Endorsement CG 40 47 01 26, attachable at general liability renewals since 1 January 2026, removes bodily injury, property damage and personal and advertising injury arising out of generative artificial intelligence from both Coverage A and Coverage B of a commercial general liability policy. It has two siblings: CG 40 48 takes Coverage B only, CG 35 08 applies the exclusion to products and completed operations, and all three are optional, so the real question is whether your carrier attached them. The trigger phrase is 'arising out of', not 'caused by', which reaches a pipeline where a model drafted something a person later approved. Two different AI definitions are now in circulation: the content-creation wording catches your chat assistant and your RAG system but not your fraud scorer, while the carrier-drafted absolute wording (Article 3(1) of the EU AI Act with the autonomy and adaptiveness clause deleted) names predictions and recommendations as outputs and therefore pulls classical machine learning inside. Pull the endorsement schedule, the definition on your own copy and the trigger phrase before renewal, then make your logs capable of proving model version, retrieval provenance and genuine human review. Self-hosting does not put you outside either definition: it changes the evidence you can produce, not the words you fall inside.
Endorsement CG 40 47 01 26 has been attachable at commercial general liability renewals since 1 January 2026. Where a carrier attaches it, it removes bodily injury, property damage and personal and advertising injury arising out of generative artificial intelligence from both Coverage A and Coverage B of the policy. If your carrier attached it at your last renewal, the AI features you shipped in 2025 now sit outside the tower you assumed covered them, and nothing in your architecture changed to make that happen.
Underwriters did not price this in a vacuum. The largest single number they had to work against was Anthropic's 1.5 billion dollar copyright settlement with authors, preliminarily approved in September 2025 and granted final approval in July 2026, at roughly 3,000 dollars per work across a class list of about 482,000 books. Alongside it sits the shape of the docket. Published trackers of United States AI-related filings disagree on scope and on totals, so treat any single percentage with suspicion, but the ones that break the count out by year show single-digit case volumes in 2022 and a step change in 2025 of several times the prior year. That is the loss curve carriers responded to.
This is a risk and operations post and not legal or insurance advice. What follows is the half nobody writes: which parts of your actual stack fall inside which definition, what you can pull out of the policy PDF this afternoon, and what your logs have to contain before the sentence "a person reviewed it" means anything after an incident.
What changed on 1 January 2026
Three things, not one. The standard commercial general liability form set now carries a family of generative AI exclusions:
All three are optional endorsements. Carriers elect whether to attach them, which means the question is never whether the form exists. It is whether your carrier attached it, and which of the three.
Adoption moved fast. Trade analysis of carrier filings put the count at more than 60 property and casualty groups with at least one AI exclusion filing by July 2026, with subsidiaries of roughly 20 further groups filing to delay adoption to a later date, and at least one large carrier publicly declining to add the generative AI endorsements to its standard liability offering. Treat those as directional counts rather than an audited census, but the direction is not ambiguous.
The important structural point is that this is not arriving as one coordinated block. The exclusions are being written line by line, so the answer to "does our insurance cover this" is genuinely different for the general liability tower, the professional liability tower and the cyber tower on the same company in the same renewal cycle.
What CG 40 47 removes, and why "arising out of" is the hinge
Read the operative clause before the definition. The readings available render it as bodily injury, property damage or personal and advertising injury arising out of generative artificial intelligence, with one rendering adding "or attributable to".
"Arising out of" is a far wider net than "caused by". It does not ask whether the model made the mistake. It asks whether the loss traces back to the system at all. A pipeline where a model drafted something and a person approved it before it went out is still a pipeline that phrase reaches, because the drafting step is part of the chain that produced the loss. Teams that added a human reviewer specifically to keep the AI out of the causal story should understand that the endorsement was not written to reward that design.
The definition follows. The generative endorsements describe the term around content creation: a machine-based learning system or model trained on data that can create content or responses, including text, images, audio, video or code. Carriers can and do amend wording on filing, so read the definition printed on your own copy rather than any summary of it, including this one. The form text itself is licensed and not publicly readable, which means every version circulating in blog posts and client alerts is a secondary reproduction.
Two definitions of AI are now in circulation
Here is where the engineering translation actually matters. The standard forms are all generative in scope. Separately, at least one carrier has filed what the market calls an absolute AI exclusion, attaching to D&O, errors and omissions and fiduciary liability. Its operative clause excludes loss on any claim "based upon, arising out of, or attributable to: (1) any actual or alleged use, deployment, or development of Artificial Intelligence".
