More than 90% of insurer AI agent exposure sits silently inside general liability, D&O, technology errors and omissions, and cyber policies, unpriced, according to a July 2026 study from the AI Underwriting Company co-authored with Anthropic and OpenAI researchers (AIUC, July 2026).

Enterprise frontier AI spending grew over 300% in 2025 alone. The exposure the figure describes is already written and already earning, which makes it a reserving question before it is a pricing one.

Key Takeaways

  • Over 90% of AI agent exposure sat in silent cover as of March 2026, meaning risks neither expressly included nor excluded, concentrated in cyber, D&O, commercial general liability and technology E&O.
  • More than 80% of enterprise AI deployments run on three foundation model providers, so one model version or shared vulnerability can trigger claims across four coverage parts on the same date.
  • Nearly 50% of Lloyd's underwriters believe policyholders have adequate AI risk management, against 20% of businesses reporting mature governance for autonomous agents.
  • Over 80% of state filings for Verisk's generative AI CGL exclusion were approved by spring 2026, but the form defines AI by content generation, not autonomous action.
  • A $25 million deepfake fraud loss at Arup and a $110 million-plus claim against Google both landed on lines priced for a pre-agentic world, coded as ordinary fraud and defamation.

What the 90% Figure Actually Counts

"Underwriting the Agent Economy" is not a vendor white paper. Its author list includes Anthropic's Matthew Botvinick and OpenAI's Adrien Ecoffet alongside insurers, brokers and university researchers, which gives the figure a provenance trade estimates of AI exposure have generally lacked.

The claim is specific: over 90% of insurers' AI agent exposure sat in silent cover as of March 2026, concentrated in four conventional liability lines (Insurance Business, July 2026).

The generative-versus-agentic distinction is what makes the number bite in 2026 rather than 2023. A chatbot that hallucinates produces a claim theory built on defamation, negligent misrepresentation or professional advice, claim types underwriters recognize and have begun excluding. An agent that operates software, moves funds or executes a transaction without a human confirming each step produces a different theory: unauthorized transaction, breach of fiduciary duty, wrongful termination, professional negligence tied to an action rather than a statement.

Two cited losses make that concrete. Engineering firm Arup lost $25 million to a 2024 deepfake video-call fraud, and Wolf River Electric is seeking more than $110 million from Google over claims tied to its AI Overviews feature. "Businesses cannot adopt AI unless they know the risk has been quantified and managed," said AIUC co-founder Rajiv Dattani (PYMNTS, July 2026). Neither loss needed an AI-specific policy to trigger.

A Correlation Structure Per-Line PML Was Not Built to See

Probable maximum loss modeling for commercial casualty is built line by line, with judgmental correlation layered on top to size clash across a tower. That architecture assumes each line's loss-generating events are largely independent. A products claim against a manufacturer does not usually share a root cause with a disclosure suit at an unrelated company.

Agentic AI breaks the independence assumption at the root. More than 80% of enterprise deployments run on three foundation model providers, so a single model version, a shared prompt-injection vulnerability or a systemic hallucination pattern is not confined to one insured or one line. A defective update could produce a professional-services claim under GL, a board-oversight suit under D&O once it becomes public, a technology E&O claim from the vendor's customers and a data-handling claim under cyber, from one root cause on one date. That is closer to a catastrophe peril than to the independent liability losses per-line PML sizes.

The confidence gap compounds it. Nearly 50% of Lloyd's underwriters believe their policyholders have adequate AI risk management, against 20% of businesses reporting mature governance for autonomous agents. Pricing on the assumption that governance is more mature than it is underprices the tail rather than the mean, because control quality determines how far a correlated event propagates.

The reserving consequence arrives first, because the exposure is already earned. A GL, D&O, tech E&O or cyber policy written in 2024 or 2025 was priced against triangles containing no AI claim code, since silent coverage means the claim gets coded as ordinary bodily injury, professional negligence or wrongful act. Arup and Wolf River sit in those triangles as a fraud loss and a defamation-adjacent dispute. A supplemental scenario-based IBNR loading, the tool built for latent mass tort and for silent cyber before affirmative wording existed, is the defensible response to a 300% spending growth rate the triangle cannot yet see.

The Exclusion Moves the Exposure Rather Than Removing It

Verisk's ISO Core Lines Services made forms CG 40 47, CG 40 48 and CG 35 08 available effective January 1, 2026, letting carriers exclude generative AI from commercial general liability and products/completed operations. Regulators approved more than 80% of the filings carriers submitted by spring (IndependentAgent.com). That adoption rate is the market conceding the AIUC finding is directionally right.

The definition is where the finding reasserts itself. CG 40 47 and its siblings define generative AI by the "ability to create content or responses, including text, images, audio, video or code." That targets output, not autonomous action. An agent that files a claim, executes a wire transfer or approves an underwriting decision without generating content a court would treat as the proximate cause sits in a gap the form was not drafted to close. Verisk is reportedly exploring a distinct agentic exclusion for that reason (The Insurer, July 2026).

Coverage lineSilent AI exposure todayEffect of the 2026 generative AI exclusion
Commercial general liabilityContent-generation and agentic-action claims both sit unrated inside Coverage A/BRemoves content-generation claims; agentic-action claims persist absent a distinct agentic form
Directors and officersBoard-oversight and disclosure failure suits tied to AI governance gapsNo standard ISO exclusion yet filed; carriers proposing proprietary "absolute AI" wording
Technology E&OProfessional-negligence claims from AI-driven service failuresMost exposed near-term line per carrier surveys; some carriers declining AI-output liability outright
CyberData breach, fraud, and unauthorized-transaction claims from compromised or manipulated agentsLargely unchanged; still the line most likely to respond to AI-enabled fraud

An exclusion only closes a gap for the insured who buys replacement cover, and the affirmative market is pricing against the thin-data problem cyber faced a decade ago, examined in AI liability pricing when the triangle has no rows. It also carries a complication cyber did not: a vendor can update the model mid-term, shifting the frequency and severity distribution the policy was priced against without touching the wording, covered in affirmative AI coverage and model drift.

So the repricing gap does not close at the exclusion filing rate. An insured who cannot find affordable standalone cover is uninsured rather than silently covered, which is where coverage litigation concentrates, over whether "arising out of" generative AI reaches an agentic action. Fenwick's June 2026 review found coverage fragmenting across cyber, tech E&O and D&O, with exclusions sometimes stacking to leave gaps no single policy was designed to catch.

Further Reading