The Underwriters Already Voted
Boards are still treating agentic AI liability as a question for later. The one industry that prices risk for a living answered it in January, and the answer was no.
AI² — ASYMMETRIC INTELLIGENCE & INNOVATIONESSAY · NO. 44
DAVID P. REICHWEIN · FOUNDER & CEO, AI² · 29 JULY 2026 · READING TIME 16 MIN
There is a particular kind of silence that precedes an expensive discovery, and it has a recognizable shape. Everyone in the room agrees the thing is important. Everyone agrees somebody should look into it. Nobody has looked into it, and the reason nobody has looked into it is that the analysis is unpleasant and no individual is accountable for producing it.
That is the current posture of most boards toward autonomous systems acting on the company's behalf. AI liability is filed under emerging risk, which is corporate for later.
But somebody did the analysis. An entire industry did it, at scale, with actuarial rigor, because their money was on the table rather than their reputation.
The insurers ran the numbers and declined the exposure.
An exclusion is not an opinion. It is a priced judgment by people who lose money for being wrong.
This matters more than any survey of executive sentiment, any consulting deck, any regulatory consultation paper. Underwriters do not have positions on technology. They have loss models. When a carrier writes an exclusion, it is publishing the conclusion of an analysis it paid for and intends to act on — and unlike almost every other opinion circulating about AI risk, this one is backed by capital.
What follows is what they concluded, how to read it, and what it implies for anyone who has already deployed.
SECTION ONE
What actually happened
The shift was not gradual. It was a structural break compressed into about twelve months, and most of the companies affected have not read their own renewal documentation closely enough to know it happened.
THROUGH 2024 — THE SILENT PERIODAI risk is addressed implicitly. Cyber policies respond to breaches involving AI systems; technology errors-and-omissions responds to software failures. Nothing in the forms mentions AI, so carriers adjudicate AI claims under pre-existing language. The industry later names this condition silent AI.
2025 — THE QUESTIONNAIRES ARRIVETransitional exclusions appear. AI disclosure questionnaires become standard at renewal. Brokers begin asking whether the firm uses AI, where, and under what oversight. Most firms treat this as paperwork.
JANUARY 2026 — THE FORMS CHANGEThe Insurance Services Office introduces standard generative AI exclusion endorsements for commercial general liability, effective 1 January. The language is broad enough to bar coverage where AI is only a contributing factor. Parallel exclusion language begins appearing across D&O and E&O forms.
THROUGH H1 2026 — THE CARRIERS FILEMajor carriers file for regulatory approval to attach AI exclusions across general liability, D&O and E&O. W.R. Berkley confirms an absolute AI exclusion across D&O, E&O and fiduciary lines. Reporting indicates the large majority of filed requests were approved, with some taking effect mid-cycle.
SIMULTANEOUSLY — THE AFFIRMATIVE MARKET OPENSStandalone AI liability products emerge and expand: Lloyd's-backed programs, dedicated MGAs, affirmative endorsements from cyber carriers, standalone limits reaching into the tens of millions. Coverage is available. It is simply no longer included.
Read those last two entries together, because the combination is the whole story. This is not a market refusing to cover AI. It is a market unbundling AI — stripping it out of the policies where it had been silently included, and offering it back as a separately underwritten, separately priced, separately conditioned product.
That distinction matters enormously, and almost everyone gets it backwards.
WHAT UNBUNDLING MEANS
When an industry moves a risk from silent inclusion to explicit exclusion plus optional affirmative cover, it is not saying the risk is uninsurable.
It is saying the risk is large enough, and variable enough between buyers, that it can no longer be averaged across the book.
Which is a statement about your company specifically. Under the old regime you were covered because everyone was. Under the new one, you are covered only if you can demonstrate you are not the bad case.
SECTION TWO
How to read an exclusion
Most executives read an exclusion as a legal document. It is more usefully read as an intelligence product.
Insurers exclude a peril for one of four reasons, and each reason tells you something specific about what their analysts found. Working out which reason applies is more informative than any amount of vendor assurance.
