The organisations most exposed to artificial intelligence liability in 2026 are not the ones building the models. They are the ones buying them.
Gallagher Re's March 2026 report Smart Systems, Blind Spots, written with MIT and the specialty insurer Testudo, found that generative AI lawsuits in the United States rose 978% between 2021 and 2025, with a 137% jump in the final year alone. Its central finding was not about model developers. It was this: courts and regulators increasingly hold the organisation that deployed the AI accountable, not the technology vendor that supplied it.
Which would be manageable, if the insurance policy you assumed absorbs that exposure had not quietly changed underneath you.
What is the AI insurance gap?
The AI insurance gap is the space between the liability your organisation now carries for its use of artificial intelligence and what your existing commercial policies will actually pay. It has widened in 2026 because insurers began writing explicit generative AI exclusions into general liability, directors and officers, and errors and omissions cover.
Until recently the position was ambiguous. Policies did not mention AI, so exposure sat in what the market calls silent AI cover, the same unresolved state cyber risk occupied before the 1990s.
Ambiguity favoured policyholders. In 2026 insurers removed the ambiguity, and they did not remove it in your favour.
What did ISO change in commercial general liability policies in January 2026?
ISO, the Verisk standards body whose forms underpin most commercial general liability policies, introduced three optional generative AI exclusion endorsements carrying a January 2026 edition date. They began attaching at CGL renewals from 1 January 2026. Carriers choose whether to apply them, which is precisely why coverage now varies policy by policy.
The three forms, as described by Verisk:
--- CG 40 47 excludes bodily injury, property damage, and personal and advertising injury arising out of generative AI, across the whole general liability coverage part. This is the broad one.
--- CG 40 48 excludes only personal and advertising injury, which covers defamation, privacy and copyright claims. Bodily injury and property damage cover survives.
--- CG 35 08 excludes bodily injury and property damage under the products and completed operations coverage part.
The definition matters more than the form numbers. Verisk defines generative artificial intelligence as a machine-based learning system or model trained on data with the ability to create content or responses, including text, images, audio, video or code.
Read that against your own operations. It captures the marketing copy your team drafts with a chatbot, the code your developers generate, and the customer replies your service platform produces. It does not require you to have built anything.
According to reporting by The Insurer in July 2026, Verisk is now weighing separate exclusions for agentic AI risks. The direction of travel is one way.
Which insurers are actually applying AI exclusions?
An analysis published by The Insurer in July 2026, reviewing roughly 10,000 regulatory filings through S&P Capital IQ, identified more than 60 property and casualty groups engaging with AI exclusions. Around 41 groups had at least one subsidiary filing to adopt one, while a further 20 filed to delay adoption.
Named in that filings analysis are Chubb, Zurich, Liberty Mutual, The Hartford, Munich Re, Tokio Marine, Arch Capital, Axis and Berkshire Hathaway, among others. Several told the publication they have no immediate plan to implement.
Two details deserve board attention.
First, one carrier went considerably further than ISO. Bloomberg Law reported in July 2026 that W. R. Berkley introduced a first-of-its-kind absolute AI exclusion, reaching directors and officers cover. Wording circulated by insurance brokers excludes claims arising from any actual or alleged use, deployment or development of AI, extending to the insured's own AI policies and procedures and to any alleged breach of duty regarding AI use.
That last clause is the one that converts a technology question into a governance question. If your board is alleged to have supervised AI adoption badly, that allegation may itself fall outside cover.
Second, not every insurer named in press reporting is proceeding. AIG publicly stated in November 2025 that it was not specifically seeking such exclusions and had no plans to implement them at that time. Do not assume your carrier's position. Ask.
Why does liability land on your organisation rather than the AI vendor?
Because your contract with the vendor almost certainly says so. Gallagher Re's finding is blunt: vendor liability caps and limited indemnities leave deployers exposed, while courts hold deployers accountable for AI failures. The contractual structure and the legal trend point the same direction, at you.
The canonical case remains Moffatt v. Air Canada, decided by British Columbia's Civil Resolution Tribunal in February 2024. Air Canada argued its chatbot was responsible for the fare policy it had invented. Tribunal member Christopher Rivers responded: in effect, Air Canada suggests the chatbot is a separate legal entity that is responsible for its own actions. This is a remarkable submission.
The award was CAD 812.02. The principle is worth considerably more than that. You own what your systems say.
Now layer the contract position on top. A law firm review published by Whiteford, Taylor & Preston in April 2026 cited industry data indicating 88% of AI vendors cap their own liability, frequently at the value of monthly subscription fees, while only 17% warrant regulatory compliance. Attribute that figure to the firm rather than to a named study, because the firm did not name one.
Set those numbers beside a live exclusion and the shape of the problem is clear. The vendor has capped exposure at your monthly invoice. The insurer has excluded the class of loss. The residual sits on your balance sheet, unpriced.
Does the AI exclusion story apply in Hong Kong?
Not directly, and the distinction matters. As of August 2026 the Hong Kong Insurance Authority has issued no guidance on AI exclusions in commercial policies, no Hong Kong court has ruled on AI liability, and no local market data on exclusion uptake exists. This is presently a United States market development.
It reaches Hong Kong through three routes, all of them ordinary.
--- Multinational programmes underwritten in the United States, or fronted locally on US forms, inherit the endorsement.
--- Reinsurance treaties transmit wording downstream over subsequent renewal cycles.
--- Hong Kong subsidiaries of groups whose master policy sits in New York or London find the exclusion arrives without a local conversation.
Meanwhile the accountability expectation locally is already firm, even without an AI statute. Mayer Brown's mid-year 2026 review of Hong Kong and Singapore AI regulation summarised the position as organisations being expected to demonstrate, not merely assert, responsible AI governance.
