Your GL Renewal Just Excluded Generative AI. Your Vendor's Cap Is Twelve Months of Fees. Nobody Is Holding the Loss.

Since January 2026, every carrier writing general liability on standard US forms has had an endorsement available that removes generative AI from the policy, and the contracts your AI vendors already had you sign cap their liability at a year of fees while disclaiming the accuracy of anything their models produce. Put the two documents side by side and the loss from an AI system that does the wrong thing has no home. The carrier excluded it, the vendor capped it, and the enterprise in the middle retained it without anyone deciding to.

This is not an argument against deploying AI. It is an argument that the retained risk on an AI deployment is a balance sheet decision, that in most companies it is currently being made by omission, and that finding out where you actually stand takes an afternoon with three documents.

The AI insurance exclusion your broker may not have mentioned

In July 2025 Verisk, which writes the standard forms much of the US commercial market builds on, filed three optional endorsements for the commercial general liability policy with state regulators, effective 1 January 2026. CG 40 47 removes bodily injury, property damage and personal and advertising injury "arising out of" generative artificial intelligence. CG 40 48 removes personal and advertising injury only, and CG 35 08 does the same job inside the products and completed operations part. All three share one definition: a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code.

Two features of that wording matter more than the form numbers. Most US courts read "arising out of" broadly, as needing some causal connection rather than proximate cause, so a claim in which an AI system was a real link in the chain of events is arguably inside the exclusion. And the definition describes essentially every model your company has licensed since 2023, with no carve-back for human review, no threshold of AI contribution, and no distinction between a chatbot that misstated a policy and a forecasting model that recommended a reorder quantity.

The endorsements are optional, which should worry you rather than reassure you. Optional means a carrier can attach one at renewal without touching the base policy, and the policyholder finds out by reading the schedule of forms. Some carriers did not wait for Verisk. W.R. Berkley's form PC 51380, an "absolute" AI exclusion for its directors and officers, employment practices and fiduciary liability coverage parts, bars claims "based upon, arising out of, or attributable to" any actual or alleged "use, deployment, or development" of AI, and one sub-paragraph expressly excludes promises "made by a chatbot or virtual customer service agent." The Financial Times reported in November 2025 that AIG, Great American and Berkley had all sought regulator approval for AI exclusions. In April 2026 The Information reported, citing a Wolfe Research review of state filings, that regulators had approved more than 80 percent of AI exclusion filings from subsidiaries of Berkshire Hathaway, Chubb and Travelers.

Filings can be counted: by mid-2026 more than 40 insurance groups had a subsidiary file to adopt an AI exclusion. What nobody can count is how many renewals it has actually been attached to; Joe Lam, the Verisk vice president who helped write the endorsements, said in July 2026 that he did not know how many insurers were adopting them yet. That is exactly why the exposure is dangerous: the endorsement arrives on a renewal, a few pages in a thick stack, and nobody on the AI programme reads insurance schedules.

What the vendor already made you sign

The other half of the problem was in place long before the insurers moved, and it is not optional.

OpenAI's current Services Agreement, version 010126, states that each party's total liability will not exceed the total amount the customer paid to OpenAI during the twelve months immediately prior to the event giving rise to liability. Indirect, consequential and lost-profit damages are excluded. Section 4.3 makes the customer "solely responsible for all use of the Outputs and for evaluating the accuracy and appropriateness of Output for Customer's use case," and the warranty disclaimer adds that OpenAI makes no guarantee that output will be accurate. Anthropic's commercial terms cap damages at the fees paid in the previous twelve months, exclude consequential loss, and tell customers that outputs "may be false, incomplete, misleading" and should not be relied on without independent checking. SAP's current cloud terms cap aggregate liability in any twelve month period at the annual subscription fees paid for the specific cloud service associated with the damage.

