The renewal notice that arrived at a fifty-person marketing agency in April 2026 looked like every other renewal notice they had ever received. Same carrier. Similar premium. Same coverage limits. The owner signed it, sent it back, and moved on. Six weeks later the agency's website chatbot, which had been running for two years without incident, told a prospective customer that a package priced at nine thousand dollars was included in a promotion for twenty-nine hundred. The customer accepted, sent a purchase order, and expected the discount. When the agency told him the chatbot was wrong, he sued. When the agency told its carrier, the carrier pointed to a two-line endorsement in the renewed policy that had not been there the year before. The claim was denied. The endorsement number was CG 40 47 01 26.
This is a story that is going to happen a lot of times in the next twelve months, and it is going to happen to businesses whose exposure to artificial intelligence they would not have described as exposure at all.
What actually changed on January 1, 2026
Verisk's Insurance Services Office, which drafts the standardized policy language that underpins most commercial general liability policies in the United States, released three endorsement forms with a January 1, 2026 effective date. CG 40 47 and CG 40 48 exclude coverage for bodily injury, property damage, and personal and advertising injury arising out of generative AI. CG 35 08 does the same for a narrower slice of coverage. All three define generative AI in essentially the same way: a machine-based learning system or model trained on data with the ability to create content or responses, including text, images, audio, video, or code.
That definition is wider than most business owners realize when they think about their own AI use. A customer-facing chatbot is generative AI. An AI drafting tool for marketing copy is generative AI. A coding assistant that shipped a bug into a product your business sold is generative AI. An AI grammar checker running inside the email tool your assistant uses is arguably generative AI. The phrase doing the most work in the exclusions is not “generative artificial intelligence.” It is “arising out of.” Under established insurance law, “arising out of” requires only a causal connection, not direct causation. A claim that would not have happened but for something a chatbot said arises out of that chatbot. The exclusion is not written for AI as your product. It is written for AI as anything you touched on the way to the injury.
ISO forms are not law. They are the standardized language that carriers file with state insurance departments and then use on the vast majority of their policies. When ISO ships new exclusion forms, they do not stay theoretical. They start showing up at renewal, usually without a phone call, sometimes without a highlighted line in the renewal letter. More than eighty percent of exclusion requests filed by major carriers in 2025 and 2026 were approved by state regulators.
The exposure this created is not hypothetical either. A Hartford Steam Boiler survey of small and mid-sized businesses in early 2026 found that seventy-four percent were already using AI tools of some kind, and ninety-one percent planned to. That is the population now walking around under exclusions they did not know were added. The moment a claim hits, they will find out.
The Air Canada rule the exclusions were written around
The reason your carrier cares about a chatbot on your website is a Canadian tribunal decision from 2024. Jake Moffatt, a British Columbia customer, asked Air Canada's website chatbot whether he could apply for a bereavement discount on a ticket after the fact. The chatbot said yes. Air Canada's actual policy, on a page the chatbot helpfully linked to, said no. Moffatt bought the ticket, applied for the refund, and was denied. He sued in the Civil Resolution Tribunal for about six hundred fifty dollars in Canadian dollars.
Air Canada's defense is the reason every insurance underwriter now reads about the case in training. The airline argued that the chatbot was a separate legal entity responsible for its own actions. The tribunal member called that a remarkable submission, held the airline responsible for everything on its website whether it came from a static page or a chatbot, and awarded the damages. The dollar amount is trivial. The rule is not. You own what your AI says. That principle is now the working assumption at every carrier writing commercial general liability, and the ISO exclusions are the direct response.
The theories of liability that flow from the Moffatt rule include negligence, agency, contract and warranty, product liability, discrimination, deception, privacy, and professional liability. The insurance exclusions do not distinguish among them. If the claim arises out of a generative AI system, the exclusion applies whether the underlying theory is that the AI defamed someone, that the AI made a promise the business now has to honor, or that the AI got the pricing wrong.
The two paths back to coverage
The good news is that the insurance market did not stop covering AI. It stopped covering it silently. The old regime, which insurance lawyers called “silent AI” coverage, was accidental — the policy did not mention AI one way or the other, so claims fell into standard categories by default. The new regime is explicit both ways. If your policy has the ISO exclusions, AI claims are out. If you buy affirmative AI coverage, they are in. There are two ways to get back in.
