CGL COVERAGE ANALYSIS
ISO’s generative AI exclusions: widening the gaps in CGL coverage
As at January 1, 2026, the Insurance Services Office (ISO) introduced three new exclusions that are beginning to appear on commercial general liability (CGL) policies. The endorsements remove coverage for certain losses arising from the use of generative AI.
The exclusions reflect insurers’ concern that the rapidly growing use of generative AI creates new and potentially significant liabilities under CGL policies that were not specifically designed or priced to cover AI-related risks, but were instead designed to protect businesses against lawsuits alleging bodily injury, property damage, and mostly advertising-related offenses. The endorsements enable insurers to expressly remove these emerging exposures rather than leave them implicitly or “silently” covered under existing policy language.
Issues with generative AI may arise during either the training of a generative AI model or the content generation stage. Because of the nature of how generative AI models are constructed, they can produce harms including plausible but incorrect results (‘hallucinations’); include material in their training data that constitutes IP infringement; facilitate unauthorized data disclosure; and lead to bodily injury and property damage, thus potentially placing a wide range of businesses that use the applications at risk of lawsuits.
The question arises whether CGL covers all of these risks in the first place, and whether standalone AI liability insurance provides wider coverage.
In more detail, the different exclusions are as follows (the filing itself is described by Verisk, and summarized outside the paywall by the Big “I” VU):
CG 40 47 01 26 – Exclusion - Generative Artificial Intelligence. This excludes Coverage A (bodily injury/property damage) and Coverage B (personal and advertising injury) losses arising out of generative AI. This is a very broad exclusion, excluding bodily injury, property damage, and personal and advertising injury arising out of generative AI under the policy parts it modifies.
CG 40 48 01 26 – Exclusion - Generative Artificial Intelligence (Coverage B). This excludes only Coverage B (personal and advertising injury) losses arising out of generative AI. This is obviously less broad, excluding just one of the coverage parts (B) instead of two (A and B), but still excludes a large portion of generative AI exposure that the form initially provides (based on current generative AI lawsuits).
CG 35 08 01 26 - Exclusion - Generative Artificial Intelligence. This only applies to the products/completed operations liability coverage part of the standard CGL policy (but is probably more useful when aimed at the separate Insurance Services Office (ISO) products/completed operations liability coverage forms which are used when the products/completed operations exposures are considered too risky for insurers of standard CGL forms). It excludes bodily injury and property damage liability arising out of generative AI in respect of products/completed operations liability. This is a very narrow exclusion because of the small part of the policy at which it is aimed, and only a small sliver of generative AI exposure will be excluded (unless AI is more widely regarded by courts as a ‘product’ in the future), and only for those policyholders who have delivered products to their customers or who have completed work at a client job site.
ISO CGL generative AI exclusions: what each exclusion removes
There are three optional endorsements available to attach from January 1, 2026, but they affect two different coverage parts.
Figure 1: What each CGL generative AI exclusion removes
The exclusions are often referred to as CG 40 47, CG 40 48, CG 35 08 since the last part of the reference is simply the date that the exclusion became available.
All three are optional endorsements that an insurance carrier can elect to attach, depending on what they wish to exclude. ISO forms sit behind the majority of U.S. commercial casualty policies, which means that these exclusions will be influential. CG 40 47 and CG 40 48 are likely to be the most applied because CG 35 08 is so narrow and is only applicable to a small sub-set of policyholders.
All exclusions use the same definition of generative artificial intelligence, and the same operative language:
1) “Gen AI means a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code.” This is a wide and classic definition of generative AI, except for the word ‘responses’ which is potentially confusing since the unique thing about generative AI is its ability to create new content and not just ‘responses’. Use of the word “responses” risks blurring the line between real generative AI and non-generative, deterministic rules-based algorithms.
2) The operative language is “arising out of” (this insurance does not apply to “bodily injury”/ “property damage”/“personal and advertising injury” arising out of “generative artificial intelligence”). This wording is very broad and means that it may apply even where AI is just one contributing factor to the loss depending on the governing jurisdiction. The phrase “arising out of” is construed more broadly than “caused by” in most U.S. jurisdictions.
“Arising out of”: how far back the exclusion reaches
All three endorsements use the same operative wording. In most U.S. jurisdictions “arising out of” is construed more broadly than “caused by”, so the exclusion can reach a loss where generative AI was one contributing factor rather than the immediate cause.