The vendors do offer an indemnity, and it is worth being precise about it. OpenAI, Anthropic, Microsoft and Google will all defend you against a third-party claim that model output infringes someone's intellectual property, on paid tiers and subject to conditions such as leaving the content filters on, and at all four that indemnity sits outside the liability cap. It is real protection against one class of claim, copyright, and it does nothing for the claim that actually keeps a CFO awake: the system produced a wrong answer, an unauthorised action or a defamatory statement, and someone lost money or worse. That loss is a plain contract claim, inside the cap, and the cap is a year of fees.

For a company spending $400,000 a year with a model provider, the ceiling on recovery from that provider is $400,000, whatever the damage, short of proving gross negligence.

Three links, and nobody carrying the weight

Draw an enterprise AI deployment and it is a chain with three links: your customer, who relies on what the system says or does; you, who deployed it; and the vendor, whose model produced the output. Every link assumes the one below is carrying the weight. Your customer assumes you are insured. You assume the vendor is liable. The vendor's contract says the loss is yours, and your carrier's endorsement says it is not theirs.

The loss falls through the carrier's exclusion and the vendor's cap and lands on the enterprise, the only party that never wrote its position down.

The reason the carriers moved explains why the middle link is where the loss lands. Kevin Kalinich, who leads Aon's intangible assets practice, told the Financial Times that the industry could absorb a $400 million or $500 million loss from one company's misfiring agent, but not 1,000 or 10,000 correlated losses from an error at one AI provider. That is the systemic risk an insurer will not price: one model, deployed at thousands of companies, failing the same way on the same day. The vendor's twelve month cap exists for precisely the same reason, seen from the other side.

Both of the parties with the balance sheets to absorb a tail event have declined, in writing, to absorb this one. The enterprise, with neither the diversification of an insurer nor the scale of a model provider, is the only party left, and the only one that never wrote its position down.

Liability is expanding in the same year cover is contracting

If liability for AI output were still theoretical, none of this would matter much. It is not.

In February 2024 the British Columbia Civil Resolution Tribunal ordered Air Canada to pay the difference on a bereavement discount its chatbot said could be claimed after flying, which the airline's own policy did not allow. Air Canada's defence amounted to treating the chatbot as a separate entity responsible for its own actions; the tribunal called that "a remarkable submission" and found the airline liable for negligent misrepresentation. The award was 812 Canadian dollars. The principle was not small: a company answers for what its AI tells a customer.

In 2025 Wolf River Electric, a Minnesota solar installer, sued Google for at least $110 million after an AI Overview falsely stated that the state attorney general had sued the company for deceptive practices; the case is now back in Minnesota state court. On 28 May 2026 the Regional Court of Munich granted a preliminary injunction against Google over false statements in AI Overviews about a publisher and its subsidiary, holding the summaries to be Google's own content and Google directly liable for them; Google has said it will appeal, and a Berlin chamber took the opposite view in a trademark case days later, so the German courts are split rather than settled. And from 9 December 2026 the EU's revised Product Liability Directive, 2024/2853, applies to products placed on the market after that date, with software, including AI systems, treated as a product: the maker of a defective one is liable without fault for injury or property damage to individuals, and the claimant proves defect, damage and causation, not negligence.

So the year in which carriers gained a standard form to exclude AI is the same year in which tribunals, courts and the European legislature moved liability for AI output onto the companies that build and deploy it. Cover contracts, liability expands, and the two lines cross on the enterprise's balance sheet.

This is the cyber playbook, run faster

None of this is new to the insurance industry. It is the sequence it ran on cyber. In 2014 ISO introduced CG 21 06, the data breach exclusion for general liability, and the market spent the next five years arguing about "silent cyber," the exposure sitting inside policies that neither excluded nor affirmed it. Lloyd's ended the argument in 2019 by requiring every policy to say one or the other. The standalone cyber market that filled the gap took the better part of a decade to reach limits and wording a large enterprise could rely on.

