1. Affirmative AI cover
Dates are the dates of the company's own announcement unless stated otherwise.
Munich Re aiSure and Mosaic
- Munich Re says it began insuring AI in 2018. Its aiSure product offers performance warranties on AI model accuracy, cover for AI liabilities (it names discrimination, IP infringement, hallucinations and regulatory fines) and cover for financial losses, using a "parametric-like structure for fast, objective claims" (Munich Re).
- On 26 February 2026 Mosaic Insurance announced a partnership with aiSure to protect AI developers and vendors "against financial loss arising from defined AI performance failures", with "up to EUR/USD/CAD 15 million in initial capacity". aiSure provides the technical foundation; Mosaic underwrites and markets the product through its cyber specialists. Mosaic says its underwriting "focuses on the AI model itself, what it does, how its outputs are used" (Mosaic).
Armilla
- Armilla says it became the first Lloyd's coverholder dedicated exclusively to AI liability in 2024.
- On 30 April 2025 it launched an AI liability policy underwritten by certain underwriters at Lloyd's, including Chaucer, covering AI underperformance, errors, hallucinations and the resulting legal costs (Armilla, 30 April 2025).
- In January 2026 it raised limits to USD 25 million per organisation. The policy lists AI model error liability, AI model output liability, AI agent failures, non-breach privacy and data leakage liability, AI-driven property damage and AI regulatory violations. Armilla says each policy "includes independent AI system certification and risk reporting, informed by more than 500 AI evaluations across regulated industries" (Armilla, FinTech Global, 23 January 2026).
- Armilla names Chaucer, Axis Capital and Convex behind Armilla Insured, and Chaucer, Greenlight Re and Swiss Re behind Armilla Guaranteed. Its policy applies to claims reported during the policy period (Armilla).
Testudo
- On 21 January 2026 Testudo launched standalone liability cover for generative AI, written on Lloyd's paper rated A+ (Superior) by AM Best, with limits of USD 1 million to 10 million. Testudo took part in the Lloyd's Lab (Cohort 14). The six insuring agreements cover financial loss and negligent misrepresentation from AI errors; defamation and reputational harm; IP infringement; unauthorised data disclosure; bodily injury or property damage; and AI regulatory proceedings. Testudo says it underwrites "without an invasive technical audit" (Testudo).
- On 9 March 2026 Atrium and QBE joined Apollo on Testudo's panel, taking capacity to USD 9.25 million per insured, with Gallagher Re as broker (Atrium, FinTech Global, 9 March 2026).
AIUC and the AIUC-1 standard
- The Artificial Intelligence Underwriting Company (AIUC) launched on 23 July 2025 with a USD 15 million seed round led by Nat Friedman at NFDG. It describes its AIUC-1 standard as "SOC-2 for AI agents" and offers liability coverage for AI vendors and their customers when agents fail, with terms tied to audit results (PR Newswire, 23 July 2025).
- AIUC-1 is organised in six domains (Data and Privacy, Security, Safety, Reliability, Accountability, Society), maps to ISO/IEC 42001, the EU AI Act, the NIST AI RMF, MITRE ATLAS and the OWASP Top Ten for AI agents, and requires annual re-certification (AIUC-1). ElevenLabs, a certified company, describes it as 51 requirements and 130 controls, with technical tests on agents every quarter (ElevenLabs).
- On 11 February 2026 ElevenLabs announced insurance for its AI agents backed by AIUC-1 certification, after "more than 5,000 adversarial simulations" (PR Newswire, 11 February 2026).
Endorsements and small-business cover
- Counterpart, 24 November 2025: expanded its affirmative AI coverage across its Miscellaneous Professional Liability and Allied Health products and added a Technology E&O insuring agreement. It says its platform is backed by five A-rated carriers, including Aspen, Markel and Westfield Specialty (Counterpart release via Yahoo Finance).
- Coalition, 9 December 2025: a Deepfake Response Endorsement for cyber policies, covering a deepfake forensics analysis with a written report, legal help to remove deepfakes from online platforms, and crisis communications. Available in the United States, the United Kingdom, Canada, Australia, Germany, Denmark, Sweden and France (Coalition).
- HSB (Munich Re), 18 March 2026: AI liability insurance for small and mid-sized businesses, covering bodily injury, property damage, and personal and advertising injury arising from AI use. HSB does not sell it directly: partner carriers add it to their business policies, subject to regulatory approval (HSB).
