More than 90% of insurer AI exposure sits silently inside general liability, D&O, technology errors and omissions, and cyber policies, unpriced and largely unnoticed, according to a July 2026 study from the AI Underwriting Company (AIUC) co-authored with Anthropic and OpenAI researchers. Enterprise frontier AI spending grew over 300% in 2025 alone (AIUC, July 2026).

90%+
Share of insurer AI agent exposure sitting in silent, unpriced coverage as of March 2026 (AIUC, July 2026)
$100B
Direct-loss scenario from a systemic AI catastrophe modeled in the AIUC report (AIUC, July 2026)
80%+
Share of state filings approved for Verisk's generative AI CGL exclusion by spring 2026 (IndependentAgent, PYMNTS, 2026)

A Study Puts a Number on Risk Carriers Already Wrote

"Underwriting the Agent Economy," the AIUC report published in mid-July 2026, is not a vendor white paper. Its author list includes Anthropic's Matthew Botvinick and OpenAI's Adrien Ecoffet alongside insurers, brokers, and university researchers, giving the 90% figure a provenance that trade press has not typically attached to AI-exposure estimates (AIUC, July 2026). The report's central claim is specific: over 90% of insurers' AI agent exposure sat in "silent" cover as of March 2026, meaning risks neither expressly included nor excluded, concentrated in cyber, D&O, commercial general liability, and technology errors and omissions policies (AIUC, July 2026; Insurance Business, July 2026).

The distinction the report draws between generative and agentic AI is the mechanism that makes the number matter now rather than in 2023. A chatbot that hallucinates a fact generates a claim theory built on defamation, negligent misrepresentation, or professional advice liability, claim types underwriters already understand and have started excluding. An agent that operates software, moves funds, or executes a transaction without a human confirming each step produces a different theory: unauthorized transaction, breach of fiduciary duty, wrongful termination, or professional negligence tied to an action rather than a statement (AIUC, July 2026). "Businesses cannot adopt AI unless they know the risk has been quantified and managed," AIUC co-founder Rajiv Dattani said of the finding (PYMNTS, July 2026). Two case examples the report cites make the theory concrete: engineering firm Arup lost $25 million to a 2024 deepfake video-call fraud, and Wolf River Electric is seeking more than $110 million from Google over claims tied to its AI Overviews feature (Insurance Business, July 2026). Neither loss required an AI-specific policy to trigger a claim; both landed on lines carriers had already priced for a pre-agentic world.

Why the Exposure Correlates Across Lines in Ways Per-Line PML Never Assumed

Probable maximum loss modeling for commercial casualty books is built line by line. A GL actuary sizes accumulation within GL, a D&O actuary sizes it within D&O, and a cyber actuary sizes it within cyber, with modest, often judgmental correlation assumptions layered on top to size clash exposure across a tower. That architecture assumes each line's loss-generating events are largely independent of the others. A products-liability claim against a manufacturer does not usually share a root cause with a director's disclosure lawsuit at an unrelated company.

Agentic AI breaks that independence assumption at the root. More than 80% of enterprise AI deployments run on just three foundation model providers, per the AIUC report, meaning a single model version, a shared prompt-injection vulnerability, or a systemic hallucination pattern is not a risk confined to one insured or one line (AIUC, July 2026). A defective update to a widely deployed agent could simultaneously generate a products or professional-services claim under GL, a board-oversight failure suit under D&O once the defect becomes public, a technology E&O claim from the vendor's own customers, and a data-handling claim under cyber, all from the same root cause on the same date. That is a correlation structure closer to a catastrophe peril, a single shared hazard propagating across many insureds and many lines at once, than to the largely independent liability losses per-line PML methodology was built to size.

The confidence gap the AIUC report measures compounds the problem. Nearly 50% of Lloyd's underwriters believe their policyholders have adequate AI risk management in place, while only 20% of businesses report having mature governance models for autonomous agents (AIUC, July 2026). A market pricing risk on the assumption that governance is more mature than it is will underprice the tail, not just the expected loss, because the gap between assumed and actual control quality is precisely what determines how far a correlated AI event propagates once it starts.

