Luphra

Join the waitlist

We'll reach out as soon as a spot opens up.

We respect your privacy.

Research

When the Policy Does Not Say AI

Dithered landscape of a river valley with pine trees

If a policy is silent on AI, that silence is not coverage. As autonomous systems start taking actions, traditional insurance lines break in ways that can leave businesses exposed.

The Policy Was Written for a Human Operator

Most commercial insurance policies were not written for a world in which software can perceive a situation, choose a course of action and execute that action through APIs, payments, customer workflows or physical machines. They were written around older categories: a person gives advice, a company ships a product, an employee clicks a link, a database is breached, or a machine physically injures someone.

Autonomous AI systems blur those categories. An AI system may draft a recommendation, trigger a refund, deny a claim, move money, modify software, operate a robot or instruct another system to act. The loss may be financial, physical, reputational, regulatory or contractual. The problem is not only that AI can make mistakes. The problem is that the mistake can become an executed business action before a human reviews it.

Risk frameworks already recognise that AI systems create risks that differ from traditional software. NIST describes AI systems as socio-technical systems whose risks can emerge from technical design, data, deployment context and human behaviour together[1]. The Geneva Association makes the insurance implication more direct: agentic AI can plan, decide and execute with greater self-direction, making causality and liability harder to assign when something goes wrong[2].

This is where the insurance gap begins. A policy can be silent on AI and still appear broad. But silence is not the same as affirmative coverage. If the policy never defines the AI system, the actions it is authorised to take, the losses caused by those actions and the evidence required to prove what happened, the insured may not know whether coverage exists until after a claim.

Silence Is Not Coverage

Many businesses assume that if AI is not excluded, it must be covered. That assumption is dangerous. Traditional policies usually respond to defined perils and defined legal liabilities. They do not automatically insure every loss merely because a business tool caused it.

This uncertainty is sometimes called "silent AI": AI-related claims may sit inside policies that neither expressly include nor expressly exclude AI. Fenwick describes the market as moving away from silent AI coverage as insurers introduce AI-specific exclusions and revised forms across cyber, technology errors and omissions, directors and officers, and employment practices liability insurance[3].

The same issue appears when AI moves from advice into execution. Jones Day notes that AI-related losses may still fall within some traditional insurance programs, but that insurers are increasingly responding with AI-specific exclusions and separate AI-specific products[4]. That means the buyer cannot treat an old policy as a clear answer merely because it does not mention AI.

The result is a patchwork. Cyber may respond to a breach, but not to a bad autonomous business decision. Errors and omissions coverage may respond to professional negligence, but not to every automated output or contractual performance failure. Commercial general liability may respond to bodily injury or tangible property damage, but not to pure economic loss. Crime insurance may respond to deception, but not always where the insured voluntarily authorised the transfer.

Where the Old Lines Break

Commercial general liability is built around bodily injury, property damage and personal or advertising injury. That structure is useful when a person slips in a store or a product physically damages another object. It is less useful when an AI system corrupts data, gives faulty instructions, causes contractual loss or triggers a purely financial mistake. The standard CGL framework has long treated electronic data differently from tangible property. Open legal scholarship on CGL treatment of data loss notes that revised commercial general liability language specified that data is not tangible property for purposes of coverage[5].

Cyber insurance is closer to the problem, but it is still not the same as autonomous AI coverage. Cyber policies are often designed around security events, privacy incidents, network interruption and incident response. An autonomous AI system may create a loss without a security breach at all: it may misprice a transaction, approve the wrong customer, hallucinate professional advice, or modify a workflow in a way that causes downstream economic damage. Verisk has described generative AI as a liability concern that can affect general liability, D&O, professional liability, E&O, employment practices and product liability at the same time[6].

Product and professional liability policies also face a fit problem. AI systems can change after deployment through model updates, fine-tuning, retrieval sources, prompts, connected tools and user context. That makes it harder to prove whether the relevant failure came from the model developer, the company deploying it, a third-party integration, a data source or a user configuration. Verisk has noted that GenAI product liability cases raise unresolved questions about which party may be liable, including the original developer or a company that commercialised or modified the model[7].

