AI Liability Insurance Gaps: What In-House Counsel Must Audit Before 2026 Policy Renewals

AI-specific risks—algorithmic bias, AI-washing securities suits, copyright training-data claims, and autonomous-agent torts—are outpacing traditional D&O, E&O, and CGL policy language. Here's a four-step audit checklist for in-house counsel before 2026 renewals.

Abstract digital fresco: a luminous crystal core inside a copper lattice, wrapped by a teal membrane torn open on two sides where deep navy voids show and cream light leaks out
Loading AudioNative Player...

If your company uses AI in any capacity—and in 2026, that is nearly every company—your standard D&O, E&O, and CGL policies were not designed for the risks you are actually carrying. Insurers know it. They are adding AI exclusions, sublimits, and entirely new underwriting questionnaires at renewal. The question for in-house counsel is no longer whether your insurance program has AI coverage gaps, but how large they are and what to do about them before the next renewal cycle closes.

The urgency is not hypothetical. The SEC brought its first AI-washing enforcement actions against Delphia Asset Management and Global Predictions in March 2024, charging both with making false and misleading claims about their use of AI (SEC Press Release 2024-36). The OpenAI copyright multidistrict litigation—consolidated as MDL No. 3143 in the Northern District of California—continues to produce rulings that reshape training-data liability. And the Delaware Court of Chancery's ruling in In re McDonald's Corp. Stockholder Derivative Litigation extended the duty of oversight to corporate officers, creating a governance-failure theory that plaintiffs are already adapting for AI-specific claims. We explored the board-level implications of that case in our guide to board oversight of AI and cybersecurity risk under Caremark and McDonald's.

Aon's 2026 market analysis identifies AI as one of the fastest-evolving underwriting risks, noting that AI-related risks now span privacy, IP, operational, and reputational exposures and are "transforming how organizations assess insurance needs and evaluate alignment with emerging loss scenarios" (Aon, AI Risk 2026). The D&O Diary has separately observed that AI "presents challenges that may not lend themselves to traditional underwriting approaches" because the technology is evolving faster than underwriting models can track (D&O Diary, June 2026).

Here is a practical, four-part audit framework for in-house counsel to close AI liability insurance coverage gaps before 2026 policy renewals.

The Four AI Exposure Surfaces

Before you can audit your coverage, you need to know what you are auditing against. AI liability is not a single risk category—it is at least four distinct exposure surfaces, each of which maps to a different line of insurance and a different litigation theory.

1. Algorithmic Bias and Discrimination Claims

Predictive AI systems used in hiring, lending, insurance underwriting, healthcare, and housing generate claims under anti-discrimination statutes, consumer protection laws, and emerging state AI regulations. NYC Local Law 144, Illinois AIFA, and Colorado's AI Act all impose obligations on deployers of AI decision-making tools. A bias claim arising from an AI hiring tool is unlikely to trigger a standard CGL policy, and it may or may not trigger E&O depending on the professional service at issue. If the tool was provided by a vendor, the indemnification chain matters—but many vendor agreements we see contain AI-specific liability carve-outs that shift risk back to the deployer.

2. AI-Washing Securities Claims

The SEC's March 2024 enforcement actions against Delphia and Global Predictions established that false AI claims in public disclosures are enforceable securities fraud. Since then, plaintiffs' attorneys have expanded beyond traditional AI-washing into securities suits against AI infrastructure companies, data center operators, and software companies whose AI initiatives allegedly failed to perform as represented (D&O Diary, June 2026). These claims hit D&O policies directly. We covered SEC AI-washing enforcement and the compliance response in our AI-washing compliance guide for 2026.

The consolidated OpenAI copyright MDL (MDL No. 3143, N.D. Cal.) has produced substantive rulings on whether training models on copyrighted works constitutes infringement, and the claims are expanding to cover output liability as well. For companies that build, fine-tune, or deploy generative AI tools trained on third-party content, the exposure is a direct IP infringement claim. Standard CGL policies exclude IP infringement outside of "advertising injury," and E&O policies may not cover IP claims unless the policy explicitly includes media or IP liability. For a detailed risk-reduction checklist, see our OpenAI copyright MDL practical checklist.