The evidence supports that reading. The Privacy Commissioner for Personal Data launched compliance checks on 60 organisations in January 2026 and published results in May: 95% used AI in daily operations and over half ran three or more AI systems, with no PDPO contravention found but recommendations covering governance structures, privacy impact assessments, AI audits and controls for agentic AI. The PCPD had issued a separate alert on agentic AI in March 2026. The HKMA and SFC both circulated guidance on AI-enabled cyberattacks in late May 2026, building on the HKMA's earlier AI cyber circular.
One counterpoint, because the picture is not uniform across Asia. In January 2026 the Hangzhou Internet Court in mainland China dismissed claims against a generative AI service provider over a hallucinated answer, finding the provider had met a reasonable duty of care through industry-standard accuracy measures and user warnings. That cuts against the US deployer-liability trend rather than with it.
What affirmative AI insurance can you actually buy in 2026?
A small affirmative market now exists, targeted mainly at organisations that use AI rather than build it. It is early, capacity is limited, and none of it is a substitute for governance. It does convert an unpriced exposure into a priced one, which is the point.
Verified products as of August 2026:
--- HSB AI Liability Insurance, launched by the Munich Re subsidiary on 18 March 2026 for small and mid-sized businesses. It covers third-party bodily injury, property damage, and personal and advertising injury arising from the insured's use of AI. HSB does not sell direct; the cover is added to partner carriers' business policies subject to regulatory approval. HSB's own survey of 1,000 US businesses found 74% already use AI programmes and 91% plan to.
--- Armilla, a Lloyd's coverholder launched in April 2025, underwritten by Lloyd's syndicates including Chaucer. It triggers affirmatively on AI hallucinations, deteriorating model performance and malfunction, covering legal fees and third-party liability.
--- Testudo, a Lloyd's Lab-backed managing general agent writing specifically for enterprises that integrate vendor generative AI, explicitly not for AI developers.
--- Google Cloud Risk Protection Program, delivered with Beazley, Chubb and Munich Re as an endorsement on the insurer's cyber policy.
Ask any broker presenting one of these how the affirmative grant interacts with the exclusion on your general liability policy. Two documents drafted by different underwriters do not automatically meet in the middle.
What should you ask before your next policy renewal?
Six questions, in this order, put to your broker in writing before renewal. Written answers matter more than a call, because the answers become the record of what your organisation knew and when it knew it.
--- Does our current general liability policy carry CG 40 47, CG 40 48, CG 35 08, or a carrier-specific AI exclusion? Send the endorsement schedule.
--- Does any AI exclusion appear on our directors and officers, errors and omissions, professional indemnity, or cyber policies?
--- Where AI exclusion language exists, does it reach alleged breaches of duty regarding our AI governance, as distinct from AI outputs alone?
--- Which of our operational uses of AI fall inside the policy definition of generative AI? Test it against marketing content, customer service replies, code generation and internal decision support.
--- What affirmative cover is available to us, at what limit and attachment point, and how does it interact with the exclusion?
--- What is our carrier's stated position for the following renewal cycle, not just this one?
Then take the endorsement schedule to the audit or risk committee. This belongs on a committee agenda, not in a broker's file.
What goes wrong when organisations handle this badly?
Four failure patterns recur, and each is avoidable at negligible cost. None require legal expertise to spot. They require somebody senior to read the endorsement schedule, which in most organisations nobody has done.
Renewing on autopilot. Most commercial renewals are processed by finance or facilities as an administrative task. An endorsement that materially reduces cover arrives inside a package nobody reads line by line. The exclusion is opt-in for the carrier, never opt-in for you.
Assuming the vendor contract is the backstop. If 88% of AI vendors cap liability at subscription value, that backstop is worth roughly one month's invoice. It is not a risk transfer. It is a rounding error.
Treating this as an IT matter. The W. R. Berkley wording reaches directors and officers. Once the exposure touches D&O, it is a board matter and delegating it downward is itself the governance failure the exclusion contemplates.
Waiting for a court ruling. Bloomberg Law and Claims Journal both confirmed in July 2026 that no bellwether ruling on AI coverage yet exists, and no verified case of a company being denied AI-related coverage has emerged. That is not reassurance. It means the first organisation to test this wording will do so during a live claim, having already suffered the loss.
The strategic takeaway
The AI insurance gap is not a technology problem that happens to involve insurance. It is a governance problem that insurance has now made visible and expensive.
The organisations that handle it well in the next twelve months will do three unglamorous things. They will read their endorsement schedules. They will map their actual AI use against the policy definition rather than against their AI strategy deck. And they will document the governance they can demonstrate, because both the Hong Kong regulators and the emerging insurance wording are asking for evidence rather than intention.
That work is not exciting and it will not appear in an annual report. It is the difference between an exposure you have priced and one you discover during a claim.
Twenty-eight years of Hong Kong enterprise technology work teaches one thing repeatedly: the risks that hurt are rarely the ones on the risk register. They are the ones everybody assumed somebody else had covered. We understand AI. We understand you. With UD by your side, AI never feels cold.
Reviewed by the UD enterprise AI team, Hong Kong. Insurance form references, carrier positions and regulatory dates in this article were verified against Verisk, Gallagher Re, Bloomberg Law, Claims Journal, Munich Re HSB and Hong Kong regulator publications in August 2026. This article is general information, not legal, insurance or financial advice. Confirm your own policy position with your broker and legal adviser.
Where to start
Before you can price your AI exposure, you need an honest picture of where AI already sits in your operations. That is exactly what the Privacy Commissioner found most organisations lack. UD's team will walk you through every step, from mapping actual AI use across departments, to governance documentation, to the evidence your board and your broker will both ask for. Twenty-eight years of Hong Kong enterprise experience, alongside you the whole way.