In other words, the old lines can each cover part of the risk. But autonomous AI systems can create losses that pass through several lines at once while fitting none of them cleanly.

The Market Is Moving Away From Ambiguity

Insurers are not ignoring the issue. They are trying to remove ambiguity. One response is affirmative coverage: endorsements or standalone policies that state which AI-related losses are insured. The other response is exclusion: wording that removes AI-related losses from traditional policies and forces the buyer to purchase separate protection if it is available.

The exclusion trend is already visible. Verisk announced that its 2025 ISO General Liability multistate filing would give insurers new optional endorsements to address generative AI liability exposures, with a proposed effective date of January 1, 2026[8]. Zelle has also reported examples of broad AI exclusions in professional liability, including wording aimed at claims arising out of the use, deployment or development of artificial intelligence[9]. Fenwick similarly describes a move away from silent AI coverage across cyber, Tech E&O, D&O and EPLI, with coverage narrowing through exclusions, revised forms, definitions and restrictive carve-backs[3].

For companies deploying autonomous AI, the practical conclusion is simple: do not ask only whether the company has cyber, E&O or general liability insurance. Ask whether the policy affirmatively covers the AI system's authorised actions. Good coverage must define the system, permitted use cases, covered losses, excluded behaviour, required human controls, audit logs, incident reporting duties and the allocation of responsibility across vendors, deployers and users.

The Shift to Action-Based Underwriting

As AI systems gain authority, insurance has to move from category-based assumptions to action-based underwriting. The core underwriting question is not only what the AI can say. It is what the AI is allowed to do, which systems it can touch, how quickly its actions can create loss and what evidence exists when the insured needs to prove the claim.

References

  1. [1] Tabassi, E. — Artificial Intelligence Risk Management Framework (AI RMF 1.0), National Institute of Standards and Technology (2023). https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf
  2. [2] Jia, R., Eling, M. & Wang, T. — Gen AI Risks for Businesses: Exploring the Role for Insurance, The Geneva Association (2025). https://www.genevaassociation.org/sites/default/files/2025-10/gen_ai_report_0110.pdf
  3. [3] Lawson, H. & Hopkins, S. — The End of Silent AI? Emerging AI Exclusions, Coverage Fragmentation, and Practical Implications for Policyholders, Fenwick (2026). https://www.fenwick.com/insights/publications/end-silent-ai-emerging-ai-exclusions-coverage-fragmentation-and-practical-implications
  4. [4] Jones Day — A-Eye on Coverage: Maximizing Insurance for AI Risks Amid Emerging Exclusions, Jones Day (2026). https://www.jonesday.com/en/insights/2026/04/aeye-on-coverage-maximizing-insurance-for-ai-risks-amid-emerging-exclusions
  5. [5] Bodden, K. — Tangible Cash for an Intangible Loss? Insurance Coverage for Damage or Loss of Third-Party Data, Washington Journal of Law, Technology & Arts (2005). https://digitalcommons.law.uw.edu/wjlta/vol1/iss2/2
  6. [6] Scoblete, G. & Bragg, E. — Generative AI In Focus, Part I: Is Generative AI Generating Liability Risks?, Verisk (2023). https://core.verisk.com/Insights/Emerging-Issues/Articles/2023/June/Week-3/potential-liability-risks-of-generative-ai
  7. [7] Scoblete, G. & Acevedo, M. — GenAI Product Liability Cases Are Making Their Way Through the Courts. Here's What We're Watching, Verisk (2025). https://core.verisk.com/Insights/Emerging-Issues/Articles/2025/May/Week-4/GenAI-Product-Liability-Cases
  8. [8] Cook, S. & Scoblete, G. — From Risk to Endorsement: Four Key Emerging Risks Shaping the Latest ISO General Liability Multistate Filing, Verisk (2025). https://core.verisk.com/Insights/Emerging-Issues/Articles/2025/July/Week-4/Emerging-Risks-in-ISO-General-Liability-Multistate-Filing
  9. [9] Gibbs, J. — AI Update: The Growing Trend of AI-Related Insurance Policy Exclusions, JDSupra (2025). https://www.jdsupra.com/legalnews/ai-update-the-growing-trend-of-ai-3672112/