Losses caused by enterprise AI agents are insured today mostly by default, through cyber, E&O and liability wordings that never contemplated them. That default is being withdrawn one carrier and one optional endorsement at a time. Affirmative cover is real but thin: a handful of specialists on overlapping capacity, at limits a large deployment can exhaust, with no public wording.
If an AI agent you deployed pays the wrong supplier, issues a thousand refunds it should not have, or makes a commitment to a customer, the question your CFO will ask is whether any policy responds. The answers in circulation come from trade press, law-firm alerts and a growing crop of AI-generated explainer sites that repeat each other's figures. The line you will see most often, that Berkshire Hathaway, Chubb and Travelers won approval for more than 80 percent of their AI exclusion filings, traces to a paywalled article citing a Wolfe Research analysis that has never been made public. So this report counts forms instead of quoting commentary. Where a policy wording, a rating-bureau form, a Lloyd's bulletin or a contract term could be read, it is cited as such. Where the only evidence is a press release or an executive's remark, the report says so and does not let a conclusion rest on it.
Two structural facts limit what anyone can count. Surplus lines and Lloyd's business in the US is largely exempt from rate and form filing, so the specialist AI products that matter most leave no trace in SERFF, the state filing system. And almost none of the specialists publishes a specimen wording. Silence in the filing record is evidence about the admitted market only, and the absence of a public wording is a finding in its own right.
Seven findings, each sourced and labeled by evidence type. The market has split three ways: some carriers exclude AI outright, a small group of specialists writes affirmative cover, and most policies say nothing at all.
Verisk's ISO unit released three optional generative AI exclusions, CG 40 47, CG 40 48 and CG 35 08, for commercial general liability and products liability, effective January 2026. The base CGL form, CG 00 01, is unchanged, and Verisk told Claims Journal it does not know how many insurers have adopted them. No Lloyd's market bulletin or LMA model clause on AI exists. The LMA is still consulting on a model AI definition.
RAND counted 112 AI exclusion forms from 60 insurance companies in the US admitted market through 21 June 2026, against seven endorsements, four applications and no standalone AI policy. Most of the exclusions attach to commercial umbrella and general liability, where limits are highest. The surge began in the summer of 2025.
Armilla and Chaucer state $25 million or more per organisation. Testudo states $1 million to $10 million. Munich Re's aiSure partnership with Mosaic states $15 million of initial capacity. The $50 million figure attached to AIUC appears only in press and think-tank accounts, never in AIUC's own releases.
Cover is gated by testing or certification (AIUC, Armilla), by historical performance data (aiSure), or by litigation-data scoring with no technical audit (Testudo). Exclusions for misuse, unauthorised changes, prior known defects and intentional acts recur wherever terms are described. A buyer cannot compare exclusions until a quote arrives.
The standard calls itself insurance-enabling, but its text sets no eligibility, price or discount. No carrier filing, wording or underwriting guideline that references it was found. Inside AIUC, the company that writes the standard also runs the tests, issues the certificate and places the insurance. Outside it, the certificate is a procurement signal.
Lloyd's scenarios, the mandatory cyber Realistic Disaster Scenarios, the commercial cyber models and reinsurer research all quantify cloud outages or describe AI concentration in words. None puts a number on a foundation-model failure. The July 2024 CrowdStrike failure is the only shared-dependency event the market has priced, and published insured-loss estimates for it span roughly five to one.
The only mandate precedents are Lloyd's silent-cyber bulletin Y5258 in 2019 and the state-backed attack bulletin Y5381 in 2022, and both came after years of loss experience. The NAIC's March 2026 issue brief covers insurers' own use of AI and says nothing about exclusions. No state disapproval of an AI exclusion was found.
Affirmative cover here means a wording that names AI model or agent failure as a covered cause of loss, as distinct from a cyber policy that happens to respond when AI is involved in a breach. Every limit below is a company statement or a journalist's report, because no specimen wording is public. Stated maxima are ceilings, not typical bound limits.
Third-party liability for model underperformance, hallucination, agent errors in decisions or execution, non-breach data leakage and AI regulatory violations, with $5 million per model use. Gated on a pre-bind assessment. Armilla lists Chaucer, AXIS Capital, Convex, Greenlight Re and Swiss Re as capacity partners.
