Verisk's ISO generative AI exclusion endorsements took effect January 1, 2026, letting commercial general liability carriers carve gen AI out of the form entirely. Alongside them, Munich Re, Coalition, Armilla and Vouch now write affirmative cover for hallucinations, prompt injection, model drift and IP infringement.

Both products sit on the same underlying loss distribution, and neither side has a credible loss history to price it from. What the market has instead is a set of surrogate rating variables, one of which goes stale inside the policy period.

Key Takeaways

  • The exclusion bars bodily injury, property damage, personal and advertising injury and medical payments arising out of the "use of" generative AI, structured as a broad bar with narrow carve-backs rather than the reverse.
  • Approvals cleared in a thirty-to-sixty-day window across the first sixteen states with minimal interrogatories, fast for a coverage-narrowing endorsement.
  • Indicative AI load factors run 1.05x to 1.10x for internal-only deployment and 2.00x to 4.00x or more for autonomous agents with tool-calling in production.
  • Model audits enter the rating algorithm as a credibility-weighted exposure factor, but measure a system that vendor upgrades, fine-tuning and prompt changes alter continuously.
  • A carrier writing affirmative AI cover is itself using AI in underwriting under the NAIC Model Bulletin's own definition, since its audit scores and risk-tier classifiers are AI systems.

Two Products, One Loss Distribution

The endorsements are optional: a carrier subscribing to the ISO CGL program can attach them per policy or as a schedule amendment, and the filings appear in SERFF under terms including generative artificial intelligence exclusion. Approvals across the first sixteen states cleared in roughly thirty to sixty days with minimal interrogatories, which is quick for a form that narrows coverage.

The trigger phrase is "use of," and it is broader than it reads. It reaches any claim where gen AI output sat in the causal chain, not only the insured's own deployment. A marketing agency whose gen AI drafted defamatory ad copy, a contractor relying on a gen AI estimator that mis-specified load-bearing requirements, and a retailer whose chatbot offered an unauthorized warranty all face the same question.

The structure is the departure. A cyber exclusion is typically a narrow bar with broad carve-backs preserving traditional coverage. This is a broad "arising out of" bar with narrow carve-backs, which moves the burden onto the insured to show the loss did not arise out of gen AI use. Our premium adequacy analysis of the endorsement covers the rate-side consequence of that choice.

The affirmative side fragmented into four architectures rather than converging. Munich Re's insureAI is a performance guarantee, triggering on output accuracy, downtime or deviation from contracted service levels, which prices closer to surety than casualty. Coalition extended its cyber wording to affirmative AI triggers, loading its cyber base rate by attestation quality against a model inventory consistent with ISO 42001 or the NIST AI RMF.

Armilla writes a standalone warranty behind an independent pre-bind model audit. Vouch embeds gen AI into its tech E&O form and builds it into the base rate rather than charging a load, because its book is AI-native throughout.

The Rating Variable Expires Before the Exposure Does

Gen AI in its current form is roughly three years old and enterprise deployment is younger, so no reporting year has run far enough to produce usable paid or incurred triangles. Pricing runs on surrogates.

The most tangible is the model audit. Armilla, Coalition and several reinsurance-backed MGAs require a pre-bind assessment measuring accuracy on a benchmark dataset, fairness across protected classes, hallucination rate on a standardized prompt suite and drift from a reference state. The output is a score or tier, and that tier enters the rating algorithm as a credibility-weighted exposure factor. Public benchmarks such as Vectara's Hallucination Leaderboard and Stanford HELM supply a weaker proxy where no audit exists, tiering the load by the underlying foundation model's performance.

Exposure bases moved too, because payroll and sales do not separate a company running every customer interaction through a chatbot from one using gen AI for internal productivity at the same revenue. Rating plans are testing inference volume, model size and capability tier, deployment surface and a regulated-industry factor instead.

