The coverage is disappearing, mid-cycle, with little fanfare
In early 2026, some of the largest insurers in the country moved to carve artificial intelligence out of standard liability coverage.
Major carriers - including Chubb, Travelers, and Berkshire Hathaway - received state regulatory approval to add explicit AI exclusions to general liability, directors and officers (D&O), and errors and omissions (E&O) policies. According to reporting on those filings, regulators approved more than 80% of the requests. In several states, the exclusions began taking effect as early as January 2026.
This was triggered by a structural change at the top of the market. In January 2026, the Insurance Services Office (ISO) - which develops the standardized policy forms underpinning roughly 82% of U.S. property and casualty policies - introduced new generative-AI exclusion endorsements for commercial general liability. When ISO moves, the market follows.
Some carriers went further than exclusions on specific claims. Berkley Insurance filed an absolute AI exclusion for its D&O, E&O, and fiduciary lines - cutting coverage for claims arising from "any actual or alleged use, deployment, or development of Artificial Intelligence," under a definition broad enough to capture almost any modern software.
This is not a footnote change. It is a structural shift in what standard commercial policies cover - and it is happening right now, in the middle of the policy cycle, with very little attention directed at the people most affected.
Why this lands on your board personally
D&O insurance is not corporate coverage in the ordinary sense. It exists to protect directors and officers individually - the scenarios where personal assets are on the line for decisions made in their roles.
So when AI gets excluded from a D&O policy, the practical effect is direct: board members and executives can lose personal liability protection for AI-related claims.
And those claims are not hypothetical. The fastest-growing source of D&O exposure tied to AI isn't the technology failing - it's AI-washing: companies overstating AI capabilities in disclosures and investor communications. The legal theory is pointed. As one analysis put it, plaintiffs don't need to prove the AI failed - they need to prove the board failed to oversee it. Regulators have already acted on this theory: the SEC brought enforcement actions in 2025 against companies over alleged misrepresentations about their AI products.
Put those two facts together and the exposure sharpens: boards face AI-related liability on two fronts - the AI systems the company deploys, and how the company describes them - at precisely the moment the insurance that would have responded is being withdrawn.
This is the cyber playbook, running faster
None of this is unprecedented. The insurance market has done exactly this before - with cyber risk.
Cyber followed a predictable arc: first "silent" coverage under traditional policies, then exclusions as insurers recognized the exposure, then premium-priced affirmative endorsements, and eventually control-based underwriting - where coverage and terms depend on what the insured can demonstrate about how they manage the risk.
AI is moving through the same arc, only faster, because the playbook already exists. Exclusions are the current phase. But exclusions are rarely the end state. What follows is a market where coverage returns for those who can show they understand and are managing their AI exposure - and remains expensive or unavailable for those who can't.
The problem underneath: you can't manage what you can't see
Here is the part most boards have not confronted.
To navigate this shift - whether that means negotiating renewal terms, answering an underwriter's questions, or simply understanding what the board is now personally exposed to - you have to be able to answer a basic question: what does our AI actually make us responsible for?
Most organizations can't.
They can tell you which AI tools they use. Far fewer can tell you which regulations those tools trigger - the EU AI Act, GDPR, cross-border data transfer rules, sector and state laws - and what each one requires. The exposure is real and present. It has simply never been mapped.
A board cannot assess a risk it cannot see. And right now, a great many boards are personally on the hook for regulatory obligations that no one in the organization has ever identified.
Where LegisGate fits
LegisGate identifies the external regulatory obligations your AI tools create - every finding traced to its primary source.
We are not insurance advisors, and we don't restore coverage. What we do is make the underlying regulatory exposure visible: for a specific AI tool, in your specific use case and jurisdiction, here are the obligations that apply and what they require - cited, so you and your counsel can act on solid ground.
That is the foundation the rest of the conversation is built on. You can't evaluate your insurance position, answer an underwriter, or understand your board's exposure until you know what your AI actually makes you responsible for.
The laws are already here. The coverage may not be. The difference is knowing exactly where you stand.
This article is general information, not legal or insurance advice. Insurance coverage varies by carrier, policy, and jurisdiction and is evolving rapidly; consult your broker and counsel regarding your specific situation.
This article is for informational purposes only and does not constitute legal advice. AI regulatory intelligence and compliance requirements vary by organization, jurisdiction, and use case. Consult qualified legal counsel before making compliance determinations or relying on this content for any legal, regulatory, or business purpose.