Limit source: company page and trade press
Chaucer cyber and tech E&O limits paired with Armilla cover that responds to erroneous outputs, model underperformance or agent actions where no cyber event has occurred. Predefined allocation rules split mixed events by harm. The most specific primary statement of structure in the market.
Limit source: carrier release, February 2026
First and third party, including agent tool-call failures, wrong payments or refunds, and reputational harm. Gated on AIUC-1 certification and quarterly retesting. The Insurer reported in May 2026 that AIUC had secured Beazley paper.
Limit source: press and CSIS, never an AIUC release
Claims-made third-party cover for generative AI deployers across six insuring agreements, underwritten on litigation data with no technical audit. Apollo leads with Atrium and QBE, reaching $9.25 million of capacity per insured.
Limit source: company release
A performance guarantee against agreed model metrics, settled on defined thresholds, after due diligence on the pipeline, data, drift and monitoring. Munich Re says it has written aiSure guarantees since 2018 and calls its limits flexible.
Limit source: carrier release
Bodily injury, property damage and advertising injury caused by AI, for small firms, sold through partner carriers. Announced in March 2026 pending regulatory approval. If approved as a filed form, it would be the first affirmative AI liability policy in the US admitted market.
Pending regulatory approval at launch
Two things sit outside this table. The cyber line is moving the other way: Coalition, Beazley and CFC have added affirmative AI language, but read closely it covers attacker-side AI such as deepfake funds-transfer fraud and AI-assisted intrusion. None of it reaches an agent you deployed doing the wrong thing with no security event. That loss falls between cyber, which wants a breach, and E&O, which wants a professional service, and it is where silent cover is thinnest. The hyperscaler indemnities often offered as a substitute are narrower still. Microsoft's Customer Copyright Commitment and Google Cloud's generative AI indemnity cover intellectual property only, on conditions, and nothing operational. And the capacity overlaps: Chaucer, Beazley, Munich Re and Swiss Re each sit behind more than one programme, so a broker stacking a tower from three specialists may be stacking the same reinsurer three times.
A point forecast of when AI will be excluded market-wide would be invented. The probabilities below are my judgment and the least reliable content in the report. The tripwires are the most useful, because anyone can watch them without private data.
Exclusions keep spreading carrier by carrier through optional ISO endorsements and individual D&O, E&O and umbrella wordings. Cyber keeps adding attacker-side AI clarifications. Specialists grow, but limits stay in the tens of millions, and cover for the same agent loss depends on which carrier wrote which line.
Watch for: another renewal season with no Lloyd's bulletin and no ISO umbrella or professional AI form
Lloyd's issues a bulletin on the Y5258 model requiring every policy to state whether AI loss is covered or excluded, and the LMA's model definition becomes model clauses. Silent cover disappears over one or two renewal cycles, some of it turning affirmative at a price and some into explicit exclusion.
Watch for: an LMA AI definition with a clause number, or a Lloyd's bulletin that names AI
A shared-model or shared-cloud event produces claims across many insureds and several lines at once. Carriers attach absolute AI exclusions at renewal, reinsurers add AI exclusions to treaties, and specialist capacity retreats. Agent risk returns to balance sheets and vendor contracts.
Watch for: a public insured loss tied to a model failure across unrelated insureds
For a risk manager at renewal, the practical read is to assume agent losses are retained unless a named wording says otherwise. Ask each carrier in writing how its forms define artificial intelligence and whether CG 40 47 or CG 40 48 is attached to general liability or umbrella. Check whether any cyber clarifying endorsement reaches your own agent acting wrongly with no breach. If D&O renewal brings a Berkley-style clause, read the disclosure limb: it removes cover for claims about the company's own statements on AI, which is the securities exposure a board most wants covered. The report carries the full tripwire table and separate implications for CFOs, general counsel negotiating vendor indemnities, and brokers placing specialist cover.
This isn't a vendor summary. Every sentence is labeled by what stands behind it: verified fact, vendor claim, third-party estimate, my assessment, hypothesis, or scenario. Sources are numbered and clickable. Forward-looking sections use scenarios with observable tripwires, not forecasts. It's the same method behind every market assessment I write.
Twenty-three pages, built from public sources with no client brief and no interviews. Read it in the browser or take the PDF.
Each report here answers a real question, directed and researched against public sources and evaluated against a stated assumption, then delivered as Word and PDF. If you're weighing a platform, sizing a category, or defending a number to a board, tell me the decision behind it and I'll tell you honestly whether a report is the right tool.
Commission an assessment