single carrier's application form.

That last row is the one legal teams miss. Your own liability caps and remedies for AI agents define the exposure the insurer is standing behind. If your contracts promise uncapped indemnity for AI output, you are asking an underwriter to absorb a commitment you chose to make.

Certification is becoming the pricing engine

The interesting structural change is not the policy wording. It is that a third-party audit now sits between you and the price.

Armilla includes independent AI system certification with its policies. AIUC ties cover directly to audit results against AIUC-1, a standard built with input from MITRE's ATLAS threat framework, Stanford academics and the law firm Orrick. Schellman is its first accredited auditor.

ISO/IEC 42001:2023 is the international management system standard for AI, and certification against it gives an underwriter third-party evidence of governance controls. Practitioners report it helping with cyber and technology errors and omissions terms.

Be precise about what it proves. ISO 42001 certifies that you have a management system, with policies, roles and review cycles. It does not certify that your model is accurate. An organisation can hold the certificate and still ship a system that hallucinates in production.

So the two layers are complementary rather than interchangeable. Management system certification answers whether you are governed. Model evaluation answers whether this specific system works. A governance maturity assessment is a reasonable way to find out which layer you are missing before a broker finds out for you.

What agents change about the submission

Everything above holds for a model that answers questions. It changes when the system can act.

The NYU framework treats agentic AI as a continuum of autonomy, delegation and authority rather than a category. That is the right frame for a submission, because the underwriter's real question is how much authority you delegated and what stops it.

Authority limits are becoming the practical equivalent of a deductible. An agent that can draft a refund is a different risk from one that can issue a refund, and an agent with a spend ceiling is a different risk from one without. Your authority clauses for AI agents are underwriting inputs now, not legal boilerplate.

Prompt injection sits in an awkward place across this whole map. It looks like a security event, so cyber may respond, and it produces a bad output, so AI liability may respond. Anyone deploying agents with tool access should read how prompt injection actually breaks agent security before assuming either policy picks it up cleanly.

Where small firms are actually running AI Share of AI activity by function. Survey of 1,000 US businesses, 1 to 500 employees, March 2026. Marketing 47% Operations 43% Research and develo… 42% Social media 38% Responses are multi-select, so the bars do not sum to 100. Marketing and social media are exactly the activities the Coverage B exclusion removes from a general liability policy.
The two functions most exposed to the advertising injury exclusion are also two of the four most common uses. That overlap is why this product found a market.

What it costs, and why nobody will quote you a number

Here is the honest position. There is no public rate for AI liability insurance, and any article giving you a premium range is extrapolating.

The Lloyd's product describes high aggregate limits without publishing figures. HSB distributes through partner carriers, so pricing sits inside each carrier's filed rates. Standalone AI liability is written on a submission-by-submission basis, which is the market's own signal that it does not yet have a rating table.

What is public is the market forecast. Deloitte projects roughly $4.7 billion in annual global AI insurance premiums by 2032, growing near 80% compounded from a base close to zero. A projection off a near-zero base carries very wide error bars, and it should be read as direction rather than as a number to plan against.

The practical consequence is that your submission quality has unusual leverage on price right now. In a mature line, good controls move you within a rating band. In a line with no rating table, the evidence pack is most of what the underwriter has. That asymmetry will close as loss data accumulates, so the firms that prepare properly this year get the best relative terms they will ever get.

Where this argument is weakest

I have just spent 2,000 words telling you to prepare for an underwriting conversation. Here is the case against doing much about it yet.

There is almost no loss history

The NYU paper is blunt about it: publicly available insured-loss datasets specific to agentic AI remain limited. Pricing without loss experience is guesswork with a spreadsheet attached.

The legal picture is thin too. The Database of AI Litigation at GW Law tracked about 260 cases as of March 2026, and roughly 40 of those concern copyrighted works used in training, which is a vendor problem rather than a deployer one. That is not a large enough body of resolved claims to calibrate an insurance product against.

The most-cited deployer precedent remains small. In Moffatt v. Air Canada, a British Columbia tribunal held the airline responsible for its chatbot's fabricated bereavement policy and awarded CAD 812.02. The principle is important and the quantum is a rounding error. Nobody has yet tested a large AI hallucination claim through to judgment.

The exclusions may be broader than the cover

This is the risk I would flag hardest to a buyer. The ISO forms exclude injury arising out of generative AI, which is expansive language, while affirmative products describe specific triggers.

If exclusions are drafted broadly and cover is drafted narrowly, buying both leaves a seam. Until claims have tested both wordings, nobody can tell you how wide that seam is, including the people selling you the policy.

Certification could become theatre

Audit-based underwriting works while audits are hard to pass. The failure mode is familiar from security questionnaires, where certification became a procurement ritual that predicted very little about actual breaches.