4. Autonomous-Agent Tort Exposure

Agentic AI—systems that take actions rather than merely generating content—creates a new category of tort exposure. When an autonomous agent enters a contract, makes a purchase, or causes physical or financial harm, the question of who pays is genuinely unsettled. We analyzed this in our guide to AI product liability, tort exposure, and insurance gaps. CGL policies were built on the assumption of human-caused bodily injury and property damage; an agent that causes loss without direct human intervention may fall outside the policy's insuring agreement entirely.

How Traditional Policies Fall Short

Each line of insurance has structural gaps when it comes to AI risk. Understanding these gaps is the foundation of the audit.

D&O Policies: D&O covers wrongful acts by directors and officers in their governance capacity. AI-washing securities suits and derivative actions alleging oversight failures map here. But the duty of oversight now extends to officers under McDonald's, meaning that a chief AI officer or CTO who fails to implement adequate AI governance could face personal liability claims that test D&O coverage in new ways. Some carriers—W.R. Berkley has confirmed this—are now attaching "absolute AI exclusions" to D&O policies that remove coverage for "any actual or alleged use, deployment, or development of AI by any person or entity connected to the insured" (AI Policy Desk, 2026). That language is broad enough to swallow most AI-related D&O claims.

E&O / Professional Liability: E&O covers errors in the performance of professional services. If your company provides AI-powered services to clients—analytics, automated decision-making, AI-generated content—the failure of those services to perform as contracted or as represented is an E&O claim. But many E&O policies contain intellectual property exclusions, technology-as-a-service exclusions, or now AI-specific exclusions that may bar coverage. The key question is whether the policy's definition of "professional services" explicitly includes AI-related activities or is silent on them—and silence does not mean coverage.

CGL Policies: This is where the most significant structural change has occurred. Effective January 1, 2026, Verisk's ISO division released three new generative AI exclusion endorsements for commercial general liability policies: CG 40 47, CG 40 48, and CG 35 08. CG 40 47 is the broadest, excluding bodily injury, property damage, and personal/advertising injury "arising out of" generative AI. The phrase "arising out of" requires only a causal connection—not a direct cause—so a claim does not need to be primarily about AI to trigger the exclusion (AI Policy Desk, 2026). If your CGL policy renewed on or after January 1, 2026, you must confirm whether this exclusion has been attached.

The 2026 Underwriting Landscape

Insurers are not waiting for claims to arrive. They are actively reshaping how they evaluate AI risk at renewal. Aon's Q2 2026 Global Insurance Market Overview confirms that "insurers increasingly leveraged AI and advanced analytics to aid underwriting decisions and differentiate between risks," and that "high-quality risk data and clear submissions are becoming more important in achieving favorable renewal outcomes" (Aon Q2 2026).

In practice, this means three things for in-house counsel:

First, expect AI-specific underwriting questionnaires at renewal. These go beyond general cybersecurity questionnaires and ask about AI use cases, model training data sources, vendor dependencies, human-in-the-loop controls, bias testing, and board-level AI governance. Marsh has published guidance noting that financial lines insurers are scrutinizing whether AI is "a core driver of revenue growth" versus an operational support tool, and that governance practices around model validation and vendor oversight are becoming underwriting focal points (Marsh, Financial Lines and AI Risk).

Second, expect AI exclusions and sublimits. The ISO CG 40 47 endorsement is being adopted by CGL carriers. D&O and E&O carriers are writing proprietary AI exclusions that may be even broader. Some carriers are offering sublimited AI coverage—capping AI-related claims at a fraction of the total policy limit—as a compromise between full exclusion and full coverage.

Third, expect pricing differentiation. Companies with demonstrable AI governance frameworks, documented use-case inventories, and board-level AI risk reporting are likely to receive better terms than those that cannot answer underwriting questions with specifics. As the D&O Diary observed, underwriters "increasingly may focus on how central AI is to a company's business model" and whether established governance frameworks exist (D&O Diary, June 2026).

