A companion read to the panel-feeding piece I published earlier this week — same evidentiary thread, different audience and context.
The insurance industry has spent the last eighteen months adding AI exclusion clauses to commercial policies. Berkshire Hathaway’s National Indemnity unit has been one of the more visible movers; state-regulator filings reported in early 2025 document carriers including Berkshire Hathaway and Chubb winning approval to drop AI coverage from commercial policies (Reference 1). The law-firm secondary literature has been tracking the pattern at scale (Reference 2). Reinsurance contracts are getting AI-specific carve-outs — Munich Re’s aiSure™ product line treats AI-induced loss as a distinct insurable category, pioneered in 2018 and expanded materially more recently (Reference 3); and the reinsurance-industry research literature signals that the layer is treating AI-induced loss as a category requiring its own pricing model (Reference 4). Cyber policies are getting silent-AI exclusions reframed as named-AI exclusions, following the same silent-to-named pattern Lloyd’s of London formalized for cyber war and state-backed cyber-attacks (References 5, 6); the London market is now turning the same lens on AI (Reference 7). Errors and omissions, professional liability, directors and officers — every line that touches enterprise AI deployment is moving in the same direction. The carriers are signaling something the public commentary has not quite caught up to.
What they are signaling is not that AI is uniquely dangerous. They are signaling that AI-induced loss is not yet well-enough understood to price — and you cannot underwrite what you cannot understand. The exclusion is the rational response of a pricing apparatus that does not yet have the evidentiary record it needs.
That same evidentiary thread is what I wrote about earlier this week ahead of my IMD Lausanne panel, reframed there for patent examiners, regulators, and auditors. The audience changes; the underlying problem does not. Insurance is just the audience the business will hear from first, because the renewal cycle is faster than the patent-litigation cycle.
Why the actuarial apparatus is stalling
Insurance underwriting requires three things from any line of business: a definable peril, a defensible loss-distribution estimate, and a way to verify the policyholder did the things their declarations said they did. AI-induced loss currently fails on all three.
The peril is not yet definable. When a model recommends the wrong dose, the wrong trade, the wrong patent-claim language, or the wrong industrial setpoint, the carrier needs to attribute the loss to something concrete: a defective component, a negligent act, a covered event. AI-induced loss spans those categories without sitting cleanly inside any of them. Was it the model? The training data? The integration with the user workflow? The human reviewer who signed off? Until the attribution chain is concrete, the peril definition is not.
The loss distribution is not yet defensible. Actuaries price what they have data on. The AI-induced loss cases that have surfaced publicly are the spectacular ones, not the boring base-rate ones — Moffatt v. Air Canada (Reference 8); Mata v. Avianca (Reference 9); the EEOC v. iTutorGroup AI-hiring-discrimination settlement (Reference 10); Louis v. SafeRent Solutions (Reference 11). Each is real and named, but each is also exceptional. The base-rate AI-induced harms — the small losses that AI workflows quietly produce in production every day — are largely uncounted because most companies do not yet capture the operational data that would let them count. Pricing only on the spectacular cases produces policies that are either wildly overpriced (when the spectacular case is treated as representative) or wildly underpriced (when it is treated as an outlier). The carriers are unwilling to do either, and the exclusions they are filing are the public-record evidence of that posture.
Verification of the policyholder’s actual practices is not yet possible. A typical commercial policy asks the policyholder to attest to security controls, training programs, incident-response procedures. The carrier does not visit the company’s data center to confirm; the attestation plus a few representations does most of the work. For AI-induced loss, the analogous question — what governance did you actually run on your AI deployments — does not yet have an attestable record format. The carrier cannot verify what the company says about its AI program because there is no widely-adopted operational record for it.
So they exclude. It is not a market failure. It is a market accurately observing that the operational record is not there yet.
What evidence insurers will eventually require
The vocabulary differs across underwriter, examiner, regulator, and auditor; the underlying question does not. Each is asking whether a stranger can evaluate what the company did rather than take it on faith.
Verification, for an underwriter, answers a narrow question: do the controls the policyholder claims are actually firing in production? The underwriter wants to see that the human-in-the-loop sign-off named in the policy declaration is happening on every AI output that hits a regulated workflow. Same shape as the patent examiner’s question about whether an AI synthesis attempt produced what the claim says — different artifact, same evidentiary discipline.
Credibility, for an underwriter, is attribution. The carrier wants to see the chain: who decided to deploy this model in this workflow, who tuned the prompts, who reviewed the outputs, who escalated when the model produced something the human did not understand. The reason credibility matters to the carrier is the same reason it matters to the patent examiner — the natural-person decisions are where liability attaches and where defenses live. A policyholder whose attribution chain is documented is insurable in a way that a policyholder whose attribution lives in chat transcripts is not.