Exposure Profile Indicative AI Load Factor Primary Risk Driver
Internal productivity only, employee-facing 1.05x to 1.10x Output leakage, copyright from training data
Customer service chatbot, non-regulated industry 1.20x to 1.40x Defamation, unauthorized promises, prompt injection
Regulated advice (legal, medical, financial) 1.60x to 2.50x Regulated advice liability, hallucinated citations
Autonomous agent with tool-calling in production 2.00x to 4.00x+ Tool misuse, cascading errors, unauthorized transactions

The spread is the point. A 1.05x internal-only load against 4.00x or more for a production agent with tool-calling is a rating structure carrying most of its signal in one variable, and that variable is measured once. An audit describes model behavior at a moment; production models change continuously through vendor upgrades, fine-tuning and prompt template edits. An assessment taken at inception can be stale by the midpoint of the policy period, which is why carriers have started requiring quarterly re-attestation or conditioning renewal on maintained audit status.

That is an unusual failure mode for a casualty rating variable. Construction class or payroll does not silently change grade mid-term. Here the insured can move from one tier to the next without any underwriting event, and the wide bands within each tier, driven by governance maturity and audit evidence, mean the drift is easily larger than the tier boundary it crosses.

The Seam, and the Carrier's Own Position Inside It

The exclusion does not resolve the overlaps it creates. A prompt injection attack that exfiltrates customer data reads as a data breach on most cyber forms, and a model trained on copyrighted material reads as an IP claim on media liability. The endorsement simply removes CGL for anything arising out of gen AI use and leaves the insured to find the pieces elsewhere.

That leaves a seam rather than a clean handoff. A gen AI-initiated exfiltration may trigger cyber for breach response and regulatory costs while the resulting defamation or bodily injury exposure falls outside both the cyber carve-back and the excluded CGL. Filling it is what the affirmative products are aimed at, which means the two halves of the market are pricing partially overlapping and partially disjoint slices of one distribution.

Europe converged faster and differently. The EU AI Act classifies systems by risk tier and imposes obligations on high-risk ones, with the AI Liability Directive proposal and the revised Product Liability Directive adding statutory exposure. European commercial treaties renewing at January 1, 2026 frequently carried an explicit AI grant or exclusion at treaty level with loadings negotiated, where US treatment remains carrier by carrier. An actuary with books on both sides is running an endorsement decision and a compliance decision at once.

The closing difficulty is reflexive. The NAIC Model Bulletin, adopted in December 2023 and implemented in roughly two dozen states plus the District of Columbia, requires an insurer deploying AI in underwriting or rating to maintain a documented program with ongoing monitoring and third-party vendor management.

A carrier pricing affirmative AI coverage from audit scores, benchmark outputs and risk-tier classifiers is deploying AI in underwriting by that definition, and a third-party vendor registry would put its audit provider under registry scrutiny. The transition from bulletin to model law would harden all of it. The market built to insure other firms' model risk is regulated as a user of the same technology, on the same unformed evidence base.

Further Reading

Sources

  1. Verisk, ISO Forms program (accessed April 2026)
  2. Verisk Newsroom archive on ISO CGL filings
  3. NAIC SERFF System Electronic Rate and Form Filing search
  4. Milliman, "Artificial intelligence regulation: Implications for insurance"
  5. EU Artificial Intelligence Act official text and guidance
  6. European Commission, AI Liability Directive proposal
  7. Munich Re, insureAI product page
  8. Coalition, cyber insurance product page
  9. Armilla AI, warranty and assurance program
  10. Vouch, technology errors and omissions coverage
  11. Carrier Management, executive viewpoints on AI and brokers (2026 coverage)
  12. Guidewire, blog coverage of AI in claims operations
  13. NAIC, Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (December 2023)
  14. NAIC, Big Data and Artificial Intelligence (H) Working Group
  15. NAIC, Third-Party Data and Models (H) Working Group
  16. Vectara Hallucination Leaderboard
  17. Stanford CRFM, HELM benchmark
  18. NIST, AI Risk Management Framework
  19. ISO/IEC 42001 AI management systems standard
  20. Actuarial Standards Board, ASOP No. 56: Modeling