Reserving for Exposure Already Sitting on the Book

The AIUC finding lands as a reserving problem before it lands as a pricing problem, because most of the exposure it describes is already earned or in force. A GL, D&O, tech E&O, or cyber policy written in 2024 or 2025 was priced against loss development triangles that contain no AI-specific claim code, because silent coverage means the claim, when it happens, gets coded under ordinary bodily injury, professional negligence, or wrongful-act causation, not flagged as AI-related. That is a materially different reserving problem than waiting for a new exclusion to attach at the next renewal. An exclusion filed for January 1, 2026 business does nothing for the unearned premium and open claims on policies already on the books, and it does nothing for claims that will emerge over the next several years of development on business written before any exclusion existed.

The Arup and Wolf River Electric losses are useful here precisely because they are not filed as "AI claims" in any bordereau. They are a fraud loss and a defamation-adjacent tech dispute that happen to have an AI-agent root cause, sitting inside loss triangles an actuary would otherwise treat as ordinary experience (Insurance Business, July 2026). A reserving actuary relying on triangle-based development to project ultimate losses on these lines is implicitly assuming the historical mix of causation holds going forward. If agentic AI adoption is accelerating enterprise-wide, and AIUC's 300%-plus growth figure in frontier AI spending during 2025 suggests it is, that assumption is the one most likely to fail first (AIUC, July 2026). The same supplemental, scenario-based IBNR loading actuaries built for latent mass-tort exposures and, more recently, for silent cyber before affirmative cyber wording existed, is the more defensible tool here: a judgmental addition to the indicated reserve that acknowledges a trend the triangle cannot yet see, reviewed and adjusted as actual AI-coded experience accumulates.

An Exclusion Narrows the Exposure, It Does Not Remove It

Verisk's ISO Core Lines Services made three endorsement forms available effective January 1, 2026, CG 40 47, CG 40 48, and CG 35 08, letting carriers exclude generative AI from commercial general liability and products/completed operations coverage. By spring 2026, state regulators had approved more than 80% of the filings carriers submitted to adopt the forms or proprietary variants (IndependentAgent; PYMNTS, 2026). That adoption rate is the best evidence that the market recognizes the AIUC finding is directionally correct: carriers are moving to shed exposure they know they never priced.

The exclusion's own definition is where the AIUC finding reasserts itself. CG 40 47 and its siblings define generative AI as a system with "ability to create content or responses, including text, images, audio, video or code" (Verisk ISO endorsement language, 2026). That definition targets output, a chatbot's answer, a generated image, a drafted document, not autonomous action. An agent that files a claim, executes a wire transfer, negotiates a settlement, or approves an underwriting decision without generating any content a court would recognize as the proximate cause of loss sits in a definitional gap the current exclusion was not drafted to close. Verisk is reportedly exploring a distinct agentic AI exclusion for exactly this reason, a second wave of form development that would need its own causation language built around autonomous action rather than content generation (The Insurer, July 2026). Until that form exists and is adopted, a carrier that has already endorsed CG 40 47 onto its GL book can still carry silent exposure to agentic harms the generative-AI exclusion never reached, the shift-not-eliminate dynamic AIUC's 90% figure is really describing.

