AI Exclusions Are Showing Up in Business Policies. Here Is How to Check Yours

A small business owner at a desk in a sunlit office reviewing printed insurance policy paperwork

Key takeaways

  • ISO released three optional generative AI exclusions for general liability with a January 2026 edition date. They are optional, so your carrier chooses whether to attach one.
  • Those forms exclude generative AI. Broader exclusions appearing in professional liability and management liability can reach predictive and scoring tools too.
  • Most policies still say nothing about AI at all. Silence is not the same as coverage, and no court has yet interpreted these exclusions.
  • Cyber is currently moving in both directions, including affirmative coverage for deepfake and voice cloning fraud.
  • Maryland, DC and Virginia have all adopted the NAIC bulletin on how insurers use AI. None of them restrict AI exclusions in your policy.

A client in Rockville called us this summer about a renewal quote. The premium was almost flat, the limits were the same, and buried in the endorsement list was a form number nobody had mentioned on the call. It was an artificial intelligence exclusion.

She was not doing anything exotic. Her team drafts proposals with an AI writing assistant and uses a scheduling tool that recommends staffing levels. That is most businesses now. The question she asked is the right one, and it is the one worth answering carefully: does this actually change anything for us?

What actually changed in 2026

ISO, the organization whose standardized forms sit underneath most commercial policies in the country, released three optional endorsements with a January 2026 edition date:

  • CG 40 47 01 26 excludes bodily injury, property damage and personal and advertising injury arising out of generative AI. It reaches both Coverage A and Coverage B.
  • CG 40 48 01 26 is the narrower version. It touches Coverage B only, so personal and advertising injury.
  • CG 35 08 01 26 applies to products and completed operations.

The single most important word in that list is optional. There is no automatic, universal AI exclusion that switched on for everyone in January. Each carrier decides whether to attach one, to which classes of business, and at what point in the policy term. Some are excluding. Some are pricing for the exposure instead, on the reasonable theory that a policy with fewer exclusions is easier to sell.

Generative AI is a narrower term than people assume

The ISO forms define generative artificial intelligence as a machine based learning system or model that is trained on data with the ability to create content or responses, including text, images, audio, video or code.

Read that again with your own operations in mind. A chatbot that writes customer replies is squarely inside it. A drafting assistant is inside it. But a predictive scheduling tool, a lead scoring model, or an algorithm that ranks job applicants does not obviously create content or responses, and a well advised business could argue it sits outside a generative AI exclusion entirely.

That distinction does not hold everywhere. In professional liability, management liability and fiduciary lines, specialty carriers have introduced considerably broader forms. Some define artificial intelligence as any machine based system that infers from its input how to generate predictions, content, recommendations or decisions. That definition does reach the scheduling tool and the scoring model. Some of these forms go further still and pick up losses arising from a failure to detect content created by somebody else using AI, or from inadequate AI policies and training.

So the honest answer to whether your business has an AI exclusion is not yes or no. It is: which policy, and which form.

The bigger problem is silence, not exclusions

A RAND study published this year looked at admitted market filings and found the market split three ways. A minority of carriers affirmatively cover AI. A growing number have filed broad exclusions, with the surge beginning in the summer of 2025 and concentrated in general liability and commercial umbrella. And the majority are still silent.

Silence feels comfortable. It should not. A policy that never mentions AI has not promised to cover an AI loss. It has simply left the argument for the day you have a claim, when your leverage is at its lowest. The industry has a name for this now, borrowed from the way cyber risk was handled a decade ago: silent AI.

Worth knowing, because it cuts both ways: there is no bellwether case yet. No court has told us how these exclusions will be read, how broadly the definitions will stretch, or what happens when an AI tool is one contributing cause among several. Anyone who tells you they know how this shakes out is guessing.

The four places to look, in order

1. General liability

Pull your declarations page and read the endorsement list, not the summary. You are looking for form numbers beginning CG 40 47, CG 40 48 or CG 35 08. If one is there, ask your advisor what it means for the specific way your team uses AI, not in the abstract.

2. Professional liability and E and O

This is where the broad forms live, and where the exposure is most real for service businesses. If you give advice, design something, or deliver a work product, and any part of that process runs through an AI tool, this is the policy that matters most.

3. Cyber

Cyber is currently the most stable line for AI related risk, and some carriers have moved the other way entirely by adding affirmative coverage for AI enabled threats like deepfake and voice cloning fraud. The specific question to ask is not a general one. Ask whether a fraudulent funds transfer initiated by a cloned voice or a deepfaked video call falls inside the social engineering insuring agreement, and at what sublimit. Sublimits on social engineering are often far below the policy limit.

