What ISO CG 40 47 and CG 40 48 Mean for AI Companies
- In January 2026, Verisk ISO released endorsement forms CG 40 47, CG 40 48, and CG 35 08 that exclude generative AI liability from standard commercial insurance policies. Approximately 95% of carriers are adopting these exclusions.
- The “arising out of” trigger language is interpreted broadly. If a generative AI model appears anywhere in your production chain, the exclusion applies — even with human editorial review.
- The exclusions extend beyond CGL into Directors & Officers, Errors & Omissions, and Cyber Liability policies, creating coverage gaps across your entire insurance tower.
- A specialty affirmative AI insurance market has emerged, but coverage requires demonstrable data provenance and governance. Self-attestation is not sufficient for underwriting.
+ Jump to Section
What Happened
For years, the insurance industry treated AI liability as “silent AI” — unpriced risk sitting quietly inside existing commercial policies. Nobody knew whether a standard commercial general liability (CGL) policy covered harm caused by an AI system, because the policies were not written with AI in mind. Carriers collected premiums without pricing the exposure. Companies deployed AI systems without knowing whether their insurance would respond to a claim.
In January 2026, the Insurance Services Office (ISO), a Verisk entity whose standardized forms are used by the vast majority of U.S. commercial carriers, ended the ambiguity. ISO released a suite of optional endorsement forms designed to explicitly exclude generative AI exposures from commercial liability policies. The endorsements define generative AI as “a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video, or code.”
The adoption rate has been approximately 95%. This is not a niche market development. It is a near-universal repricing of risk that affects every company that builds, deploys, licenses, or sells AI systems.
The Three Endorsements
ISO released three primary endorsement forms, each targeting a different part of the commercial liability policy:
CG 40 47 is the broad form. It excludes all bodily injury, property damage, and personal/advertising injury arising out of generative AI. This eliminates coverage for both physical harm (an AI system issuing dangerous instructions) and reputational or intellectual property harm (AI-generated defamation, copyright infringement, voice misappropriation). If your company has a CGL policy with this endorsement, your standard insurance does not cover any liability connected to generative AI.
CG 40 48 is the narrow form. It excludes only personal and advertising injury — Coverage B in insurance terminology. This leaves physical injury coverage intact but removes the primary defense for copyright infringement, voice misappropriation, libel, and defamation claims arising from AI systems. For media companies, content platforms, and AI audio companies, Coverage B is historically the most critical component of a CGL policy. Losing it is not “narrow” in any practical sense.
CG 35 08 is the products and completed operations form. It excludes bodily injury and property damage that arises after a product or service has been delivered. For AI software vendors, this means that if a customer deploys your AI system and it causes harm downstream, your products liability coverage will not respond — even though products liability was historically the specific coverage designed for exactly this scenario.
In addition to the ISO forms, individual carriers including W.R. Berkley, Chubb, Great American, and Hamilton Insurance Group have drafted their own absolute exclusions that strip all coverage touching the “use, deployment, or development” of AI from Directors & Officers, Errors & Omissions, and fiduciary liability policies.
The “Arising Out Of” Problem
The operative phrase in all three ISO endorsements is “arising out of, or attributable to, generative artificial intelligence.” This phrase has a specific legal meaning that is broader than most non-insurance professionals realize.
In U.S. insurance jurisprudence, “arising out of” does not require proximate causation. It requires only a minimal “but-for” causal connection to the excluded peril. If a generative AI model appears anywhere in the causal chain — even as an intermediate tool among traditional production techniques — the exclusion triggers.
Consider a concrete example: a podcast production company uses an AI tool to transcribe, edit, or translate audio content. A human editor reviews and approves the final output. The output contains a defamatory statement. Under a CGL policy carrying the CG 40 47 or CG 40 48 endorsement, the carrier will deny coverage. The human-in-the-loop does not matter. Because the content originated from a process involving a generative AI model, the exclusion applies.
This is not a hypothetical interpretation. It follows directly from decades of case law on “arising out of” language in insurance exclusions. The practical consequence is that any company using generative AI in any part of its workflow — not just as the primary production tool, but as any component in the chain — should assume that its standard CGL coverage will not respond to claims connected to that workflow.
Beyond CGL: The Fracturing of the Insurance Tower
The exclusion wave is not limited to general liability. Carriers are expanding AI exclusions across the entire professional liability stack:
Directors & Officers (D&O). Absolute exclusions strip coverage for shareholder lawsuits alleging governance failures related to AI — including “AI washing” claims, failure to disclose AI-related risks, and inadequate board oversight of AI deployment.
Errors & Omissions (E&O). Tech E&O policies that previously covered software defects are now excluding liability arising from AI outputs. An AI developer facing a class-action lawsuit for scraping copyrighted audio to train a text-to-speech model will find its E&O policy unresponsive.