Figure 2: The causal reach of the operative wording
Illustrative. How far either phrase reaches is decided by the governing jurisdiction and the facts of the claim. The chain shown is the property damage example discussed above.
Why is the exclusion tied to Coverage A (bodily injury/property damage) important in the context of generative AI?
In short, generative AI can lead to bodily injury and property damage.
Examples of leading to bodily injury: The direct route could involve a generative AI tool such as ChatGPT, or a wrapper around ChatGPT (supplied by an AI vendor) providing:
- unsafe medical advice (for example, an overdose of medicine),
- dangerous nutritional advice (a harmful diet or weight-loss guidance, or advice to taste poisonous mushrooms),
- toxic chemical instructions (e.g. for household cleaning),
- self-harm support (leading to self-harm or even suicide), or
- hazardous operational advice (e.g. explosive-hazard battery repair steps) that is acted on by the user.
The most famous case is probably Garcia v. Character Technologies (filed Oct 22, 2024, in the Middle District of Florida): the family of a 14-year-old filed a wrongful death lawsuit claiming he developed an emotional attachment to a character.ai chatbot, repeatedly expressed suicidal thoughts, and received encouraging messages from the chatbot shortly before he died by suicide. This was an important case because a federal court declined at the pleading stage to accept that chatbot output was protected First Amendment speech and allowed product liability and wrongful death claims to proceed. However, this case was settled in January 2026, and the settlement terms are undisclosed. As such, it will not be a binding precedent but remains as persuasive authority.
Examples of leading to property damage: Property damage could arise where, for example, an AI assistant advises a building manager to set the HVAC to the wrong temperature, which leads to freezing and bursting of the pipes in a tenant’s unit.
Why is the exclusion tied to Coverage B (personal and advertising injury) important in the context of generative AI?
Generative AI leads to several offenses that may be covered under coverage points (d) and (e) under personal injury and points (f) and (g) under advertising injury of Coverage B, and such harms have shown up in our lawsuit data. To explain, Coverage B is offense-based: it is triggered only if the claim arises out of the policyholder’s business and from one of seven listed offenses. Roughly, paragraphs a to e are the “personal injury” side and paragraphs f to g are the “advertising injury” side. In short, there is no coverage for a “generative AI claim” as such. The claim must fit one of the specified personal and advertising injury offenses. Let’s look at the lawsuits each offense attracts.
Which Coverage B (personal and advertising injury) offenses generative AI actually reaches
Coverage B is offense-based. Four of the seven listed offenses reach generative AI at all, and each carries its own trigger and its own restriction. It is the restrictions, rather than the offenses, that decide how much generative AI exposure the form actually answers.
| Coverage B offense | What triggers it | The limit that bites |
|---|---|---|
| (d)Defamation and trade libelOral or written publication, in any manner, of material that slanders or libels a person or organization, or disparages a person's or organization's goods, products or services | Publication of material | The output must concern defamation or disparagement. It does not cover hallucinations generally. |
| (e)Right of privacyOral or written publication of material that violates a person's right of privacy | Publication of material | A narrow trigger: the injury must arise from publication of material, and it does not reach discriminatory decision-making. Some carriers apply CG 21 06 05 14, which neutralizes the coverage to a degree, and its application to BIPA, wiretapping and session-replay theories is unclear and heavily contested. |
| (f)Another's advertising ideaUse of another's advertising idea in your “advertisement” | Use in an “advertisement” | A conventional one-to-one chatbot may not satisfy the CGL definition of an advertisement, particularly where it is operational rather than promotional. |
| (g)Copyright, trade dress or sloganInfringing upon another's copyright, trade dress or slogan in your “advertisement” | Infringement in an “advertisement” | Advertisement only, not chatbot output. Only copyright, trade dress and slogan are covered: patent, trademark and trade secret infringement are expressly carved out. |
Figure 3: Which Coverage B (personal and advertising injury) offenses generative AI actually reaches
General descriptions of common policy forms, not a substitute for the terms of any specific policy. Coverage depends on the exact wording, endorsements, and facts of each claim.