Coverage lineSilent AI exposure todayEffect of the 2026 generative AI exclusion
Commercial general liabilityContent-generation and agentic-action claims both sit unrated inside Coverage A/BRemoves content-generation claims; agentic-action claims persist absent a distinct agentic form
Directors and officersBoard-oversight and disclosure failure suits tied to AI governance gapsNo standard ISO exclusion yet filed; carriers proposing proprietary "absolute AI" wording
Technology E&OProfessional-negligence claims from AI-driven service failuresMost exposed near-term line per carrier surveys; some carriers declining AI-output liability outright
CyberData breach, fraud, and unauthorized-transaction claims from compromised or manipulated agentsLargely unchanged; still the line most likely to respond to AI-enabled fraud

The Repricing Gap Between Silent Cover and the Affirmative Market

An exclusion only closes a gap for the insured who buys replacement cover. The affirmative AI liability market exists, but it is pricing with the same thin-data problem cyber carriers faced a decade ago, a methodology this site has detailed in its analysis of AI liability pricing when the loss triangle has no rows. Carriers offering standalone or affirmative AI wording also face a complication cyber underwriters did not: the underlying peril changes shape after the policy is bound, because a foundation-model vendor can update the model mid-term, shifting the frequency and severity distribution the policy was priced against without any change to the policy language itself, a dynamic covered in this site's reporting on affirmative AI coverage and model drift as a pricing input.

That combination, a narrowing exclusion on the conventional side and a thin, drift-exposed affirmative market on the other, is why the repricing gap does not close as fast as the exclusion filing rate suggests. An insured that does not understand its GL policy now excludes agentic AI harms, or that cannot find affordable standalone cover for a risk with essentially no loss history, is left genuinely uninsured rather than silently covered. That is a worse outcome for the policyholder, but it is also where coverage litigation concentrates, over whether "arising out of" generative AI reaches an agentic action, in exactly the pattern silent cyber litigation followed before cyber wording matured. Fenwick's June 2026 review of the exclusion wave found coverage now fragmenting across cyber, tech E&O, and D&O/EPLI lines, with each policy responding to only a subset of an insured's actual AI risk and exclusions sometimes stacking to leave gaps no single policy was designed to catch (Fenwick, June 2026).

What a Systemic AI Event Does to Accumulation and Treaty Response

The AIUC report's headline scenario is not the $100 billion figure alone, it is what that figure could trigger. A catastrophe with roughly $100 billion in direct AI-related damages could erase several trillion dollars in GDP if it triggers a broader economic slowdown, magnified specifically by insurers withdrawing AI coverage capacity in response to the shock (AIUC, July 2026). That is a materially different tail than a conventional liability catastrophe, where the insurance market's response to a large loss event does not itself become a second-order driver of the macroeconomic outcome.

For reinsurers, the practical question is whether existing per-line treaty structures can even see this exposure. Quota share and excess-of-loss treaties written on GL, D&O, cyber, and tech E&O books separately were not built to detect a single AI-model root cause triggering claims simultaneously across all four cessions. The aggregate-scanning discipline cyber reinsurers built to size silent cyber PML inside conventional P&C wording, detailed in this site's coverage of AI wording scanners changing cat model certification, is the closest existing tool for this problem, but it was built to scan for cyber peril language, not for agentic-AI causation spanning four distinct coverage parts at once. Extending that scanning discipline across lines, not just within one line, is the unfinished actuarial work the AIUC report's accumulation finding actually points toward, and it is the kind of cross-line correlation testing that rate filings and treaty submissions do not currently require anyone to perform.

What the Next Renewal Cycle Should Test For

Three things separate a carrier that has absorbed the AIUC finding from one that has only read the exclusion filing count. The first is whether GL, D&O, tech E&O, and cyber reserves for in-force business carry any supplemental loading for AI-coded causation, independent of whether an exclusion has attached, since the 90% figure describes exposure already written rather than exposure yet to be sold. The second is whether the carrier's own exclusion language, however it is drafted, actually reaches agentic action or only generative content, a distinction the definitional gap in CG 40 47 makes concrete rather than theoretical. The third is whether treaty submissions this renewal season ask reinsurers to look at AI-related accumulation across lines rather than within a single cession, since the correlation the AIUC report describes does not respect the boundaries any individual treaty was drawn along.

None of that requires waiting for a fully priced affirmative AI market to mature. It requires treating the 90% figure as a statement about a book of business that already exists, not a forecast about one that is coming.

Further Reading