Its definition of artificial intelligence is the interesting part: any machine-based system that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
That is Article 3(1) of the EU AI Act with the autonomy and adaptiveness clause deleted. Compare them word for word and the only material difference is that the regulation's "designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment" is gone. Removing it removes the only qualifier that a plain statistical model could have escaped through. What remains names predictions and recommendations as outputs, which puts a gradient-boosted fraud scorer, a churn model and a ranking system inside the definition just as firmly as a chat assistant.
So there are two endorsements, both called AI exclusions, that draw the boundary in completely different places on the same architecture diagram.
The last row is the one most teams get wrong. "Use, deployment, or development" covers a company that merely turns on a supplier's AI feature. You do not need an ML team to be inside these words.
| System in your stack | Content-creation wording (CG 40 47 family) | Machine-based-system wording (absolute) | What decides the argument |
|---|---|---|---|
| LLM chat assistant, customer-facing | Inside | Inside | Nothing to argue. It creates content. |
| RAG over internal documents | Inside | Inside | Retrieval provenance decides which document caused the loss, not whether the exclusion applies |
| Summarisation and drafting inside a workflow | Inside | Inside | Whether the human step is evidenced, not whether it existed |
| OCR and document parsing | Arguable | Inside | Whether extraction counts as creating content or reading it. Layout-model output text is contested |
| Fraud and risk scoring, gradient boosted | Outside | Inside | "Predictions" is a named output in the absolute wording |
| Recommendation and ranking | Outside | Inside | "Recommendations" is named explicitly |
| Demand forecasting | Outside | Inside | Same. A forecast is a prediction |
| Classical regression scorecard | Outside | Arguable | Whether a fitted linear model "infers from input". Read literally, yes |
| Third-party AI inside licensed software | Inside | Inside | "Use, deployment" reaches you even though you built nothing |
Where the exclusions land outside general liability
General liability is the visible change, but it is rarely the tower a technology company actually claims against. Professional liability and technology errors and omissions, D&O, fiduciary, employment practices and media liability are each being narrowed independently. Cyber has moved least so far, because many carriers still treat AI incidents as an extension of existing perils such as unauthorised access and social engineering fraud rather than as a new class.
Two of the four prongs in the absolute endorsement fire without anything going wrong in a model at all: statements or disclosures regarding AI, and demands to investigate AI risk. The other two cover AI use, deployment or development, and AI regulatory violations. In practice that means marketing copy about your AI capabilities is now a coverage question, and so is a shareholder demand that the board investigate AI risk exposure. Nothing has to fail for those to be triggered.
If you operate in a regulated sector, this sits directly next to the obligations you already carry. Our companion piece on AI compliance for financial services covers what regulators require of you before deployment. This post is the opposite direction: what your own carrier will decline to pay after something goes wrong.
Eight things to pull from the policy before renewal
Do this as a document exercise, not a conversation. Everything below is in PDFs you already have.
pdftotext -layout policy-2026-renewal.pdf - \ | grep -n -i -E "artificial intelligence|generative|machine-based|\ CG 40 4[78]|CG 35 08|arising out of|attributable to"
The single highest-value line is the second one. A summary of the definition is not the definition. Filing amendments are where the real variance lives, and a two-word change in the definition can move an entire product line from outside to inside.
| What to pull | Where it lives | What a bad answer sounds like |
|---|---|---|
| The full forms and endorsements schedule | Declarations page, usually the last section | "The broker has that somewhere" |
| The AI definition as printed on your copy | The endorsement itself, not a summary | "It's the standard wording" (carriers amend on filing) |
| The trigger phrase | Operative clause, first sentence of the endorsement | "It only applies if the AI caused it" |
| Which coverage parts are hit | Form number and its title suffix | "We have AI coverage" |
| Whether products and completed operations is separately endorsed | A CG 35 08 line in the schedule | "GL is one policy, so one answer" |
| Professional liability and tech E&O AI wording | A different policy entirely | "The GL is clean, so we're fine" |
| D&O and fiduciary AI prongs | Endorsements on the management liability tower | "We don't use AI at board level" |
| Cyber definitions of computer system and security failure | Definitions section of the cyber form | "Cyber covers anything digital" |
After an incident, your logs argue the coverage question
Once a claim is live, "arising out of" gets argued over facts, and the facts are whatever your telemetry can produce. Most production AI stacks cannot answer the four questions that matter.
