They're refusing to cover AI they cannot evaluate. Your policy was priced on a snapshot of a firm that has since changed — new workflows, new data flows, new AI touching client work. Insura keeps the two matched, produces documentation an underwriter can actually price, and routes what needs binding to your licensed broker.
Three ISO endorsements — CG 40 47, CG 40 48, and CG 35 08 — landed in January, and ISO forms underpin the overwhelming majority of the US property and casualty market. That means the language is not confined to the carriers that filed it.
One exclusion in circulation reaches further than the rest. It excludes a policyholder's failure to identify content generated by a third party's use of AI. Read that again: not your AI. Someone else's, in a document that arrived at your firm. No policy wording closes that gap — only a documented screen and a record of who reviewed it does.
On the other side, affirmative coverage is arriving with conditions attached. Standalone AI liability products now exist with limits from $2 million to $50 million, and firms that can document structured AI oversight tend to obtain better terms. Gartner projects that by 2030 P&C insurers will require strong AI risk controls as a condition of affirmative AI coverage.
And the examination question is being standardised. Insurance regulators have been piloting an AI risk evaluation instrument across a dozen states, with adoption targeted for November. Its questions are specific: list every AI system you use, show who is accountable for each one, prove you test them and how often, name the vendors behind your data — and explain how you oversee the AI used by the MGAs writing on your paper.
We insured our own AI governance company this year — professional liability and cyber. The application asked whether we use artificial intelligence and whether we have controls around it. We answered yes to both, truthfully, with a governance architecture we could actually demonstrate.
Nobody asked to see a single control. The policy bound in under twenty minutes.
That is not a criticism of the carrier. It is how the process works, and it is exactly why the answers matter more than anyone treats them as mattering. Everything you assert on that application becomes a representation the carrier relied on to price and issue the policy. The verification does not happen at binding. It happens at claim, when a loss has already occurred and someone is reading your answers back to you.
Most firms fill in the AI questions in thirty seconds, in good faith, based on what they believe is happening. Whether it matches what is actually happening inside the firm is a question nobody asks until it is expensive.
Coverage is bought once a year, from outside the firm. Operations change every week, inside it. The distance between the two widens continuously — and in a firm adopting AI, it can widen far enough to matter inside a single policy term.
Assumes the broker is watching the coverage as the business changes.
Assumes the insured will call if something material changes.
Only ever sees the application — a snapshot from the moment of placement.
Three parties, and the firm-to-policy match belongs to none of them. Insura makes it someone's.
Real workload, workflow, data flows, delegated decision authority, and the AI risk surface — observed from inside, not inferred from an annual form.
WISP, AI usage statements, and a compliance library that describe that reality in the language underwriting uses to price risk.
The coverage held, set against the risk surface actually run — and precisely where the two diverged, before a loss forces the question.
A clean, documented, correctly-scoped picture. The broker and underwriter determine and bind. Insura produces evidence and a question.
When an underwriter asks whether you use AI, whether you police it, and whether protocols exist, the answer is a document rather than an assurance — an inventory, named accountability, and a record that reviews actually happened.
The exclusion that reaches failure to identify someone else's AI-generated content is answered by one thing only: a documented screen on what arrives, with a named reviewer and a sealed record.
A new workflow, a new tool, a new data flow, a new delegation of decision authority — surfaced when it happens rather than remembered at renewal, if at all.
AI-assisted professional error frequently sits between the professional liability form and the cyber form. Insura flags it as a question for the broker to confirm — never as a coverage determination.
The evidence assembled as the year goes, so the renewal conversation starts from documentation rather than recollection — and better documentation tends to produce better terms.
For carriers, MGAs and agencies, the regulator's questions are already known. The work is having the answers in a form that survives being asked.
Calyx carries combined professional liability and cyber coverage written at Lloyd's, plus a commercial package. We went through the same application every firm goes through — and built the governance evidence base first, so the answers we gave were ones we could demonstrate.
That experience is the origin of this vertical. We learned how thin the verification actually is by being the one submitting the form.
Inside a regulated accounting firm running Calyx architecture on live client financial data, the AI governance framework was taken into a commercial underwriter at renewal. The carrier reviewed it and wrote the AI systems into coverage as submitted — no exclusions, no exceptions.
Most AI vendors have never put their governance framework in front of a carrier. That is a material validation event, and it is the reason this vertical exists rather than a claim about it. Read the engagement →
A routine renewal email for that same firm triggered a structured reassessment rather than a rubber stamp. The program was re-checked against the firm's current operating profile, including AI-assisted work on client financial data.
It surfaced one specific, non-obvious seam around AI-assisted professional error sitting between the professional liability and cyber forms. It was framed as a question for the licensed broker to confirm — not a determination — and logged. One confirmable item, not an alarm on every renewal.
It produces the documentation and the operational interpretation. Your licensed broker and the underwriter determine and bind. Every finding is evidence and a question routed to the people licensed to answer it — sealed under SHA-256 through LedgerGuard, traceable, and defensible if it is ever reviewed by a regulator, auditor, insurer, or court.
It does not render coverage determinations, does not say a claim is or isn't covered, and does not replace the broker. It is the thing the broker needs in order to bind accurately and fast.
Look at what you told the carrier about AI, and ask whether you could demonstrate it today. That single question is the fastest way to see whether this is worth a conversation.
Start the conversation