Lessons from a year of underwriting AI liability insurance

August 18, 2026
5 min read

After sixteen months writing AI liability insurance, the clearest change we have seen is not in what carriers exclude, it is in what your client's customers now demand in their contracts.

When Armilla launched its third-party AI liability product on 30 April 2025, the conversations we had with brokers were a mix of interest, intrigue and scepticism. Most of the debate was about whether AI risk was a real line or a rebranding of technology errors and omissions.

That debate has largely ended, and not because the exclusion question got settled. It ended because AI outcome guarantees started appearing in the master services agreements our insureds sign with their own customers.

This is what we learned in that year, drawn from bound policies, live submissions, and what brokers told us during our August 11 webinar, “The Emergence of the AI Insurance Market.”

TL;DR

  • Of brokers polled during our webinar, 38% said they did not know whether their clients' current policies adequately cover AI-related exposures, and only 13% said the policies do.
  • 78% named errors causing financial or physical harm as their clients' leading AI concern, against 22% for data privacy and security.
  • ISO has published a template exclusion for generative AI, with an agentic AI template in progress, and some carriers have filed exclusionary language for approval. AI exclusions are emerging rather than broadly in force.
  • Contractual liability and employment practices exclusions in technology errors and omissions policies exist today, and that is where much AI agent exposure lands.
  • Enterprise buyers now write AI outcome guarantees into MSAs and SLAs, which creates insurable demand ahead of any coverage debate.
  • 54% of organisations with 1 billion dollars or more in revenue are actively deploying AI agents, up from 12% in 2024, per the KPMG US AI Quarterly Pulse Survey, Q1 2026, based on 237 US C-suite and business leaders surveyed 17 February to 17 March 2026.

What changed in the AI insurance market over the past year?

Exposure and awareness rose together. AI moved from pilots into production across most of the middle market, litigation began arriving in volume, and high-profile security incidents involving frontier labs pushed AI risk onto boardroom agendas. Every news cycle increases the broker and insured enquiries reaching us.

What has not kept pace is clarity about which policy answers when an AI system causes harm. Reports from brokerages tracking AI claims describe outcomes split between covered, partially covered and not covered.

AI exclusions are emerging

ISO has published a template exclusion for generative AI and an agentic AI template is in progress. Carriers have filed exclusionary language for approval, which signals intent, and we see exclusions applied case by case rather than portfolio-wide, most often in intellectual property and media forms.

Two exclusions deserve to be stated plainly, because they exist in technology errors and omissions policies today rather than being proposed. Contractual liability exclusions and employment practices exclusions are already in wide use.

That matters because AI agent exposure lands inside both. An agent screening job applicants creates employment practices exposure, and a guarantee about AI performance creates contractual liability exposure.

More carriers are taking affirmative positions by endorsement, updated definition, or standalone product, and new entrants keep announcing intentions to write the line. Sixteen months ago the field was close to empty.

Silent AI costs your client rather than the carrier

Why? Because the policyholder funds the test case. Silent AI is the absence of language either granting or excluding the risk, which means the answer arrives through claims and case law rather than through the wording. Until then your client is carrying an argument, not a coverage position.

Andrew Correll, Armilla's Director of Underwriting, has watched this pattern before. "We're seeing a lot of silent AI being brought up very similar to what we saw in silent cyber," he said. "And what we found in cyber, and I think what we might experience over the next couple years in AI, is silent good enough?"

The brokers we polled reflected that uncertainty. Asked whether their clients' policies adequately cover AI exposures, 38% said they did not know and only 13% said yes.

We put a question to the room that reframes the standard. Where else would you accept "probably fine"? Not in a medical device that is probably safe, a flight system that probably lands, or bank controls that probably hold.

Affirmative cover holds AI assurance to the standard every other critical system meets.

That argument is already being run in court. Defending the New York Times copyright claims in February 2024, OpenAI described training data regurgitation and hallucination as "two uncommon and unintended phenomena", and argued that "any user who received such an output would immediately recognize it as a hallucination."