Path one: a standalone AI liability product. On March 18, 2026, Hartford Steam Boiler, a Munich Re subsidiary, launched the first widely available AI liability insurance product built specifically for small and mid-sized businesses. It covers third-party claims from a business's use of AI tools: bodily injury, property damage, and personal and advertising injury from AI-generated content. Coverage typically addresses AI hallucination-driven errors, IP infringement and defamation from AI output, unauthorized disclosure of confidential data, and where relevant, bodily injury or property damage tied to reliance on AI-generated guidance. Coverage limits are not publicly disclosed at launch; they depend on the partner carrier program. Other carriers are expected to follow with comparable products through 2026, and insurtech brokers like Vouch, Embroker, Counterpart, and Coalition are already packaging tech E&O, cyber, and D&O for AI-adjacent risk with AI-specific enhancements.
Path two: an affirmative endorsement on your existing policy. Rather than buying a separate policy, you negotiate coverage back in through an endorsement. This is usually cheaper than a standalone policy for a business whose AI use is incidental — a chatbot, an AI grammar checker, AI features embedded in software the business uses. It is usually not enough for a business whose AI use is central — a business that sells AI-powered services, or that has replaced substantial human judgment with automated systems. The right answer depends on which side of that line you are on.
The four questions to ask your broker
Whether you go standalone or endorsement, the same four questions decide whether you are actually covered.
One: is my current CGL policy carrying CG 40 47, CG 40 48, or CG 35 08? These are the ISO exclusion forms. If any of them appears in the endorsement schedule, you are excluded from AI-related claims under the base policy. If your broker cannot answer this in five minutes, that is itself an answer.
Two: does the exclusion apply to AI as my product, AI as a tool I use, or both? The exclusion language is broad, but the practical scope depends on how the carrier applies it. Some carriers will treat a chatbot on your website as a covered risk with proper endorsement; others will not.
Three: what is the definition of generative AI in my policy? The ISO definition covers a lot of ground. Some carriers use narrower definitions. Some use broader ones. A one-word change in the definition can shift millions in exposure.
Four: if I bought affirmative coverage, what triggers it? Affirmative AI coverage should respond to a defined incident, not require you to prove that AI was the proximate cause of the injury. Ask for the trigger language and read it before you sign.
What to check today
Pull your current commercial general liability declarations page and the endorsement schedule. If any endorsement number begins with CG 40 or CG 35 and includes 47, 48, or 08, you have the exclusion. Then pull your errors and omissions policy and check for parallel exclusions — carriers are adding them there too, and E&O is often where the real exposure lives for a professional services business.
If your business does anything that would recognizably fall under the definition of using AI — a website chatbot, AI-generated marketing copy, an automated pricing tool, an AI scheduler, or AI features inside a product you sell — you have three options. Buy affirmative coverage now, before a claim. Change your AI practices so the exposure is small enough to accept uninsured. Or accept the exposure knowingly and reserve the funds. Doing nothing is not one of the options. Doing nothing means finding out at the claim.
Frequently Asked Questions
Does an AI grammar checker trigger the exclusion?
The ISO definition of generative AI is wide enough that it probably does. Whether the carrier will actually deny a claim on that basis depends on the specific facts of the claim and the carrier's own posture. The risk is real enough that you should not rely on the incidental nature of the use to keep you covered.
What if the AI is inside software I already use?
The same answer applies. If a claim arises out of AI-generated output, it does not matter whether the AI is your product, your tool, or a feature of your accounting software. The exclusion attaches to the causal connection, not the ownership of the AI.
Does E&O cover what CGL now excludes?
Not necessarily. Carriers are adding AI exclusions to E&O policies too, on parallel timing. Check both.
How do I know if my current policy has an AI exclusion?
Look at the endorsement schedule for CG 40 47, CG 40 48, or CG 35 08, all with the 01 26 form date. If they are there, the exclusion is there.
Does the Hartford Steam Boiler coverage extend to AI tools I use vs. AI tools I sell?
The product is written primarily for third-party liability from AI use, not for AI-as-your-product exposure. A business that sells AI-powered services should ask about tech E&O with AI-specific enhancements, not the standard SMB liability product.
For ongoing tracking
For every change to insurance forms, carrier positions, and regulatory guidance on AI liability since this article went to press, see silvertonpublishing.com/ai-current.
This article reflects insurance market conditions as of September 2026. Insurance forms and carrier practices are shifting rapidly in this area. Confirm any specific coverage question with your broker and the current policy language before relying on this information. Nothing in this article is legal or insurance advice for your specific situation.
This article is for educational purposes only and does not constitute legal, tax, or financial advice. Consult a qualified professional for guidance specific to your situation.