REASON FOR EXCLUSIONWHAT IT MEANS THEY FOUNDUnbounded severityNo credible ceiling on a single loss. The tail is not fat, it is open.Untraceable causationWhen it goes wrong, nobody can establish what caused it or who is responsible. Claims cannot be adjudicated, only litigated.Correlation across the bookThe same failure hits many insureds at once. Diversification, which is the entire basis of insurance, stops working.No actuarial baseInsufficient loss history to price at any confidence. The premium would be a guess.
Agentic AI triggers all four, and it is worth being precise about why, because the reasoning is not hand-waving.
Severity is unbounded because an autonomous system executes at machine tempo across every case simultaneously. A human employee who makes a bad judgment produces one bad outcome and then, usually, notices. A system with a flawed objective produces the same bad outcome ten thousand times before the first complaint is filed. The loss does not scale with the error. It scales with throughput.
Causation is untraceable in precisely the way insurance requires it to be traceable. A claim needs a chain: this action, by this actor, under this authority, produced this harm. Where an output was shaped by training data, a system prompt, a retrieval layer, a vendor's undisclosed update, and a configuration set by an employee who has since left, the chain does not resolve. It disperses.
Correlation is severe because the industry has concentrated on a handful of foundation models. Thousands of insureds are running variations of the same underlying system. A defect at that layer is not a series of independent events. It is one event with thousands of claimants, which is the exact shape of loss that destroys an insurer.
And the actuarial base does not exist, because the deployment pattern is roughly three years old and the claims that will define the category have not yet been litigated.
Four independent reasons to exclude, all firing at once. The remarkable thing is not that they moved. It is that they waited this long.
SECTION THREE
Evidence is now the currency
Here is where the story turns from insurance news into a governance argument, and it is the part most worth a board's attention.
The market did not simply split into covered and uncovered. It split on a specific criterion, and the criterion was not size, sector, or spend. Firms that entered 2026 with documented governance evidence obtained affirmative coverage, heavily conditioned. Firms that could not produce it received absolute exclusions.
The decision was not the buyer's to make. It was the underwriter's, made on the basis of what the buyer could demonstrate.
And note carefully what underwriters are asking to see. Not policies. Not commitments. Not an AI ethics statement or a responsible-use framework or a slide about the company's principles.
WHAT UNDERWRITERS ARE ACTUALLY REQUESTING
Timestamped review logs. Version control documentation. Audit trails. Governance records demonstrating contemporaneous compliance — evidence created at the time the decision was made, not attestations assembled afterward.
A live inventory of every model and tool in use, including third-party APIs, internal models, coding assistants and support bots, with a record of what data each one can reach.
Documented authorization points: which actions the system may take on its own, which require a person, and proof that the boundary was enforced rather than merely stated.
Read that list with an engineer's eye and notice what it describes. It is not a compliance regime. It is an audit trail of authorization.Who permitted what, when, on what basis — and can you prove it now, under adverse examination, years later.
The insurance industry, pursuing nothing but its own solvency, has independently arrived at the position I have been arguing from the direction of systems engineering: that the governing question about an autonomous system is not what it can do but what it was permitted to do, and that a permission which cannot be evidenced did not functionally exist.
They did not get there through philosophy. They got there through loss modeling, which is a considerably harder test.
SECTION FOUR
The chain nobody has traced
Ask the liability question plainly. An agentic system takes an action on behalf of a company — approves a claim, sets a price, sends a communication, screens a candidate, adjusts a safety parameter — and the action causes harm.
Who is liable?
Run the chain and watch where it fails.
THE CHAIN
The model vendor
→ indemnity in most enterprise agreements is capped, often at
fees paid, and carved out for customer configuration
The integrator or deployer
→ liable for negligent implementation, if negligence can be
established — see: untraceable causation
The system itself
→ not a legal person. Holds no assets. Cannot be sued,
deterred, deposed, or disciplined.