The first three offenses: a) false arrest, detention or imprisonment; b) malicious prosecution; c) wrongful eviction, will ordinarily have little connection to generative AI.
d. Oral or written publication, in any manner, of material that slanders or libels a person or organization or disparages a person’s or organization’s goods, products or services: this is defamation or trade libel, publishing false statements that harm a person’s or business’ reputation. The statement must be about the plaintiff, be published to a third party, and cause actual harm. This is relevant to generative AI because generative AI often produces hallucinations, and this flaw remains difficult to eliminate completely (see “Why Language Models Hallucinate” by OpenAI, September 2025). So, for example, a customer service chatbot could falsely call a competitor’s product ‘defective’ (trade libel).
An example of a third-party defamation claim arising from generative AI output is Starbuck v. Google LLC(Del. Super. Ct., C.A. No. N25C-10-211 MAA). In October 2025, Robby Starbuck sued Google for defamation, alleging that its generative AI tools (Bard, and then Gemini) produced false statements accusing him of serious misconduct, including sexual assault, sexual misconduct involving a minor, and having a criminal record. On July 24, 2026, Delaware Superior Court Judge Meghan A. Adams denied Google’s motion to dismiss “in its entirety”, allowing the defamation action to proceed. The decision did not determine Google’s liability, but held that Starbuck had pleaded sufficient facts for his claims to survive dismissal.
However, liability for defamatory generative AI outputs will depend on the specific facts. In Walters v. OpenAI, OpenAI obtained summary judgment (a decision without a full trial) in the Superior Court of Gwinnett County, Georgia on May 19, 2025, after ChatGPT generated false embezzlement allegations. The court relied in part on the recipient’s awareness of AI hallucinations and applicable disclaimers and found insufficient evidence of the requisite fault. In Starbuck v. Google, however, the court distinguished Walters as a fact-specific decision reached after discovery, allowing the claim against Google to proceed.
But (d) does not cover hallucinations generally. The generative AI output must concern defamation or disparagement.
e. Oral or written publication of material that violates a person’s right of privacy. Again, because training data of LLMs contain scraped internet content, there is the possibility of invasions of privacy or possible violation of privacy laws when generative AI discloses, for example, information about individuals, or uses a former employee’s or a celebrity’s photograph in a marketing brochure without their consent.
For example, one generative AI dataset was found to contain patient photographs from medical records, used without patient consent (see Ars Technica, September 2022).
However, some carriers apply an optional May 1, 2014 exclusion/endorsement (CG 21 06 05 14) that neutralizes this coverage to a certain extent, but even then, it is not clear whether it applies to BIPA, wiretapping/session-replay and other non-disclosure privacy theories, and the point has been heavily contested.
It should be noted that personal injury lawsuits (including privacy) comprised 10.2% of AI-related lawsuits according to Testudo’s 2020-2025 data.
But (e) has a narrow trigger: the injury must arise from publication of material. It does not provide coverage for discriminatory decision-making.
f. Use of another’s advertising idea in your “advertisement” (an advertisement is defined in the CGL form as “a notice that is broadcast or published to the general public or specific market segments about your goods, products or services for the purpose of attracting customers or supporters”): for example, copying a competitor’s campaign concept, or distinctive marketing theme (e.g. a color scheme) without permission. This could be generative AI relevant because the replicated idea could come from generative AI training data. Note the restrictive nature of this CGL coverage: it only covers this aspect in an ‘advertisement’. If such material was available in a conventional one-to-one chatbot it may not satisfy the CGL definition of an “advertisement,” particularly where it is operational rather than promotional.
g. Infringing upon another’s copyright, trade dress or slogan in your “advertisement”: this could be generative AI relevant. The combination of copyrighted content being used in training LLMs and the potential for models to generate identical or substantially similar copies creates a risk that the use or output of generative AI systems may give rise to use of protected content without authorization. Many businesses use generative AI to generate sales and marketing collateral such as images, videos, and text without realizing their potential exposure to copyright infringement. An example of a lawsuit in this area is the use of iconic photographs used to generate a video on the defendant’s website, with stills from that video then appearing in print advertising. These were the allegations in a June 12, 2026 lawsuit called Rodney Smith Ltd. v. Masco Corp. (No. 1:26-cv-04991, S.D.N.Y.). Again, note the restrictive nature of this CGL coverage: it only covers this aspect in an ‘advertisement’, not in a chatbot. This advertisement restriction has a large impact in the context of generative AI exposure. Also, only copyright, trade dress and slogan are covered. The exclusion to Coverage B makes it clear that the following are not covered for the avoidance of doubt: patent infringement; trademark infringement; and trade secret infringement.
