AI insurance gaps widen as exclusions surge

The gist
As insurers scramble to dodge the fallout from unpredictable AI risks, CFC is making a bold play: embrace AI, but only if you can prove you’re in control.
What to know
- By mid-2026, 42% of companies faced AI-specific exclusions in their cyber policies, as traditional insurance increasingly carves out autonomous AI risks.
- CFC rolled out affirmative AI coverage across its entire portfolio, but only for firms with documented AI governance and human oversight.
- Insurers are now offering premium discounts for well-governed, AI-powered security tools, while most brokers and insurers still rely on in-house validation teams to keep up with evolving rules.
AI Exclusions Reshape Coverage
Insurers are rewriting policies to explicitly exclude autonomous AI risks, leaving critical gaps for harms caused by agentic systems and penalizing firms without robust AI governance.
Traditional general liability (GL) and cyber insurance policies are increasingly carving out AI-related risks through explicit exclusions and narrower endorsements, driven largely by insurers’ struggles to underwrite and price the unpredictable exposures posed by autonomous AI systems. By mid-2026, a Delinea survey revealed that 42% of companies faced AI-specific exclusions in their cyber policies, reflecting a market shift away from the prior era of 'silent AI' coverage where AI risks were implicitly covered. Notably, the Insurance Services Office’s CG 40 47 01 26 form now excludes bodily injury, property damage, and personal injury claims arising from generative AI, underscoring insurers’ cautious stance amid uncertainty about causation and foreseeability in AI-driven losses.
A critical coverage gap has emerged around autonomous or agentic AI actions that cause harm without traditional cyber breach triggers, such as AI agents autonomously deleting records or authorizing erroneous payments. Standard cyber policies, which typically require an external attacker or unauthorized access to trigger coverage, often exclude these losses, leaving firms exposed. This gap is compounded by underwriters’ reluctance to insure AI-generated errors due to the inherent opacity of AI decision-making processes, as exemplified by cases like Air Canada’s chatbot-generated refund policy and Wolf River Electric’s lawsuit against Google over false AI claims.
In response to these emerging gaps, insurers such as Chubb have introduced narrower AI-specific products and riders that mandate rigorous AI governance practices—including documented risk assessments, adversarial testing, and human oversight—as prerequisites for coverage. This evolving underwriting paradigm rewards firms with robust AI inventories and governance frameworks, influencing both premium pricing and coverage availability, while penalizing those lacking transparency or control over their AI deployments. As ACA Group highlights, organizations demonstrating strong AI risk management are better positioned to negotiate favorable terms and avoid exclusions in an increasingly complex insurance landscape.
Beyond underwriting challenges, the legal and operational complexities introduced by autonomous AI blur traditional lines of accountability and coverage triggers, raising thorny questions about whether AI-induced harms fall under cyber incidents, professional liability, or operational failures. This ambiguity complicates claims and coverage determinations, as insurers grapple with causation and foreseeability issues that were largely absent in pre-AI policy frameworks. Consequently, organizations must carefully evaluate their existing policies and governance to mitigate the risk of uncovered losses stemming from AI’s autonomous decision-making capabilities.
Governance Unlocks Better Terms
Rigorous AI oversight, inventories, and risk assessments are now prerequisites for affirmative coverage and premium discounts, as insurers reward companies that can prove control over their AI deployments.
By early 2026, CFC had completed the rollout of its affirmative AI coverage across its entire insurance portfolio, notably extending this specialized protection to its media policy, signaling a strategic commitment to address AI risks comprehensively. This expansion reflects a broader industry trend where insurers are refining underwriting standards to incorporate rigorous AI governance criteria—such as maintaining AI inventories, conducting documented risk assessments, adversarial testing, and ensuring human oversight—to more accurately evaluate and price AI-related exposures. As ACA Group highlights, firms demonstrating robust AI governance stand to negotiate more favorable cyber insurance terms, potentially avoiding restrictive exclusions or securing valuable policy endorsements.
Insurers are innovating by distinguishing AI's dual role in risk management: while uncontrolled or poorly governed AI amplifies loss exposures, well-managed AI deployed as a cybersecurity tool can actually enhance an organization's risk profile. This nuanced perspective has prompted companies like ACA Group to incentivize the adoption of AI-powered security technologies through premium discounts or credits, especially when these tools complement existing security measures. Such proactive underwriting approaches underscore a shift from merely mitigating AI risks to leveraging AI defensively, aligning insurer incentives with clients’ investments in advanced cybersecurity frameworks.
Governance Gaps and Human Oversight
Despite rapid AI adoption, most insurers and brokers remain unprepared to manage AI-driven risks, relying heavily on in-house validation teams and facing mounting regulatory demands for accountability.
Effective AI risk management in insurance hinges on a dynamic interplay between external regulation and robust internal governance frameworks. As articulated in a 2026 opinion piece, this 'tango' requires regulators to set clear standards while organizations implement practical accountability structures, policies, and operational controls to prevent violations and manage AI risks effectively. This dual approach ensures that governance is not merely a compliance checkbox but an embedded organizational practice.
The rise of autonomous, agentic AI systems is forcing insurers to fundamentally rethink governance, accountability, and risk management frameworks. According to Davies’ 2026 analysis, traditional compliance controls are inadequate for these AI agents, which require continuous, lifecycle-based monitoring and real-time human oversight to mitigate risks such as unintended decision loops, model drift, and third-party vendor complexities. This shift underscores a growing governance gap despite existing regulatory coverage, with frameworks like the EU AI Act increasingly serving as de facto benchmarks even beyond Europe.
Despite rapid adoption of generative AI in claims processing—74% of Australian insurers use it—there remains a significant preparedness and accountability gap among brokers and insurers alike. A 2026 survey revealed that while 83% of brokers anticipate technology’s impact by 2035, only 61% feel ready to manage AI-related risks, compounded by unclear accountability for AI errors in claims decisions. Human oversight remains critical, with 90% of insurers maintaining in-house validation teams to ensure quality and compliance amid intensifying regulatory scrutiny from bodies like ASIC and upcoming Privacy Act regulations.
AI governance is evolving from a narrow compliance function into a foundational business imperative that demands adaptive oversight, clear accountability, and integration into daily operations. Industry leaders like HGS’s Global CTO Mouli S. emphasize embedding governance-by-design from AI’s earliest development stages, unifying enterprise-wide frameworks to manage multi-model environments, and treating cybersecurity as an integral component of governance. This comprehensive approach not only preserves trust and resilience but also enables innovation by establishing accountability upfront, as underscored by the necessity of assigning clear AI ownership and operational controls to prevent harm before deployment.

