The Coverage Memo

AI Product Liability and Insurance for Startup Founders

Standard tech insurance won't cover AI failures, and policies are being rewritten to prove it.

Features Editor · · 9 min read
Cover illustration for “AI Product Liability and Insurance for Startup Founders”
Tech and Product Liability · September 23, 2026 · 9 min read · 2,031 words

Most AI startups think their existing tech insurance covers what happens when their model screws up. That assumption is wrong, and the insurance industry has spent the last two quarters making sure everyone knows it. What used to be silence, policies that neither confirmed nor denied AI coverage, has hardened into explicit exclusion, and the shift happened fast enough that a lot of founders won't find out until a claim gets denied.

The paper trail is public. Berkley Insurance Group and Hamilton Insurance Group filed broad AI exclusions across their E&O, D&O, and cyber liability lines in late 2025. Verisk's ISO Form CG 40 47 01 26, effective January 2026, gives carriers a standard mechanism to strip generative AI claims out of commercial general liability policies. Berkshire Hathaway and Chubb both won regulatory approval to drop AI coverage. None of this is a rumor circulating on some founder messaging group. It's filed, dated, and sitting in state insurance department records. Policies renewing in the first half of 2026 are the ones most likely to get hit first, and a founder mid-contract has no real way of knowing the exclusion is there until the moment they need the policy to pay out.

Here is the assumption that just died: "my policy covers this" stopped being a safe thing to say to a board or a customer. Everything below follows from that one fact, and founders who treat it as a formality rather than a structural problem are going to find that out the hard way.

What AI systems do that legacy policies were never designed to cover

Standard tech policies were built around a simple model of failure in which a human wrote code, the code had a bug, and the bug caused a loss. AI breaks that model because the failure doesn't originate in a line of code anyone can point to. It originates in a statistical process that behaves differently depending on the data it sees, and it fails in ways a compiler error never could.

Hallucination is the clearest example. A model states something false with the same confident tone it uses for something true, including a fabricated legal citation or a discount that was never authorized. Drift is quieter and slower: a model trained on one distribution of data degrades as the real world moves away from that distribution, and nobody notices until the error rate has already climbed. Agentic workflows add a further wrinkle, since an autonomous system that books, purchases, or executes on its own can take an action a human reviewer would have caught in half a second. Prompt injection lets a malicious input hijack the model's behavior. Algorithmic bias produces discriminatory outcomes in hiring, lending, or healthcare decisions, exposure that's civil and regulatory at once. Training data brings its own liability, tangled up in copyright disputes and privacy claims tied to what the model actually learned from. Data poisoning, the deliberate corruption of inputs, sits alongside all of it as a distinct attack surface legacy underwriters never modeled.

The Air Canada case shows how this plays out once it leaves the whiteboard and hits a courtroom. The airline's chatbot invented a discount that didn't exist, a customer relied on it, and the tribunal ruled Air Canada had to honor the fabricated offer anyway. The airline attempted to distance itself from the chatbot's statements. The tribunal wasn't interested. A company is on the hook for what its AI tells a customer the same way it's on the hook for what a human employee tells a customer, and that principle doesn't stay contained to chatbots. The Landgericht München's May 2026 ruling on Google's AI Overviews reinforced the same logic in the context of AI-generated content, not just conversational outputs. Once a court decides that AI output is company output, liability stops being theoretical for anyone whose product generates text, images, or decisions at scale.

The regulatory pressure compounding the insurance gap

Diagram: The Dedicated AI Insurance Market: Three Providers, Early Limits. Visualizes: Visualize a ranked comparison of the only three standalone AI liability insurers as of March 2026.

Founders now have to track two regulatory regimes moving in opposite directions, and both raise the cost of the exact failures insurers are busy excluding.

The EU has picked precision. The revised Product Liability Directive entered into force in December 2024 and has to be transposed into national law by member states by December 9, 2026. It explicitly extends product liability to software, AI included, and ties that liability to compliance with EU product safety law, which makes the EU AI Act the practical yardstick for whether an AI system counts as defective. The AI Act carries significant financial penalties, putting it in the same weight class as GDPR fines. The AI Omnibus and Digital Omnibus proposals soften some deadlines around high-risk system rules, but the underlying obligations aren't going anywhere.

The US has picked fragmentation. There's still no single federal AI statute as of mid-2026, just a mix of executive orders, the NIST AI Risk Management Framework, and scattered sector guidance. Colorado has moved furthest, first with SB 24-205 and now its replacement, SB 26-189, which creates obligations for developers and deployers of "high-risk" AI systems touching employment, housing, lending, insurance, healthcare, education, government services, or legal services. Those obligations include impact assessments, disclosure to the people affected, and an appeals process. Other states have added their own measures, a patchwork that founders operating across state lines now have to track state by state.

Regulators are creating new grounds for claims (mandatory disclosures, impact assessments, appeals rights) at the exact moment insurers are writing exclusions for the AI behavior those claims arise from, which creates the bind. Regulators are creating new grounds for claims (mandatory disclosures, impact assessments, appeals rights) at the exact moment insurers are writing exclusions for the AI behavior those claims arise from. Neither side is coordinating with the other. The founder sits in the middle, and the size of that middle only grows.