Cyber Liability. Traditional cyber insurance was designed for network security breaches, ransomware, and unauthorized data exfiltration. It does not cover the intentional, algorithmic ingestion of copyrighted content for AI training purposes. Even where cyber policies provide sub-limits for AI-triggered events, these are routinely capped at $500,000 — negligible against mass copyright litigation where statutory damages can reach $150,000 per infringed work.
The cumulative effect is that an AI company can find itself with coverage gaps across every line of its insurance program simultaneously. Standard CGL does not cover AI liability. E&O does not cover AI outputs. Cyber does not cover intentional data ingestion. D&O does not cover governance failures around AI. The company is paying premiums across multiple policies and receiving coverage for none of its core AI-related risks.
The Affirmative AI Insurance Market
The vacuum created by the ISO exclusions has produced a new market: dedicated, affirmative AI liability insurance built from scratch to cover the risks that standard policies now exclude.
This market is still concentrated. The primary capacity comes from Lloyd's of London coverholders and Munich Re, not from standard commercial carriers:
- Armilla AI (Lloyd's coverholder) offers standalone AI liability coverage up to $25 million. Coverage explicitly includes AI agent failures, model hallucinations, IP infringement defense, and regulatory investigations. The critical underwriting requirement: independent AI system certification before binding.
- Munich Re / Mosaic (aiSure) provides up to €15 million in performance guarantee coverage. Claims are settled based on measurable telemetry and performance thresholds rather than fault-based investigation. The structure requires verifiable performance data.
- Testudo (Lloyd's Lab alumnus) offers up to $9.25 million covering errors from AI outputs, IP infringement, defamation, and resulting bodily injury. Targets mid-market enterprises with demonstrated governance.
- Relm Insurance (50-state MGA) offers Difference-in-Conditions wrap policies explicitly designed to cover the exclusions left by standard policies, including deep-fake digital crime cover and training data IP disputes. Underwriting is governance-tiered.
The common thread across all of these carriers is that access to coverage requires demonstrable data governance. None of them will bind a policy based on self-attestation alone. They all require some form of independent verification of data provenance, consent documentation, or algorithmic governance — because the loss experience that prompted the ISO exclusions taught them that self-attestation is insufficient to price AI risk.
Why Data Provenance Is Now a Business Requirement
The ISO exclusions have transformed data provenance from a compliance nicety into a business necessity. The logic chain is straightforward:
Enterprise customers require their AI vendors to carry adequate insurance. Government contracts require it. If an AI developer cannot obtain AI liability coverage, it loses access to its most valuable customers. To obtain coverage in the affirmative AI market, the developer must demonstrate verifiable data provenance. To demonstrate verifiable data provenance, the developer needs independent certification of its training data practices.
This is not a regulatory mandate. It is a market mechanism. The insurance industry has created an economic forcing function that makes independent data certification commercially necessary, regardless of what any regulator requires. Even if every AI governance regulation were repealed tomorrow, the insurance market would still demand provenance verification — because insurers cannot price risk they cannot measure.
For AI companies, the practical implication is that data provenance infrastructure is no longer optional. It is a prerequisite for insurance, which is a prerequisite for enterprise sales, which is a prerequisite for revenue. Companies that build this infrastructure now will be insurable, saleable, and defensible. Companies that do not will face an increasingly narrow market as the ISO exclusions work their way through policy renewal cycles.
What to Do Now
If you are an AI developer, deployer, or media company using AI in your workflow, there are five immediate steps:
- Read your policy endorsements. Contact your broker and ask specifically whether your CGL, E&O, cyber, and D&O policies carry AI exclusionary endorsements. Many companies have not checked since their last renewal and may have been endorsed without their knowledge.
- Map your AI exposure. Identify every point in your workflow where a generative AI model is used. Remember that the “arising out of” trigger applies to any use in the causal chain, not just primary use.
- Evaluate affirmative AI coverage. Contact specialty brokers who work with the Armilla, Munich Re/Mosaic, Testudo, and Relm markets. Understand what underwriting information they require.
- Document your data provenance. Begin building the documentation and audit trail that affirmative AI insurers require. If you use third-party training data, determine whether it carries independent certification.
- Review your vendor contracts. If you license AI tools from third parties, determine whether the vendor carries affirmative AI coverage and whether their indemnification obligations survive the ISO exclusions.
The ISO exclusions are not going away. They represent the insurance industry's considered judgment about how to handle AI risk, and that judgment is being ratified by a 95% adoption rate. The companies that adapt their risk management to this new reality will maintain their insurability and their market access. The companies that do not will discover, at the worst possible moment, that the insurance they have been paying for no longer covers the risks they are running.
Related Filing: Box Commons Public Comment on Colorado ADMT Proposed Rules (4 CCR 904-6) — Filed September 23, 2026
Related Analysis: Audio Data Is the Next AI Liability Frontier
Content Integrity Notice: This analysis was authored by the Box Commons Policy Working Group. Generative AI was used for research synthesis and drafting support. All policy positions, recommendations, and normative claims were formulated and reviewed by human authors.