Which model, exactly, at that moment. Not "GPT-class model" and not "our assistant". A pinned identifier and, where you host it yourself, a weights digest. If your provider rotated a version under you between the event and the investigation, you cannot reconstruct behaviour, and you will be arguing about a system nobody can re-run.
What it retrieved. Document identifiers, revisions and source systems, not just the answer text. When the loss came from a stale policy document rather than the model, provenance is the difference between a document-management failure and an AI failure.
What the human actually did. This is where most approval workflows collapse under inspection. A reviewer identity and a timestamp are not evidence of review. A draft hash, a final hash, an edit count and a dwell time are. If every record in the log shows an identical draft and final with a four-second review interval, you have documented a rubber stamp, and you have documented it in your own systems.
{
"request_id": "req_01J8K2M4",
"model_id": "llama-3.3-70b-instruct",
"weights_digest": "sha256:9f2c...",
"serving_stack": "vllm 0.11.0",
"prompt_template_version": "claims-summary@v7",
"retrieved": [
{"doc_id": "POL-4471", "revision": "2026-03-11", "chunk": "3/9", "source": "policy-admin"}
],
"draft_hash": "sha256:41ab...",
"final_hash": "sha256:77de...",
"edit_count": 2,
"reviewer_id": "u-2841",
"review_opened_at": "2026-05-04T09:12:41Z",
"review_submitted_at": "2026-05-04T09:14:58Z",
"policy_version_in_force": "ai-use-policy@2026-04"
}Two fields there do disproportionate work. policy_version_in_force ties the output to the internal rules that were live at the time, which is the record a regulator and an underwriter both ask for. The draft and final hash pair is the only cheap way to prove that human review changed anything. Design the approval gate so that meaningful review is the default rather than a click, as we set out in when to require human approval for AI agents, and keep the failure-tracing path intact so you can reconstruct a single bad output months later, which is the discipline covered in how to trace AI system failures.
On-premise does not exit the definition, it changes the evidence
Be honest about this, because the on-premise pitch is easy to overstate here. Self-hosting an open-weight model on your own hardware does not put you outside either definition. Neither the content-creation wording nor the machine-based-system wording references hosting model, cloud provider, model weights or deployment topology. They are written on use, not on infrastructure.
What on-premise deployment changes is the material you can hand over. You own the full request and response log rather than a provider's retention window. The model version is pinned by you rather than rotated under you. The data boundary is documentable, so "no customer data left the network" is a claim with an artefact behind it rather than a vendor assurance. That is exactly the material a coverage argument is made from, and it is the same material an audit needs. The broader tradeoff, including where the cost curve actually crosses, is in our cloud versus on-premise AI comparison.
Build the AI inventory once, use it twice
The artefact that answers a broker's questions is the same artefact the EU AI Act already expects you to maintain. Build it once. One row per system, machine-readable, owned by engineering rather than by a slide deck.
{
"system_id": "claims-triage-01",
"purpose": "Ranks inbound claims for adjuster queue order",
"output_types": ["recommendation", "score"],
"generates_content": false,
"hosting": "on-premise, isolated VLAN, no egress",
"human_decision_point": "adjuster confirms order before any action",
"generative_definition": "outside",
"machine_based_definition": "inside",
"third_party_components": ["none"],
"log_retention_days": 2555
}Add a row for every vendor product with an AI feature enabled, including the ones enabled by default in software you have licensed for years. Those are the systems nobody inventories and the ones the "use, deployment" language reaches most cleanly.
Two neighbouring pieces close the loop. Data residency and the obligations that attach to a deployment are covered in EU AI Act data sovereignty, and the mechanics of assessing systems you already run are in how to audit existing AI for bugs, bias and performance. For the wider strategic context, the AI for business pillar is the map.
The recommendation is narrow and it is a build task, not a procurement task. Inventory every system against both definitions, not one. Fix the logging so model version, retrieval provenance and genuine human review are provable per request. Then take that inventory into the renewal conversation. A carrier attaching a blanket exclusion to a company that cannot describe its own AI surface is making a rational decision. The inventory is what changes the conversation, and it is the same work that makes the systems defensible whether or not anyone ever files a claim.
FAQ
Quick answers to the questions this post tends to raise.



