AI Liability Insurance Buyer's Guide
Underwritten Essay

Coverage by Silence

For most of insurance history, silence in a policy tended to favor the policyholder. With AI, that silence is being written out of existence.

Written by

Joel R. Singh

Section

Underwritten

Published

2026

The Un-named Peril


A cargo of frozen goods sits in a cold-storage warehouse on a Tuesday, stacked and inventoried, worth a number large enough to appear on a spreadsheet someone in a corner office reviews each morning. By Thursday it is ruined. The cause is some peril nobody in the room had a name for when the contract was signed, a mode of spoilage that behaves unlike anything the underwriters had modeled. The claim that follows gets paid, and it gets paid on the strength of everything the policy fails to mention. The adjuster reaches for the document, reads it front to back, and finds no clause that names the thing that happened. Because the policy is written on an all-risks basis, meaning it insures against physical loss or damage from any cause not specifically excluded[1], the absence of an exclusion becomes the whole case. The loss is covered. It was never foreseen. It was simply never ruled out.

[1] Saxe Doernberger & Vita — All Risk vs. Covered Peril

That is a strange kind of power, and for a very long time it worked almost entirely in the policyholder's favor. The gaps in a contract, the perils left unnamed, the futures never drafted for, all of it tended to fall on the side of the person who bought the coverage rather than the company that sold it. There is a reason for this that goes beyond luck, and understanding it is the whole point of what follows. The history of insurance is in large part a history of silence, and of what happens to a business when the industry can no longer afford to stay quiet. That history has entered a new chapter, and artificial intelligence is the peril that is turning the page.

Consider how an all-risks property policy actually reads, because the mechanics matter more than the marketing. The policy does not list the good things that are covered, one by one, in the hopeful way a wedding registry lists gifts. It works the other way around. It lists the bad things that are not covered, the exclusions, and everything outside that list is presumed to be in. War, wear and tear, inherent vice, deliberate acts of the insured, these get named and carved out with great specificity, often across pages of dense clauses that lawyers have spent decades refining. The rest, the vast and uncatalogued field of ways the world can go wrong, stays covered by default. Coverage is the ground state. Exclusion is the exception[2] that has to be argued for and written down.

[2] HUB International — All Risks Insurance

This design has a consequence the original drafters did not always intend and could not always prevent. When a genuinely new peril arrives, something the world had not yet produced when the form was written, the policy meets that peril with silence. Under an all-risks structure, silence resolves to yes. A refrigeration technology that fails in a way no one anticipated, a contaminant that behaves unlike anything the underwriters had ever tabulated, a mode of loss that simply did not exist in the actuarial record. If it caused physical loss or damage, and if no exclusion caught it, the insurer paid. The very novelty of the risk became the policyholder's good fortune, because novelty is precisely what an exclusion cannot describe in advance. You cannot exclude what you cannot yet imagine, and the drafter is always writing against the world as it exists on the day the pen touches the page, not against the world as it evolves.

You can see why the industry finds this uncomfortable, and the discomfort is not merely emotional. It is structural. An insurer prices a policy against the losses it can imagine and enumerate. The losses it cannot imagine are, by definition, unpriced, unreserved, and unreinsured with any precision. Under an all-risks form, the unpriced losses are the covered ones. The entire arrangement runs on the insurer's ability to foresee and name its own exclusions, and human foresight has a poor record against genuinely new things. Every new technology that has ever entered commercial life has, for a period, ridden inside insurance policies as an unpriced passenger, covered because the form had not yet caught up to the world. The passenger rides free until the insurer notices the fare it never collected.

There is a temptation to read this as a flaw in the system, a bug that the industry simply failed to patch for a century or more. That reading is too easy. The all-risks form was a deliberate commercial promise, a way of selling certainty to a buyer who could not possibly anticipate every future harm any more than the insurer could. The buyer paid for peace of mind about the unknown, and the unknown, by the logic of the form, was covered. The silence was 'the product', and NOT merely an oversight.