Copyright infringement lawsuits comprised 11.2% of AI-related lawsuits according to Testudo’s 2020-2025 data. Copyright infringement claims carry meaningful financial exposure.
Why is the exclusion tied to the products/completed operations liability coverage part less important in the context of generative AI?
Under the standard ISO CGL Coverage Form (CG 00 01 04 13), there are only three coverage grants: Coverage A (bodily injury and property damage liability), Coverage B (personal and advertising injury liability), and Coverage C (medical payments). There is no standalone insuring agreement for products-completed operations; those claims are paid directly under Coverage A as “bodily injury” or “property damage”. The products-completed operations coverage of the CGL is basically just an aggregate limit, it is not a separate coverage grant. So, if exclusion CG 40 47 is used, then there is no need to apply exclusion CG 35 08, since Coverage A is already excluded.
Silent AI
The generative AI exclusions can be regarded as ISO’s answer to the ‘silent AI’ problem in commercial general liability (‘CGL’), meaning the form never explicitly covered or excluded generative AI harms, it was just silent on the issue. So businesses did not know if harms caused by generative AI would definitely be covered.
The limitations of CGL coverage in the context of generative AI harms
As we can see from the above, CGL was designed to protect businesses against lawsuits alleging bodily injury, property damage, and mostly advertising-related offenses in an age before the widespread use of generative AI.
Especially for Coverage B which has the most generative AI exposure, the covered offenses are narrowly defined and the exclusions are broad.
Certainly, for companies whose primary output is media content rather than physical products or services, the CGL is a narrow coverage with (d), (e), (f), (g) of Coverage B excluded for such companies, and forcing them to find other insurance protection.
Illustrative comparison: selected wording from the Testudo form
Compared to a standalone AI liability policy (e.g. Testudo), the following is restrictive:
- The CGL's trigger for one of the most generative AI relevant parts (points d and e of Coverage B) is publication of material. (Testudo's trigger is any Claim arising from an Output. This is broader, since it doesn't require the AI's output to have been "published" in the traditional sense).
- The CGL's coverage for copyright infringement is limited to being in an 'advertisement' (Testudo has no such restriction. This is particularly relevant to generative AI, where infringing content may be generated or communicated through a generative AI system without forming part of the insured's advertising activities).
- The CGL's privacy coverage is quite narrow, "publication of material that violates a person's right of privacy" (Testudo covers 'Invasion, infringement, or interference with rights of privacy or publicity, including public disclosure of private facts' which is wider).
- The CGL offense (g) is limited to infringement of copyright, trade dress, or slogan (in advertisement). (Testudo covers in addition infringement of trademark, service mark, domain name, title, dilution or infringement of trademark or service mark; and improper deep-linking or framing).
- Testudo additionally covers right-of-publicity or commercial-appropriation, and unfair competition.
In addition, there is no coverage for classic generative AI harms such as:
- hallucinations which lead to financial loss
- unauthorized data disclosure
- AI regulatory violation
What has to happen before Coverage B (personal and advertising injury) responds
Coverage B is offense-based, and its conditions stack. Each gate below is another thing a claim has to satisfy, and the blue gates are the restrictions that keep generative AI exposure out. A form written for this exposure asks fewer questions.
Every Coverage B claim has to arise out of your business first. After that, each offense adds its own conditions.
Every additional condition is another way a generative AI claim falls out of the form before the exclusions are reached at all.
Figure 4: Conditions on the trigger, standard CGL against a standalone form
Selected wording from the Testudo form as set out above, shown against general descriptions of the standard CGL. Not a substitute for either policy. Coverage in every case is subject to the terms of the issued policy.
US carriers are ready to apply the AI exclusions quickly at renewals
With these three January 2026 exclusions, carriers now have ready-to-go, standardized, regulator-ready language that they can drop into renewals of CGL at any time.
Indeed, several E&S carriers have applied their own AI exclusions from 2026, and some of those are broader than the ISO endorsements.
Why is the ‘duty to defend’ under CGL and standalone AI liability policies important?
When someone files a lawsuit against a business alleging one of the harms covered by the CGL, the CGL insurer has a duty to defend the lawsuit, not just pay the policyholder if they lose the case. The insurer must provide and pay for a defense attorney. The defense obligation applies if the lawsuit’s allegations potentially fall within CGL coverage. The duty to defend is historically triggered under the CGL form more frequently than the duty to pay.
