The Exclusion Is the Spec

Carriers spent July filing to strip generative AI out of commercial liability policies. An industry whose entire product is getting paid to accept risk wants no part of this one — not because AI is dangerous, but because everyone's AI fails the same way at the same time.

The Exclusion Is the Spec

The Insurance Services Office (ISO) has three endorsements in circulation with a 01 26 edition date: CG 40 47, CG 40 48, and CG 35 08. Let's say these names were not presented in front of a marketing committee, but what do I know? What they do, between them, is carve bodily injury, property damage, and personal and advertising injury arising out of generative AI out of the Commercial General Liability form and the Products/Completed Operations form both. In the past six months, carriers have been lining up at state insurance regulators for permission to actually use them, and the attorney tracking those filings for Lathrop GPM called it an industry-wide reaction to the explosion of AI. Berkley went even further last year with an absolute AI exclusion for D&O, E&O, and fiduciary lines, one that reaches past your AI's output to your AI policies, your AI procedures, and your failure to notice somebody ELSE's AI. Talk about the long arm of the law.

For context, ISO writes the forms most of the American commercial market runs on, so an ISO exclusion is about as close as insurance gets to a standards body publishing a deprecation notice.

And keep in mind what the business of insurance actually IS. You take a risk of some kind. They calculate the risk and tell you how much it will cost if it goes wrong. You pay them, and now you are protected. That's the product; there isn't another part. And, for whatever reason, a meaningful chunk of that industry - whose ENTIRE job is to evaluate the risk of just about anything - has now looked at generative AI and said, some version of, no thanks.

They are not being cowards about it

Joe Lam, the Verisk VP who helped write the endorsements, gave the least dramatic (and, I'd argue, most honest) account of it in that Claims Journal piece: "Without exclusions to allow underwriters a level of stability to accept a risk, you run into a situation where they might just walk away from the risk. So exclusions are very essential in the marketplace."

The exclusion, as it stands, fences off the one piece the underwriters can't measure, so they can keep writing everything around it, because the alternative was walking away from the whole line. A narrow exclusion is more coverage than no market at all, and anybody who has watched a line of business go uninsurable (e.g., Enron) knows exactly which of those two is worse.

They're not doing this in a vacuum. Gallagher counted a 978% increase in AI-related litigation between 2021 and 2025, with a 137% jump in the final year of that window alone. And on July 24, the Delaware Superior Court ordered Google to defend a defamation suit over what its AI said about a person. If something has a docket number, people are going to stand up and take notice.

The problem isn't that AI is dangerous

Most of the commentary goes straight to the black box: AI is unpredictable, its outputs aren't deterministic, and underwriters can't model what they can't explain.

That said, insurance has never needed predictability at the individual level. Nobody knows which house is going to burn down, because no one is measuring just one house. The actuarial math asks for exactly one property: that the losses be independent—ten thousand houses, uncorrelated fires, the law of large numbers, everybody goes home happy. Correlation is what kills an insurance market (Go look at the mortgage insurance market in 2008 if you want to see how). Correlation is why nobody will sell you a single policy covering every house on one street against the same fire, and why flood ended up as a federal program.

Now let's look at AI. A handful of foundation models, three clouds, overlapping training corpora, the same inference frameworks and orchestration layers, and vector stores wired together off the same blog posts. I've spent most of my career (Google, Microsoft, Amazon, now Expanso) building distributed systems where a big part of the job is keeping failures from correlating, so watching this particular stack assemble itself has been, let's say, uncomfortable. Gallagher Re has been flagging it for a year, and Aon's Kevin Kalinich distilled the underwriter's view into three words: "aggregated, systemic, correlated." One vulnerability in a common dependency, and the losses land on an entire book of insureds the same afternoon.

I wrote in June about what happens when everything speaks one format and routes through one provider, and the underwriters have now put a price on the answer. Or rather, declined to put a price on it. Fragile things get insured all day long, every day, everywhere. The issue with a monoculture is that when it goes, it all goes at once, and the pool that was supposed to absorb your loss turns out to be built from the same stuff that just failed.

Which means CG 40 47 is a verdict on the topology.

Silent cover is how this always starts

"Silent AI" is exposure sitting within conventional policies that neither confirm nor deny it, left to be argued at claim time by lawyers after the loss. According to one industry estimate, more than 90% of insurers' AI-agent exposure is silent, tucked inside cyber, professional indemnity, general liability, and D&O policies written by people who were not thinking about agents at all.

