CFC embedded affirmative AI wording across seven policy lines in June 2026, naming hallucination, erroneous output and model drift as explicit perils. Mayflower Specialty and Hadron launched the first dedicated US affirmative AI liability program at $5 million in limits (BusinessWire). Both put named perils on the balance sheet before any claims triangle exists for them.
Key Takeaways
- Seven lines at once for CFC, treating AI as an accelerant inside existing coverage; $5 million standalone for Mayflower and Hadron, with a difference-in-conditions layer that drops down where legacy policies are silent or exclusionary.
- The four named perils have four different tails: 12 to 36 months for hallucination, 24 to 60 for erroneous output, 36 to 84 or longer for content infringement, and an ambiguous trigger date for model drift.
- $5 million against Armilla's $25 million Lloyd's-underwritten limit is the market's stated range of uncertainty about where the loss distribution ends.
- $3.6 billion of insured loss from NotPetya and WannaCry against $8 billion of economic loss is what correlated accumulation looked like the last time it surfaced in books nobody had priced for it.
- 57% of 1,250 companies surveyed named AI errors, misinformation and hallucinations as a key risk, the highest-ranked AI liability concern, which is enterprise awareness running ahead of carrier product.
Four Perils, Four Loss Architectures
CFC covered Technology E&O, Professional Liability, eHealth, Intellectual Property, Management Liability, Media and Cyber Proactive Response in one pass, treating AI as an accelerant of existing risk rather than a new class. "We see value in being explicit about how AI is treated," said Nick Line, Chief Underwriting Officer, in Insurance Journal.
Mayflower and Hadron came at it from the other side: a standalone program across D&O, employment practices liability and E&O, plus a difference-in-conditions and excess layer that drops down where an existing policy is silent, sublimited or exclusionary on AI. That structure names what the endorsement approach leaves open, since most enterprise buyers still hold forms written before AI deployment was widespread.
| Peril | Primary Coverage Home | Frequency Profile | Reporting Tail |
|---|---|---|---|
| Hallucination | Tech E&O, Professional Liability | High raw, low claim frequency | 12 to 36 months |
| Model drift | Cyber, Tech E&O | Low individual, correlated aggregate | Trigger-date ambiguous |
| Content infringement | IP, Media | Moderate; discovery-rule driven | 36 to 84 months or longer |
| Erroneous output | E&O, Professional Liability | Moderate | 24 to 60 months |
The perils behind those wordings do not share a loss shape. Hallucination is frequent in raw terms and rarely insurable; the claims subset concentrates where a user reasonably relied on AI work product, which makes it an E&O claim with a familiar 12-to-36-month reporting window.
Model drift inverts the usual relationship between claim size and portfolio risk. Individual drift is imperceptible, since accuracy declines gradually rather than producing a discrete event. But when a foundation model is retrained, fine-tuned or silently updated, every enterprise on that version changes behaviour at once. At claim level it looks attritional. At portfolio level it behaves like a catastrophe.
Content infringement runs on a discovery-rule clock rather than a first-occurrence clock, so claims can surface long after both the policy period and the generation event, on doctrine still being settled across federal circuits.
Pricing on Proxies, Reserving on Two Clocks
With no experience on the named perils, first-year pricing runs on exposure proxies. Model users and transaction counts do what employee count and revenue did in early cyber, proxying frequency: an enterprise with a hundred internal users carries a different hallucination exposure than a vendor serving five hundred thousand customer-facing API calls a day.
Revenue dependency on AI output is the severity variable. The same model running the same task class produces different severity distributions depending on how the output is used: a compliance team drafting internal risk summaries sits in a different tier from a firm whose associates draft client-facing briefs that reach a court.
Vendor concentration is the accumulation variable, and it is the one cyber actuaries learned to ask about only after events exposed the gap. Which foundation models does the insured run, via API from a single provider exposed to updates without notice or as locally hosted weights under version control, and what contractual protection exists against performance degradation after an update?
Governance is the weakest rating variable available, because there is no AI equivalent of SOC 2 Type II or the multi-factor authentication requirement that anchored cyber underwriting improvements after 2018. The NAIC's 12-state pilot running January through September 2026 is testing whether examiners can assess an AI governance program from outside at all.
The reserving problem is that one contract can carry two clocks. A cyber-adjacent component reports within 30 to 60 days, because the triggering event is discrete and observable. A professional liability component, where an erroneous output drove a downstream decision that failed later, may not surface for 24 to 60 months after the policy year closes. Applying cyber development factors to the E&O half understates IBNR; applying E&O patterns to the cyber half overstates it and ties up capital.
