- AI insurance exclusions moved from bespoke wording to standard forms in January 2026, which means they now arrive by default at renewal rather than by negotiation.
- Three ISO endorsements do the work: CG 40 47, CG 40 48 and CG 35 08, covering bodily injury, property damage, advertising injury and completed operations.
- The era of silent AI cover, where AI risk was included because nobody had excluded it, is closing.
- The vendor will not fill the gap. Most AI terms cap liability at fees paid and exclude the indirect losses that make up almost all of a real claim.
- Europe removed the claimant friendly route. The AI Liability Directive was dropped in 2025, while software and AI became products under the revised Product Liability Directive.
- What now decides your cover is documentation. Insurers are pricing on whether you can show governance, not on whether you use the tools.
A photographer runs her client proofs through an AI upscaler, delivers a set of prints, and the colour profile is wrong on forty of them. A florist lets an assistant tool answer enquiries and it quotes a wedding at half the real price. A shop's stock system, tuned by a model, orders eleven pallets of something instead of one.
None of these are dramatic. All of them are ordinary small business accidents with an AI step in the middle, and each is the kind of thing a business owner assumes their insurance handles, because it always has. The question of 2026 is whether that assumption still holds, and for a growing share of policies the answer is no.
What changed, and when?
The insurance market spent the previous two years in a position the industry calls silent cover. AI was not mentioned in policy wordings, which meant that an AI assisted mistake was covered if the resulting harm fell inside the ordinary insuring clause. Nobody had decided that; it was simply what happens when technology moves faster than forms.
That ended with standard form language. Claims Journal reported in July 2026 on three ISO endorsements now in circulation: CG 40 47, which excludes bodily injury, property damage and personal and advertising injury arising out of generative AI; CG 40 48, aimed at personal and advertising injury specifically; and CG 35 08, which applies the exclusion to products and completed operations. The same reporting notes Berkley introducing an absolute AI exclusion across directors and officers, errors and omissions, and fiduciary lines.
Why now is answered by the claims data in the same piece. A Gallagher study cited there recorded a 978 percent rise in AI related lawsuits between 2021 and 2025, with a 137 percent jump in the final year alone. Patent infringement made up 11.9 percent of those cases, copyright 11.2 percent, and personal injury claims covering privacy violations and misuse of data 10.2 percent. Insurers did not react to a philosophical worry. They reacted to a curve.
Does this actually apply to a small shop?
More than it applies to a technology company, which is the counterintuitive part. A software business buys specialist errors and omissions cover, reads its exclusions, and argues about them with a broker who understands the product. A bakery buys a combined commercial policy once a year, renews it by email, and finds out what it says after something goes wrong.
The breadth of the definitions is what pulls ordinary businesses in. Some wordings define artificial intelligence as any machine based system that infers from its input how to generate outputs such as predictions, content, recommendations or decisions. Read that literally and it reaches the recommendation engine on your storefront, the spam filter on your inbox, the fraud score your payment provider returns and the route planner your driver uses. None of those feel like AI to the person running the business. All of them are inside that sentence.
This is the practical hazard. Not that a shop's deliberate AI project gets excluded, but that a mundane claim with no obvious AI character gets contested because some system in the chain made an inference. We looked at the same definitional creep from a different angle when we wrote about auditing the AI features that switched themselves on inside tools you already pay for, and the overlap is not a coincidence: the features nobody chose are the ones nobody has documented.
Who pays when the tool is wrong?
Start with the vendor, because that is where most owners assume the buck stops, and it is the assumption that costs the most.
Commercial terms for AI services almost universally cap the provider's total liability at the fees you paid them, often over the preceding twelve months. For a small business paying twenty pounds a month, that ceiling is two hundred and forty pounds. The same terms then exclude indirect and consequential loss, which is the category that contains lost profit, reputational damage and the cost of redoing work. What remains recoverable after both clauses is close to nothing, and it is not because any particular vendor is being harsh. It is the standard shape of a software contract applied to a product whose output you publish as your own.
The important consequence is directional. The vendor sells you a capability and hands you the output risk. Whether that output is accurate, lawful, non infringing and appropriate for your customer is your problem the moment you press send. That is a reasonable allocation, and it is also exactly the risk your insurer is now declining to absorb. Our list of questions worth asking an AI vendor before you buy exists because the liability clause is the one nobody reads and the one that decides this.
What about the law, rather than the contract?
Two European developments pull in opposite directions and both matter to a shop selling into the European Union.
The first is a road that closed. The AI Liability Directive was proposed in 2022 to make it easier for people harmed by AI systems to bring claims, chiefly by easing the burden of proof. The Commission listed it for withdrawal in the 2025 work programme adopted on 11 February 2025, citing no foreseeable agreement, and reserved the option of tabling something different later. The practical effect is that there is no harmonised European route for AI specific claims, and injured parties fall back on national regimes that vary considerably.
The second is a road that opened. The revised Product Liability Directive brings software into the definition of a product. The International Bar Association's analysis sets out that Article 4 covers any software placed on the market or put into service, standalone or combined with another product, with open source excluded only where it is not supplied commercially. Compensable damage under Article 6 runs to death, personal injury and property damage, and notably to the destruction of or damage to data where that data is not used for professional purposes. Member states have until 9 December 2026 to transpose it, claims run three years from knowledge of damage, defect and liable operator, with a ten year longstop and twenty five years for latent defects.
These two facts together describe the shape of the next few years. Strict liability attaches further up the chain, to whoever made the software. The easier procedural route for claimants against AI users specifically did not arrive. For a small merchant that is mildly good news, and it changes nothing about whether your own insurer will pay.