We have run this movie before, and it did not turn out well.

General liability policies written from the 1940s through the 1970s said nothing about asbestos, because why would they? The exposure was silent, unpriced, and enormous, and it surfaced decades later as long-tail claims against contracts nobody remembered signing. Lloyd's underwriters lost roughly £9 billion between 1988 and 1992. And here is the detail people tend to forget about Lloyd's. The capital behind the market came from about 34,000 Names, individuals carrying unlimited personal liability, and when the bill arrived, many of them lost everything they had; at least fifteen killed themselves. Lloyd's survived only by walling the old years off inside a separate reinsurance vehicle called Equitas, and lawyers were still picking at that structure's solvency a decade later.

Asbestos was in everything; the policies said nothing; and the bill came due twenty years after the premium had been paid. So when somebody tells me that 90% of the industry's AI exposure is currently silent, that sends shivers down insurers' and reinsurers' spines.

Underwriters end up writing the spec

So what do we do?

When insurers can't price something, walking away is only their first move. The second move, reliably, after more than a century of doing this, is to fund someone to go measure the thing. And whoever does the measuring ends up dictating how the thing gets built.

In 1893, the Chicago fire insurance authorities watched the Palace of Electricity at the World's Columbian Exposition light up with a hundred thousand Edison bulbs and kept noticing an inconvenient pattern: the building kept catching fire. Was it the wiring? The hookups? This new alternating current? Nobody knew, and the insurers were not inclined to keep writing the coverage while everybody wondered. So they hired an electrical inspector named William Henry Merrill and funded him, through the Chicago Board of Fire Underwriters and the Western Insurance Association, to investigate. His lab was a room above Fire Insurance Patrol Station Number One. A bench, a table, some chairs, $350 of measuring equipment, and that's it, that was the whole operation.

His first test, filed March 24, 1894, was a sheet of asbestos paper a manufacturer had claimed was noncombustible and nonabsorbent. Merrill found it absorbed water and would not burn, making it useless as insulation, decent for fire resistance, and, either way, a measured fact now instead of a sales claim. (And yes, the first thing Underwriters Laboratories ever tested was asbestos, the same material from the section you just read. Let it never be said that history does not have a sense of irony.) After several thousand tests, the lab published its first list of approved fittings and devices in 1898, and approved products got a label. In 1901, it was chartered in Illinois as Underwriters Laboratories, taking the name of its new sponsor, the National Board of Fire Underwriters, with a stated purpose of testing appliances and recommending them to insurance organizations. Its first Standard, in 1903, covered tin-clad fire doors. After the 1906 San Francisco earthquake, UL was helping the National Board write building codes, and its engineers went on to shape the early National Electrical Code.

It's insane, but true, that a meaningful share of the electrical safety rules governing every building you have ever walked into exists because a group of fire insurers refused to keep writing policies until somebody could tell them what was in the wall. The refusal came first; the standard is the reason coverage ever came back.

So I honestly don't care whether CG 40 47 is fair. What I want to know is what the AI equivalent of a tin-clad fire door looks like, because somebody, somewhere, has to write that before this exposure becomes insurable again.

I can tell you what it won't be: any of the "benchmarks" we have today (which are starting to feel a bit like Goodhart's law). An underwriter does not give a damn that your model came in three points higher on some eval, because an average tells you nothing about the day it goes wrong. What an underwriter needs is provable data provenance, a record of which decisions the system actually made (not just recommended), tenant isolation, and some ceiling on how far a bad model update travels before anyone notices. I argued in April that you can't sue an agent, and these exclusions are what that argument looks like as an invoice. If nobody can locate the liability, nobody can price it, so it goes out of the form.

Every item on that list is a property of how the system is built, not of the model sitting inside it — which is a mildly humiliating thing for our industry to be learning from an insurance endorsement, but here we are.

The carriers that filed exclusions in July did not end anything. They're Merrill in 1894, standing in front of the exposition wiring, declining to sign until someone tells them what's behind the panel. Nobody could tell him. He had to build the lab to find out.


Want to learn how intelligent data pipelines can reduce your AI costs? Check out Expanso. Or don't. Who am I to tell you what to do?

NOTE: I'm currently writing a book based on my observations of real-world challenges in data preparation for machine learning, focusing on operational, compliance, and cost issues. I'd love to hear your thoughts!