Insurance & Liability14 min read

Insurers Are Writing AI Out of Their Policies. Caribbean Boards Are Assuming It's Still In.

By Howard Williams·Jul 20, 2026
TLDR
  • Since 1 January 2026, Verisk's Insurance Services Office (ISO) has published standard commercial general liability endorsements, CG 40 47 and CG 40 48, that exclude bodily injury, property damage, and personal or advertising injury claims arising from generative AI. A third endorsement, CG 35 08, excludes damage from autonomous systems and robotics.
  • By April 2026, major carriers including Chubb, Travelers, W.R. Berkley, Berkshire Hathaway, and Cincinnati Financial had filed to adopt the exclusion or an equivalent of their own, and state regulators had approved more than 80 percent of the filings submitted. One industry estimate puts eventual adoption across US commercial general liability books near 95 percent.
  • The National Association of Insurance Commissioners' own survey found 84 percent of insurers already using AI or machine learning somewhere in their operations. Insurers are deploying AI in underwriting and claims at scale while simultaneously removing AI-related harm from what their own policies will pay for.
  • A federal court in Minnesota allowed discovery into UnitedHealth Group's nH Predict tool, used to evaluate post-acute care claims, in a ruling that shows plaintiffs' lawyers exactly where AI-driven claims decisions create exposure, the same exposure the new exclusions are built to wall off.
  • No CARICOM insurance regulator or domestic carrier has published AI-specific exclusion language or governance guidance of its own, even though Caribbean commercial policies commonly track US and London market wordings through reinsurance treaties and broker relationships. The exclusion is likely arriving in regional renewal packets already, without anyone in the room deciding it should.
Monochrome view of a courthouse pediment reading Equal Justice Under Law, representing the liability and legal exposure now being written out of AI-related insurance coverage

Image: Margaret Giatras, Unsplash

Since 1 January 2026, the standard commercial general liability form used across the United States insurance market has carried a clause most policyholders have never read. Generative AI is excluded. Two new endorsements, drafted by Verisk's Insurance Services Office and already adopted by several of the world's largest commercial carriers, remove AI-related bodily injury, property damage, and advertising injury claims from coverage that used to apply by default, silently, because nobody had written the exclusion yet. No Caribbean insurer or regulator has said anything equivalent in public. That silence is not evidence the region is unaffected. It is evidence nobody has checked.

What Changed on the First of January

ISO's endorsement CG 40 47 is the broad form. It strips coverage under Coverage A and Coverage B of the standard CGL policy, meaning bodily injury, property damage, and personal or advertising injury, for any claim arising out of generative AI. CG 40 48 is the narrower variant, removing only the Coverage B personal and advertising injury piece, useful for a carrier that still wants to write bodily injury and property damage risk but has decided the reputational and intellectual-property exposure from AI-generated content is not one it wants to hold. A third form, CG 35 08, does the same job for autonomous systems and robotics, catching the physical-world cousin of the same problem: harm caused by a system nobody at the point of injury was directly steering.

None of the three forms are mandatory. ISO drafts standard language; individual carriers choose whether to file it, adapt it, or write their own version. What makes January 2026 a genuine inflection point rather than a paperwork footnote is how fast carriers chose. By April, Chubb, Travelers, W.R. Berkley, Berkshire Hathaway, and Cincinnati Financial, a group that between them underwrites a meaningful share of US commercial liability, had filed to adopt the ISO language or a proprietary equivalent. State regulators approved more than 80 percent of the filings submitted. One actuarial estimate circulating in the market puts ultimate adoption across US commercial general liability books near 95 percent within a couple of renewal cycles. Fenwick, the law firm that has tracked the shift closely, calls it the end of "silent AI", the practice of AI-related harm being covered only because older policy language never anticipated it and so never excluded it. That accident of drafting is closing fast.

Rows of legal reference volumes on a shelf, including a law dictionary, representing the policy wording now defining what AI-related liability is covered and what is excluded

Image: Krists Luhaers, Unsplash

Insurers Are Using AI and Refusing to Insure It

The part of this story worth sitting with is not the endorsement language. It is the behaviour behind it. The National Association of Insurance Commissioners' AI/ML survey, drawing on responses from insurance companies across sixteen US states, found 84 percent already using AI or machine learning somewhere in their operations, in underwriting, pricing, claims triage, or fraud detection. These are the same organisations now writing exclusion language into the policies they sell to everyone else. An insurer is, functionally, a professional risk-pricer. When the industry that prices risk for a living deploys AI enthusiastically inside its own operations while refusing to accept the liability AI creates for its customers, that is not caution. It is a revealed preference, and a more honest one than most voluntary AI governance commitments manage. Insurers are not saying AI is safe. They are saying it is not a risk they are willing to hold on someone else's behalf, at a price anyone would pay.

That distinction matters for how Caribbean boards read the moment. A vendor's responsible-AI pledge is a marketing document. A regulator's framework is a statement of intent that may or may not carry enforcement teeth for years. An insurer walking away from a class of risk it used to cover by default is capital voting with its feet, and capital rarely votes wrong about tail risk for long. The Caribbean insurance sector's own trade coverage has tracked how unevenly AI adoption is spreading through underwriting and claims regionally; this is the moment that coverage needs to start tracking the exclusion side of the ledger too, not only the adoption side.

