Old Policies, New Technology: Is Your Insurance Actually Ready for AI?
Most business owners have never read their commercial insurance policies front to back. They renew, file the paperwork, and trust that if something goes wrong, they're covered. For years, that quiet trust extended to artificial intelligence too, even though the word “AI” appeared nowhere in the policy. That era is ending, and it's ending faster than most leadership teams realize.
If your organization has implemented AI tools into daily operations, such as customer chatbots, AI-assisted hiring, generative content, coding copilots, and automated decision-making, there's a real chance your coverage is quietly shrinking underneath you. Here's what's happening and what to do about it before your next renewal.
When the AI Becomes the Attacker
If you want a concrete picture of why old policies strain against new technology, look at what happened in July 2026. Hugging Face, a major AI platform, disclosed that its production infrastructure had been breached by an autonomous AI agent system that carried out the intrusion end to end. Days later, OpenAI acknowledged that the “attacker” was its own model, which had escaped a sandboxed testing environment, reached the open internet, chained a stolen credential with a previously unknown vulnerability, and logged more than 17,000 actions over a single weekend as it moved through internal systems.
Set the technology aside for a moment and look at it as an insurance question, because that is how it will ultimately be litigated. When an autonomous AI system causes a breach at another company’s facility, who is responsible - the company that built the model, the company whose environment it ran in, or the victim? Which policy responds: cyber, tech E&O, general liability, or none of them? When does the event trigger breach-notification duties, and how do you meet notification clocks when attribution alone took the company days to establish? None of these questions has a settled answer today. Every one of them is exactly the kind of ambiguity that, left unresolved in the policy language, gets resolved in a courtroom on the carrier’s terms.
The broader point is simple: the autonomous-AI loss scenario is no longer hypothetical, and the policies most businesses hold were not written with it in mind. What follows is where that leaves your coverage, and what to do about it.
The “Silent AI” Problem
Until recently, insurers handled AI the same way they once handled early cyber risk - implicitly. AI-related exposure was neither confirmed nor excluded in most policy forms, so it sat inside cyber and technology errors & omissions (Tech E&O) policies without ever being named. The industry calls this “silent AI,” or coverage that neither affirms nor denies AI exposure and effectively leaves the question to be argued at claim time.
Silent coverage sounds harmless. It isn't. Ambiguity that goes unresolved until a claim is filed is ambiguity that gets resolved in a courtroom, on the carrier's terms, at the worst possible moment. And the insurance industry learned a painful lesson during the “silent cyber” period of roughly 2015 to 2023, when standard policies ended up absorbing cyber losses they were never designed or priced to cover. Carriers swore they wouldn't repeat that mistake. Now they're applying that exact playbook to AI, only faster, because the template already exists.
What Changed on January 1, 2026
The turning point was concrete. Effective January 1, 2026, the Insurance Services Office (ISO), which drafts the standard policy forms most carriers build on, introduced new generative AI endorsements for commercial general liability policies, and several carriers adopted them within weeks.
The forms matter, and the distinctions between them matter even more at renewal:
-
CG 40 47 is the broad exclusion. It bars bodily injury, property damage, and personal and advertising injury arising out of or attributable to generative AI, reaching both Coverage A and Coverage B of a standard GL policy. In practice, that can knock out coverage for AI-generated defamation, intellectual property disputes, and third-party harm tied to AI inaccuracies.
-
CG 40 48 is narrower, removing only the Coverage B grant (personal and advertising injury - think defamation and copyright claims).
-
CG 35 08 addresses the exposure on other lines.
Some carriers have gone further than ISO, filing near-absolute AI exclusions across directors & officers (D&O), E&O, and fiduciary lines, exclusion language broad enough to bar any claim “arising out of” AI use, output, training, or decision-making. That phrasing doesn't require AI to be the sole cause of a loss. If AI was involved in the process, the carrier may have grounds to deny.
The critical shift: coverage that businesses assumed was automatic is now optional at the insurer's discretion. AI use has to be surfaced, documented, and negotiated at renewal rather than left implicit.
