What the CIAB forum said about AI exclusions
Much of the 2026 discussion has assumed that AI cover would erode clause by clause, as carriers bolted generative-AI exclusions onto general liability, cyber and professional lines. Reporting from the CIAB Insurance Leadership Forum, published by Business Insurance (Gavin Souter) on 7 October 2026, describes a different picture: AI exclusions are struggling to gain traction because brokers and policyholders are resisting broad restrictions, and the market prefers to address AI exposure through underwriting.
The comments came from senior people on both sides of the table:
- Pat Donnelly of Willis said AI exclusions have not become common because "AI is too embedded."
- Alex Wells, CEO of Zurich North America, said the optional ISO generative-AI GL exclusions are "generally only being adopted by smaller carriers" and that Zurich treats AI "as an underwriting question rather than a contract question."
- Shawn Ram of Coalition said many AI exclusions have been filed but few have been widely adopted.
- Marc Kunney of EPIC warned that some insurers' affirmative AI coverage can act as "cloaked exclusions" by covering only certain AI perils.
The first three comments are reassuring for an Indian CFO. The fourth is the one that should shape the April 2027 renewal file. If blanket exclusions are not sticking, the restriction has to go somewhere, and the most natural place is inside an endorsement that looks like a coverage grant.
Why a blanket AI carve-out is hard to write and harder to sell
Donnelly's point that AI is "too embedded" is a drafting problem as much as a commercial one. A blanket exclusion has to define AI, and almost any definition broad enough to be useful also reaches the ordinary software an Indian manufacturer, bank, hospital or IT services firm runs every day: fraud scoring, demand forecasting, document classification, chat-based customer service, code assistants and quality inspection on a production line.
An exclusion that wide does two things a buyer will not accept. It removes cover for losses that have nothing to do with novel AI risk, and it makes the policy hard to compare against an expiring wording that said nothing about AI at all. That is why brokers have pushed back, and why carriers such as Zurich, on Wells's account, prefer to price and select AI risk at underwriting rather than write it out of the contract.
Our earlier posts covered both halves of that story. The silent AI exclusion map traces where an AI incident falls between GL, D&O, cyber and Tech E&O, and the CG 40 47 tower audit shows how to find ISO's optional GL forms on a global programme. This post deals with what comes next: the endorsement that says it adds AI cover.
How an affirmative AI endorsement can work as a cloaked exclusion
An affirmative AI endorsement names AI perils and states that they are covered. That is useful where the base wording was silent and an insurer might later argue that AI loss was never contemplated. The trap Kunney described is structural: once a policy lists the AI perils it covers, a claims handler can argue that AI losses outside the list were deliberately left out.
Three patterns to look for
- A closed list of perils. The endorsement covers, for example, errors in AI-generated output or algorithmic bias claims, and nothing else. A loss from model drift, a third-party model failure or an autonomous agent acting outside its instructions does not fit any named peril.
- An "exclusive" or "sole" coverage clause. Wording that says the endorsement is the only cover under the policy for loss arising from AI turns a grant into a replacement. Every AI-related loss is pushed into the endorsement and its sublimit, even where the base form would have responded.
- A broad AI definition paired with a narrow grant. If the definition of AI system is wide but the covered perils are narrow, the gap between the two is excluded by implication.
The test is simple to state: compare what the policy would pay for an AI-related loss with the endorsement attached and without it. If any loss scenario pays less with the endorsement, it is functioning, at least partly, as an exclusion.
Reading the endorsement line by line: cyber, tech E&O, D&O and GL
The same endorsement language behaves differently on each line, because the base forms trigger on different things.
Cyber and technology E&O
Cyber forms trigger on security failures and privacy events; technology errors and omissions forms trigger on a wrongful act in providing a technology service. An AI endorsement on either should be checked for whether it covers only named AI failures, such as inaccurate output, while the base wording's definition of wrongful act or computer system is amended to carve AI out elsewhere. Indian IT services and SaaS firms selling AI-enabled work to overseas clients are most exposed here, because their contracts often promise outcomes that a closed peril list does not track.
