Your customer service chatbot just promised a refund policy that doesn't exist. A customer took a screenshot, demanded the refund, and threatened to sue when you said no. You call your insurance broker expecting your general liability policy to have your back — and instead you learn it might not, because your carrier quietly added an AI exclusion at your last renewal and nobody flagged it for you.
This isn't a hypothetical. In 2024, a Canadian tribunal held Air Canada liable after its website chatbot invented a bereavement-fare discount that didn't match the airline's actual policy — the airline argued the bot was "a separate legal entity responsible for its own actions," and the tribunal rejected that argument outright. Companies are on the hook for what their AI says, full stop. The open question for 2026 is whether your insurance is on the hook too — and increasingly, the answer is no.
What Changed: Insurers Are Writing AI Out of Standard Policies
For most of the generative AI boom, coverage questions lived in a gray zone. If your business used a chatbot, an AI drafting tool, or an automated decision system and something went wrong, your existing commercial general liability (CGL) or errors & omissions (E&O) policy probably covered it — not because anyone designed it that way, but because nobody had written AI in or out.
That gray zone is closing fast. In late 2025 and into 2026, major carriers — including large names in commercial liability like Chubb, Travelers, and Berkshire Hathaway — sought and received state regulatory approval to add explicit AI exclusions to general liability, directors and officers, and errors and omissions policies. More than 80% of those exclusion requests were approved.
The Insurance Services Office (ISO), which drafts the standardized policy language most U.S. commercial carriers build from, introduced two new optional endorsements specifically for this:
- CG 40 47 — a broad exclusion applying to both bodily injury/property damage coverage and personal/advertising injury coverage. Under this endorsement, harms traced back to generative AI output — defamatory statements, IP infringement in AI-generated marketing copy, even physical damage if an AI-driven process caused it — can fall outside your policy entirely.
- CG 40 48 — a narrower version that excludes only personal and advertising injury claims (think: AI-generated content that defames someone or infringes a trademark), while leaving bodily injury and property damage coverage intact.
Separately, "absolute AI exclusions" are showing up in management and professional liability lines — D&O, employment practices liability, and fiduciary liability policies — that go further and eliminate coverage for essentially any claim connected to AI use, not just generative AI specifically.
What's Actually Falling Through the Gap
The exclusions aren't limited to exotic AI failures. They can reach into everyday small-business AI use:
- Chatbot and virtual agent statements. If your support bot promises a policy, price, or warranty term that doesn't match reality — the Air Canada scenario — the resulting claim may be excluded.
- AI-generated marketing or product content. Blog copy, product descriptions, or ad creative drafted with an AI writing tool that turns out to defame a competitor or lift copyrighted material can trigger a personal/advertising injury exclusion.
- Automated decisions that cause harm. AI-assisted hiring screens, pricing engines, or credit decisions that produce a discriminatory or harmful outcome can fall under an absolute AI exclusion in your employment practices or D&O coverage.
- Inadequate AI governance. Some exclusion language is written broadly enough that simply lacking documented AI oversight — not having a policy for who reviews AI outputs before they reach a customer — can itself be treated as an aggravating factor in a coverage dispute.
- Regulatory investigations. If your state's AI-specific rules (several states, including Colorado, have moved on this) trigger an inquiry into automated decision-making, defense costs for that investigation may not be covered either.
The unifying thread: even incidental AI use — a chatbot widget, an AI grammar checker, an automated invoice-matching tool — can be enough to trigger exclusion language that was written with worst-case AI product liability in mind, not your specific low-risk use case. The exclusions generally don't distinguish between "AI is our core product" and "we use an AI tool for one part of our workflow."
Why Small Businesses Are the Most Exposed
Larger enterprises typically have risk management teams reviewing renewal language line by line, and many can afford dedicated AI liability coverage as a rider. Small and mid-sized businesses usually don't have either. Renewal packets arrive, a broker highlights the premium change, and a new exclusion endorsement slides through unnoticed because nobody is specifically looking for it.
That exposure is compounding because AI adoption among small businesses has moved fast. Surveys put small-business AI usage in some form as high as 89% in 2026, up sharply from just a few years earlier, with the most common uses being AI writing and content tools, customer service chatbots, and scheduling or admin automation. In other words, the exact tools most likely to trigger an AI exclusion — customer-facing chatbots and AI-generated content — are also the most widely adopted ones. Most business owners installed a chatbot widget or turned on an AI writing assistant without ever asking their insurance broker whether it changed their coverage.
What to Do Before Your Next Renewal
1. Ask your broker directly whether your policy has an AI exclusion endorsement — don't wait for renewal to find out. Request the actual endorsement language (CG 40 47, CG 40 48, or a carrier's proprietary equivalent), not just a summary. Broad exclusions and narrow ones look similar in a renewal cover letter but behave very differently in a claim.
2. Inventory your actual AI usage. List every AI tool touching customer interactions, content, hiring, pricing, or financial decisions — including tools embedded in software you didn't choose specifically for AI (many CRMs, help-desk platforms, and e-commerce tools have quietly added AI features that are on by default).
3. Put a human-review step in front of anything AI-generated that reaches a customer or regulator. A documented review process is both a practical risk reducer and something you can point to if a carrier or plaintiff argues you had inadequate AI governance.
4. Ask about standalone AI liability coverage. A market for this now exists specifically because standard policies are pulling back — carriers including Munich Re and Lloyd's-backed programs (some through the MGA Armilla, now a Lloyd's coverholder dedicated to AI liability) offer standalone policies with limits from roughly $2 million up to $25–50 million that explicitly cover AI-specific losses like hallucinations, model drift, and inaccurate outputs — the exact scenarios standard exclusions carve out.
5. Revisit vendor and customer contracts. If you use a third-party AI tool (a chatbot vendor, an AI scheduling platform), check who bears liability when that tool malfunctions. Don't assume your vendor's insurance covers you — get it in writing.
The Bookkeeping Angle: Insurance Costs Are a Line Item You Need to See Clearly
Whether you keep your current CGL policy, add an AI exclusion buyback endorsement, or purchase standalone AI liability coverage, the premium difference needs to show up somewhere in your books — and it needs to be visible enough that you notice when it changes. A surprisingly common failure mode isn't ignoring insurance costs entirely; it's burying every policy under one generic "Insurance Expense" account, so a $3,000 jump from adding AI coverage (or a gap from not adding it) never stands out on a P&L until someone goes looking.
Splitting insurance into sub-accounts — general liability, E&O/professional liability, cyber, and any standalone AI liability rider — makes it trivial to see exactly what you're paying for which risk, and to justify that spend if you ever need to explain a coverage decision to a lender, an auditor, or a new business partner. This is exactly the kind of structural clarity that plain-text accounting is built for: each policy is its own account in your ledger, version-controlled alongside every other transaction, so the history of what you were covered for — and when that changed — is permanently auditable rather than living in a stack of PDF renewal notices.
Keep Your Financial Records as Clear as Your Coverage
As AI tools become a standard part of running a small business, understanding exactly what your insurance does and doesn't cover is now as important as understanding your lease or your payroll obligations. Beancount.io gives you plain-text accounting that's transparent, version-controlled, and easy to audit — so when you add a new insurance line item, a new AI tool subscription, or any other change to how you run the business, it's tracked clearly from day one, not reconstructed after the fact. Get started for free and see why finance-minded business owners are switching to plain-text accounting for records they can actually trust.