AI Agent Liability Insurance Quietly Disappeared From Standard Policies in 2026
New ISO exclusion endorsements, three real incidents, and an EU directive rewired who pays when an agent gets it wrong.
Most companies that put an AI agent into production this year treated it as an engineering decision: pick a model, scope its tool access, ship it, watch the logs. Almost none of them treated it as an insurance decision. That gap closed faster than most budgets accounted for.
Between January and April 2026, five of the largest US commercial insurers W.R. Berkley, Chubb, Travelers, Berkshire Hathaway, and Cincinnati Financial filed new general liability wording built specifically for AI agent liability insurance. The wording came from Verisk, the industry's dominant policy-language provider, and it does something simple: it takes AI-agent losses out of the policy by default. If a company wants that cover back, it now has to ask for it, in writing, on separate terms. Understanding what changed, and what it means for a team running agents today, takes about eight minutes, not a law degree.
The quiet rewrite: how AI agent liability insurance changed in January 2026
Verisk's January 2026 endorsement set standardises the exclusion across three forms, according to the coverage framework published by agentinsured.eu: CG 40 47 excludes generative-AI losses across both Coverage A (bodily injury and property damage) and Coverage B (personal and advertising injury), CG 40 48 narrows the same exclusion to Coverage B only, and CG 35 08 is a companion form insurers attach for broader AI exposures. By April, the five carriers named above had filed to adopt either the ISO language or their own equivalent proprietary wording.
The reason this matters is what it replaces. Reporting from Insurance Business magazine found that more than 90 percent of insurers' AI agent exposure had been sitting inside conventional policies never written with the technology in mind, a pattern the industry calls silent AI cover: risk the insurer was carrying without pricing it, because nobody had written a clause that named it. One in five insurance professionals surveyed said a client had already suffered a loss tied to AI. The 2026 endorsements are the industry's attempt to stop carrying that risk for free.
Three incidents underwriters keep citing
Ask an underwriter why the market moved this fast and three cases come up on repeat, each a different flavour of loss.
Arup, the British engineering firm, lost roughly $25 million in 2024 after an employee at its Hong Kong office was fooled by a deepfaked video call impersonating the company's chief financial officer and authorised a series of transfers. No AI agent executed the fraud directly, but the incident is the reference case underwriters use for AI-enabled internal fraud, the loss vector that sits under crime and cyber policies.
Air Canada gave a different lesson. A grieving customer asked the airline's website chatbot about bereavement fares, and the bot invented a discount policy that didn't exist. A Canadian tribunal ordered the airline to honour it anyway, rejecting the airline's argument that the chatbot was a separate legal entity responsible for its own words. The ruling is now the standard citation for why a customer-facing agent's output is treated as the company's own statement, not a disclaimer away from it.
Wolf River Electric, a solar installer, sued Google for more than $110 million, alleging that its AI Overviews search feature generated false claims about the company that cost it business. The case is still working through the courts, but underwriters cite it as the clearest example of third-party harm from AI-generated content, a loss vector nobody wrote a clause for because it doesn't require the company to have deployed the AI at all.
Three incidents, three different policy lines: crime and cyber for the fraud, general liability and professional indemnity for the chatbot's own statements, and media or technology errors-and-omissions for harm caused by someone else's AI output about you. That spread is the actual problem with the 2026 exclusions.
Why a general liability exclusion alone doesn't settle it
The clean way to think about it, from the same coverage framework, is three policy lines answering three different questions. Professional indemnity and errors-and-omissions cover pure economic loss from bad advice or a professional mistake. Cyber covers data breach, network interruption, and security failure. General liability responds to bodily injury and property damage. A single AI agent incident, say, an agent that both leaks customer data and gives a customer bad financial advice, can trigger two or three of these at once, and insurers then argue over who pays what share.
The 2026 exclusions were written onto general liability forms specifically. They do not automatically amend a separate cyber policy, a separate professional indemnity policy, or a directors-and-officers policy. Each of those lines carries its own, insurer-specific AI wording, and that wording varies a lot between carriers. A company that reads its general liability exclusion and assumes the rest of its insurance stack treats AI the same way is guessing, not checking.
“An agent with write access to your CRM and your bank feed is not one risk sitting behind one API key. It is three risks, fraud, data exposure, and reputational harm, each landing on a different policy and judged by a different underwriter.”
The EU adds a second front
The exclusions above are a US commercial-insurance story, but a separate EU rule raises the stakes on the same question. The revised Product Liability Directive, 2024/2853, takes effect on 9 December 2026 and, for the first time, treats software and AI components as products under strict liability. Under the directive, failing to supply a security update for a deployed AI system can itself count as a defect, which is a much lower bar for a claimant to clear than proving negligence.
For a company selling an AI-agent-enabled product or service into the EU, that means the same agent behaviour a US general liability exclusion already treats warily now sits under a second, stricter liability regime on the other side of the Atlantic. Anyone expanding into Europe with agent-based features should read the directive before an incident, not after one.
