The affirmative AI cover market that opened between 2025 and 2026
For a decade the standard insurance answer to an AI failure was silence. General liability, property, and most professional indemnity wordings never named artificial intelligence, so a loss caused by a model either fell into a grant by accident or was argued out by an adjuster. That ambiguity, known as silent AI, is now being closed from both ends. Insurers are writing AI exclusions into cyber and technology wordings, and a separate market of standalone, affirmative AI cover has opened to sell the risk back deliberately.
The anchor products are real and recent. Armilla launched an affirmative AI liability policy in April 2025, underwritten by certain Lloyd's syndicates including Chaucer and backed by Axis Capital, with per-organisation limits expanded to USD 25 million or more by January 2026. Munich Re has run its aiSure performance-guarantee programme since 2018, and in March 2026 Mosaic Insurance partnered with Munich Re to offer aiSure-backed cover of up to USD 15 million to AI developers and vendors. Counterpart launched an Affirmative AI Coverage product in November 2025, and Testudo, a Lloyd's Lab-backed managing general agent, began writing mid-market AI liability from January 2026.
The distinction matters for an Indian buyer. Affirmative cover names the peril, so a claim adjuster cannot deny it on the grounds that AI was never contemplated. That certainty is the product. It also changes the purchasing decision from arguing over silent grants in an existing policy to buying a defined instrument. For a chief risk officer at an Indian corporate or a global capability centre, the first question is no longer whether AI risk is insurable. It is which affirmative structure fits the deployment, and what evidence the underwriter will demand before quoting.
What a standalone AI policy actually pays for: hallucination, model drift and underperformance
Affirmative AI wordings are built around three failure modes that traditional liability policies were never designed to price, and it is worth separating them because they trigger cover differently.
Hallucination is the model asserting something false with confidence, for example a customer-facing assistant inventing a policy term, a discount, or a legal position the enterprise is then held to. The insured loss is the cost of honouring or defending that false output, plus third-party claims from anyone who relied on it. Model drift is slower and more dangerous to reserve against. A model that performed to specification at deployment degrades as real-world data diverges from its training distribution, so accuracy erodes over months without any single visible failure. Mechanical underperformance is the model failing to meet a contracted accuracy, latency, or availability benchmark, which is the peril Munich Re's aiSure was originally built to guarantee.
The payout logic follows the peril. Performance-guarantee cover of the aiSure type pays when a model, measured against an agreed benchmark and evaluation set, falls below the warranted threshold. Liability-style cover of the Armilla type responds to third-party claims and defence costs arising from the AI's output, closer in shape to a technology errors and omissions grant than to a parametric guarantee.
For Indian buyers this reframes the internal conversation. A GCC running a document-extraction model for a European parent is exposed to drift and underperformance far more than to a dramatic single hallucination, so the cover it should shop for, and the warranties it can honestly give, differ from those of a consumer-facing chatbot operator.
The qualification bar: kill switches, human-in-the-loop inventories and data-provenance audits
The defining feature of this market is that it is not open-market rated. Every affirmative carrier prices model-failure cover only against documented governance evidence, and an Indian buyer that cannot produce that evidence will be declined rather than surcharged. Treat the underwriting submission as an audit, not a proposal form.
Three evidence categories decide the quote. First, kill switches and rollback: the underwriter wants proof that a misbehaving model can be halted or reverted to a prior version within a defined time, with the control tested and logged, not merely designed. Second, a human-in-the-loop inventory: a documented map of which decisions the model makes autonomously and which require a human reviewer, because a fully autonomous high-value decision path is the exposure carriers fear most and price hardest. Third, a data-provenance audit: evidence of where training and inference data came from, consent and licensing for it, and controls against poisoning, which under India's DPDP Act 2023 also carries a separate regulatory exposure a GCC processing personal data cannot ignore.
Buyers should map their evidence to a recognised framework so the submission reads cleanly. The NIST AI Risk Management Framework and ISO/IEC 42001 are the two most underwriters now recognise, and an internal control set already aligned to one of them shortens the placement materially.
This is the practical reason affirmative cover is spreading unevenly. Firms that already run model governance can buy it; firms that treat governance as documentation to be produced after the fact find the premium either prohibitive or the risk simply declined.
How Indian GCCs and AI-first firms fit the underwriting box
Global capability centres are the sharpest test case in India because they build or operate models on Indian soil for a foreign parent, which splits the exposure across jurisdictions and complicates placement. The centre carries operational and data risk locally while the loss often lands on the parent's balance sheet abroad, so the cover has to follow the liability, not the servers.