The employee who operated it
→ increasingly the residual holder, which is why documenting
your own AI use has become a personal matter
The officer who authorized deployment
→ the D&O question, and the reason this essay exists
The company
→ strictly liable in most consumer-facing scenarios,
with coverage that was just excluded
Notice the structural oddity. Liability requires a decider. Doctrine, insurance and litigation all assume that somewhere behind a harmful act there was a person who chose, and that person's choice is what gets examined.
An autonomous system produces acts without that person. Not because responsibility vanished, but because it relocated — backward in time, to whoever authorized the system to act unsupervised in that domain.
WHERE IT LANDS
When no human decided the specific act, the examination moves to whoever decided the system could act at all.
That is a deployment authorization, and in most companies it was never formally made. A pilot became a rollout. A rollout became infrastructure. No document, no date, no name.
Which means the officer whose signature would have appeared on that authorization now carries its consequences without ever having had the opportunity to decline them.
This is the same structure I wrote about earlier this month in the context of measurement: the highest-consequence decision in the system, made by nobody, on no date, with no paperwork. There the unsigned artifact was the success metric. Here it is the deployment authorization.
The difference is that in this case the party who noticed first was not an essayist. It was an underwriter with a loss model, and the notification arrived as an exclusion.
SECTION FIVE
Why the policy binder does not help
Most organizations that take AI governance seriously have produced a document. Principles, acceptable use, human oversight commitments, a review board, mandatory training. It represents real effort by serious people.
It will not survive contact with a claims examiner, and the reason is instructive.
There is a well-established failure pattern in cyber insurance: a company attests on its application to a control it has — multi-factor authentication, most commonly — suffers a loss, and then cannot produce evidence the control was actually operating at the time. The claim is denied not because the loss was uncovered but because the representation was unsupported.
The same mechanism is now being pointed at AI governance attestations. You will be asked what controls you represented at binding. You will be asked to evidence that they operated on the date of loss. A policy document establishes that you intended a control. It does not establish that one existed.
A policy is a statement of intent. A control is a thing that stops something. Only one of them is admissible.
This is the distinction I have argued for years in a different vocabulary. Hardware enforces. Software begs. A written guideline requests that a system not exceed its authority. A control makes exceeding it impossible. Under normal conditions the difference is philosophical. In a claims examination it is the difference between a policy that pays and a very expensive PDF.
THE PRACTICAL TEST
For any AI control you believe you have, ask one question: if someone wanted to bypass this, what would stop them?
If the answer is that it would violate policy, that they would be reprimanded, or that they know better — you do not have a control. You have an expectation.
If the answer is that the system would refuse, the action would fail, or the request would halt for authorization and generate a record — you have a control, and it will produce the evidence an underwriter wants without anyone having to remember to write it down.
SECTION SIX
The gap, priced
I have spent several years arguing that the defining structural failure of this era is what I call the Authorization Gap™: capability scaling faster than the architecture governing what capability is permitted to do. Systems that can act arriving ahead of the structures that decide whether they should.
It has been, until recently, an argument I made to rooms that found it interesting and filed it under important-but-not-urgent. The gap was real but abstract. Nobody had put a number on it.
The insurance industry has now put a number on it. The number is the difference between your premium with affirmative AI coverage and your premium without it — and for firms that cannot evidence their controls, the number is that the coverage is not available at any price.
THE CONVERGENCE
An underwriter and a systems engineer ask the same question in different words.
The engineer asks: what is this system permitted to do, and what enforces the boundary?
The underwriter asks: what is this system permitted to do, and can you prove the boundary held?
They are the same question. One of them now has a price attached, which is the only form in which most institutions have ever been able to hear it.
This is why the regulatory picture, while genuinely consequential, is not where I would direct a board's attention first. State adoption of the NAIC model bulletin, the Colorado act, the EU phases — these arrive with consultation periods, implementation runways and enforcement discretion. They can be prepared for on a schedule.