Audit trail, for an underwriter, is the document the carrier asks for the first time a claim is filed. The audit trail tells the carrier whether the policyholder’s controls actually fired, whether the model versions were what the policy declarations said they were, whether the human sign-offs were captured at the moments they were claimed to be captured. The audit trail is the difference between a defensible claim and a denied one.
This pattern is not new. The cyber-insurance market spent the past decades in the same position around cyber liability — peril ill-defined, loss distribution speculative, controls unverifiable. The market only stabilized after a layer of attestation infrastructure built up around it: ISO/IEC 27001 reports, SOC 2 Type II audits, NIST Cybersecurity Framework profiles, HIPAA Security Rule audit trails, PCI-DSS attestations. None of those frameworks was originally designed for the underwriter. Underwriters adopted them because they gave the loss-distribution conversation a defensible footing. AI underwriting will follow the same path — likely faster, because the cyber precedent is still alive in carriers’ institutional memory, and slower in the sense that the AI control surface is broader and harder to inventory.
What companies should build now
The reasonable response to the current AI-exclusion wave is not to wait for the carrier-side apparatus to mature. It is to build the operational record now, before upcoming renewal cycles force a frantic reconstruction. Some considerations:
Build the AI-deployment evidentiary record as a side effect of the work, not as a separate compliance artifact. Most organizations today document AI deployments in slide decks for the AI committee or governance review. Slides are not auditable documentation. The operational record is — versioned prompts, model fingerprints, output snapshots, sign-off captures, attribution at each branch. If the AI governance program produces those artifacts continuously, the carrier-attestation answer is already on the shelf when the underwriter asks for it.
Pin model versions to specific deployments and keep the pinning across years. I covered this in the prior companion piece in detail; the short version is that “GPT-5” or “Claude 4” is not a model version — the dated, fingerprinted release identifier is. The retention horizon should be the longer of the policy term, the relevant statute of limitations, and any regulatory retention obligation. For most enterprise AI deployments, this is likely seven to ten years. If patent related, perhaps much longer.
Treat the AI governance frameworks as exam questions, not deliverables. The frameworks the carriers will eventually align with — NIST AI RMF (Reference 12), ISO/IEC 42001 (Reference 13), OECD AI Principles (Reference 14), the DoD Responsible AI Strategy, whichever sector-specific overlay applies — converge on a small set of obligations that map cleanly onto the cyber-insurance attestation pattern. Identify the risks the system can create. Measure them. Document the controls. Show the chain from policy to operation. The company whose AI-funnel governance program produces those artifacts continuously can answer underwriter questions, regulator questions, and patent-examiner questions out of the same record. The company whose governance work happens only when an exam is announced is the one whose policy gets non-renewed.
Decide attribution at the moment of recognition. When a human recognizes that an AI-generated output solves a problem — the moment of possible for patent purposes, the moment of human-in-the-loop sign-off for governance purposes, the moment of policyholder-attestable-control-firing for insurance purposes — that recognition is the inventive moment, the governance moment, and the underwriting moment all at once. Capturing it contemporaneously is cheap. Reconstructing it later is likely impossible. Recognized output without contemporaneous attribution capture is the same defensibility hole the patent examiner sees and the underwriter will see.
A note from the operational side
I have managed the dig-out from a major cyber-security event in a prior executive role. The thing I learned, that no framework document fully conveys, is that the value of the operational record is not in the controls you ran while the breach was happening — it is in the controls you can prove were running before it. When a carrier or a regulator or a litigant asks what your governance looked like at time T, the company that can produce the record from time T is in a different posture than the company reconstructing it from memory and slide decks, if they can even get to them. AI deployments likely will go through the same gravity. The companies building the operational record before they need it will not look like the ones building it during the claim notice.
What the standards work will eventually catch up to
Some of the evidentiary infrastructure is going to come from formal standards work. ISO/IEC 42001 (Reference 13) is partially there. NIST AI RMF (Reference 12) profile guidance is partially there. The IEEE 7000-series is partially there. Sector-specific overlays — model risk management for financial services, NIST 800-218 SSDF (Reference 15), FDA Software-as-a-Medical-Device guidance — are partially there. None of them is yet a single artifact that an underwriter can use as the attestation foundation the way ISO/IEC 27001 reports function for cyber underwriting today. The standards will eventually converge. The convergence will lag the underwriting demand.