Ambiguity Against the Draftsman


The silence was reinforced by a doctrine that lawyers have carried for centuries, usually named in Latin, contra proferentem, which means roughly that ambiguity is construed against the party who drafted the language.[3] The reasoning behind it is old and, on its own terms, fair. The insurer wrote the contract. The insurer chose the words, controlled the form, and employed the lawyers who had spent entire careers refining every clause and anticipating every reading. If after all of that effort the language turns out to be unclear, the party who wrote it should bear the cost of the confusion rather than the party who merely signed what was placed in front of them. The rule puts the risk of murky drafting where the power to draft clearly already sat.

[3] Cornell Law School LII — Contra Proferentem

For the policyholder, this doctrine turned silence into a second layer of protection sitting on top of the first. It was not only that unnamed perils fell inside coverage by the very structure of the all-risks form. It was also that when the language was murky, when a single clause could honestly be read two ways, the reading that favored coverage tended to prevail. Courts in many jurisdictions have long leaned this way[4] with consumer and commercial policies alike, on the theory that an insurance policy is a contract of adhesion, offered on the insurer's terms and presented to the buyer on a take-it-or-leave-it basis, with little practical room for the buyer to negotiate the wording clause by clause.

[4] Property Insurance Coverage Law Blog — Policies Are Adhesion Contracts

It is worth dwelling on what a contract of adhesion actually is, because the phrase does a great deal of quiet work in this story. A negotiated contract is a document that two roughly matched parties hammer out together, each striking language the other proposes, each winning and conceding points. A contract of adhesion is nothing of the kind. One party writes it in full, prints it, and hands it over[5]. The other party's only real choices are to accept the whole thing or to walk away and find no meaningfully different terms anywhere else, because every insurer in the market is offering some close cousin of the same form. The law noticed this imbalance long ago and responded by leaning, in close cases, toward the side that had no hand on the pen. When two readings of a clause were each plausible, the courts in many places chose the reading the drafter could have foreclosed with clearer words and did not.

[5] UpCounsel — Contract of Adhesion

So the buyer sat inside a comfortable arrangement they had not been specifically informed about in plain terms. The gaps in the form and the ambiguities in the language favored them. The future, whatever it happened to hold, arrived first as silence, and silence was on their side. It was one of the very few places in ordinary commercial life where not being mentioned was the best possible outcome a business could hope for. A company could be protected, materially and durably, by things its own insurance contract had entirely failed to say. That protection was quiet, nearly invisible, unbilled, and for generations it was remarkably durable. Most policyholders never knew they were leaning on it, which is precisely why its removal has been so easy to overlook.

When Silence Turns Expensive


The trouble is that silence has two faces, and the insurer has always been looking at the other one. Every unnamed peril that quietly pays a policyholder is a loss the insurer did not price, did not reserve capital against, and did not lay off to a reinsurer with any real precision. For a single odd claim once in a while, this is a rounding error, the cost of doing business under an honest all-risks promise. For an entire category of loss that grows silently underneath thousands of policies that were not designed to cover this, the same dynamic becomes an existential threat to the balance sheet. The passenger who rode free on one voyage is a curiosity. The stowaway population that swells across the whole fleet, unseen, is a solvency problem. There is no cleaner modern illustration of this than the episode the industry came to call silent cyber.

Through the decades when computers moved from the back office to the operational center of every business, the property and casualty policies that companies bought said very little about them. A factory carried a fire policy. A professional firm carried a general liability policy. These forms had been written for a physical world of buildings, inventory, machinery, and bodily injury, and they mostly did not mention data, or networks, or the peculiar new ways a modern business could be harmed through its own computers. When a cyber event caused a traditionally covered kind of loss, physical damage to equipment, an interruption of the business, a liability owed to some injured third party, policyholders and their lawyers made the obvious and time-honored argument. The policy does not exclude this. Therefore it covers it. It was the old logic of silence, applied without modification to a wholly new peril.

