A dark underwriting desk with an AI risk map and policy binder.

Who Insures Your AI in 2026?

Specialist insurers are finally writing policies for hallucinations, drift, and agent failures. The biggest carriers are filing exclusions. The gap between those two moves is your real risk map.

By Dellon S.June 18, 202612 min read

Two markets are moving in opposite directions

Some insurers now offer policies for harm caused by AI, such as false answers or failed recommendations. At the same time, other insurers are adding AI exclusions to ordinary business policies, so your existing cover may not pay when an AI system causes a loss.

The specialist market is genuinely new. Munich Re’s aiSure is built around AI performance failures such as prediction errors, calibration or data drift, and unexpected model deviations. In March 2026, Mosaic partnered with Munich Re to offer aiSure-backed capacity of up to 15 million in EUR, USD, or CAD for AI developers and vendors.

Armilla, writing on Lloyd’s capacity through Chaucer, treats hallucinations and model underperformance as insurable events. AIUC took a different route: it created AIUC-1, a certification standard for agent controls, then tied insurance to the evidence. ElevenLabs became the first company to secure its AI-agent insurance. HSB launched AI liability cover for small and medium businesses, and Ollive is targeting a summer 2026 launch for vendor-focused coverage.

The incumbents are sending the opposite signal. The Financial Times reported that AIG, Great American, and WR Berkley sought permission to exclude AI-related liabilities from standard corporate policies. WR Berkley’s proposed language reaches “any actual or alleged use” of AI, including products or services that merely incorporate it.

Read that as an underwriting decision, not a headline. The people whose profession is pricing risk looked at AI deployment and decided that correlated failure across thousands of customers is still too difficult to price inside ordinary coverage.

Specialists sell a condition. Incumbents sell a carve-out.

The difference is not optimism versus pessimism. It is whether the operator can show enough evidence for the risk to be priced.

Entering: performance cover, agent certification, vendor capacity.

Leaving: silent AI exposure inside general policies.

A split diagram showing specialist AI insurers entering while incumbent carriers file exclusions.

The ruling that concentrated everyone’s minds

Liability stopped being theoretical when an AI answer became a company’s published statement.

A Munich regional court ruled that Google is directly liable for false claims in its AI Overviews, treating the AI-generated text Google selected and presented as its own published statement rather than a neutral search result. The full legal story belongs in the German ruling analysis; the insurance point is simpler.

The deployer that puts AI output in front of a customer may own the output. Vendor terms that disclaim liability do not necessarily move exposure away from the company that configured the system, selected the use case, approved the answer, and benefited from the interaction.

That principle explains the split market. Specialists are building products for the exposure. Generalists are writing exclusions so they are not holding it by accident. If your risk register still says “covered under existing E&O,” your next renewal is the moment to find out whether that sentence remains true.

The same logic applies below the level of a landmark court decision. A product selector that recommends an unsuitable use case, a support agent that invents a refund promise, or an ad system that targets a protected audience can turn a model behavior into a company action. The model may be the mechanism, but the brand is the interface customers recognize.

That is why vendor disclaimers are not the same thing as risk transfer. A vendor can still owe duties under a contract, and a carrier can still respond to a scheduled loss, but neither fact answers who reviewed the output, whether the use case was approved, or what happened after the first warning appeared. Those are deployment facts, and they sit with the operator.

For marketing teams, the practical shift is severe: customer-facing copy is no longer just a content artifact. It is a production surface with a model version, an audience, a reviewer, a publication decision, and a correction path. Each of those facts may become relevant to coverage.

A legal reviewer compares an AI-generated customer answer with a marked court filing in a courthouse records room.
The risk changes when an AI answer becomes the company’s public statement.

What the new policies actually cover

Strip out the category names and specialist policies cluster around four buckets. Each one is useful, but none is a blanket promise that the brand is protected.

01

01

Performance failure

Prediction errors, calibration failures, data drift, hallucinations, and unexpected model deviations.