However, if the coverage falls outside the CGL, there is no duty to defend.
How is London responding?
There is no ISO exclusion equivalent in London as of August 12, 2026. The LMA, the likeliest candidate, has published on AI risk but has yet to introduce a generative AI exclusion clause.
Conclusion
The introduction of ISO’s generative AI exclusions should not eclipse a more fundamental problem: even without the exclusions, the traditional CGL provides only partial and fragmented protection against generative AI liability.
Coverage A can respond where generative AI causes bodily injury or property damage. Coverage B covers a narrow band of reputational, privacy and IP claims, but via triggers that fit generative AI poorly: (d) and (e) require publication of material; (f) and (g) require the infringing content to appear in an “advertisement”, which a chatbot output is not; and (g) is confined to copyright, trade dress and slogan, with trademark, patent and trade secret expressly carved out.
These are traditional coverage categories being applied to a new technology. They were never designed as insurance for the consequences of deploying generative AI. Important generative AI exposures including hallucinations causing pure financial loss, unauthorized data disclosure, AI regulatory liability and significant categories of intellectual property infringement, fall outside the CGL altogether.
The January 2026 ISO endorsements therefore compound the problem of insufficient coverage. Businesses start from a CGL policy that already provides incomplete protection against generative AI harms, and insurers now have standardized regulator-ready exclusions capable of removing some or perhaps all (CG 40 47) of the generative AI protection that did exist.
The result is an insurance gap that will widen as exclusions are applied (especially the loss of the duty to defend), and as generative AI adoption increases. To be comprehensively protected businesses need AI liability insurance which is written for this exposure rather than awkwardly adapted to it (and has a duty to defend).
Two kinds of gap: coverage removed, and coverage never written
The endorsements take away part of what a CGL did answer. The larger problem sits underneath them. A significant set of generative AI exposures falls outside the form altogether, and no endorsement had to be filed to keep it out.
Businesses start from a policy that already answers only part of the exposure. The endorsements remove some or, under CG 40 47, all of the protection that did exist.
Figure 5: What the CGL reached, and what it never reached
General descriptions of common policy forms, not a substitute for the terms of any specific policy. Coverage depends on the exact wording, endorsements, and facts of each claim.
Sources
Every case, endorsement, and paper referenced above, with the primary record where one is publicly reachable. Checked August 18, 2026.
- Verisk, “Emerging Risks in ISO General Liability Multistate Filing” (July 2025)The filer's own notice of the multistate filing that introduced the three endorsements.
- Big “I” Virtual University, “Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures”Ungated trade summary of the same filing, naming all three form numbers.
- Garcia v. Character Technologies, Inc., No. 6:24-cv-01903 (M.D. Fla., filed Oct. 22, 2024)Docket. Carries the May 2025 order allowing the product liability and wrongful death claims past the pleading stage.
- Starbuck v. Google LLC, C.A. No. N25C-10-211 MAA (Del. Super. Ct. July 24, 2026) (Adams, J.)Opinion denying the motion to dismiss. The phrase “in its entirety” is the court's own.
- Walters v. OpenAI, L.L.C., No. 23-A-04860-2 (Ga. Super. Ct., Gwinnett Cnty. May 19, 2025)Order granting summary judgment, on no defamatory meaning, no fault, and no damages.
- Rodney Smith Ltd. v. Masco Corp., No. 1:26-cv-04991 (S.D.N.Y., filed June 12, 2026)Docket. Copyright infringement under 17 U.S.C. § 501 against Masco and Delta Faucet.
- Kalai, Nachum, Vempala & Zhang, “Why Language Models Hallucinate” (OpenAI, Sept. 2025), arXiv:2509.04664Why the failure mode is structural rather than a bug awaiting a patch.
- Ars Technica, “Artist finds private medical record photos in popular AI training data set” (Sept. 2022)The training-data privacy example cited under Coverage B offense (e).
- Lloyd's Market Association, “Understanding artificial intelligence risk in insurance products: the challenges”The LMA's published position on AI risk, absent any model exclusion clause.
For how a standalone form sits beside CGL, cyber, and E&O, see the generative AI liability insurance overview. If you place coverage for clients, the broker page sets out appetite, limits, and how to submit a risk.
Disclaimer: This is general information, not advice; coverage is subject to the terms of the issued policy.
Last updated: August 20, 2026