The argument worked, and it worked often enough to genuinely alarm the market. Insurers found themselves paying cyber losses under policies that did not charge a single dollar of cyber premium[6], nor modeled a cyber catastrophe, and most assuredly, had not contemplated the correlated nightmare that defines the peril: a single piece of malware, propagating across the internet in hours[7], striking thousands of insured businesses at very nearly the same moment. Traditional insurance mathematics rests on the assumption that losses are largely independent, that one policyholder's fire does not ignite the next. A worm that hops from network to network violates that assumption at the root. The exposure was real, it was large, and worse than either, it was invisible on the insurers' own books, buried inside traditional lines of business as an unpriced and uncounted passenger. Silent cyber was the industry discovering that its own accumulated silence had become a liability it could neither see nor measure.

[6] Guy Carpenter — Silent Cyber Explained  ·  [7] Munich Re — Silent Cyber

The correction came from the top of the market, where the appetite for uncounted catastrophe is smallest. Lloyd's of London, the centuries-old marketplace that sets much of the tone for global specialty insurance[10], issued a mandate in July 2019[8], effective January 1, 2020 for first-party property and phased through 2021 for liability lines[9], requiring that policies address cyber exposure explicitly, that each policy state affirmatively whether cyber was in or out rather than leaving the question to the old presumption of coverage by omission. The instruction was blunt in its logic. There would be no more coverage by accident. If an insurer wished to sell cyber protection, it should sell cyber protection openly, price it, name it, and hold reserves against it. If it did not wish to sell that protection, it should exclude cyber plainly, in language, so that every party to the contract knew exactly where they stood before a loss ever occurred. The age of the silent passenger was drawing to a close, at least for that one peril.

[8] Lloyd's — Market Bulletin Y5277/Y5258  ·  [9] Kennedys Law — Non-affirmative Cyber, Phase 2  ·  [10] Lloyd's — History

What deserves close attention is who this correction helped and who it hurt, because both the surface and the deeper stories point in different directions. Making a silence explicit is, on its face, an act of tidying, a matter of good hygiene and honest pricing that no reasonable person could object to. In practice, however, resolving the ambiguity resolved it, overwhelmingly, in the insurer's direction. When silence had meant coverage, forcing an explicit choice meant that a great deal of what had previously been quietly covered was now openly excluded, pushed out of the traditional policies and into standalone cyber policies that had to be sought out, purchased separately, and priced deliberately. The policyholder who had once been protected by omission now had to go out into the market and buy the thing by its proper name, or else go entirely without it. The favorable silence did not migrate into favorable language. It largely evaporated in the conversion. A protection that had cost the buyer nothing became a line item with a premium attached, and the businesses that did not notice the change in time found the coverage gone precisely when they reached for it.

The Same Drama, Now Called AI


If you have followed the argument this far, you know what is coming, the same play being invoked for a new peril... Artificial Intelligence. The pattern is not a coincidence and it is not a conspiracy. It is the predictable behavior of a system that sells certainty about the unknown and then discovers, once the unknown has a name and a loss history, that it can no longer afford to give that certainty away.

For a few years now, AI has lived inside ordinary business insurance the way cyber once did, mostly by omission, mostly unnamed, mostly covered by default. A company deploys a model that gives a client bad advice with real financial consequences. A generative system produces something defamatory or infringing and a third party sues. An automated decision process discriminates against applicants in a way no human in the building ever intended or even noticed until the pattern surfaced. In each case the harm lands somewhere the old policies were built to catch. Professional errors fall toward errors and omissions coverage. Third-party bodily injury and property damage fall toward general liability. Wrong decisions by leadership and their downstream fallout drift toward directors and officers coverage. In every one of these scenarios the AI itself was nowhere named in the governing form, and so the familiar old argument became available to the policyholder once again. The policy does not exclude AI. Therefore, for the moment, it covers the loss. Coverage by omission, one more time, riding on the newest peril of them all.

That window is closing, and the closing is something you can watch happen in the paperwork if you know where to look. The insurance industry standardizes much of its contract language through common forms, and in the United States a great deal of that standardization runs through ISO[11], the organization whose endorsements ripple outward across countless carriers at once, so that a single drafting decision made in one place reshapes coverage in thousands of policies almost simultaneously. Two of those endorsements, CG 40 47 and CG 35 08, took effect on January 1, 2026[12], and they exclude generative-AI-related injury and damage on general liability policies. That is the industry doing to artificial intelligence exactly what it once did to cyber. It is converting the silence into language, and it is doing so, primarily, by writing AI out.