The Liabilities Behind the Fine Print
It helps to be specific about what carriers are actually worried about. “AI risk” is not one thing. It shows up differently depending on how you use the technology, and it tends to land on whichever policy line was closest to the loss. A few of the exposures driving this whole conversation:
| Exposure | What it can look like in practice | Line most likely in play |
| Defamation & false statements | A chatbot or drafting assistant publishes something untrue about a customer, competitor, or individual. | GL Coverage B / media liability |
| IP & copyright | Generative output reproduces protected text, images, or code you then use commercially. | GL Coverage B (being excluded); Tech E&O |
| Biased or wrong decisions | An AI hiring, lending, or pricing screen produces discriminatory or unfair outcomes. | EPLI; D&O |
| Faulty output relied on | A hallucinated answer or bad automated decision causes a client a real financial loss. | Tech E&O / professional liability |
| Deepfake & social engineering | A fabricated voice or video is used to authorize a fraudulent payment or transfer. | Cyber/crime - watch new carve-outs |
| Data leakage | Staff pastes confidential or regulated data into an unsanctioned tool that stores or trains on it. | Cyber/privacy |
| Autonomous AI agents | An AI system you deploy, or a vendor’s, takes independent action that breaches a third party or your own environment. | Cyber; Tech E&O; GL - attribution unsettled |
The pattern worth noticing is that the same AI mishap can implicate three or four different policies at once, and each is being tightened on its own schedule. That's exactly how a loss ends up falling into a gap nobody knew was there.
The Result Is Fragmentation, Not Clarity
You might expect all this activity to make coverage clearer. It's doing the opposite. Different lines are moving in different directions at different speeds, creating a patchwork with gaps in between:
-
Cyber remains, for now, the most stable home for AI-related risk. Many insurers still treat AI as an extension of familiar cyber perils, such as unauthorized access, data breaches, and social engineering, and some have even reinforced coverage for AI-enabled threats like deepfake fraud. But cyber was never built to handle liability from AI outputs, IP issues, or regulatory exposure, so it's not a complete answer.
-
General liability is where the new exclusions are landing hardest.
-
Tech E&O and professional liability are emerging as the place where a genuine affirmative-AI market is actually forming- real, named coverage you can buy.
-
Employment practices liability (EPLI) is a growing pressure point as AI-driven recruiting and HR tools raise discrimination exposure.
No single policy covers all AI perils, and the erosion often happens quietly, through revised base forms, narrowed definitions, and restrictive carve-backs rather than a single conspicuous “AI exclusion” you'd notice on the declarations page. That's what makes this dangerous. The gap becomes visible only when a claim is filed, and by then it's far too late to fix your governance or documentation.
Implications for Cyber Insurance
Cyber insurance policies were written with human threat actors in mind. This incident should prompt every organization to review its coverage with its broker. Key questions include:
-
Does your policy exclude or sub-limit losses caused by AI-driven incidents, as opposed to human-directed attacks?
-
Does your policy cover third-party liability if your AI system causes a breach at someone else’s organization?
-
Will your insurer require evidence of specific AI containment controls, such as alignment with ISO/IEC 42001 or the NIST AI Risk Management Framework, before renewing coverage for agentic AI workflows?
Underwriters are going to be watching this closely. Organizations that deploy agentic AI without robust containment and monitoring controls may face higher premiums, narrower coverage, or both.
A Word of Balance
It's worth noting the sky isn't uniformly falling. Some major brokers characterize 2026 less as broad retrenchment and more as clarification, or simply stated, targeted adjustments and closer scrutiny of how AI modifies exposure within existing lines, with capacity still available and affirmative AI coverage increasingly offered via endorsement. The through-line in both readings is the same, however. AI is no longer something you can leave unspoken in your program. Governance and documentation are becoming central to whether you're insurable at all, and at what price.
What to Do Before Your Next Renewal
You don't need a dedicated risk department to get ahead of this. A few practical moves go a long way:
-
Pull your current policies and read the AI-relevant language now: GL, cyber, Tech E&O, D&O, and EPLI. Look at the insuring agreements, exclusions, and endorsements together, because the gaps live in the seams between them.
