The Coverage Memo

Intellectual Property Infringement Coverage in Tech Startup Policies

Most tech startups lack IP enforcement coverage and underestimate training data liability risks.

Senior Writer · · 8 min read
Cover illustration for “Intellectual Property Infringement Coverage in Tech Startup Policies”
Tech and Product Liability · September 24, 2026 · 8 min read · 1,905 words

Global intangible assets, meaning software, algorithms, proprietary datasets, large language models, and brand equity, now add up to more than $79.4 trillion. That figure sits at the center of a problem most startups don't see coming: the gap between what these assets are worth and what actually protects them. Insurance is supposed to close that gap, and for most AI companies, it doesn't. The reason has less to do with bad luck than with founders skimming their policies instead of reading them line by line, and that habit is going to get expensive for a specific, predictable group of them: anyone who trained a model on data they can't fully trace.

The two-sided structure of IP coverage: defense and enforcement

IP coverage does two separate jobs, and mixing them up is where a lot of confusion starts. One side is defense: someone accuses the company of infringing their patent, copyright, or trademark, and the policy pays the legal fees, court costs, settlements, or judgment that follow. The other side is enforcement, sometimes called abatement: the company holds IP that somebody else is ripping off, and the policy pays to go after them.

Most founders buy defense and stop there, which is the wrong instinct. Defense-only coverage leaves a startup with no way to recoup lost value once a rival has already shipped a near-copy of a feature the startup spent a year building. Neither function comes bundled into a general liability policy by default, so founders have to check, clause by clause, whether IP is named as a covered loss or quietly written out.

For companies working with AI, a third category of exposure doesn't map cleanly onto either defense or enforcement: liability tied to how a model was trained. That's a different animal, and it's reshaping how the rest of the insurance stack gets built.

What the standard policy stack covers before AI enters the picture

Most tech startups end up assembling a core set of policies over time, typically including Technology Errors & Omissions, Commercial General Liability, Directors & Officers, Cyber Liability, standalone IP insurance, and sometimes Communications and Media Liability.

Tech E&O responds when a software product fails to do what it promised and costs a client money. It's also the policy most founders wrongly assume covers IP disputes involving software output, and that assumption is the single most common coverage mistake in this list. Commercial General Liability picks up bodily injury, property damage, and something called advertising injury, which can catch some trademark and copyright claims, but the scope is narrow and gets overestimated constantly. D&O protects the people running the company from personal liability, and most investors won't close a round without it in place. Cyber Liability responds to data breaches and privacy incidents, which matters more than it used to now that training data and customer data blur together. Standalone IP insurance is the only policy in the group that explicitly names infringement defense and enforcement as covered losses, and it has to be added on purpose, not assumed. Communications and Media Liability rounds out the stack, covering content claims like defamation and copyright, relevant to any startup whose product generates or publishes content.

Even before AI enters the picture, a real gap sits inside this stack, and it's a structural one, not an edge case. Standard Tech E&O was underwritten for a world of human-coded software errors, where a developer wrote a bug, the bug caused a loss, and the policy paid out. It wasn't built around autonomous or probabilistic outputs, the kind a model produces on its own without a line of code dictating the exact result. When that kind of output causes harm, carriers dispute whether the policy was ever meant to apply, and they win that argument more often than founders expect.

How generative-AI exclusions are reshaping what standard policies cover in 2026

A lot of Tech E&O and general liability policies written before generative AI went mainstream never mention AI at all, not to include it and not to exclude it. That silence means the outcome of a claim depends on how a judge or an adjuster reads a policy that was never written with this risk in mind. No founder should want to bet on that reading going their way, and holding an old, unamended policy is a bet on exactly that outcome.

Insurers have started closing the gap themselves, and not in the startup's favor. In 2026, ISO introduced optional generative-AI exclusion endorsements, forms CG 40 47 and CG 40 48, built for general liability policies, with similar exclusion language now showing up in D&O and E&O forms too. CG 40 47 is the broadest of the three: it bars coverage under Coverages A and B for harm connected to generative-AI outputs, including defamatory content, IP infringement from AI-generated material, and physical damage traced back to an AI error.

ISO forms underlie roughly 82% of domestic Property & Casualty policies, so these exclusions will soon affect the mainstream, not just a niche group of policyholders. New endorsements narrowing AI coverage often appear quietly at renewal, and this is where founders get caught flat-footed. A policy that covered an AI startup's exposure last year can stop covering the same risk the next time it renews, with no dramatic announcement, just a new endorsement buried in the paperwork nobody flagged.

Between 2023 and 2024, more than 50 copyright lawsuits were filed against AI companies. Courts have moved past the early filing stage into substantive rulings that now set the terms for how underwriters price this risk, and the rulings are not treating all training data the same way. That distinction is the whole ballgame.