[11] Verisk / ISO — ISO's Policy Forms  ·  [12] Gallagher — ISO Generative-AI Exclusion in CGL

The individual carrier filings tell the very same story from the level of the single company. Insurers are adding AI definitions, AI exclusions, and AI-specific conditions to their forms across multiple lines of business, deciding deliberately and in advance where AI risk will be covered, where it will be excluded outright, and where it will be offered back to the buyer only as a separately priced and separately negotiated grant of coverage. The direction of travel is not perfectly uniform. Some carriers will choose to affirm AI coverage as a deliberate competitive offering rather than exclude it, treating a clear yes as a way to win business from rivals who default to no. But the era in which AI was simply, quietly, and freely covered because no one had gotten around to mentioning it, that era is ending on a schedule you can read directly in the effective dates printed on the forms. The dates are not speculative. Some of them have already passed.

What Silence Meant, and What Reading Means Now


Here is the shift that matters, stated as plainly as I can make it. If you are a Small Business Owner, a Mid Tier business or even an Enterprise; silence is no longer a guarantee that you are covered for AI related liability. Your best course of safety is to understand if your insurance actually offers coverage for the domains that you operate in and determine if you are willing to pay the premium for protection.

For most of the long history of insurance, the safest place for a new risk to sit was unmentioned, because unmentioned meant covered, and ambiguity broke in the buyer's favor. A policyholder could be protected, in a way that genuinely paid claims, by the things the contract had failed to say. That protection was quiet, nearly invisible, and for a very long stretch of commercial history it was dependable enough that most businesses relied on it without even knowing they were doing so.

That arrangement is over for AI, or it is ending quickly enough that a prudent business owner should treat it as already over. The endorsements are being written and filed. The definitions are being added to the forms. The exclusions are taking effect on real, specific dates, and some of those dates have already passed. Silence is being converted into language across the market, and language, when it is the insurer who holds the pen, does not favor the buyer the way silence once reliably did. The comfortable presumption that a new peril simply rides along inside your existing coverage until someone objects is being revoked deliberately, peril by peril and form by form. The revocation is orderly, scheduled, and largely invisible to any policyholder who is not reading the endorsement pages.

Which means the burden has moved squarely onto you, the buyer, and it has moved onto the least glamorous part of the entire transaction, the endorsements. The real terms of your AI coverage no longer live in the reassuring one-page summary, or in the broker's friendly cover note, or in the general impression that a comprehensive policy surely covers everything a reasonable business might face. The real terms live in the specific endorsement forms physically attached to your policy, in the defined terms buried among them, and above all in the difference between an exclusion that is absolute and one that carves some measure of coverage back under stated conditions. You cannot rely on omission any longer, because omission is being actively erased from the market. You have to read what the policy now says out loud, in its own words, and you have to do that reading before you need the coverage rather than in the anxious aftermath of a loss, when the language has already hardened into either a yes or a no that you had no hand in shaping.

If you want a concrete place to begin, ask one blunt question of your own coverage. Does your existing errors and omissions or commercial general liability policy actually cover your use of AI, or has that coverage already been quietly written out from under you in an unread Amendment or Addendum? That question has its own dedicated page on this site, and it is the right place for you to start, because it turns the abstract historical shift described here into the specific forms sitting in your own file drawer.

A field guide

How to read for silence

A short field guide for reading your own policies before the silence is gone from them entirely.

01

Hunt for AI as a defined term

Search the whole policy and every attached endorsement for words like artificial intelligence, machine learning, algorithmic, automated decision, large language model, and generative. A defined term is the surest tell that the insurer has taken a deliberate position on AI, and the wording of the definition itself quietly sets the scope of whatever exclusion or grant follows it.

02

Check every line separately, and never assume they move together

AI risk touches general liability, errors and omissions, directors and officers, and cyber in different ways, and an exclusion added to one line says nothing at all about the others. Read each policy in your insurance tower on its own terms, because a carrier can write AI out of one and leave it silent in the next.

