Worried About AI Risk? Double-Check Your GL Policies
There’s a lot of noise right now about AI liability. Insurers are calling it a massive unpriced risk. New products are being pitched. Exclusions are being drafted. If you spend any time in this industry, the whole scene feels familiar.
It should. We did this with cyber.
About 10 years ago, as cyber became more than just a data breach problem, the industry went through the same exercise: What can this peril actually cause? Where does it fall in existing policies? Who’s exposed and doesn’t know it? The answers took years to sort out, and frankly, we’re still sorting some of them.
In 2017, NotPetya hit. Maersk, Merck, Mondelez. Companies that hadn’t bought cyber tried to collect on their property policies because coverage was silent, and carriers pushed back. That’s when property underwriters started filing cyber exclusions. An exclusion to prop up a new product line. Buyers were furious. But the market had spoken.
AI is on the same track. We’re just earlier in the film.
The good news, if you’re an organization trying to figure out where you stand right now: most AI-related losses are already covered.
E&O and professional liability policies have no AI exclusions. Same with cyber and D&O.
GL is a different story. Some general liability carriers have started filing AI exclusions with state regulators, mostly because they don’t understand the exposure and exclusion is easier than underwriting something new. That’s the line worth watching, especially for any organization where AI could touch a physical outcome: autonomous equipment, AI-assisted medical decisions, that kind of thing.
So where are the actual gaps?
Two places. AI performance risk is mostly uninsured. If you pay for an AI tool that doesn’t do what it promised, or produces outputs that cause real business harm, you’re largely on your own today. The second gap is affirmative cover. Some clients want to see AI on the policy explicitly, not just implied by the absence of an exclusion. That market is early and thin.
A few products are starting to appear. Munich Re has the most developed standalone AI policy. More recently, CFC announced its adding explicit AI language across seven of its core policy lines, including tech E&O, professional liability and cyber.
But demand hasn’t caught up yet, because the losses haven’t materialized at scale. But CFC’s move suggests carriers aren’t waiting or the triggering event.
Working with Axio, whose modeling engine continuously tracks emerging AI loss events, we identified four categories of AI-related losses that organizations should understand before evaluating their coverage
The first two, malicious external attacks and malicious insider threats, are essentially cyber events that happen to use AI as the weapon or access point. Prompt injection, ransomware through an exposed AI repo, an employee using AI to rapidly exfiltrate data they shouldn’t have. We know how to model these. We know what they cost.
Non-malicious insider events are ones where no one meant to cause harm. An employee pastes proprietary data into a public AI tool without realizing it’s being retained for training. A platform engineer rolls out a new object-storage container for meeting recordings and AI-generated transcripts but leaves an overly permissive access token in an internal wiki. A scraper finds it. Suddenly a financial services firm is looking at GLBA notifications, potential FINRA inquiries, client remediation offers, and a reputational problem with exactly the kind of high-net-worth clients who are most sensitive to confidentiality lapses.
No malicious intent. Significant loss.
Non-malicious external events are the frontier: autonomous agents that lose context and execute actions they weren’t supposed to, AI systems that do something technically correct but operationally catastrophic. The precedents are thin, but they’re building.
What makes this modeling valuable isn’t just knowing the categories exist. It’s the prioritization it enables. A CISO fielding four AI adoption requests in a single day can’t spend equal time on all of them. The one whose use case, if it goes wrong, lands in the non-malicious bucket with a seven-figure tail — that’s the one to focus on. The others are manageable. That distinction is almost impossible to make without actually modeling the exposure.
So what can you do now? Start with exposure identification. Based on how you’re using AI right now, if something goes wrong, what does that loss look like? Where does it fall? What does it cost? An AI tool that gives bad HR recommendations is a very different loss than an autonomous system that causes physical harm. You need to know your scenarios before you can evaluate your coverage.
Then map those scenarios against your existing portfolio. E&O, cyber, D&O, GL. Find where you’re covered, where you’re silent, and where you’re genuinely exposed.
Once you’ve done that work, you can have a real conversation with your broker and carriers. The clarity that comes from actual modeling does two things at once: it tells you what coverage you actually need, and it builds the business case for buying it.
Organizations that show up with a clear exposure map and documented controls spend a lot less time convincing underwriters. Carriers respond to clients who understand their risk. That’s always been true.
The exclusions are coming. A big, visible AI loss will hit an organization that isn’t adequately covered and tries to collect everywhere it can. That’s when underwriters move. It’s how it worked in 2017, and the pattern hasn’t changed.
Scott Kannry, co-founder and CEO of Axio, contributed to this article.