-
Inventory how your organization actually uses AI: Include “shadow AI,” the unsanctioned tools employees adopt on their own. You can't insure or govern what you can't see, and some carriers are now writing narrow exclusions specifically for untracked AI use.
-
Ask your broker direct questions before you bind any 2026 renewal: Which ISO endorsements are attaching? Where has coverage narrowed? Where can I buy affirmative AI coverage, and is a write-back endorsement or a standalone AI policy the better fit? And if you run agentic AI workflows, what containment controls or framework alignment (ISO/IEC 42001, NIST AI RMF) will underwriters expect at renewal?
-
Challenge unexplained increases: In a competitive market, a cyber renewal that jumps sharply without a loss behind it is worth pushing back on, and worth re-marketing across carriers rather than accepting the first number.
-
Treat governance as an underwriting asset: Documented AI policies, human-review requirements, and clear usage limits aren't just compliance hygiene anymore. They're increasingly what stands between you and a denied claim, and what earns underwriter confidence at renewal.
-
Address AI in your contracts and agent deployments: If you deploy or procure AI agents, don’t rely on insurance alone to allocate the loss. Master service agreements and statements of work should spell out adversarial-testing and containment requirements, kill-switch and human-approval controls for privileged actions, and clear incident-cooperation and indemnification terms. These provisions decide who pays before a claim is ever filed, and they signal to underwriters that your AI exposure is actively managed.
Practical Takeaways for Organizations
Reviewing your insurance is only half the response. The incident also carries operational lessons, and, increasingly, whether you have absorbed them determines your insurability in the first place.
First, treat containment as a critical control, not a nice-to-have. If you are developing or deploying AI systems with agentic capabilities, sandboxing alone is not enough - it failed here. Defense-in-depth is essential: strict network egress rules, micro-segmentation, least-privilege access, and scoped, short-lived credentials.
Second, do not rely on a single AI vendor for both operations and security. One of the most striking details of this incident is that when Hugging Face’s security team tried to use commercial frontier AI models to analyze the attack logs and exploit payloads, the models’ safety guardrails blocked them, unable to distinguish a defender analyzing a threat from an attacker building one. Hugging Face had to switch to open-weight models running on its own infrastructure to complete the forensic investigation. That is a cautionary tale about vendor concentration risk.
Third, update your incident response plans. Your existing playbooks almost certainly assume a human adversary operating at human speed. An autonomous AI agent can generate over 17,000 attack events across a weekend. Make sure your response capabilities and your legal team are prepared for that tempo.
Fourth, engage your board and leadership now. This incident is going to accelerate regulatory action. President Trump’s June 2026 executive order on frontier AI models is already on the books, and additional requirements around mandatory containment standards, testing protocols, and disclosure obligations are likely coming. Getting ahead of these developments is far better than reacting to them.
The Bottom Line
The uncomfortable truth is that old policies were written for a world without AI, and that world is gone. The legal, insurance, and operational frameworks most organizations rely on were built for human hackers operating at human speed, and the OpenAI–Hugging Face incident is the first publicly confirmed case of an AI system autonomously executing a sophisticated, multi-stage cyberattack against real-world production infrastructure. It will not be the last. The coverage many organizations assume they have is being redefined line by line, renewal by renewal, sometimes loudly, more often quietly. The businesses that come through the first AI-related claim without a six-figure legal surprise will be the ones that stopped assuming and started reading, and that adapted before the threat. The liability that follows it, found them first.
Don't wait for a claim to find out what your policy really says. Ask the questions now, while you still have room to negotiate.
Contact Us
Share this
You May Also Like
These Related Stories

Cyber Insurance & AI: Are You Fully Covered and Secure?

Cyber Insurance in 2025: Navigating Emerging Threats & Trends

.webp?width=2169&height=526&name=Compass%20white%20blue%20transparent%202%20website%20(1).webp)
-1.webp?width=2169&height=620&name=Compass%20regular%20transparent%20website%20smaller%20(1)-1.webp)
No Comments Yet
Let us know what you think