The AI version is on a compressed clock. Affirmative products exist: Coalition folded an affirmative AI endorsement into its base cyber policy in 2025, Axa XL has offered a generative AI endorsement since October 2024 for companies building their own models, and Armilla, a Lloyd's coverholder, writes standalone AI liability with limits up to $25 million. Those are real, and a broker who knows the market can get you a quote. They are also small against the exposure. A $25 million limit next to a chain where the vendor's contribution is a year of fees and the general liability policy has stepped away is the first product in a market that will take years to mature, and the gap between the exclusion and the mature market is the period you are in now.

Why this lands on the CFO

The retained risk is not on anyone's ledger, and the reason is organisational. The broker sees the policy. Procurement sees the vendor contract. The AI team sees the deployment. Legal sees the customer terms. Nobody's job is to reconcile the four documents and write down the number that falls through.

That number is a self-insured retention the company took on without a decision. Self-insuring is legitimate; large companies do it deliberately all the time, with a captive, a reserve or a board minute. What is not legitimate is discovering the retention after the loss, in a claims letter citing an endorsement nobody flagged, on a deployment the vendor's contract had already placed outside its responsibility.

The Loss Ledger

The fix is a table with four columns, kept for every AI system that acts on or speaks to anyone outside the team that built it.

Column one: the carrier's position. Pull the current general liability, cyber, E&O and D&O policies and search the schedule of forms for CG 40 47, CG 40 48, CG 35 08 and any endorsement with "artificial intelligence" in its title. If one is present, ask the broker what it would cost to remove it, and what an affirmative carve-back for named processes would cost instead. If none is present, ask the carrier in writing to confirm the policy responds to AI-related claims. Silence is the silent cyber position, and it is not cover.

Column two: the vendor's position. For each model provider and each SaaS or ERP vendor with AI in the product, record the liability cap, the consequential damages exclusion, and whether the indemnity extends beyond intellectual property. Then decide, on paper, whether to negotiate a super-cap for AI output on your largest contracts or to accept the standard terms and record the retained amount. Either is defensible. Not knowing is not.

Column three: the customer's position. What did you promise downstream? Service levels, accuracy warranties, your own caps and exclusions. If your customer contract does not cap your liability for AI-assisted output the way your vendor capped theirs, you are carrying the risk on both sides.

Column four: the retained gap, and who signed it. Subtract what the carrier and the vendor will pay from a realistic loss scenario for each process, write down the residual, and have someone with authority sign it. That signature is the entire point. It converts an accident into a decision.

Then use the number. A retained gap in the millions on a process where an agent can act without a human above a threshold is an argument for the approval gate, not for cancelling the deployment. The circuit breaker I argued for on metered ERP agents is also the control that keeps a loss inside a cap you can recover.

The honest counterargument

The exclusions are optional and adoption is early. AIG told regulators it had no plans to implement its own yet and wanted the option. Your carrier may not have attached one, and a well-run programme may already have affirmative cover on the cyber policy that responds to the events you are most worried about.

All true, and none of it changes the argument. The point is not that you have lost cover; the point is that you do not know whether you have, and that the vendor cap is not optional, is in every contract already, and is the larger of the two holes. An afternoon with the schedule of forms and three master agreements settles the first question. The second was settled when procurement signed.

Where this lands

Do not stop deploying. The exposure I have described is a reason to know your position, not a reason to hold back a system that pays for itself, and every company in your sector is running the same chain with the same holes in it.

The market that prices tail risk for a living looked at generative AI and reached for an exclusion. The vendors who built the models looked at the same risk and reached for a cap. Both were right to protect themselves, and both did it in documents you signed or renewed. The only party in the chain that has not written down its position is you.

Write it down. Then decide whether you like it.


Shubhendu Tripathi is an AI and ERP strategy consultant based in Toronto, and the host of The Integration Layer, a podcast on AI, enterprise systems, and the work of making them fit together. Connect on LinkedIn or reach out at tripathis@qubittron.com.