Cost control

Your Insurer Quietly Changed Its Mind About AI. Check These Two Form Numbers

If an AI tool you use causes a loss, is it covered? Until recently the answer was usually yes — but only because policies did not mention AI at all. Insurers spent 2026 ending that, in both directions at once, and the change arrives at renewal without a conversation.

Disclosure, up front

We are not brokers and we do not sell insurance, which means we have no commercial interest in what you conclude here. We also cannot read your policy for you — the whole point of this article is that coverage has fragmented, so the only answer that counts is the one on your own schedule. Not insurance or legal advice.

Here is a question almost no small business can answer: if an AI tool you use causes a loss, is it covered?

Until recently the answer was usually yes, but for an uncomfortable reason. Policies did not mention AI at all, so AI losses fell inside cover by silence rather than by any deliberate grant. The industry has a term for this — "silent AI" — and 2026 is the year insurers set about ending it.

That is happening in two directions at once, which is why nobody can tell you what the market does. Some carriers are excluding AI. Others are affirmatively covering it. The one thing you cannot do is assume.

What changed

  • On 1 January 2026 the standard forms body introduced generative AI exclusion endorsements for commercial general liability — forms CG 40 47 and CG 40 48 — and carriers began attaching them at renewal.
  • A 2026 survey found 42% of companies now have AI-related exclusions written into their cyber policies.
  • Meanwhile the opposite is also happening: affirmative AI cover is appearing in mainstream cyber and tech E&O forms, plus a small standalone AI liability market.
  • Some insurers now require proof — red-teaming, documented risk assessment — before extending AI cover.
  • Systemic exclusions are common even where cover exists: at least one major carrier covers AI incidents but excludes losses hitting many policyholders at once.

01Why "silent AI" was never as good as it sounded

Being covered by silence means being covered until someone decides to argue about it. It was never a considered grant of cover; it was an absence of exclusion in policies written before the risk existed.

The endorsements arriving now are the industry resolving that ambiguity, and resolving it in both directions. If you renewed in 2026 without reading the endorsements, your cover may have changed materially without anyone drawing your attention to it, because an endorsement attached at renewal is not a new policy and does not feel like a decision.

That is the actionable point of this whole article: this is a renewal-time change that arrives quietly.

02The two form numbers worth searching for

If you take one thing away, take these. Open your commercial general liability policy and search the endorsement schedule for CG 40 47 and CG 40 48.

These are optional generative AI exclusion endorsements introduced for use from 1 January 2026. They allow a carrier to eliminate coverage for claims arising out of generative artificial intelligence. If one is attached to your policy, your general liability cover has a generative AI carve-out and you should know that before you need to know it.

They are optional, so their presence is a decision your carrier made about your account. Their absence is equally informative.

The three-minute version

Find your policy documents. Search the endorsement list for "artificial intelligence", and for the two form numbers above. Do the same on your cyber policy and, if you have one, your professional indemnity or tech E&O. Write down what you find and the date you looked. That is the entire exercise, and almost nobody has done it.

03Where the gap actually opens for a small business

Not in the exotic scenarios. In ordinary ones where AI happened to be the instrument:

Realistic AI-related losses and which policy would normally respond
What happens Which policy would usually respond Where an AI exclusion could bite
Staff paste customer data into a tool; it is exposed Cyber An AI exclusion on the cyber policy could remove the response entirely.
Your chatbot tells a customer something wrong and they act on it General liability or professional indemnity CG 40 47 / CG 40 48 territory. The clearest exposure.
Generated marketing material infringes someone's rights General liability (advertising injury) or media cover Both an AI exclusion and any vendor indemnity conditions apply here.
An automation sends the wrong thing to the wrong list Cyber or professional indemnity Depends whether the AI involvement is characterised as the cause.
A deepfake induces a payment Crime / social engineering cover Often already sub-limited or excluded, quite separately from AI.

Illustrative mapping of common scenarios to policy types. Which policy responds to any actual claim depends entirely on your wordings, the characterisation of the cause, and facts we cannot see — this table is a prompt for a conversation with your broker, not a coverage opinion. Coverage in this area fragmented significantly during 2026 and differs sharply between carriers.

The second row is the one to sit with. A chatbot giving wrong information is not a hypothetical; it is the most predictable failure mode of the most commonly deployed AI in small business. It is also squarely the kind of claim a generative AI exclusion is designed to remove.

04The other direction: cover is also being written

It would be misleading to present this as insurers simply withdrawing. The countertrend is real: AI cover is being written affirmatively into mainstream cyber and technology E&O forms, and a small standalone AI liability market has emerged.

Two features of that market are worth knowing:

  • Systemic risk is commonly carved out. At least one major carrier covers certain AI incidents while excluding losses that hit many policyholders simultaneously — guarding against one flawed model triggering claims across an entire book. Reasonable from their side; it means a widely-used tool failing may be exactly the scenario least covered.
  • Underwriters increasingly want evidence. Some insurers now ask for proof of red-teaming and documented risk assessment before extending AI cover. For a small business the practical version is modest — an AI tool inventory and a dated note of what you considered will answer more of an underwriting question than most owners expect.