Set that against a legal technology company whose customers demand an indemnity precisely because a court sanctioned a lawyer who did not recognise it.

AI failures that are producing claims, and where they land

Errors, more than privacy breaches, and they land across four different forms. Of brokers polled, 78% said errors causing financial or physical harm concern their clients most, against 22% for data privacy and security. Privacy has a settled home in cyber, and errors do not.

An AI error can land in professional liability, employment practices liability, contractual liability or general liability, depending on what the system did and to whom. Three cases show the range.

Case Failure mode What it established
Moffatt v. Air Canada, BC Civil Resolution Tribunal, 2024 Hallucination A support chatbot described a bereavement fare policy that did not exist. The tribunal held the airline liable for what its chatbot said.
Mobley v. Workday, N.D. Cal., claims sustained July 2024, ADEA collective conditionally certified May 2025 Bias Age discrimination claims over an AI applicant recommendation system proceeded against the software vendor on the theory that it acted as the employer's agent.
Bartz v. Anthropic, N.D. Cal., final approval July 2026 Intellectual property A 1.5 billion dollar settlement over training data drawn from pirated books, the largest copyright settlement in US history.

No data was breached in the Air Canada matter. A system stated something untrue, a customer relied on it, and liability followed.

The Workday ruling repays a close read, because the mechanism matters more than the outcome. Claims survived on the theory that Workday acted as the employer's agent. The theory that Workday was itself an employment agency was dismissed without leave to amend.

That is the liability reversal, stated precisely. A vendor does not have to be the employer to carry the exposure. It only has to have been handed the decision. Workday's own filings put 1.1 billion rejected applications in the relevant period.

We have also seen the gap from the insured's side. One company asked its carrier to name its autonomous agent as a person on its employment practices policy, and the request was declined.

Agents in leasing, hiring and customer service all test forms drafted on the assumption that a person acted.

AI guarantees are appearing in customer contracts

Enterprise buyers stopped accepting best efforts. Large customers now write AI outcomes into MSAs and SLAs, asking suppliers to guarantee accuracy, cap hallucination rates, or show evidence of AI insurance. The obligation arrives inside a deal cycle or a renewal, which makes it commercially urgent.

This is the single biggest change we have seen in a year, and it is where demand originates. The insured is usually a software company that cannot close or renew until it answers a new clause.

The copyright litigation is reshaping that clause. After final approval of the Bartz settlement, enterprise customers began asking application-layer providers for indemnities directly, rather than accepting the indemnity a foundation model provider passes through.

Courts are already routing AI disputes into contract, and the clearest examples sit inside our own industry. Two class actions concern an AI model used to make post-acute care coverage decisions.

In Barrows v. Humana, (W.D. Ky.), the court allowed breach of contract, breach of the implied covenant, unjust enrichment and common law fraud to proceed, while dismissing four statutory insurance claims with prejudice. Estate of Lokken v. UnitedHealth Group (D. Minn.) reached the same conclusion on the contract claims.

The court's framing is the line to keep: "the question is not whether the use of AI to make coverage opinions is prohibited under the Medicare Act, but whether insurance companies use of AI is in violation of its contract with insureds."

Read that as a broker. The statutory claims fell away and the contract claims survived. The enforceable promise is the one written into the agreement.

What is actually being underwritten right now

Specific, measurable promises about AI behaviour, mostly for AI solution providers selling into larger enterprises. Armilla writes two things: affirmative third-party AI liability insurance, and AI performance warranties structured as contractual liability insurance sitting behind the guarantee an insured gives its own customer.

The warranty responds when an agreed KPI is missed, with no requirement to prove an error in the model. That distinction is what makes these risks writable.