03

Ask your broker for the form numbers, in full

Endorsements are identified by codes rather than plain names, and requesting a complete list of every form and endorsement number attached to your policy is the fastest way to surface the AI language, including forms whose innocuous titles give no hint that AI provisions live inside them.

04

Watch the difference between absolute and carve-back language

An absolute exclusion removes an entire category of loss with no return. A carve-back exclusion removes the category and then hands a defined portion of it back under stated conditions. The gap between those two structures is often the whole practical value of your coverage, and it can turn on a single clause or even a single word.

05

Read for the silent lines as carefully as the loud ones

The absence of AI language on a given policy no longer reliably means coverage the way it once did. Where a line is still silent, ask the carrier directly and in writing where it stands on AI, and insist on receiving the answer as an endorsement to the policy rather than as a reassuring sentence in an email.

06

Confirm every effective date against your own renewal timeline

Standardized AI exclusions are attaching to policies on specific calendar dates, and a form that was nowhere in last year's renewal can appear in the next one without any fanfare or plain-language warning. Compare this year's full endorsement schedule against last year's, line by line, and question anything that is newly present.

07

Get the position in writing before you need it, not after

A verbal assurance from a broker or an adjuster has almost no weight against the printed forms once a loss has occurred. If a carrier tells you that your AI use is covered, ask them to say so in the policy itself, on a form with a number, so that the coverage rests on language you can hold up rather than on a conversation you can only recall.

08

Treat renewal season as the moment of maximum leverage and maximum risk

The endorsements change at renewal, quietly, and that is also the one moment when you can shop the market, ask for affirmative AI grants, and refuse a form you do not understand. Read before you sign, because after you sign, the silence is already spoken for.

Before you go

Your endorsements, however, are the thing that will actually pay a claim, or fail to.

The era of favorable silence around AI is closing. The way to know where you actually stand is to read what your own endorsements now say out loud, line by line, before a claim rather than after.

See where your E&O and CGL actually stand

Does your E&O or CGL cover AI? The plain-English breakdown.

Works Cited

Every factual claim in this essay is sourced below, with primary sources preferred. The numbers match the citation after each paragraph. Where a source compresses a more layered reality, the note says so.

  1. 1Saxe Doernberger & Vita, P.C., Whose Burden Is It Anyway: All Risk vs. Covered Peril Policies.
  2. 2HUB International, All Risks Insurance (glossary).
  3. 3Cornell Law School Legal Information Institute, Contra Proferentem (Wex).
  4. 4Property Insurance Coverage Law Blog, Insurance Policies Are Adhesion Contracts and Not Bargained For.
  5. 5UpCounsel, Contract of Adhesion: Definition, Legality, and Modern Use.
  6. 6Guy Carpenter, Silent Cyber Explained.
  7. 7Munich Re, Silent Cyber: a journey shared across industry participants.
  8. 8Lloyd's of London, Market Bulletin Y5277, updating Y5258 (July 2019): Providing clarity on coverage for cyber exposures.
  9. 9Kennedys Law, Non-affirmative cyber risk: phase 2 classes of business. The phase-in ran in stages (property Jan 2020; political risk and crime Jul 2020; PI, D&O, EL/PL and aviation Jan 2021; medical malpractice and treaty Jul 2021). "Phased through 2021" states the end date and compresses the intermediate steps.
  10. 10Lloyd's of London, History of Lloyd's.
  11. 11Verisk / ISO, ISO's Policy Forms.
  12. 12Arthur J. Gallagher & Co., ISO Introduces Generative AI Exclusion in Commercial General Liability Policies. Form numbers and the January 1, 2026 effective date are confirmed. These are optional endorsements each carrier elects to adopt; CG 35 08 applies to the products and completed operations coverage part.
Informational only. This essay is analytical commentary on insurance market practices and is not insurance advice, legal advice, or a recommendation of any policy. Endorsement form designations and carrier actions cited reflect publicly available filings and market reporting; coverage terms change frequently and vary by state. Research and writing by Joel R. Singh for iSinghLabs Inc.
HOME