The In-House Counsel Audit Checklist

Here is a four-step framework to close AI liability insurance gaps before renewal.

Step 1: Map Your AI Exposure Surfaces

Build an internal inventory of every AI system the company uses, develops, or deploys. Include vendor-provided tools, internal-built models, customer-facing AI features, and any agentic AI tools that take actions on behalf of the company. For each, document: the use case, the data sources used for training or inference, whether the output reaches customers or third parties, and the human-in-the-loop controls in place. This inventory is both a governance document and the foundation of your underwriting submission.

Step 2: Map Exposures to Existing Policy Language

For each AI exposure surface identified in Step 1, determine which policy line it maps to (D&O, E&O, CGL, cyber, or none), and then read the actual policy language. Specifically, check for: (a) AI-specific exclusions—look for CG 40 47 or proprietary equivalents on CGL; look for "absolute AI" exclusions on D&O and E&O; (b) sublimits on AI-related claims; (c) the definition of "professional services" in E&O and whether it encompasses AI activities; (d) IP exclusions that would bar copyright training-data claims; and (e) cyber policy language on AI-related data breaches, deepfake fraud, and social engineering. Do not assume that silence means coverage. Insurers are actively drafting new exclusions, and a policy that was silent on AI at last renewal may not be silent this time.

Step 3: Negotiate AI-Specific Endorsements or Bridge Coverage

If Step 2 reveals gaps—and it will—there are three paths. First, negotiate a carrier-specific AI endorsement that restores coverage for defined AI risks, potentially with a sublimit. This is increasingly available as carriers compete for well-governed AI companies. Second, explore affirmative AI liability products that are emerging in the market. HSB (a Munich Re company) launched AI Liability Insurance for small and mid-size businesses in March 2026, and Munich Re's aiSure program offers higher-limit coverage for AI vendors (AI Policy Desk, 2026). Third, consider whether cyber insurance can bridge certain AI-related gaps—particularly for data breach, deepfake fraud, and social engineering exposures—though cyber policies are also adding AI exclusions and underwriting questionnaires.

Step 4: Prepare for Insurer AI Questionnaires

The underwriting questionnaire is where renewal outcomes are won or lost. Prepare a comprehensive, accurate AI risk submission that includes: your AI use-case inventory; governance documentation (board reports, AI use policies, risk tiering frameworks); vendor due diligence records for AI suppliers; bias testing and model validation documentation; incident response plans that address AI-specific scenarios; and regulatory compliance evidence (e.g., NIST AI RMF alignment, state law compliance). Aon's 2026 guidance emphasizes that organizations with "early governance, clear accountability and resilient controls" are better positioned for favorable renewals (Aon, AI Risk 2026). Vague or incomplete answers signal unmanaged risk and may trigger exclusions or pricing penalties.

Actionable Next Steps

Start the audit at least 90 days before your next renewal. The timeline matters because negotiating AI endorsements, evaluating affirmative AI products, and preparing underwriting submissions all require lead time. Here is the sequence we recommend:

  1. Inventory AI use cases across the company—include shadow AI and vendor-provided tools.
  2. Request current policy language from your broker—specifically ask whether any AI exclusion endorsement has been or will be attached at renewal.
  3. Map each AI exposure to a policy line and identify gaps where no coverage exists.
  4. Engage your broker on AI-specific endorsements and affirmative products—do not accept an AI exclusion without exploring buyback options.
  5. Prepare the AI underwriting submission with governance documentation, vendor diligence, and testing evidence.
  6. Document the audit—the process itself is part of your board-level AI oversight under the Caremark framework as extended by McDonald's.

The companies that will fare best at 2026 renewals are not the ones with the least AI risk—they are the ones who can demonstrate they understand and manage it. In-house counsel are the ones who can bridge the gap between the company's AI strategy and the insurer's underwriting requirements. Starting now gives you the time to do it properly.

Need help auditing your company's AI liability insurance gaps before your next renewal? Our team works with in-house counsel to map AI exposures, negotiate carrier language, and prepare underwriting submissions that hold up.

Book a consultation