Five examples from bound policies and live submissions, anonymised by sector:

  1. AI-powered loan decisioning. The client's problem was institutional trust rather than accuracy. We evaluated the model on performance, fairness and robustness, then warranted against measurable underperformance so lenders could adopt without extended pilots.
  2. Autonomous voice and chat customer service agents. Agents answering enterprise customers with no human in the loop. The insured was ISO 42001 certified with monitoring that had brought measured hallucination rates in production from four to five percent down to under one percent. Bound as standalone affirmative primary cover, not an endorsement.
  3. Generative media, intellectual property indemnity. A platform chaining more than twenty third-party models wanted to indemnify enterprise customers against IP claims on generated output.
  4. Agentic accessibility compliance. An agent scans e-commerce storefronts for accessibility violations, applies fixes and runs human quality assurance. The warranty responds if a screened and remediated storefront still draws an ADA claim.
  5. Legal technology, hallucinated output. Court sanctions for fabricated authority made an indemnity against hallucinated citations a purchase condition, so the warranty tied to an agreed accuracy metric rather than proof of model error.

The common thread is that each insured could measure its own performance. Correll puts the underwriting reality plainly: "With AI, errors are a feature and not a bug, so to speak. So there are expected failure rates just within AI systems in general."

Providers often know their own numbers. The GitHub Copilot complaint quotes GitHub's own research finding that "about 1% of the time, a suggestion may contain some code snippets longer than ~150 characters that matches code from the training data." A measured rate is an underwritable one.

Underwriting AI is not a search for systems that do not fail. It is pricing a known error rate the insured can evidence and control.

Half the brokers we polled follow AI litigation closely. If you are in the other half, case law is the cheapest education on this line, and is accessible to brokers and partners through Armilla’s AI litigation database.

What you should do at your next renewal

Ask the coverage question directly and treat uncertainty as a finding. Put "does this programme respond to an AI loss" to your client's existing tower, and review their customer contracts alongside the insurance. The AI obligations that create insurable interest are increasingly in the MSA, not the policy.

Three practical moves follow.

  1. Separate the errors conversation from the privacy conversation. Your client's leading AI worry is probably an error with financial consequences, and that does not live in the cyber policy.
  2. Ask which forms assume a human acted. Employment practices, professional liability and media forms were drafted for people. Autonomous agents test all three.
  3. Find the AI nobody procured. Agents built directly on frontier platforms often have no vendor contract, so they will not show up in a vendor review.

About this article and its data

This article draws on Armilla's broker webinar of 11 August 2026, The Emergence of the AI Insurance Market, presented by Phil Dawson, who leads distribution at Armilla, and Andrew Correll, Armilla's Director of Underwriting. Case examples are anonymised by sector.

Full poll results

Poll question Results
How many of your clients are actively using AI in their business today? Most of them 64%, roughly half 18%, nearly all 9%, a handful 9%
Are you aware of AI-related litigation affecting industries your clients operate in? Yes, closely following it 50%, not tracking but would like to 30%, aware but not tracking closely 20%
Which AI risk concerns your clients most? Errors causing financial or physical harm 78%, data privacy and security 22%
Do you believe your clients' current policies adequately cover AI-related exposures? Partially 38%, I do not know 38%, no 13%, yes 13%
In the past year, how often have clients asked you about AI-specific coverage? Several times 50%, once or twice 30%, regularly 20%

Live poll results, Armilla broker webinar, 11 August 2026. Respondents were brokers and distribution partners.

A note on the poll data. The percentages in this article come from live polls of a small group of brokers and distribution partners who chose to attend a session about AI insurance. They should be read as directional signals from that room, not as market consensus or as a representative survey of the brokerage community. Percentages are rounded to whole numbers.

Armilla AI is a Managing General Agent and a coverholder at Lloyd's, providing AI performance warranties and AI liability insurance to AI developers and deployers. Underwritten by certain underwriters at Lloyd's and other insurers. For informational purposes only and subject to underwriting review and policy terms.

Share this post

Ready to Insure Your AI?

Armilla’s AI insurance is your fail-safe against fast-evolving AI risks. We combine deep technological insight with robust insurance solutions so you can focus on innovation, without interruption.
Get in Touch