The four coverage types an AI startup needs and what each one does

Coverage for an AI company works as a stack. Each layer catches something the others don't, and a gap in one leaves an opening the others were never built to close. Skipping any layer doesn't save money; it just chooses which claim bankrupts you first.

Tech E&O, or Tech and AI Liability specifically, sits at the center. It's a hybrid of errors-and-omissions and product liability coverage, built for companies selling something between a service and a product, and it's meant to cover claims that a model or algorithm failed to perform as promised and cost a customer real money. A standard Tech E&O policy has to name hallucination, drift, algorithmic bias, and training data disputes explicitly. Silence on those points means it's a legacy form wearing an AI-era label, and silence is what carriers have stopped honoring as coverage. Underwriters use the word "affirmative" for a policy that names the AI risk outright instead of leaving it to be inferred, and that's the only version worth buying now. Anything less isn't really coverage, it's a policy that happens to exist.

Cyber liability shapes an AI company's exposure to data breaches directly, because that exposure is structural rather than incidental. These companies sit on top of large volumes of training data and customer inputs, running through cloud pipelines that make a breach a matter of when, not if. Cyber policies are getting the same AI exclusion treatment as everything else, so the audit logic that applies to Tech E&O applies here too: check what's actually named, not what's assumed.

D&O rounds out the stack by protecting the people running the company rather than the company itself, covering claims that leadership mismanaged the business. Most VCs and board members require D&O in place before a funding round closes, a term sheet condition as much as a risk management decision. AI-related D&O claims have grown materially in recent years, sitting in court records right now.

Auditing an existing policy before the next renewal

Reading the declarations page tells a founder almost nothing. The exclusions live in the endorsements, buried in language that rarely gets discussed out loud during a renewal call, and the AI carve-outs have shown up there since late 2025.

A handful of direct questions cut through most of it. Does the policy name AI, machine learning, generative AI, or autonomous systems anywhere, and if it does, is that naming an inclusion or an exclusion? Has a new endorsement appeared at the most recent renewal that wasn't attached the year before, something visible only by pulling the prior year's form and comparing form numbers side by side? Is there a Verisk ISO Form CG 40 47 01 26 attached to the commercial general liability policy, or language doing the same job under a different label? Does the Tech E&O policy's definition of "error" cover only human-coded mistakes, or does it reach model outputs specifically? Has the cyber policy picked up any AI-related exclusion language since the fourth quarter of 2025?

The timing here isn't neutral. Policies that renewed in the first half of 2026 without this scrutiny are the ones most likely to already carry a gap the founder hasn't found yet, because that's the window when the exclusions were rolling out.

Before shopping for replacement or supplemental coverage, a founder needs a clear written account of what the AI system actually does in production: what decisions it touches, which industries it operates in, whether it acts autonomously or waits for a human to sign off before anything happens. Underwriters also want the provenance of the training data, any licensing agreements attached to it, and an honest answer to whether the product falls into a high-risk category under applicable AI regulation or the EU AI Act, such as employment, credit, health, or housing decisions. Underwriters in this market ask for this detail up front. Show up without it, and the process just slows down until someone produces it anyway.

The specialist AI insurance market: what the dedicated providers offer

As of March 2026, three companies sell standalone, dedicated AI liability insurance. Not three market leaders among many, three companies, full stop. That's the entire market, a narrow and young category still figuring out its own shape, even as capital pours in ahead of the underwriting expertise needed to price it properly: AI startups captured 95.2% of all insurtech funding in the first quarter of 2026, up from 77.9% the quarter before, out of $1.63 billion in total insurtech funding for the quarter.

Armilla AI, based in Toronto and operating as a Lloyd's coverholder, launched the first standalone AI liability policy written at Lloyd's of London in April 2025, underwritten by Chaucer at Lloyd's. The policy covers financial damages and legal defense costs tied to AI underperformance: hallucination, drift, mechanical failure, any deviation from the behavior the system was supposed to exhibit. Armilla has pushed its coverage limits to $25 million, and it partnered with Chaucer to launch "Vanguard AI," a structure that pairs Chaucer's cyber and tech E&O coverage with Armilla's standalone AI policy so a company isn't stitching two separate carriers together on its own. Every Armilla policy comes bundled with independent AI system certification, drawing on more than 500 prior AI evaluations across regulated industries, along with model verification, bias testing, stress testing, and red-teaming with ongoing monitoring after the policy is in force. The company has raised $6 million in venture funding, backed by Mistral Venture Partners, Y Combinator, and Yoshua Bengio.

Munich Re's aiSure program, now offered through Mosaic, has the longest track record of the three, tracing back to some of the earliest AI policies written in the market. It's currently available through Mosaic at limits up to $15 million. The available detail doesn't go much further than that, but the program's age relative to the rest of this market makes it the closest thing to an established, institutional-grade option sitting inside the broader Lloyd's structure, rather than a startup entrant testing the waters for the first time. Founders comparing the two aren't choosing between a young company and an old one so much as choosing between a purpose-built product and a mature program bolted onto newer infrastructure, and that distinction should drive the decision more than brand recognition does.

Sources

  1. “Quick everyone! Let's make an insurance AI startup”
  2. What Insurance Do AI Startups Need, and Which Companies Provide It? | Corgi Insurance
  3. legalnodes.com
  4. bakermckenzie.com
  5. freshfields.com
  6. munichre.com
  7. armilla.ai
  8. fintech.global

More in Tech and Product Liability