- Google Cloud Risk Protection Program, May 2025: added affirmative AI insurance coverage for Google-related AI workloads, with Beazley and Chubb joining founding partner Munich Re (Google Cloud).
2. AI exclusions
ISO's generative AI exclusions for commercial general liability (CG 40 47, CG 40 48 and CG 35 08, edition 01 26) are covered in the library report "Generative AI Exclusions in Commercial General Liability: ISO CG 40 47, CG 40 48 and CG 35 08". Two carrier exclusions described by law firms:
- W.R. Berkley: an "Absolute" AI exclusion for D&O, E&O and fiduciary liability products that "purports to broadly exclude coverage for 'any actual or alleged use, deployment, or development of Artificial Intelligence'", including any product or service "incorporating Artificial Intelligence" (Hunton Andrews Kurth, 28 May 2025; also Zelle, 31 October 2025).
- Hamilton Insurance Group: a Generative AI Exclusion defining generative artificial intelligence as "any system that produces content such as text, imagery, audio, or synthetic data in response to user prompts, including but not limited to ChatGPT, Bard, Midjourney, or Dall-E" (Zelle, 31 October 2025).
3. Rules for insurers
United States
- NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers, adopted 4 December 2023. It asks insurers for a written AI Systems (AIS) Program with senior management and board accountability, testing, and oversight of third-party vendors, and takes effect through adoption by each state (NAIC Model Bulletin). The NAIC map, with status as of 31 August 2026 (checked 2 October 2026), shows 26 adopting jurisdictions and 4 states with their own insurance-specific AI regulation or guidance: California, Colorado, New York and Texas (NAIC adoption map).
- New York, Insurance Circular Letter No. 7, 11 July 2024, on AI systems and external consumer data in underwriting and pricing. Paragraph 37 says vendor contracts should "provide audit rights or entitle the insurer to receive audit reports by qualified auditing entities" and require vendors to cooperate with regulatory inquiries. Paragraph 39 says reasons for an adverse underwriting or pricing decision should include "the source of the specific information" relied on. Paragraph 9 refers to examinations under Insurance Law section 309 and special reports under section 308 (NYDFS).
- Colorado: Senate Bill 21-169 (2021) (Colorado General Assembly) and Regulation 10-1-1 (3 CCR 702-10), first effective 14 November 2023 for life insurers. The amended regulation, effective 15 October 2025, covers individual life, private passenger auto and health benefit plan insurers that use external consumer data, algorithms and predictive models. It requires a board-overseen governance and risk management framework, including an inventory of models and documented quantitative testing for unfair discrimination, and an annual compliance report signed by an officer: from 1 December 2024 for life insurers, and from 1 July 2026 for auto and health insurers (3 CCR 702-10).
European Union
- EU AI Act: AI systems "intended to be used for risk assessment and pricing in relation to natural persons in the case of life and health insurance" are high-risk under Annex III, point 5(c) (AI Act Service Desk). Deployers must assign human oversight to people "who have the necessary competence, training and authority" and keep automatically generated logs for at least six months (Article 26); deployers of these insurance systems must carry out a fundamental rights impact assessment (Article 27). Serious incidents are reported within 15 days, within 2 days for a widespread infringement or a serious incident under Article 3(49)(b), and within 10 days in the event of a death (Article 73). After the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force 27 July 2026), the rules for stand-alone high-risk systems under Annex III apply from 2 December 2027, not 2 August 2026 (European Commission).
- EIOPA Opinion on AI governance and risk management, consultation opened 12 February 2025 (EIOPA), final Opinion 6 August 2025. It explains how insurance legislation, including Solvency II and the Insurance Distribution Directive, applies to AI systems, and covers data governance, record keeping, fairness, cybersecurity, explainability and human oversight. Systems that are high-risk or prohibited under the AI Act are outside its scope (EIOPA).
International
- IAIS Application Paper on the supervision of artificial intelligence, 2 July 2025, covering risk-based supervision and proportionality; governance and accountability; robustness, safety and security; transparency and explainability; and fairness, ethics and redress (IAIS). In 2026 the IAIS released a members-only supervisory question bank on AI governance and risk management, built on the Application Paper (IAIS).
