
Blog Post
Does Cyber Insurance Cover AI Incidents?
August 14, 2026
The answer changed on a specific date. Until the start of 2026, most organizations were covered for AI losses by silence rather than by grant, because policies neither affirmed nor excluded AI and the question would have been argued at claim time. On January 1, 2026 the standard forms organization introduced generative AI exclusion endorsements for commercial general liability, and carriers began attaching them at renewal.
Cyber policies are moving separately and in two directions at once. Some carriers are adding AI sublimits, reported at close to a tenth of policy limit at certain names. Others are writing affirmative AI coverage on purpose, and pricing it against documented governance. What follows covers where an AI incident currently lands, why the cyber playbook fits AI badly, and what to establish before a renewal conversation.
What Silent AI Was and Why It Ended
Silent coverage is coverage that exists because a policy failed to exclude something rather than because it intended to include it. The industry has done this before and remembers how it finished.
The Cyber Precedent Took Eight Years
Between roughly 2015 and 2023, conventional property, casualty and marine policies absorbed cyber losses they were never priced for. A 2019 Lloyd's requirement forced insurers to state whether cyber was covered or excluded, exclusions and affirmative write-backs worked through the lines, and cyber eventually separated into a standalone market. Reinsurance research warned explicitly in 2024 against repeating the exercise with AI.
What Changed on January 1
Three endorsements arrived, covering a broad generative AI exclusion, a narrower version, and one addressing products and completed operations. Together they exclude bodily injury, property damage and personal or advertising injury arising out of or attributable to generative AI. The trigger language is wide enough to reach AI embedded in ordinary software rather than only custom-built models, which matters because most organizations now use AI they did not choose to deploy.
The narrowing rarely appears as a single conspicuous clause. Reviewers should expect it in revised base forms, new definitions, application questions, underwriting file positions and restrictive carve-backs, which makes a form-by-form comparison against the expiring policy more useful than searching for the words artificial intelligence.
Where an AI Incident Lands
No single policy answers for AI, and the same underlying event can present as four different claims depending on what went wrong.

Cyber Responds to Security Events, Not Bad Outputs
A cyber policy is built around unauthorized access, data compromise and interruption caused by a security failure. An AI system that leaks regulated data through a prompt, or an agent whose credentials are abused, sits reasonably inside that architecture. An AI system that produces confidently wrong advice does not, because nothing was breached. Understanding how regulated data reaches AI tools is therefore the part of AI exposure most likely to be covered by an existing cyber policy.
Four Routes for the Same Underlying Failure
Technology errors and omissions responds where an AI-enabled service fails a customer. Professional liability responds where advice was wrong. General liability historically responded to defamation, privacy and advertising injury involving generated content, and is precisely where the new exclusions bite. Employment practices liability responds where a hiring model discriminated. Cyber sits alongside all four rather than above them, which makes the cyber policy one component of an AI answer rather than the whole of it.
Why the Cyber Playbook Fits AI Badly
The market is applying a familiar template on a compressed timeline, and the underlying risk does not have the same shape. Conditions have moved before without the drafting keeping pace, which buying fit-for-purpose cover in a volatile market covers from the conventional side. Cyber losses arrive as discrete events, being a ransomware detonation or a breach, with an identifiable moment and an external cause.
AI produces outputs that become part of the insured's own conduct. Advice given, communications issued, decisions made about applicants. Excluding that cleanly is difficult because the loss is not an event happening to the organization, it is something the organization did with a tool. Market participants have said as much, arguing that AI is too embedded to carve out and that articulating what is covered would serve better than expanding what is not.
Attribution Is the Practical Problem
Establishing that an AI system caused a loss requires knowing what it did, under whose authority and with what inputs. Where those records do not exist, a coverage dispute becomes an argument about facts nobody logged, and the insured is the party who needed them. Recording what each system did, and when, therefore carries a commercial dimension alongside the compliance one, which incident records already exist to serve.
Sublimits Are the Quiet Change
An exclusion is visible and a sublimit is not. Reporting indicates some cyber carriers are applying AI sublimits near ten percent of the policy limit, which leaves the headline number intact while capping what responds to an AI-related event.

A Sublimit Is a Limit for the Event You Are Buying Against
Where AI is involved in the majority of an organization's data handling, a sublimit at a tenth of the master limit is the operative figure rather than a detail. Modeling exposure per coverage line rather than in aggregate is the only way to know whether that figure is adequate, and the question belongs in the renewal conversation rather than in a claim. Organizations that have tested whether their limit was already the wrong size have the modeling in place to answer it.
Ask Which Definition Triggers the Sublimit
Definitions do more work than exclusions here. Whether a sublimit attaches when AI was involved in the event, caused the event, or merely existed in the environment produces very different coverage, and the drafting varies by carrier. Reviewing wording rather than headline terms is what surfaces it, which is the same discipline policy wording analysis applies to conventional coverage.
Agents Sit Outside the Current Language
An omission in the drafting is worth flagging, and it comes from within the market rather than from critics. Underwriters have observed that the new endorsements were written around chatbots and generative output, and do not address autonomous agents well, despite agents being the fastest-growing deployment category and the one most likely to raise attribution questions.
For an organization deploying agents, neither the exclusion nor the affirmative grant plainly contemplates what it is running. The practical response is to describe the deployment specifically in the submission rather than answering a generic AI question, since a carrier that understood what it wrote is a carrier less likely to dispute later. Documentation of which agents act under whose authority does double duty as underwriting evidence.