The practitioner discipline is the part that does not have to wait. The exclusion clauses are the carrier-side signal that the renewal calculus is changing. The operational record is what changes the answer when it does.
Why this matters for an industrial-platform business specifically
For executives running AI deployment in regulated industries — energy, manufacturing, healthcare, financial services, transportation — the AI exclusion wave is not abstract. The lines that exclude AI are the lines those industries depend on for operating coverage. Errors and omissions, products liability, professional liability, directors and officers, cyber. The same record that solves the carrier problem solves the regulator problem and the patent-examiner problem. Build it once, satisfy three audiences.
References
Reference 1. Berkshire Hathaway, Chubb Win Approval to Drop AI Insurance Coverage, THE INFORMATION (2025), https://www.theinformation.com/articles/berkshire-hathaway-chubb-win-approval-drop-ai-insurance-coverage.
Reference 2. Hunton Andrews Kurth LLP, The Continued Proliferation of AI Exclusions, HUNTON INS. RECOVERY BLOG, https://www.hunton.com/hunton-insurance-recovery-blog/the-continued-proliferation-of-ai-exclusions.
Reference 3. Munich Re, aiSure™—More AI Opportunity, Less AI Risk, https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html.
Reference 4. Swiss Re Inst., AI—Unintended Insurance Impacts and Lessons from “Silent Cyber,” SONAR 2024, https://www.swissre.com/institute/research/sonar/sonar2024/ai-silent-cyber.html.
Reference 5. Lloyd’s of London, Market Bulletin Y5381: Cyber-Attack Exclusions, https://assets.lloyds.com/media/35926dc8-c885-497b-aed8-6d2f87c1415d/Y5381%20Market%20Bulletin%20-%20Cyber-attack%20exclusions.pdf.
Reference 6. Lloyd’s of London, Market Bulletin Y5433: State-Backed Cyber-Attack Wordings, https://assets.lloyds.com/media/6335bcb0-e2a2-4378-8328-1ddf54828f2f/Y5433.pdf.
Reference 7. Lloyd’s Mkt. Ass’n, Understanding Artificial Intelligence Risk in Insurance Products—The Challenges, https://lmalloyds.com/understanding-artificial-intelligence-risk-in-insurance-products-the-challenges/.
Reference 8. Moffatt v. Air Canada, 2024 BCCRT 149 (Can. B.C. Civ. Resol. Trib. Feb. 14, 2024), https://www.canlii.org/en/bc/bccrt/doc/2024/2024bccrt149/2024bccrt149.html. (Air Canada held liable for negligent misrepresentation by its chatbot regarding bereavement-fare eligibility; CAD $650.88 in damages.)
Reference 9. Mata v. Avianca, Inc., 678 F. Supp. 3d 443 (S.D.N.Y. 2023), https://law.justia.com/cases/federal/district-courts/new-york/nysdce/1:2022cv01461/575368/54/. (Attorneys sanctioned $5,000 plus letter-writing obligations for filing brief with ChatGPT-fabricated case citations.)
Reference 10. EEOC v. iTutorGroup, Inc., No. 22-cv-2565 (E.D.N.Y. consent decree Aug. 9, 2023), https://www.eeoc.gov/newsroom/itutorgroup-pay-365000-settle-eeoc-discriminatory-hiring-suit. ($365,000 settlement; software automatically rejected female applicants age 55+ and male applicants age 60+; first EEOC AI-hiring-discrimination resolution.)
Reference 11. Louis v. SafeRent Sols., LLC, No. 22-cv-10800 (D. Mass. final approval Nov. 20, 2024), https://www.justice.gov/crt/case/louis-et-al-v-saferent-et-al-d-mass (U.S. Dep’t of Justice, Civ. Rights Div., case page). ($2.275M settlement; tenant-screening algorithm produced disparate impact against Black and Hispanic applicants holding housing vouchers; DOJ and HUD filed a Statement of Interest Jan. 9, 2023.)
Reference 12. Nat’l Inst. of Standards & Tech., AI Risk Management Framework (AI RMF 1.0), https://www.nist.gov/itl/ai-risk-management-framework.
Reference 13. Int’l Org. for Standardization & Int’l Electrotech. Comm’n, ISO/IEC 42001:2023—Information Technology—Artificial Intelligence—Management System, https://www.iso.org/standard/81230.html.
Reference 14. Org. for Econ. Co-operation & Dev., OECD AI Principles, https://www.oecd.org/digital/artificial-intelligence/.
Reference 15. Nat’l Inst. of Standards & Tech., Special Publication 800-218: Secure Software Development Framework (SSDF), https://csrc.nist.gov/Projects/ssdf.