What the research says is actually excluded
A recent academic mapping of the market, “The Insurability Frontier of AI Risk”, checked 55 distinct AI threat classes against 26 insurance products and sorted the results into four tiers: perils that are affirmatively insured with explicit wording, silent-AI exposures that legacy policies cover by accident, perils carriers actively exclude, and a fourth category the paper calls perils outside private insurance entirely, chiefly the risk that a single foundation-model failure could produce correlated losses across many insureds at once, a systemic-risk problem the industry doesn't yet have a market structure for.
The same research found that carriers do not agree on what an AI agent actually threatens. Munich Re's public positioning emphasises model-performance risk, while Coalition emphasises deepfake and cyber-response coverage. Two insurers can both offer something called AI cover and mean substantially different things by it, which makes the specific wording of a policy more important than the presence of the phrase “AI” in its table of contents.
| Policy line | Built to cover | 2026 status for AI agents |
|---|---|---|
| General liability | Bodily injury, property damage, advertising injury | Excluded by default under CG 40 47 / 40 48 at most major US carriers |
| Cyber | Data breach, network interruption, security failure | Separate, insurer-specific AI wording; not standardised |
| E&O / professional indemnity | Economic loss from professional error or bad advice | Varies by carrier; often the line that actually pays for a bad agent decision |
| D&O | Claims against directors and officers for mismanagement | Increasingly carved out where AI governance failures are alleged |
Buying the cover back: governance as underwriting evidence
The exclusions are not the end of the story. Insurers that decline to cover AI agents by default are, in the same breath, building products that will cover them for a price, provided the buyer can show its agents are actually governed rather than just deployed.
Three frameworks keep showing up as the evidence underwriters ask for: ISO/IEC 42001:2023, a certifiable AI management system standard; the NIST AI Risk Management Framework 1.0; and AIUC-1, an agent-specific standard developed with Orrick, Stanford, the Cloud Security Alliance, and MITRE that scores an agent across six dimensions: data and privacy, safety, security, reliability, accountability, and societal impact. AIUC-1 updates on a fixed quarterly cadence, 15 January, April, July, and October, which is a faster refresh cycle than SOC 2 or ISO 42001 typically see.
The clearest working example is ElevenLabs, which went live in February 2026 with what its insurer describes as the first AIUC-1-backed policy covering AI voice agents, with the audit score feeding directly into the premium. It is a small example so far, one company, one carrier, but it is the first sign of underwriters pricing AI-agent risk off actual audited controls instead of declining to write the risk at all.
A short checklist before your next renewal
None of this requires a new department. It requires five specific questions, asked in order, before the next renewal date rather than after a claim.
- Ask your broker whether general liability, cyber, E&O, and D&O each carry AI exclusion or sublimit language, and get the wording in writing rather than a verbal summary.
- Inventory what each agent can actually do. Read-only access to a support queue and write access to a bank feed or a contract template carry entirely different loss profiles, and a single blanket answer usually means nobody has separated them.
- Decide, deliberately, whether you need affirmative AI cover as a distinct product rather than continuing to rely on silent coverage that the 2026 endorsements are actively closing off.
- If you sell into the EU, read the Product Liability Directive's software and AI provisions before an incident forces you to read them during one.
- Check whether a recognised governance framework, ISO 42001, the NIST AI RMF, or an agent-specific standard, would move a given policy line from excluded to priced, and what evidence the underwriter would actually want to see.
What this changes about deploying agents
None of this is an argument against running AI agents. It is an argument for treating the insurance conversation as a normal part of deploying one, the same way a security review or a data-processing agreement already is.
The pattern has a precedent. Cyber risk spent roughly a decade sitting silently inside property and crime policies before insurers split it out into its own line with its own underwriting questions. The AI-agent version of that split is happening in under two years, not ten, because the loss events, Arup, Air Canada, Wolf River Electric, arrived close enough together that carriers didn't have the luxury of a slow transition.
For a team running agents today, the practical shift is who owns the question. It used to belong entirely to engineering: what can the agent do, and did we test it. It now belongs to finance and legal in equal measure: what happens, financially, when the agent does the thing it was tested against, and who is on the hook for it. Most teams haven't had that second conversation yet. The 2026 renewal cycle is forcing it.
Frequently asked questions
Related reading
Multi-agent LLM systems keep failing in production. A Berkeley taxonomy shows it is rarely the model.
A 2025 UC Berkeley taxonomy of multi-agent LLM failures found 14 distinct failure modes across three categories, and none of them is about model quality.
GitLost and Clinejection both got blamed on prompt injection. The real gap was AI agent permissions.
GitLost and Clinejection got framed as prompt-injection bugs. Both actually trace back to agents holding standing permissions unrelated to the task at hand, and a checklist for closing that gap.
Context compaction is now a platform feature. Deciding what survives it still isn’t.
Automatic context compaction is now a platform feature across every major model provider. It solves the token-budget problem completely, and the state-loss problem only if someone configures it well.