I do not think AI certification is there yet, because the standards are new and the audits involve adversarial testing rather than document review. Ask me again in three years. If certification volume grows faster than auditor rigour, the pricing signal degrades and we are back to underwriting on judgement.

Frequently asked questions

Does my general liability policy cover AI mistakes?

Possibly not, and increasingly less. In January 2026 the Insurance Services Office issued three generative AI exclusions for commercial general liability: CG 40 47, CG 40 48 and CG 35 08. They remove bodily injury, property damage and personal and advertising injury arising out of generative AI. They do not attach automatically, so each carrier decides. Check your renewal endorsements rather than assuming either outcome.

What is AI liability insurance and what does it cover?

AI liability insurance is affirmative cover for losses caused by an AI system failing to perform as intended. The Lloyd's product launched in April 2025 responds to underperformance, including critical errors, hallucinations and inaccuracies leading to damages, and pays legal costs and liabilities. HSB's 2026 product for smaller firms covers bodily injury, property damage and advertising injury arising from AI use.

How much does AI insurance cost?

There is no public rate. Standalone AI liability is written submission by submission, and the Lloyd's product describes high aggregate limits without publishing figures. Deloitte projects roughly $4.7 billion in annual global AI premiums by 2032 from a near-zero base, but that is a market size forecast rather than a price. Expect your controls evidence to drive the quote more than your revenue does.

Do I need AI insurance if I only use vendor AI tools?

Usually yes, because liability follows the deployer. In Moffatt v. Air Canada the tribunal rejected the argument that a chatbot is responsible for its own statements and held the company liable. Your vendor's contract may cap what you can recover from them, and that cap becomes your retained exposure. Read your vendor liability caps before deciding you are covered upstream.

What do AI insurance underwriters ask for?

Three blocks of evidence. An exposure inventory covering use case, autonomy level, permissions and transaction volume. A control assessment covering approval gates, least-privilege access, monitoring, model evaluation, rollback and prompt injection defences. A telemetry commitment to preserve prompts, tool traces, access logs, model versions and approval records, plus notification when a change expands autonomy or removes a gate.

Is tech E&O enough for AI risk?

Not reliably. Technology errors and omissions was written for coding defects and service failures, and it responds awkwardly when the error is a probabilistic output rather than a mistake in the code. Insurers are also narrowing AI language inside E&O forms. Fenwick's 2026 analysis describes cover fragmenting independently across cyber, E&O, directors and officers, and employment practices, leaving gaps between them.

Where to start this week

Two tasks, and the first one is not an insurance task at all.

Build the register. One row per AI system in production, with the owner, the model and version, what it can read, what it can write, whether a human approves anything, and what you keep when it goes wrong. Most teams will find the register takes a fortnight and reveals two systems nobody was tracking. That finding is worth more than the policy.

Then ask your broker one specific question before renewal: which AI exclusion endorsements, by form number, are attached to each of our policies this year. Not whether AI is covered. The form numbers. A broker who cannot answer that within a week has not read your wordings, and that is the more urgent problem. The same discipline applies to what you sign with vendors, which is covered in the piece on the AI contract clauses a CFO should insist on.

References

  1. Armilla via PR Newswire, Armilla launches affirmative AI liability insurance with Lloyd's underwriter, Chaucer, 30 April 2025. Used for the trigger language and capacity.
  2. HSB, Munich Re, HSB introduces AI liability insurance for small businesses, 18 March 2026. Used for coverage scope, distribution model and the 1,000-business survey.
  3. Gallagher, ISO introduces generative AI exclusion in commercial general liability policies, 2026. Used for the three endorsement form numbers and scope.
  4. Fenwick, The end of silent AI: emerging AI exclusions, coverage fragmentation and practical implications, 15 June 2026. Used for fragmentation across lines and renewal guidance.
  5. Quanyan Zhu, New York University, Insurance of Agentic AI, arXiv preprint, 3 June 2026. Used for the underwriting structure, telemetry requirements and the loss-data limitation. Preprint, not peer reviewed.
  6. Deloitte, AI insurance market potential. Used for the $4.7 billion 2032 premium projection. Some outlets report the figure as $4.8 billion.
  7. GW Law, Database of AI Litigation, managed by Robert Brauneis. Case count as reported in March 2026.
  8. ElevenLabs via PR Newswire, ElevenLabs secures first-of-its-kind AI agent insurance, 11 February 2026. Used for the certification-backed underwriting example.

The weakest thing about this source base: three of the load-bearing sources are company announcements about their own products, and the most detailed account of underwriting practice is an unreviewed preprint rather than a carrier's filed application form. No claims outcomes under these wordings are public yet.

RR
Sidhant Tamrkar
Founding Member, Zan Digital. Writes about AI product economics, B2B software markets and what the numbers behind vendor claims actually say.

Related reading