4. Employment practices liability

If you use any automated tool to screen, rank or schedule applicants, this is the policy a discrimination claim would land in. Broad AI exclusions are appearing in this line as well.

A note on the employment side, because the rules did not loosen

The EEOC removed its AI technical assistance documents from its website in early 2025. Those documents were explanations of existing law, not law themselves. Title VII, the Americans with Disabilities Act and the Age Discrimination in Employment Act are statutes and they did not change. Private plaintiffs can still sue, and they are.

The Mobley v. Workday litigation in California is the case to watch, because the claim is against the software vendor and the court has allowed a nationwide age discrimination collective action to proceed. Even so, the practical risk for an employer is unchanged: if you use a vendor tool to screen people, you own the outcome of that screening.

The state picture in our area is quieter than the headlines suggest. Illinois amended its Human Rights Act effective January 1, 2026 to make discriminatory AI use in employment a civil rights violation and to require notice to employees. Maryland has had a narrow law since 2020 requiring an applicant to sign a consent waiver before facial recognition is used in a job interview. Virginia had a comprehensive AI bill in 2025 and it was vetoed. A similar DC bill has never been enacted. Colorado repealed and replaced its AI act before it ever took effect, with the replacement scheduled for 2027.

One thing that will confuse you if you go looking

Search for Maryland and AI and insurance and you will find Maryland Insurance Administration Bulletin 24-11, issued in 2024. It follows the NAIC model bulletin, and Maryland, Virginia and the District of Columbia have all adopted it.

It is a real regulation, and it does not do what the title suggests to a policyholder. It governs how insurers use AI in their own underwriting and claims decisions, and requires them to maintain a written AI systems program. It says nothing about AI exclusions in your policy and gives you no protection against one. Useful to know, just not for this.

What we would actually do about it

None of this calls for panic, and we are not going to tell you to buy something new today. It calls for a fifteen minute read of your own paperwork before your next renewal, and a short list of questions for whoever places your coverage.

  • Make a plain list of where AI already sits in your operations, including tools your vendors use on your behalf.
  • Check the endorsement list on general liability, professional liability, cyber and EPLI. All four, not just the one you think matters.
  • Where a policy is silent, ask the carrier in writing whether an AI related loss would be covered. A written answer before a claim is worth a great deal more than an argument after one.
  • Ask specifically about deepfake initiated fraud on the cyber policy, and about the sublimit.
  • If a broad exclusion has appeared on a renewal, ask what it would take to narrow it. Markets vary, and right now they vary a lot.

We work with businesses across Maryland, Washington DC and Northern Virginia, and we are reading these forms as they come in. If you want a second set of eyes on your declarations page before renewal, that is a conversation worth having early rather than late.

Frequently Asked Questions

Does my general liability policy exclude AI?
It depends entirely on whether your carrier attached one of the new optional endorsements. Look on your declarations page for form numbers starting CG 40 47, CG 40 48 or CG 35 08. If none appear, your policy most likely does not contain a specific AI exclusion, though that is not the same as affirmative coverage.

What is the difference between a generative AI exclusion and a broad AI exclusion?
The ISO general liability forms are limited to generative AI, meaning systems that create content such as text, images, audio, video or code. Broader forms used in professional and management liability often define AI as any system that generates predictions, recommendations or decisions, which sweeps in predictive and scoring tools that are not generative at all.

If my policy says nothing about AI, am I covered?
Not necessarily. Most policies in the market are still silent on AI, and silence leaves the question open until you have a claim. Where a policy does not address AI either way, it is worth asking the carrier in writing for its position before you need to rely on it.

Does cyber insurance cover a deepfake voice that tricks my bookkeeper?
Often yes, but usually under the social engineering or fraudulent instruction insuring agreement rather than the main policy limit, and frequently at a sublimit well below it. Some carriers have added affirmative language for AI enabled fraud. Ask for the specific insuring agreement and the sublimit rather than a general reassurance.

We only use AI through a vendor. Is that still our problem?
Usually yes. Employment discrimination claims arising from an automated screening tool are generally treated as claims against the employer, even when the tool belongs to a vendor. Some of the broader AI exclusions also reach losses connected to content created by a third party using AI.

Related reading from Capitol Benefits

Ready when you are

Let's take a look at what you've got.

A real review of your current coverage. No deck, no pressure, and usually some money saved along the way.