Five scenarios and where the money comes from
The table below takes the kinds of incident a small business actually has, rather than the AI catastrophes that appear in conference slides, and asks who is realistically on the hook under the wordings now circulating.
| Scenario | Traditional cover | With a generative AI exclusion | What closes the gap |
|---|---|---|---|
| Assistant quotes a price you cannot honour | Usually a commercial dispute, not an insured loss | Unchanged, still your commercial problem | A confirmation step before a quote is binding |
| Generated ad copy infringes a competitor's mark | Advertising injury cover may respond | CG 40 48 aims squarely at this | Human sign off plus a records trail of the approval |
| Product image generated with someone else's likeness | Advertising injury or media liability | Likely excluded on new forms | Licensed inputs and a written provenance note |
| Model driven stock order causes a warehouse injury | Public liability responds | CG 40 47 may bar bodily injury tied to the system | A human authorisation threshold on every order |
| Customer data pasted into a tool leaks | Cyber policy, subject to its own terms | Depends on how the cyber form defines AI | A data class rule staff can follow without thinking |
Read the last column rather than the third. In four of the five rows, the thing that protects the business is a control, not a policy. That is not a coincidence, and it points at where the market is heading.
The renewal conversation to have
Insurers are not uniformly retreating. Alongside the exclusions, some have introduced AI security riders that restore cover in exchange for evidence, typically documented risk assessment and some form of testing. Fenwick's guidance to policyholders is to identify AI related exclusions across every policy, examine how each document defines AI, and assess how the exclusions interact rather than reading any one form in isolation. That last point is where small businesses lose: a gap between a general liability exclusion and a cyber policy definition is invisible until a claim falls into it.
Four questions are enough for an annual renewal, and none of them require you to become an insurance specialist.
First, does any policy I hold now contain an AI exclusion, and on which form number. Second, how does each policy define artificial intelligence, and does that definition capture ordinary software I already use. Third, if two of my policies define it differently, which one governs an incident that touches both. Fourth, what would you need me to show you to write the cover back, and is that a realistic list for a business my size.
The fourth question is the useful one. A broker who answers it concretely is telling you the shape of the documentation market is settling on, which is roughly: an inventory of where AI is used, a note on what a human checks before output is published, and a record that the check happens.
Why documentation is now the actual product
There is a quiet shift here worth naming. For most of the history of small business insurance, price was driven by what you do and how big you are. Cover for AI risk is being priced on what you can demonstrate, which is a different variable and one a very small business can actually move.
That is unusual and it is an opportunity. A sole trader cannot change their turnover band or their trade classification before renewal. They can absolutely produce a one page record of which tools touch customer data, who signs off generated copy before it publishes, and what happens when the model is unavailable. The same page answers the broker, the regulator and the customer who asks an awkward question, which is the argument we made at greater length about what to put in place in the first ninety days of using AI seriously.
We hold ourselves to the same standard rather than only recommending it, which is why our own AI policy is a published page rather than a paragraph in the terms. If you are going to ask vendors what they do with your inputs, the question has to be answerable about us too.
Does the exclusion apply if a human approved the output?
This is the question brokers are being asked most and the one with the least settled answer. The wordings exclude harm arising out of or attributable to generative AI, and neither phrase is obviously satisfied or obviously defeated by a person reading the text before it went out.
The argument for cover is straightforward. If a copywriter drafts an advertisement, a manager approves it and it turns out to infringe a trademark, the harm arises from the publication decision rather than from the drafting tool. The argument against is that the exclusion was written precisely to capture the chain, and that a rubber stamp approval does not break it.
Until claims settle the point, the practical move is to make your approval look like a decision rather than a formality. That means the person signing off has the authority to reject, the record shows what they checked, and the check is specific to the risk. A note saying reviewed is worth very little. A note saying trademark searched, three competitor names cleared, image rights confirmed as licensed stock is a different document, and it is the kind of thing that turns a contested claim into a paid one.
It also happens to be the cheapest version of the control. Nobody needs a workflow tool for this. A dated line in a shared document beside the published item does the whole job, and it takes about twenty seconds per item on the small number of things a shop actually publishes in a week.
What not to do about it
Do not stop using the tools to preserve cover. The exclusions are drawn broadly enough that abstinence would mean abandoning spam filtering and payment fraud scoring, and no insurer is asking for that. The exclusion is about where the loss lands, not about whether you are permitted to operate.
Do not assume a standalone AI policy is the answer for a business of five people. A small standalone AI liability market exists and it is mostly built for companies whose product is the model. For a shop, the money is better spent on the controls that get cover written back into the policies already held.
And do not treat a broker's reassurance as cover. Ask for the form number. A wording is a document with a name on it, and the difference between an insurer who has not yet adopted the exclusion and an insurer who has adopted it quietly at this renewal is a single line in the schedule that takes thirty seconds to find once you know to look.
The premium used to price your trade. It is starting to price your paperwork, which is the first time in a long while that the smallest business in the room has the cheapest path to a better answer.
Where this is heading
Two things are worth watching over the next year. The first is whether the broad definitions survive contact with claims. A wording that captures a spam filter will eventually be tested by an insured arguing that the exclusion swallows the policy, and how that argument lands will determine whether the current drafting narrows.
The second is transposition. The revised Product Liability Directive has to be in national law across the European Union by December 2026, and the national implementations will not be identical. For a merchant selling across several member states, the practical question is not what the directive says but what the country your customer lives in decided it says, which is the same lesson cross border sellers keep relearning in every other area of consumer law.
Neither of those is something a shop can influence. Both are reasons to spend an hour this quarter finding out what your own policies currently say, because the answer changed while nobody sent a letter about it.