02

02

Tech E&O

Misclassified customers, recommendation errors, and professional mistakes translated into AI-system terms.

03

03

IP infringement

Claims that training material or generated output reproduces protected content, usually with sub-limits.

04

04

Privacy violations

Model leakage, unlawful processing, retention failures, and AI-specific extensions of familiar privacy risk.

Performance cover is the most important change for teams that use AI in live decisions. An ordinary software policy may respond to a service failure; an AI-specific policy can ask whether the system stayed within a warranted performance range, whether drift was detected, and whether the output fell below an agreed threshold. That turns “the model was wrong” into a question an underwriter can actually evaluate.

Tech E&O is more familiar territory. It can matter when an AI-assisted service misclassifies a customer or provides a professional recommendation that causes third-party financial loss. The difficult question is whether the brand is the professional service provider, the software buyer, or both. The answer often depends on the wording and on what the team promised customers the system would do.

IP and privacy coverage are established categories with new AI pressure. Training data disputes, generated material, prompt data, model retention, and personal information leakage can all create a claim, but the policy may carry sub-limits, consent requirements, or exclusions for material the company supplied to the model. A broad “AI covered” headline tells you very little about those boundaries.

Third-party harm is the loosest bucket. Defense costs can be valuable even when a final judgment is uncertain, but the buyer should distinguish defense, indemnity, remediation, regulatory response, and fines. They are different financial events and rarely receive identical treatment.

Notice what is missing: regulatory fines are often uninsurable, reputational harm is difficult to translate into a covered loss, and negligent deployment is excluded when the operator knew the system was unreliable. The policy can answer a failure only after the buyer has named the failure precisely enough to price.

Hands reviewing AI evaluation sheets and incident records across an underwriting desk.
Coverage becomes usable when a team can show what it tested, what it watched, and what it stopped.
A diagram mapping four coverage buckets against three conditions that can eat a claim.

The exclusions that eat your claim

The policy is not really insuring your AI. It is insuring your discipline around the AI.

01

Known defects

If testing showed the failure mode and the team deployed anyway, the claim can become a governance failure.

02

Missing evidence

Without evaluations, monitoring logs, guardrail records, and approvals, diligence is hard to prove.

03

Broad AI carve-outs

“Any actual or alleged use” can remove the customer-facing output risk from older policies entirely.

Known-risk exclusions are especially uncomfortable. If a test report, Slack thread, incident note, or vendor notice shows that the company knew about a failure mode and deployed anyway, the future claim may be treated as a governance failure rather than a surprise loss.

Diligence requirements close the other loophole. Teams that never test can say they never knew, but insurers increasingly ask for the evaluation set, monitoring cadence, review owners, and rollback record. No evidence means no leverage.

There is also a practical difference between an exclusion that is narrow enough to negotiate and one that swallows the product. Ask whether “AI” means a particular scheduled system, a model family, a use case, or any software that includes an AI feature. The answer changes the size of the hole. A carrier can leave a team believing it has cover while the operative phrase removes the exact workflow that reaches customers.

Do the same exercise with known risk. It should be possible to tell the difference between a defect that was discovered, documented, and actively managed and a defect that was accepted without controls. The first is a risk-management fact. The second can look like the reason the claim exists.

An editorial evidence file diagram showing tests, monitoring, guardrails, and rollback records.

The buyer’s playbook

Five moves make the insurance conversation more concrete, whether the organization buys a specialist policy or simply renegotiates its current cover.

01

Map the liability surface

List every place AI generates claims, recommendations, decisions, or customer-facing answers. Underwriters price the surfaces, not the AI budget.

02

Interrogate current policies

Ask in writing which policies respond today, which AI exclusions have been filed or added, and what changes at renewal.

03

Build the evidence file

Keep pre-deployment tests, regulated-category reviews, monitoring logs, guardrail documentation, incidents, and rollback records together.

04

Buy specific coverage

Negotiate scheduled systems, performance warranties, IP and privacy sub-limits, known-risk wording, notice duties, and defense costs.