That allocation is often not explicit in the coverage trigger. And in endorsement-based products, where AI sits inside a broader Tech E&O or cyber policy, whether claims handlers code an AI-triggered claim as AI-originated or as generic E&O decides whether the segmentation exists at all. The first cohort is when that data matters most and when it is easiest to lose.
The Book Looks Diversified Because of Where the Correlation Sits
The number behind the urgency is $3.6 billion, the estimated insured loss from NotPetya and WannaCry across affirmative and non-affirmative cyber cover in 2017, against $8 billion of economic loss. Individual claims looked like isolated business interruption. The shock was not that losses occurred but that carriers could not separate what they had priced from what had accumulated without pricing.
AI failure propagates the same way: one shared dependency, one behavioural change, simultaneous triggers across unrelated industries. Three or four providers supply the model weights underlying most enterprise deployments, and capital expenditure by the five largest cloud providers is forecast above $600 billion in 2026 with roughly 75% tied to AI infrastructure. That concentration does not diversify the liability. It correlates it.
Consider a carrier holding two hundred affirmative AI policies across healthcare, financial services and professional services. The industry spread looks like a diversified professional liability book. If seventy percent of those insureds run on a single foundation model architecture, the correlation structure is closer to a catastrophe portfolio, and no amount of industry diversification in the underwriting file changes that.
Munich Re put it directly in its 2026 outlook: as systemic dependencies on shared infrastructure increase, accumulation models for AI cover will need to be rebuilt rather than borrowed from adjacent lines. The cyber market took from the UK Prudential Regulation Authority's 2016 warning to Lloyd's January 2020 mandate to reach that discipline, and it had two events in between to force it. The affirmative AI programs written in 2026 are being priced before the equivalent event, which is the point of them and also the reason the exposure base behind them cannot yet be checked against anything.
Further Reading on actuary.info
- Silent AI Exposure: 90% of Insurer Risk Sits Unpriced - Why affirmative AI coverage still has to solve for thin data and model drift even after the conventional-policy exposure is excluded.
- Model Drift and the Rate Filing Gap - How ML model retraining creates a version-control gap between state-approved and deployed pricing models, with a four-part governance workflow for P&C pricing actuaries.
- Carriers Win 80% State Approval for CGL AI Exclusions - The market-wide CGL exclusion filing wave and the standalone AI liability gap it is accelerating into existence.
- Verisk CG 40 47 Creates an AI Liability Pricing Gap - Form-by-form analysis of the three Verisk endorsements and what each removes from GL coverage for AI-related losses.
- How Actuaries Price AI Liability Coverage When the Loss Triangle Has No Rows - The credibility problem underlying affirmative AI coverage pricing, with the analogical transfer and scenario-loading methods carriers use in place of a loss triangle.
- Cyber and AI Liability Converge Into One Digital Risk Line - How the CGL exclusion cycle is driving a structural merger of cyber, professional indemnity, and AI liability into a single underwriting discipline.
- Cyber Insurance Aggregation Risk and Underwriting - The accumulation modeling challenge in cyber that AI liability will need to solve under even greater uncertainty about correlated loss sources.
Sources
- BusinessWire, “Mayflower and Hadron Launch the First Dedicated Affirmative AI Liability Program in the US Market” (June 2026).
- Insurance Journal, “CFC Embeds Affirmative AI Cover in Product Portfolio” (June 2026).
- Reinsurance News, “CFC Adds Affirmative AI Coverage” (June 2026).
- Munich Re, Cyber Insurance: Risks and Trends 2026 (2026).
- Munich Re, Cyber Insurance: Risks and Trends 2025 (2025).
- Guy Carpenter, “Affirmative vs. Silent Cyber: An Overview” (2020).
- NAIC, Insurance Topics: Artificial Intelligence (2026).
- Quarles, “Nearly Half of States Have Now Adopted NAIC Model Bulletin on Insurers’ Use of AI” (2026).
- Business Insurance, “Mayflower, Hadron Unveil Affirmative AI Liability Program” (June 2026).
- Arxiv / Insurability Frontier, “The Insurability Frontier of AI Risk: Mapping Threats to Affirmative Coverage, Silent Exposures, and Exclusions” (May 2026).
- Risk & Insurance, “Traditional Insurance Leaves Enterprises Exposed as AI Liability Claims Surge” (2026).