Affirmative Coverage Prices on Governance
The more useful development is that a deliberate AI coverage market now exists. Carriers have introduced affirmative AI endorsements treating an AI security event as a covered security failure and extending funds transfer fraud triggers to deepfake-generated instructions. Cloud providers have partnered with major carriers on affirmative programs, and a standalone AI liability policy written at Lloyd's in 2025 has since reached limits in the tens of millions per organization.
The condition attached to all of it is evidence. Reported underwriting requirements cluster on a documented ability to stop an AI system, an inventory recording where human review applies, a data provenance and classification audit, and a named executive accountable for AI. Those are governance artifacts rather than security products, so an AI governance program has become an insurance asset in a way it was not eighteen months ago.
Litigation Is Shaping the Underwriting File
Underwriters reportedly price against a small set of costed losses, including a substantial settlement concerning training data provenance involving an AI developer, a tribunal decision holding an airline responsible for its chatbot's statements, and a discrimination claim concerning an AI hiring platform. The pattern across them is that liability attached to the deploying organization rather than the model vendor, which is the assumption to plan around.
What to Establish Before Renewal
Three preparations change the conversation, and all of them are documentation rather than expenditure.
- An Inventory With Human Review Recorded: Which AI systems operate, what each decides, and where a person reviews output.
- Modeled Exposure Per Coverage Line: What an AI-driven interruption or data event would cost, so a sublimit can be assessed rather than accepted.
- A Named Accountable Executive: An individual rather than a committee, which appears on underwriting requirement lists consistently.
Comparing the renewal form against the expiring one completes the set, with attention to new definitions rather than new exclusions. Quantified submissions have measurably helped in conventional cyber placements, and negotiating on modeled figures transfers directly to this conversation.
Do Not Assume Last Year's Coverage
The most expensive assumption available is that a policy which would have responded in 2025 will respond in 2026. Coverage narrowed at many carriers without a headline announcement, and the organizations discovering it during a claim will be the ones that renewed on price. Reviewing this alongside the coverage failures that already existed is the efficient way to do it once.
Coverage by Grant Rather Than by Silence
Cyber insurance covers some AI incidents, specifically those that look like security failures, and increasingly it covers them explicitly rather than by omission. Everything else has moved into a contested space where general liability now carries exclusions, sublimits cap what remains, and affirmative products are available to organizations able to evidence how they govern AI. The variable an insured controls is the evidence. Kovrr's cyber insurance coverage optimization models exposure per coverage line so a sublimit can be evaluated against a figure rather than accepted as a term.
To see modeled AI and cyber exposure mapped against your current program and its sublimits, book a demo with our risk experts.
AI and Cyber Insurance FAQs
Speak to an ExpertDoes cyber insurance cover AI incidents?
Partly, and the answer narrowed at the start of 2026. Cyber policies are built around unauthorized access, data compromise and interruption caused by a security failure, so an AI system leaking regulated data or an agent whose credentials are abused sits reasonably inside that architecture. An AI system producing confidently wrong advice generally does not, because nothing was breached. Several carriers now offer affirmative AI endorsements treating an AI security event as a covered security failure, while others have introduced sublimits that cap what responds. Policy language varies considerably, so the expiring and renewal forms need comparing directly.
What is silent AI in insurance?
Silent AI describes coverage that exists because a policy failed to exclude AI rather than because it intended to include it, leaving the question to be argued at claim time. The industry went through the same pattern with cyber between roughly 2015 and 2023, when conventional policies absorbed losses they were never priced for, until a 2019 Lloyd's requirement forced insurers to affirm or exclude cyber explicitly. Reinsurance research warned in 2024 against repeating the exercise with AI. The market is now applying the same template on a faster timeline because the playbook already exists.
What changed in January 2026?
The organization that drafts standard policy forms introduced generative AI exclusion endorsements for commercial general liability, effective at the start of 2026, and carriers began attaching them at renewal. Three endorsements cover a broad exclusion, a narrower version and one addressing products and completed operations, together excluding bodily injury, property damage and personal or advertising injury arising out of or attributable to generative AI. The trigger language is wide enough to reach AI embedded in ordinary software rather than only custom-built systems, and the narrowing frequently appears in revised definitions and application questions rather than as a single conspicuous clause.
What is an AI sublimit and why does it matter?
A sublimit caps what a policy pays for a particular category of loss while leaving the master limit unchanged, and reporting indicates some cyber carriers are applying AI sublimits near a tenth of policy limit. Where AI is involved in most of an organization's data handling, that becomes the operative figure rather than a detail. The definition triggering the sublimit does more work than the number, since attaching when AI was involved in an event differs considerably from attaching when AI caused it. Modeling exposure per coverage line rather than in aggregate is how to assess whether the sublimit is adequate.
Do the new exclusions cover AI agents?
Underwriters have observed that they do not do so well. The endorsements were drafted around chatbots and generative output, while autonomous agents are the fastest-growing deployment category and the one most likely to raise attribution questions about who or what caused a loss. For an organization running agents, neither the exclusion nor an affirmative grant plainly contemplates the deployment. Describing it specifically in the submission rather than answering a generic AI question reduces the chance of a later dispute, and documentation of which agents act under whose authority serves as underwriting evidence.
How do you qualify for affirmative AI coverage?
Carriers writing AI risk deliberately price it against documented governance rather than against a questionnaire. Reported requirements cluster on a documented ability to stop an AI system, an inventory recording which systems operate and where human review applies, a data provenance and classification audit, and a named executive accountable for AI. Those are governance artifacts rather than security purchases. Litigation shaping underwriting files has consistently attached liability to the deploying organization rather than the model vendor, which is the assumption to plan around when assembling evidence.




