State regulators have approved more than 80% of the AI exclusion applications carriers have filed since Verisk's ISO CG 40 47 and CG 40 48 endorsements took effect on January 1, 2026, with Florida, Connecticut and Maryland clearing them fastest. Chubb, Travelers, Berkshire Hathaway, AIG, W. R. Berkley and Great American are all in the wave.

The number behind the headline is not the approval rate. It is that ISO forms sit under roughly 82% of US property and casualty policies, so a standard endorsement moves the whole market at once.

Key Takeaways

  • More than 80% of filed AI exclusion applications have been approved, a markedly easier passage than cyber exclusions received in the mid-2010s, when several states asked carriers to justify the coverage reduction actuarially.
  • Three endorsements, three scopes. CG 40 47 removes Coverage A and Coverage B, CG 40 48 removes only Coverage B, and CG 35 08 reaches completed products. All share one generative AI definition.
  • 82% of US P&C policies rest on ISO forms, so the endorsements bifurcate GL books on a schedule set by renewal dates rather than by carrier strategy.
  • 0.5 to 2.0 points of expected loss ratio is the near-term AI loss load estimated for a standard commercial GL policy, which is the size of the pricing difference between an endorsed and an unendorsed policy.
  • 74% of small and midsize businesses already use AI programs, per Munich Re subsidiary HSB, against a coverage position that now excludes the resulting damages on most renewals.

Three Endorsements, One Definition, Different Reach

All three forms run off the same definition of generative artificial intelligence: a machine-based learning system trained on data with the ability to create content or responses, including text, images, audio, video or code. That captures large language models, image generators and code assistants, and leaves traditional predictive scoring outside, a boundary that is getting harder to locate as vendors add generative features to previously predictive tools.

Form Applies To Excludes Preserves
CG 40 47 CGL Coverage Part Coverage A + Coverage B (BI, PD, personal/advertising injury) Nothing AI-related
CG 40 48 CGL Coverage Part Coverage B only (personal/advertising injury) Coverage A (BI, PD)
CG 35 08 Products/Completed Ops Section I (BI, PD from AI in products) Premises/operations exposure

The operative phrase in all three is "arising out of," which coverage law reads broadly. A claim needs a causal connection, not proximate causation, to fall inside the exclusion. That reach is what makes embedded AI the practical problem: generative features now ship activated by default inside enterprise platforms, so an insured can be using generative AI within the meaning of the endorsement without having chosen to.

Carrier language often goes past the ISO wording. W. R. Berkley's Form PC 51380, "Artificial Intelligence Absolute Exclusion," bars any claim based upon, arising out of, or attributable to AI use, deployment or development, whether the model is owned, licensed, third-party or embedded. That covers all AI rather than only the generative subset, across D&O, E&O and fiduciary lines. Great American amended Washington commercial umbrella and excess forms; Berkley filed comparable management liability exclusions in Connecticut. Verisk's own survey found 32% of insurers moderately concerned about generative AI product liability within one to two years and 23% extremely concerned.

What Splits When the Book Splits

The exclusion does not remove AI exposure from the pricing problem. It splits a GL book into two populations that need different expected loss assumptions from the first endorsed renewal onward.

Endorsed policies should carry a lower loss load; unendorsed ones a higher and rising one. The near-term gap is estimated at 0.5 to 2.0 percentage points of expected loss ratio depending on industry and deployment intensity. That is a real number to file, and it has no triangle behind it. Commercial generative AI is roughly three years old, enterprise deployment younger, and the reported claim universe through 2025 is dominated by copyright and intellectual property disputes rather than the bodily injury and advertising injury categories a CGL policy actually covers.

Classification is the second thing that breaks. The current system cannot separate an AI-heavy insured from an AI-light one inside the same NAICS code: a marketing firm generating most of its content with AI tools and one using none rate identically. Until AI adoption intensity becomes a filed rating variable, the endorsement is doing the segmentation work that a relativity should do, and it segments by form rather than by exposure.

Cyber ran this exact sequence. ISO's CG 21 06 and CG 21 07 stripped data liability from CGL in 2014, standalone volume grew to $15.3 billion of global premium by 2024 with $10.6 billion of that in North America, and policies in force rose from about 2.2 million to over 3.6 million between 2016 and 2019. It also repriced painfully from 2020 to 2022 as ransomware overwhelmed the early assumptions. Deloitte's projection of roughly $4.7 billion in annual AI insurance premium by 2032 assumes the growth half of that pattern.

Where the Excluded Exposure Actually Goes

Excluding a peril from a primary form does not retire it. It relocates it, and two of the destinations are not yet priced by anyone.

The first is the excess and umbrella tower. If the primary excludes AI and the excess follows form, the exclusion passes through the whole tower. If the excess does not follow form, it retains AI exposure the primary carrier has shed, at attachment points set when the primary was silent. That follow-form question is not consistently resolved across market wordings, which means some excess layers are now the only place in a program where AI liability sits, without having been rated for it.

The second is accumulation inside the standalone market absorbing the displaced demand. Corgi writes six AI risk categories on its own paper after a $160 million Series B at a $1.3 billion valuation, Armilla writes limits to $25 million behind Lloyd's syndicates, and Testudo's capacity reached $9.25 million per insured. All of them concentrate on a peril whose loss mechanism is correlated by construction: a small number of foundation models sit under thousands of unrelated insureds, so a single defective model update propagates across industries without the shared physical event that traditional casualty accumulation assumes.

Adverse selection runs through both. Buyers who read the endorsement will find coverage elsewhere or retain the risk deliberately. Buyers who do not will discover the change when a claim is denied, and Gartner expects more than 2,000 legal claims linked to AI incidents worldwide by the end of 2026 to start supplying those test cases. The residual population left inside the unendorsed segment of a GL book is therefore not a random sample of it.

Further Reading

Sources