The insurance market does not work that way. A renewal date is a hard boundary that arrives whether or not you are ready, and the terms on offer are set by evidence you either accumulated over the preceding year or did not. There is no retroactive path. Contemporaneous means contemporaneous.
Regulation will eventually compel governance. Insurance is compelling it now, on a twelve-month cycle, using the only mechanism that has ever reliably moved a board.
SECTION SEVEN
What to do before renewal
Concrete, in the order I would run it.
Pull your actual policies. Not the summary, not the broker's overview — the endorsement schedule. Look for AI exclusion language across general liability, D&O, E&O and cyber. Assume it is present until you have read otherwise. Many companies acquired these exclusions mid-cycle without a conversation.
Establish the inventory. Every model, API, assistant and agent in operation, what data each can reach, and what actions each can take without a human. Most organizations discover the inventory is substantially larger than leadership believed, and that discovery is itself the most valuable output of the exercise.
Identify the authorization points. For each system, the specific boundary between what it does alone and what requires a person. Write it down. If no such boundary exists, that is the finding.
Test each boundary against the bypass question. If someone wanted to exceed it, what would stop them? Sort your controls into enforced and expected. Underwriters will do this sorting whether or not you do; better to know your own answer first.
Instrument for contemporaneous evidence. Logs generated automatically at the time of decision, not reports assembled at renewal. If producing the evidence requires anyone to remember anything, it will not be there when it matters.
Name the deployment authorizer. For each consequential system: who authorized it to act unsupervised, on what date, on what basis. If there is no name, this is the moment to establish one — before an examiner does it for you.
That last item is the one that will meet resistance, for exactly the reason the whole pattern persists. Signing creates accountability for failure and confers nothing for success. Nobody wants their name on it.
But the name is going to be attached regardless. The only variable is whether it is attached deliberately, in advance, by someone who understood what they were accepting — or reconstructed afterward by opposing counsel, from calendar entries and email threads, in the least favorable light available.
CLOSE
The trigger event
One more observation, offered as a watch item rather than a prediction.
The market has moved a long way on analysis alone. Exclusions have been filed, approved and attached without a single widely reported claim denial to point at. The industry is pricing a loss it has modeled but not yet experienced — which is, incidentally, exactly what a well-functioning insurance market is supposed to do.
The first publicized denial of an AI-related claim will change the tempo. Not because it will reveal anything the underwriters do not already know, but because it will convert a modeled loss into a reported one, and every board that filed this under later will suddenly find it filed under now. Form-side change accelerates. Terms harden. The firms that spent the intervening period accumulating evidence will find themselves in a different market from the ones that did not.
That event has not happened yet. It is the last quiet interval, and it is worth using.
The people whose entire profession is pricing risk looked at autonomous systems acting on a company's behalf, ran the numbers, and declined.
Boards are still asking whether AI governance is worth the investment. The market that would have to pay for the failure has already answered, in the only language it speaks, and the answer is on the endorsement schedule of a policy most executives have never personally read.
Capability is not authority. It never was. The difference is that the cost of pretending otherwise now appears on a renewal quote.
SOURCES & FIGURES
ISO/Verisk generative AI exclusion endorsements for commercial general liability, effective January 2026.
Carrier filings and regulatory approvals for AI exclusions across GL, D&O and E&O lines; W.R. Berkley absolute AI exclusion across D&O, E&O and fiduciary.
Silent AI, coverage fragmentation and the affirmative market: Fenwick; Aon, AI Risk 2026; Hinshaw & Culbertson D&O trends.
Underwriting evidence requirements and the 2025–2026 market bifurcation: professional liability market reporting.
Regulatory backdrop: NAIC AI Model Bulletin state adoption; Colorado AI Act; EU AI Act phased obligations.
Positions described are current as of 29 July 2026 and are moving continuously. Nothing here is legal, insurance or financial advice; confirm your own position with your broker and counsel.
David P. Reichwein — Founder & CEO, AI²
Pattern > Noise. 🌹∞
© 2026 Asymmetric Intelligence & Innovation. All rights reserved.
Ai2advisory.com