D&O and GL
On D&O, the concern is an AI exclusion or sublimit slipped into the definition of loss or into the conduct exclusions, so that a securities or regulatory claim alleging poor AI oversight is capped at the endorsement limit. On GL, check whether an AI endorsement is being offered alongside or instead of ISO's optional forms. Wells's remark that those GL exclusions are mainly adopted by smaller carriers is a useful benchmark when a renewal quote includes one: ask the carrier why it is applying a form the larger markets are generally not.
For each line, place the expiring wording, the proposed base wording and the AI endorsement side by side, and track every amended definition. The policy wording is the contract; the endorsement schedule decides what it says.
Five tests to tell a grant from a cloaked restriction
Before accepting any AI endorsement at the April 2027 renewal, run it through five questions. Each one is answerable from the documents, without a claims scenario.
- Does it add or replace? Look for words such as "solely", "exclusively" or "this endorsement is the only coverage" for AI-related loss. A true grant sits on top of the base form and says that the base cover is otherwise unaffected.
- Is the peril list open or closed? An open list ("including but not limited to") broadens cover. A closed list narrows it by implication. Ask for open wording or a residual clause confirming that AI-related loss not named in the endorsement remains subject to the base terms.
- Does it carry its own sublimit? A sublimit inside an exclusivity clause caps every AI loss at that figure. Check whether the sublimit is part of or in addition to the main limit, and whether it erodes the aggregate.
- What does the AI definition reach? If the definition captures routine automation, the endorsement's conditions and sublimit follow it into ordinary claims. Push for a definition tied to the specific systems the business has disclosed.
- What changed in the base form? Compare the expiring and proposed base wordings. A new AI definition, exclusion or amended wrongful-act wording in the base form, combined with a grant in the endorsement, is the clearest sign of a cloaked restriction.
Why the underwriting route still lands on Indian buyers
If carriers treat AI as an underwriting question rather than a contract question, the scrutiny moves to the proposal form and the submission. That cuts both ways for an Indian buyer. A clean wording is only as good as the disclosures behind it, and a material AI use left out of the submission gives the insurer a different line of defence at claim time under the duty of utmost good faith.
Practical steps for the renewal submission:
- Inventory the AI systems in use, separating customer-facing tools, decision systems (credit, pricing, claims, hiring) and internal productivity tools.
- Record which systems rely on third-party models and what the vendor contracts say about liability and indemnity.
- Describe human review steps for decisions that affect customers, patients or counterparties.
- Note any AI incidents, complaints or near misses in the policy period, even where no claim followed.
A buyer that discloses well is in a stronger position to refuse a closed-peril endorsement, because the underwriter has the information it needs to price the risk without narrowing the contract. Where a business needs a dedicated limit for model failure, the affirmative AI liability market offers standalone cover, but that should be bought as an addition to the existing tower, not as a reason to accept narrower base wordings.
A renewal checklist for CFOs and risk managers before April 2027
Most Indian corporate renewals cluster around the start of the financial year, which leaves time between now and the April 2027 cycle to fix wordings rather than discover them after binding. A practical sequence:
- Collect every AI-related endorsement on the cyber, technology E&O, professional indemnity, D&O and GL policies, including local policies under any global programme.
- Run the five tests above on each endorsement, and flag any exclusivity clause, closed peril list or new sublimit.
- Map the gaps between lines. If cyber covers only named AI perils and Tech E&O has a new AI definition, a single model failure may fall between them.
- Brief the broker early with a written list of the wording changes you will and will not accept, so negotiation happens before quotes are final.
- Get confirmations in writing. Any assurance that the endorsement does not restrict base cover should appear in the policy, not only in an email.
- Tell the board what changed. Directors approving the insurance programme should know whether AI cover broadened or narrowed at renewal.
The message from the CIAB forum is that blanket AI exclusions are not winning in the market. That is good news only if buyers notice where the restriction moves instead. An endorsement that grants AI cover deserves the same line-by-line reading as an endorsement that removes it.