
After sixteen months writing AI liability insurance, the clearest change we have seen is not in what carriers exclude, it is in what your client's customers now demand in their contracts.
When Armilla launched its third-party AI liability product on 30 April 2025, the conversations we had with brokers were a mix of interest, intrigue and scepticism. Most of the debate was about whether AI risk was a real line or a rebranding of technology errors and omissions.
That debate has largely ended, and not because the exclusion question got settled. It ended because AI outcome guarantees started appearing in the master services agreements our insureds sign with their own customers.
This is what we learned in that year, drawn from bound policies, live submissions, and what brokers told us during our August 11 webinar, “The Emergence of the AI Insurance Market.”
Exposure and awareness rose together. AI moved from pilots into production across most of the middle market, litigation began arriving in volume, and high-profile security incidents involving frontier labs pushed AI risk onto boardroom agendas. Every news cycle increases the broker and insured enquiries reaching us.
What has not kept pace is clarity about which policy answers when an AI system causes harm. Reports from brokerages tracking AI claims describe outcomes split between covered, partially covered and not covered.
ISO has published a template exclusion for generative AI and an agentic AI template is in progress. Carriers have filed exclusionary language for approval, which signals intent, and we see exclusions applied case by case rather than portfolio-wide, most often in intellectual property and media forms.
Two exclusions deserve to be stated plainly, because they exist in technology errors and omissions policies today rather than being proposed. Contractual liability exclusions and employment practices exclusions are already in wide use.
That matters because AI agent exposure lands inside both. An agent screening job applicants creates employment practices exposure, and a guarantee about AI performance creates contractual liability exposure.
More carriers are taking affirmative positions by endorsement, updated definition, or standalone product, and new entrants keep announcing intentions to write the line. Sixteen months ago the field was close to empty.
Why? Because the policyholder funds the test case. Silent AI is the absence of language either granting or excluding the risk, which means the answer arrives through claims and case law rather than through the wording. Until then your client is carrying an argument, not a coverage position.
Andrew Correll, Armilla's Director of Underwriting, has watched this pattern before. "We're seeing a lot of silent AI being brought up very similar to what we saw in silent cyber," he said. "And what we found in cyber, and I think what we might experience over the next couple years in AI, is silent good enough?"
The brokers we polled reflected that uncertainty. Asked whether their clients' policies adequately cover AI exposures, 38% said they did not know and only 13% said yes.
We put a question to the room that reframes the standard. Where else would you accept "probably fine"? Not in a medical device that is probably safe, a flight system that probably lands, or bank controls that probably hold.
Affirmative cover holds AI assurance to the standard every other critical system meets.
That argument is already being run in court. Defending the New York Times copyright claims in February 2024, OpenAI described training data regurgitation and hallucination as "two uncommon and unintended phenomena", and argued that "any user who received such an output would immediately recognize it as a hallucination."
Set that against a legal technology company whose customers demand an indemnity precisely because a court sanctioned a lawyer who did not recognise it.
Errors, more than privacy breaches, and they land across four different forms. Of brokers polled, 78% said errors causing financial or physical harm concern their clients most, against 22% for data privacy and security. Privacy has a settled home in cyber, and errors do not.
An AI error can land in professional liability, employment practices liability, contractual liability or general liability, depending on what the system did and to whom. Three cases show the range.
No data was breached in the Air Canada matter. A system stated something untrue, a customer relied on it, and liability followed.
The Workday ruling repays a close read, because the mechanism matters more than the outcome. Claims survived on the theory that Workday acted as the employer's agent. The theory that Workday was itself an employment agency was dismissed without leave to amend.
That is the liability reversal, stated precisely. A vendor does not have to be the employer to carry the exposure. It only has to have been handed the decision. Workday's own filings put 1.1 billion rejected applications in the relevant period.
We have also seen the gap from the insured's side. One company asked its carrier to name its autonomous agent as a person on its employment practices policy, and the request was declined.
Agents in leasing, hiring and customer service all test forms drafted on the assumption that a person acted.
Enterprise buyers stopped accepting best efforts. Large customers now write AI outcomes into MSAs and SLAs, asking suppliers to guarantee accuracy, cap hallucination rates, or show evidence of AI insurance. The obligation arrives inside a deal cycle or a renewal, which makes it commercially urgent.
This is the single biggest change we have seen in a year, and it is where demand originates. The insured is usually a software company that cannot close or renew until it answers a new clause.
The copyright litigation is reshaping that clause. After final approval of the Bartz settlement, enterprise customers began asking application-layer providers for indemnities directly, rather than accepting the indemnity a foundation model provider passes through.
Courts are already routing AI disputes into contract, and the clearest examples sit inside our own industry. Two class actions concern an AI model used to make post-acute care coverage decisions.
In Barrows v. Humana, (W.D. Ky.), the court allowed breach of contract, breach of the implied covenant, unjust enrichment and common law fraud to proceed, while dismissing four statutory insurance claims with prejudice. Estate of Lokken v. UnitedHealth Group (D. Minn.) reached the same conclusion on the contract claims.
The court's framing is the line to keep: "the question is not whether the use of AI to make coverage opinions is prohibited under the Medicare Act, but whether insurance companies use of AI is in violation of its contract with insureds."
Read that as a broker. The statutory claims fell away and the contract claims survived. The enforceable promise is the one written into the agreement.
Specific, measurable promises about AI behaviour, mostly for AI solution providers selling into larger enterprises. Armilla writes two things: affirmative third-party AI liability insurance, and AI performance warranties structured as contractual liability insurance sitting behind the guarantee an insured gives its own customer.
The warranty responds when an agreed KPI is missed, with no requirement to prove an error in the model. That distinction is what makes these risks writable.
Five examples from bound policies and live submissions, anonymised by sector:
The common thread is that each insured could measure its own performance. Correll puts the underwriting reality plainly: "With AI, errors are a feature and not a bug, so to speak. So there are expected failure rates just within AI systems in general."
Providers often know their own numbers. The GitHub Copilot complaint quotes GitHub's own research finding that "about 1% of the time, a suggestion may contain some code snippets longer than ~150 characters that matches code from the training data." A measured rate is an underwritable one.
Underwriting AI is not a search for systems that do not fail. It is pricing a known error rate the insured can evidence and control.
Half the brokers we polled follow AI litigation closely. If you are in the other half, case law is the cheapest education on this line, and is accessible to brokers and partners through Armilla’s AI litigation database.
Ask the coverage question directly and treat uncertainty as a finding. Put "does this programme respond to an AI loss" to your client's existing tower, and review their customer contracts alongside the insurance. The AI obligations that create insurable interest are increasingly in the MSA, not the policy.
Three practical moves follow.
This article draws on Armilla's broker webinar of 11 August 2026, The Emergence of the AI Insurance Market, presented by Phil Dawson, who leads distribution at Armilla, and Andrew Correll, Armilla's Director of Underwriting. Case examples are anonymised by sector.
Live poll results, Armilla broker webinar, 11 August 2026. Respondents were brokers and distribution partners.
A note on the poll data. The percentages in this article come from live polls of a small group of brokers and distribution partners who chose to attend a session about AI insurance. They should be read as directional signals from that room, not as market consensus or as a representative survey of the brokerage community. Percentages are rounded to whole numbers.
Armilla AI is a Managing General Agent and a coverholder at Lloyd's, providing AI performance warranties and AI liability insurance to AI developers and deployers. Underwritten by certain underwriters at Lloyd's and other insurers. For informational purposes only and subject to underwriting review and policy terms.