The Court Case That Shows Why

The liability shape insurers are trying to wall off is not hypothetical. In The Estate of Gene B. Lokken v. UnitedHealth Group, Inc., filed in the US District Court for the District of Minnesota, plaintiffs alleged that UnitedHealth used an AI tool called nH Predict to deny post-acute care claims without meaningful human review. When the insurer resisted producing internal documents, the court granted a motion to compel, permitting discovery into how nH Predict works, what it was built to achieve, and whether it was designed to substitute for a clinician's judgement rather than support it. The ruling, reported in March 2026, does not decide the underlying merits. It does something arguably more consequential for the insurance market: it confirms that when a plaintiff alleges an AI system drove a harmful decision, a court will let them see inside the system to test that claim. Discovery into model design, training objectives, and the degree of human oversight is now a live litigation tool, not a theoretical one. Every carrier writing an AI exclusion in 2026 has that ruling, or one like it, somewhere in the actuarial memo behind the decision.

Where This Lands in the Caribbean

No CARICOM member state has an insurance regulator that has published AI-specific exclusion guidance, and no regional carrier has issued a public statement on how it treats AI-related liability in its own general liability book. That gap looks, at first read, like a reason for Caribbean firms to relax: nobody local has moved, so perhaps nothing has changed locally either. It is the wrong reading. Caribbean commercial insurance runs on capacity borrowed from outside the region. Local insurers place a large share of their commercial general liability risk into reinsurance treaties written against London and US market forms, and brokers placing regional business routinely default to ISO-based wordings because that is the market standard their reinsurance partners recognise. When the underlying form used to build a Caribbean policy changes at its source, the change travels with the paper, whether or not a regional regulator has said a word about it.

The practical result: a Caribbean hotel group running an AI concierge, a fintech using a generative model to draft customer communications, or an insurer itself using AI to triage claims, may already be renewing into a general liability policy that quietly excludes the exact harm those systems could cause, without a broker flagging the change or a board minute recording the decision to accept it. That is a materially different risk position than the one most Caribbean risk committees believe they hold, and the gap between believed and actual coverage is the kind of thing an auditor finds during a claim, at the worst possible moment to discover it.

What a Market Signal Means for Governance Work

There is a second, more constructive reading of the same facts. An insurer that excludes a risk by default is not permanently unwilling to underwrite it. Specialty AI-liability products already exist in the US market, priced and underwritten individually rather than bundled silently into general coverage, and the underwriters writing them ask for exactly the kind of evidence a mature AI governance programme produces: a model inventory, documented human-oversight controls, incident logging, and a record of independent assessment against a recognised standard. That is not a coincidence. It is the same evidence base a regulator wants under the EU AI Act's high-risk obligations for insurance underwriting and pricing systems, obligations that Omnibus VII pushed from August 2026 to December 2027 for standalone high-risk categories such as insurance risk assessment, but did not eliminate. It is also, not incidentally, the evidence base CAIRMC's CARA methodology and the QAIRP certification are built to produce.

The practical implication for a Caribbean compliance officer is that governance work done now serves two audiences that used to require separate paperwork: the regulator that will eventually ask for it, and the underwriter who might, sooner, be willing to write bespoke cover if the evidence exists. Firms with a documented model inventory and a recognised assessment behind it are the ones a specialty AI-liability market will actually want to insure. Firms without one are the ones left holding a general liability policy that no longer covers the risk they are running.

What Caribbean Risk and Compliance Officers Should Do This Quarter

Pull the current general liability wording and read the exclusions, not just the coverage grants. Ask the broker directly whether the policy includes an AI or generative AI exclusion, whether it has been added at the most recent renewal, and what the effective date was. Silence from the broker is not the same as confirmation the exclusion is absent.

Build the model inventory before a claim forces one. List every AI system that touches a customer-facing decision, a claims process, or a public communication, who owns it, what data trains or informs it, and what human review sits between the system's output and the decision that follows. This is the same document an underwriter, a regulator, and a QAIRP-certified assessor will each ask for, in different language.

Treat CARA and ISO/IEC 42001 alignment as insurance infrastructure, not just compliance infrastructure. A governance programme built to CAIRMC's CARA methodology produces the documentation trail that both regulatory frameworks and emerging AI-liability underwriting products are converging on. Building it once, to a recognised standard, is cheaper than building it twice under deadline pressure from two different directions.

Ask what happens to a claim today. If an AI system used in the business caused a harm right now, would the current general liability policy respond? If the honest answer is "we do not know", that answer belongs in the next risk committee minutes, not left for a claims adjuster to discover during an actual loss.

