Your Carrier Already Ran Your AI Due Diligence

Picture the CFO who did everything right. She inventoried the AI tools, briefed the board, and told the broker she wanted the exposure insured and was willing to pay for it. The broker came back with the answer that is becoming standard: the market is still figuring this out.

The market is further along than that answer suggests. It just did its figuring in filings rather than press releases.

A Center for Strategic and International Studies report by Gregory C. Allen of the CSIS Wadhwani AI Center, published September 4, argues that the insurance industry's retreat from AI risk has itself become a brake on safe AI adoption, and it assembles the numbers. Citing reporting by The Information from April 23, 2026, the report states that state insurance commissioners approved more than 80% of carrier requests to exclude AI-related damages from corporate insurance policies. It counts more than 60 property and casualty providers filing for AI exclusions on 2026 policies (CSIS). One thing to know as you read it: CSIS states the report was sponsored by Fathom, the nonprofit that developed the independent verification organization concept California enacted this month. The people who counted the exclusions and the people who designed the auditor are working the same problem from both ends.

This briefing has covered the forms themselves. The ISO generative AI endorsements ran here on August 12. Identifiers matter, so here they are again: CG 40 47, CG 40 48, CG 35 08. The W. R. Berkley management liability exclusion ran on August 25. What is new is not that exclusions exist. What is new is the approval rate.

Filing is not the last step. Approval is. When commissioners clear more than four out of five requests, the exclusion stops being something your broker will contest and becomes the form your renewal arrives on.

And the retreat is not happening at the edges of the coverage map. The CSIS report reproduces a Geneva Association matrix from October 2025 in which 90 of 112 combinations of AI risk and insurance line, roughly 80%, were marked Excluded, against 13 Available and 9 Limited. Applying the Berliner insurability framework, that same assessment found generative AI failed three of nine criteria outright, and CSIS calls the most fundamental of the three information asymmetry: the carrier cannot see which models you run, how they are governed, or whether the controls you claim exist. Those figures come from a survey of 600 corporate insurance decisionmakers across six major economies and cover all commercial lines, so read them as the weather system rather than your local forecast.

Demand has not softened at all, which is what makes this a market failure rather than a market correction. More than 90% of those decisionmakers said they need coverage tailored to AI threats, and more than two-thirds said they would pay at least 10% more in premium for an explicit generative AI extension. On the other side of the table, 86% of underwriters expected their insureds' AI usage to rise over the following two to three years, in a Lloyd's Market Association survey of 144 market participants in mid-2025. Both sides can see the exposure growing. Only one side writes the form.

Specialty capacity exists and it is thin. The CSIS report describes Armilla AI writing up to $25 million per insured and the Artificial Intelligence Underwriting Company up to $50 million, and notes Financial Times reporting from October 8, 2025 that OpenAI secured AI risk coverage of up to $300 million, brokered through Aon. Against that sits the correlated loss problem, described in the report by Aon's Kevin Kalinich: one foundation model failure could produce losses across 1,000 or 10,000 policyholders at once. That is why the practical answer is not to shop for an AI policy. It is to shrink the number of places an AI failure can land uninsured, and that work happens in your vendor contracts. The report notes OpenAI's standard business terms cap liability at fees paid in the twelve months before an event, with comparable terms from other providers. If your documentation vendor's contract mirrors that, your indemnity is roughly one year of subscription fees against a resident harm claim.

Run the 30-Day AI Coverage and Contract Audit against your renewal calendar, not your policy binder. Put the three questions to your broker in writing this week. Has your carrier filed an AI exclusion endorsement in the states where we operate? Does our policy respond to a claim arising from an AI failure? Have you reviewed our vendor contracts for indemnification language? Then add the question your broker will not volunteer: which of our lines already carry an approved AI exclusion today, and what is the renewal date on each. Finally, rank your AI vendors by the worst plausible resident or employee harm each could contribute to, and read their liability caps in that order. Where the cap is twelve months of fees, you have not transferred that risk. You are holding it. Price it, reserve for it, or renegotiate it.

Disclosure: the figures above include litigation data compiled by Testudo Global as reported by Gallagher Re, showing cumulative U.S. generative AI lawsuits up 978% from 2021 to 2025 and 137% year on year in 2024 to 2025. That is vendor-published research from a broker and reinsurance intermediary. Gallagher is my employer.

Let's talk about it. If you cannot name which of your lines already carry an approved AI exclusion, that is the Second Ledger conversation to have before your next renewal. Reach me at kenleatherman.com →.

← Back to Insurance Coverage