05

Wire the pause button

Give a named owner authority to flag, review, remove, and correct a suspect output before a small error compounds into a public claim.

The application should read like an evidence brief, not a software inventory. Name every customer-facing surface, the model or vendor behind it, the decision it can make, the harm that decision could create, and the person who can stop it. This gives the broker something better than a promise that the organization is taking AI seriously.

Ask for examples in the policy language before asking about the premium. A buyer should be able to point to a hallucinated product claim, a discriminatory recommendation, a model update, and a data leakage event and explain which coverage responds, which exclusions apply, and what notice is required. If the answer changes when the workflow is described in operational terms, that ambiguity is itself a risk to resolve.

SignalBusiness responseCoverage response

False product claim

Remove or correct the output and identify the source workflow.

Preserve the prompt, output, reviewer, and affected audience.

Biased recommendation

Pause the path and test for protected-class impact.

Notify counsel and map discrimination or regulatory language.

Vendor model change

Retest critical workflows before full release.

Check notice rights, indemnity, and underwriting facts.

Coverage exclusion

Reclassify the surface as an uncovered operating risk.

Ask for an endorsement, standalone cover, or written confirmation.

When underwriters become regulators

Step back and the 2026 insurance market is doing something regulation has not managed at the same speed: forcing operational discipline with a price signal.

EU AI Act obligations, US federal rules, and sector-specific enforcement will continue to move through policy and litigation. An insurer that refuses to cover undocumented AI deployment changes behavior today, at contract speed, with no comment period. Certification-linked cover turns “nice to have” governance into a requirement you can buy only after you demonstrate it.

That is why the most useful question for a marketing leader is not “can we get a certificate?” It is “what evidence would make this risk legible to an underwriter?” The answer is usually the same evidence that makes the system safer to customers: mapped surfaces, fixed evaluation sets, output logs, named reviewers, and a pause path.

For a CMO, this changes the order of operations. The insurance conversation should start before procurement chooses a model, because the limits and exclusions can influence which workflows are safe to automate. A vendor with strong indemnity but weak change notices may be a worse fit than a smaller vendor that can expose version history, evaluation results, and escalation contacts.

That evidence also creates negotiating leverage. A buyer who can show a tested launch boundary can ask for narrower exclusions, clearer notice periods, and a defined response when a vendor changes the model. Governance is not only the cost of getting covered. It is the material a buyer brings into the negotiation.

If specialists will only insure AI with proof of testing and monitoring, and generalists will not insure it at all, the actuarial consensus on unmanaged AI risk is already in. The boring, paranoid operators are not being excessive. They are the only ones making their exposure transferable.

FAQs

Does existing E&O cover AI failures?+

Increasingly, not reliably. AIG, Great American, and WR Berkley have sought permission for AI exclusions in standard policies, while other carriers are adding similar wording at renewal. Ask the broker to identify the exact AI claims each policy would answer today.

Who sells AI liability insurance in 2026?+

The specialist field includes Munich Re’s aiSure, Mosaic’s capacity for AI vendors, Armilla on Lloyd’s capacity, AIUC with certification-linked agent cover, HSB for small businesses, and new MGAs such as Ollive targeting vendor-focused coverage.

What do AI policies usually exclude?+

Common exclusions include known defects, negligent deployment, losses that cannot be supported by testing and monitoring evidence, regulatory fines where uninsurable by law, reputational harm, and overly broad AI carve-outs in older policies.

What evidence will an insurer want?+

Expect questions about the evaluation set, output monitoring, guardrails, review owners, model or prompt changes, incident response, and rollback authority. AIUC-1 formalizes that evidence logic through certification.

Is AI liability insurance worth buying?+

For customer-facing AI in regulated or high-stakes categories, it can be a useful backstop. The underwriting process is also valuable because it forces the organization to name its exposure and show how it controls it.

A risk operator holding a policy folder beside an emergency stop console.

Insurance matters most when the evidence is already there.

A policy can transfer some risk. It cannot perform the test, keep the log, or press pause. That part is still yours.