The case doing the most work here is Bartz v. Anthropic, decided by Judge Alsup, and the ruling split training data into two very different outcomes. Training on books Anthropic had lawfully acquired was found "exceedingly transformative" and protected as fair use. Training on a corpus the company knew to be pirated was not fair use, and that finding exposed Anthropic to willful-infringement statutory damages capped at $150,000 per work, the math behind the roughly $1.5 billion settlement figure that made headlines.

Fair use survives when the training corpus is clean and collapses the moment provenance is tainted. Founders who treat "we used publicly available data" as a legal shield are misreading this ruling badly: the court didn't ask whether the data was public, it asked how the company got it. Discovery in these cases now turns on tracing exactly where each book, image, or article in a training set came from, a forensic exercise that barely mattered in copyright litigation a decade ago and now sits at its center.

Other cases are pulling in different directions at once. On May 5, 2026, Hachette, Macmillan, McGraw Hill, Elsevier, Cengage, and novelist Scott Turow filed a proposed class-action copyright suit against a major technology platform operator, naming Mark Zuckerberg individually and pushing a theory of personal liability, a move built to address the market-harm gap that sank an earlier author suit against the same company back in June 2025. A separate 2026 suit against Google over Gemini alleges the company removed or altered copyright management information to obscure where its training data came from, a legally distinct claim from ordinary infringement and a harder one to defend against. Cases against OpenAI, Anthropic, and Perplexity continue moving through California federal courts in 2026. In November 2025, Warner Music settled its suit against the AI music platform Suno, with both sides forming a licensing partnership instead of fighting to a verdict, a signal that licensing deals, not courtroom wins, may end up settling most of these disputes in practice.

Fair-use doctrine isn't converging on a single answer across these cases, and appellate courts haven't unified the approach yet. That unresolved legal uncertainty is itself a risk, and underwriters have to price it whether the case law is settled or not.

The affirmative AI insurance market: what specialized policies now cover for IP exposure

Demand for AI-specific coverage isn't in question. In a Geneva Association survey of 600 businesses, more than 90% said they'd value insurance built specifically for generative-AI risks. Figuring out which products on the market actually deliver that takes more digging, and the honest answer is that most general carriers still don't.

Vouch launched a dedicated AI insurance program in February 2024 covering AI errors and omissions, bias and discrimination claims, IP infringement (including allegations that a model trained on copyrighted data or generated infringing output), and regulatory investigations. It also picks up defense costs tied to AI-specific regulatory inquiries under CCPA, GDPR, and the growing pile of state-level AI laws. Underwriting runs on the usual variables: how the AI technology is built and used, along with industry, company size, and claim history.

Relm Insurance rolled out three AI-specific policies in January 2025. NOVAAI is a cyber and Tech E&O policy built for companies that build AI platforms or AI-based products. PONTAAI is an excess difference-in-conditions wrap policy aimed at organizations carrying third-party liability exposure from AI use or development, designed specifically to fill the holes where an existing liability program excludes AI. Both NOVAAI and PONTAAI are designed to affirmatively cover IP infringement, both copyright and trademark, along with discrimination claims. Corgi pitches itself as an AI-powered insurer built specifically for AI startups, offering modular coverage that names model hallucinations, algorithmic bias, and training data disputes directly instead of leaving them to inference.

How to read a policy for IP coverage before buying

Plenty of standard policies restrict or flatly exclude intellectual property claims, unauthorized data collection, biometric information, defamation, AI-generated output disputes, scraping allegations, and investor claims tied to AI model development, and the summary page won't tell you that. It sits buried in the exclusions section, in language dense enough that most people skim past it, which is exactly the point.

A few questions deserve a straight answer before anyone signs. Coverage should explicitly name IP infringement, both defense and enforcement, as a covered loss. Does it say anything at all about AI-generated outputs, one way or the other? Does it address training data disputes specifically, or only downstream product failures once the model is already deployed? What does it say about willful infringement, since many policies exclude coverage the moment infringement is found to be knowing or intentional, the exact finding that exposed Anthropic to statutory damages over its tainted training corpus? And is a generative-AI exclusion endorsement attached, whether that's ISO's CG 40 47 or CG 40 48 or a carrier's own version of the same idea?

Revenue and sector shape both what's available and what it costs. A SaaS company working in a patent-dense field like fintech carries more exposure than a pre-revenue startup with no product in market yet, and a company with real revenue makes a bigger, more attractive litigation target, so underwriters price the difference accordingly.

Data provenance has quietly become an underwriting input in its own right, and this is the piece founders consistently underestimate until a carrier asks for it. Carriers now want to see the contracts, the data sourcing records, the provenance controls, before they'll even quote a specialized AI policy. A startup that can't produce that paper trail may find itself unable to bind the coverage at all, no matter how much it's willing to pay for it.

Sources

  1. What Insurance Do AI Startups Need, and Which Companies Provide It? | Corgi Insurance
  2. IP insurance demystified: What to know before you buy - WTW
  3. phl-firm.com

More in Tech and Product Liability