The first structural question is admitted versus non-admitted. Under the Insurance Act, 1938, only an insurer registered with IRDAI can write an admitted policy covering an Indian risk, and Indian affirmative AI capacity is still thin, so much of this cover is placed on a non-admitted or master-policy basis through the parent's programme or via an IFSCA GIFT City structure. That choice drives whether an Indian claim is paid locally in rupees or through the global tower, and whether premium is deductible in the Indian entity. Brokers should settle it before marketing the risk, not after a claim.
Data and model governance obligations compound the picture. A GCC serving European users sits under GDPR and, for financial-sector clients, the EU DORA regime, while the same operation answers to the DPDP Act 2023 and the MeitY advisories on AI deployment at home. An affirmative AI policy does not discharge those duties, and most wordings exclude regulatory fines that are uninsurable as a matter of public policy, so the cover sits alongside compliance rather than replacing it.
For an AI-first Indian startup selling a model as a product, the exposure inverts. It is closer to a vendor than an operator, so the relevant purchase is developer-facing cover of the aiSure or Armilla type that responds when its model underperforms in a customer's hands, a distinct shape from the enterprise-user cover a GCC buys for its own deployments.
Pricing, sublimits and where the affirmative grant stops
Affirmative AI cover is priced tightly, and reading the schedule as carefully as the marketing sheet is what separates a useful placement from a decorative one. The published limits are headline aggregates. A USD 25 million Armilla tower or a USD 15 million aiSure-backed Mosaic line is the ceiling, but the operative numbers are the per-claim sublimits, the deductible, and the warranties that can void a grant.
Several carve-outs recur across the market and buyers should assume them unless the wording says otherwise. Bodily injury and physical property damage are usually excluded, because those belong to product liability and public liability towers, not to an AI errors grant. Intellectual property infringement from model output is frequently sublimited or excluded, which matters for any generative deployment. Bias and discrimination cover is inconsistent, present in some Counterpart-style wordings and absent elsewhere. Regulatory fines are generally excluded on public-policy grounds. And a breach of the governance warranties, a disabled kill switch or an undocumented model change, can convert a covered loss into a declined one.
The retroactive date and the drift problem interact awkwardly. Because model drift develops slowly, a loss can crystallise long after the degradation began, so the trigger basis, whether claims-made or performance-measured, decides whether a slow failure is caught at all. Buyers should read this the way they read a claims-made trigger and retroactive date on any liability policy.
The structural advance of 2026 is coordination. Armilla and Chaucer's Vanguard AI, launched in February 2026, deliberately pairs the standalone AI limit with cyber and technology E&O so that an AI-driven loss does not erode the cyber tower, giving roughly USD 25 million of AI aggregate beside a separate USD 10 million of cyber. For Indian programmes stacking several liability lines, that separation is the point: it stops one AI event from cannibalising unrelated capacity.
A procurement checklist for brokers placing AI cover in FY2026-27
For a broker advising an Indian corporate or GCC, placing affirmative AI cover is closer to a governance engagement than a quote-and-bind transaction, and the sequence matters.
- Classify the deployment. Establish whether the client is an operator (using models in its own decisions) or a vendor (selling a model), because that single distinction determines whether developer-facing performance cover or enterprise-user liability cover is the right instrument.
- Build the evidence pack before marketing. Model cards, the evaluation set and benchmark, the human-in-the-loop inventory, kill-switch test logs, and a data-provenance record mapped to the
NIST AI RMForISO/IEC 42001. The maturity of this pack, more than any technical detail, sets the premium. - Fix the trigger and the evaluation set in the schedule. An undefined benchmark makes an underperformance claim unwinnable, and an ill-fitted trigger basis lets slow model drift escape cover entirely.
- Coordinate the tower. Map the AI grant against the client's existing cyber, technology E&O, professional indemnity, and product-liability wordings so exposures are neither double-insured nor left in a gap, using a coordinated structure of the Vanguard AI type where capacity allows.
- Settle admitted versus non-admitted early. Decide whether the risk is written by an IRDAI-registered insurer, through the parent's global programme, or via an IFSCA GIFT City placement, and confirm how an Indian claim would actually be paid.
Doing that comparison well means reading the affirmative AI grant against the exclusions in the cyber, PI, and technology wordings the client already holds, clause by clause, across multiple insurers. Sarvada gives commercial-insurance brokers structured, searchable access to insurer policy wordings, so an AI grant, its carve-outs, and the surrounding liability tower can be mapped side by side rather than reconstructed by hand. Brokers building AI programmes for Indian corporates and GCCs can Request Access to evaluate the platform for their liability practice.