Caribbean institutions have spent much of 2026 tracking what regulators in Brussels and Washington plan to require. The insurance market has moved faster and said something more direct: it is not willing to hold AI liability for free anymore. StarApple AI, the Caribbean's first dedicated AI company, and CAIRMC, the region's AI risk governance body founded and chaired by Adrian Dunkley, exist because someone in the region concluded that waiting for outside institutions to define Caribbean AI risk was not a strategy. The exclusion endorsements landing in general liability renewals this year are further evidence of the same lesson from a different direction. The market has already priced its answer. The question left for Caribbean boards is whether they read it before or after a claim tests it.

Related reading across the Caribbean AI network

This article sits alongside ongoing CAIRMC coverage of AI governance, regulation, and risk across the region. For related perspectives:

Frequently Asked Questions

What are the ISO CG 40 47 and CG 40 48 endorsements?

CG 40 47 and CG 40 48 are standard commercial general liability endorsements published by Verisk's Insurance Services Office (ISO), effective 1 January 2026. CG 40 47 is the broad form, excluding bodily injury, property damage, and personal or advertising injury claims arising from generative AI under both Coverage A and Coverage B of a standard CGL policy. CG 40 48 is narrower, excluding only the Coverage B personal and advertising injury element. A related endorsement, CG 35 08, excludes damage arising from autonomous systems and robotics.

How widely have insurers adopted the AI exclusion?

By April 2026, major carriers including Chubb, Travelers, W.R. Berkley, Berkshire Hathaway, and Cincinnati Financial had filed to adopt the ISO language or an equivalent exclusion of their own. State insurance regulators had approved more than 80 percent of the filings submitted, and one industry estimate projects eventual adoption across roughly 95 percent of US commercial general liability books.

Does a US insurance exclusion actually affect Caribbean businesses?

Indirectly, but materially. No CARICOM insurance regulator has published AI-specific exclusion guidance, but Caribbean commercial general liability policies commonly rely on reinsurance capacity placed against US and London market wordings, and regional brokers routinely default to ISO-based policy forms. When the underlying standard form changes, the change can arrive in a Caribbean renewal without a local regulator or broker flagging it as a deliberate decision.

What is "silent AI" coverage, and why is it disappearing?

"Silent AI" describes coverage that applied to AI-related claims only because older policy language predated generative AI and never explicitly excluded it, not because insurers had deliberately decided to accept the risk. The new ISO endorsements close that gap by making the exclusion explicit, converting an accidental, unpriced exposure into a stated one that policyholders can see and, in principle, negotiate around.

What happened in the Lokken v. UnitedHealth Group case?

In The Estate of Gene B. Lokken v. UnitedHealth Group, Inc., filed in the US District Court for the District of Minnesota, plaintiffs alleged UnitedHealth used an AI tool called nH Predict to deny post-acute care claims without meaningful human review. The court granted a motion to compel discovery into how the tool works and whether it was designed to replace clinical judgement, a ruling reported in March 2026 that confirmed AI model design and oversight practices are now subject to litigation discovery.

Are insurers using AI themselves while excluding it from coverage?

Yes. The National Association of Insurance Commissioners' AI/ML survey found 84 percent of surveyed insurers already using AI or machine learning somewhere in their operations, including underwriting, pricing, and claims. The same organisations deploying AI internally at that rate are the ones now excluding AI-related harm from what their liability policies will pay other businesses for.

What should a Caribbean risk or compliance officer do this quarter?

Four steps: read the current general liability policy's exclusions directly rather than relying on a broker's summary; build a full inventory of AI systems touching customer-facing decisions; align governance documentation to a recognised standard such as CAIRMC's CARA methodology or ISO/IEC 42001, since both regulators and emerging AI-liability underwriters ask for the same evidence; and get a clear answer, in writing, on whether the current policy would respond to an AI-related claim today.

Does CAIRMC's CARA methodology or QAIRP certification help with AI insurance coverage?

CARA and QAIRP were built as risk governance and certification tools, not insurance products, but the documentation they produce, a model inventory, human-oversight controls, and independent assessment evidence, matches what specialty AI-liability underwriters and regulators under frameworks such as the EU AI Act both request. Organisations that build this evidence base are better positioned for both regulatory scrutiny and future underwriting conversations than those that have documented nothing.

Sources and References
  • Verisk / Insurance Services Office (ISO): generative AI exclusion endorsements CG 40 47, CG 40 48, and CG 35 08, effective 1 January 2026
  • Fenwick: "The End of 'Silent AI'? Emerging AI Exclusions, Coverage Fragmentation, and Practical Implications for Policyholders"
  • Gallagher (AJG): "ISO Introduces Generative AI Exclusion in Commercial General Liability Policies"
  • National Association of Insurance Commissioners (NAIC): Health Insurance Artificial Intelligence/Machine Learning Survey Report
  • Hunton Andrews Kurth: "Court Allows Discovery Into Insurer's Use of AI to Deny Claims", covering The Estate of Gene B. Lokken v. UnitedHealth Group, Inc., No. 23-CV-3514 (D. Minn.)
  • European Union: Artificial Intelligence Act, Annex III high-risk categories and Omnibus VII timetable revisions
  • Caribbean AI Risk Management Council: CARA methodology and QAIRP certification, caribbeanairisk.com