05What to actually do

  • Search your policies for "artificial intelligence" and the two form numbers. Three minutes, and it is the only step that produces a fact rather than an assumption.
  • Ask your broker one specific question in writing: "does any policy we hold exclude claims arising from artificial intelligence, and did that change at our last renewal?" Specific questions get specific answers.
  • Tell them what you actually run. A chatbot answering customer questions is a materially different risk from an internal drafting tool, and brokers cannot place cover for a use case they have not been told about.
  • Keep the inventory. It is now doing double duty — governance and underwriting evidence.
  • Diarise the renewal. This is where the change arrives, and it arrives without a conversation unless you start one.
  • Do not buy standalone AI cover reflexively. First find out what you already have; the market is young, thinly tested by claims, and priced accordingly.

06The honest summary

AI losses used to be covered by silence. From 1 January 2026 that silence is being replaced — sometimes by exclusions like CG 40 47 and CG 40 48, sometimes by affirmative cover, and increasingly by conditions requiring you to show your work. Around 42% of companies now report AI exclusions in their cyber policies.

Nobody can tell you what your position is, because the market has fragmented and the answer is in your own wordings. But the exercise that resolves it is three minutes with a search box and one written question to your broker.

Do it before your renewal rather than after a claim, because those are the only two moments when anyone ever finds out.

07Common questions

Does my insurance cover AI-related losses?

Possibly, and you cannot assume. Until recently most organisations were covered for AI losses by silence rather than by any deliberate grant, because policies neither affirmed nor excluded AI. Since 1 January 2026 insurers have been resolving that ambiguity in both directions — attaching exclusions at renewal in some cases, writing affirmative AI cover in others. Coverage has genuinely fragmented, so the only reliable answer is in your own policy wordings.

What are CG 40 47 and CG 40 48?

Optional generative AI exclusion endorsements introduced by the standard forms body for commercial general liability, for use from 1 January 2026. They allow a carrier to eliminate coverage for claims arising out of generative artificial intelligence. Because they are optional, their presence on your policy reflects a decision your carrier made about your account — and their absence is equally informative. Searching your endorsement schedule for these form numbers is the single most useful check in this article.

How common are AI exclusions now?

A 2026 survey found 42% of companies have AI-related exclusions written into their cyber policies. That figure covers cyber specifically; general liability is a separate question governed by whether one of the generative AI exclusion endorsements has been attached. Both are worth checking, along with professional indemnity or technology errors and omissions cover if you carry it.

What is silent AI?

Coverage that exists because a policy does not mention AI rather than because it deliberately grants cover for it. Until the start of 2026 most organisations were in this position, and it was never as reassuring as it sounded: being covered by silence means being covered until someone decides to argue about it. The endorsements now appearing are the industry resolving that ambiguity, which is why this is a renewal-time issue.

Which AI scenario is most likely to fall into a coverage gap?

A chatbot giving a customer wrong information that they act on. It is the most predictable failure mode of the most commonly deployed AI in small business, it would normally be a general liability or professional indemnity matter, and it is squarely the kind of claim a generative AI exclusion is designed to remove. Which policy actually responds to any real claim depends on your wordings and how the cause is characterised.

Are insurers only withdrawing cover?

No, and presenting it that way would be misleading. Alongside exclusions, AI cover is being written affirmatively into mainstream cyber and technology errors and omissions forms, and a small standalone AI liability market has emerged. Two caveats: systemic losses are commonly carved out, so one widely-used tool failing across many policyholders may be the least-covered scenario, and some insurers now require evidence such as red-teaming and documented risk assessment before extending cover.

What should I ask my broker?

One specific written question: does any policy we hold exclude claims arising from artificial intelligence, and did that change at our last renewal? Then tell them what you actually run, because a chatbot answering customer questions is a materially different risk from an internal drafting tool, and a broker cannot place cover for a use case nobody mentioned. Specific questions get specific answers; general ones get reassurance.

Should I buy standalone AI insurance?

Not reflexively, and not first. Establish what your existing policies already do and do not cover, since the answer may be better than you expect or the gap may be somewhere you did not anticipate. The standalone AI liability market is young, thinly tested by actual claims and priced accordingly. Some underwriters also want evidence of governance before extending cover, so an AI tool inventory and a dated record of what you considered is useful groundwork either way.

Three minutes with your policy

Search your general liability and cyber policies for "artificial intelligence", and for the form numbers CG 40 47 and CG 40 48. Send us what you find, along with what AI you actually run. We will tell you where the obvious gaps sit and what to put to your broker. We do not sell insurance, so there is nothing at the end of this for us to sell you.

Ask for a gap check

Sources, read 9 September 2026: 2026 insurance and law firm commentary on the end of "silent AI", the introduction of optional generative AI exclusion endorsements CG 40 47 and CG 40 48 for commercial general liability effective 1 January 2026, the 42% figure for AI-related exclusions in cyber policies from a 2026 industry survey, and reporting on affirmative AI cover, systemic-loss carve-outs and underwriting evidence requirements. This is not insurance or legal advice. Coverage in this area fragmented materially during 2026 and differs by carrier, by wording and by renewal date; the scenario table is a prompt for a conversation with your broker rather than a coverage opinion, and no statement here should be relied on in place of your own policy documents. Related: The FBI Started Counting AI Fraud and Six Clauses to Check Before You Sign.

Hero image from Unsplash, used under the Unsplash License.