Why Your Firm Needs One Named Owner for AI Answers Across Six Insurance Policies

Who answers your insurer’s AI questions?

Your firm gives six different answers to the same question, and the market prices all six.

The Situation

Questions about AI now show up on the applications for six different insurance policies your firm uses: general liability, cyber, technology Errors and Omissions (E&O), Directors and Officers liability (D&O), employment practices liability (EPLI) covering when an employee or applicant sues, and Fiduciary Liability covering whoever runs your benefit plans. Those six renew on different dates, go to different insurers, and get filled out by whoever in your firm happens to sit closest to that policy. No one at your firm owns making those answers consistent, so the market is getting six versions of your answer and pricing each one separately.

The Exposure

In January 2026 the Insurance Services Office, whose forms most US commercial insurers build on, published three endorsements letting an insurer strip generative AI out of your general liability policy, triggered by losses "arising out of" generative AI, which catches the AI already inside ordinary business software. W.R. Berkley, one of the largest commercial insurers in the country, went further by excluding AI absolutely across its D&O, E&O, and Fiduciary policies and defining it as any machine-based system that infers from its inputs how to generate outputs. That's essentially the OECD and NIST definition, and it extends past generative tools into the predictive models you've been running in credit, claims, and fraud for a decade. None of that redefinition surfaces naturally; it surfaces when you file a claim and the insurer decides whether to pay by reading your submitted application. Six applications, six authors, each answering for their own policy, and no one answering for the firm.

The Judgment Call

Your broker coordinates the policies and your CRO signs the applications, a division of labor that's worked for decades. But AI is the first exposure to sit across six policies at once, while staying invisible to whoever signs them because your CRO owns the renewal but not the deployments, and your broker owns the insurer relationships but not the systems you’re using. What's happening is a reallocation, and both sides of the table are open about it: Beazley's head of cyber risks, at one of the largest cyber insurers in the world, compared it to "silent cyber" where one insurance line excluded the risk and another had to absorb it, and the broker Aon reads 2026 as a year of "clarification and targeted adjustment...but underwriting scrutiny is rising". While the market sorts out which policy absorbs what, one named officer has to hold the AI inventory, the control evidence, and the incident record, and make every application say the same thing. That officer can be an existing executive with the formal mandate, a new hire, or a fractional officer, but whoever it is, the responsibility has to be named - because the person who signs the applications won’t be able to stand behind an answer nobody owns.

  • Risk: The AI inventory you build to answer insurers becomes a dated record of what you knew and when. Ask your General Counsel how they want it scoped and retained before you start.

  • Benefit: You walk into every renewal with one consistent documented position, which lets you argue for a carve-back. On any claim that touches AI, the difference between a narrowed exclusion and an absolute exclusion is your entire limit.

This Week’s Action

  • What to do: Pull the renewal calendar for all six policies. For each one, get the most recent completed application and find every question that mentions AI. Tag each question by what it's actually asking: what AI you use and where, who governs and tests it, which vendors supply it, whether any of it has failed before. Then write down who answered it.

  • Who to involve: Your General Counsel, who should scope the exercise before it starts, and your head of risk management, who owns the renewal calendar. Bring in your broker to confirm which AI endorsements are actually attached to each schedule.

  • What outcome to achieve: A single page listing each policy, its renewal date, which of the four question categories that insurer asked about, who answered, and whether those answers match across the six policies.

  • Time required: 60 minutes to pull the applications, mark the AI questions, and tag them. 30 minutes with your General Counsel and head of risk management to reconcile the answers and decide who owns them at the next renewal. 90 minutes total.

Artifact

AI Coverage by Insurance Type

1. GENERAL LIABILITY
Gets asked about: injury or property damage traced to an AI-assisted output or AI-enabled product. Insurers will want to see: AI in your customer-facing products and purchased software.
Look on the schedule for: CG 40 47, CG 40 48, CG 35 08 (January 2026)
OWNER TODAY:_______________

2. CYBER
Gets asked about: AI as the way in - prompt injection, model compromise, deepfake-instructed payments, LLMjacking. Insurers will want to see: access controls on models, logging of AI tool use, payment verification.
Look on the schedule for: AI sublimits, shadow AI exclusions, deepfake carve-outs, affirmative AI endorsements
OWNER TODAY:_______________

3. TECHNOLOGY ERRORS AND OMISSIONS (E&O)
Gets asked about: erroneous AI output delivered to a client that cost them money, with nothing hacked. Insurers will want to see: model testing records, human review points, client contract terms on AI liability.
Look on the schedule for: AI error exclusions, endorsements listing covered scenarios, AI sublimits
OWNER TODAY:_______________

4. DIRECTORS AND OFFICERS (D&O)
Gets asked about: oversight failure, overstated AI claims in public statements, regulatory investigation. Insurers will want to see: board oversight record, AI in the risk register.
Look on the schedule for: absolute AI exclusions, and the definition of AI they use
OWNER TODAY:_______________

5. EMPLOYMENT PRACTICES (EPLI)
Gets asked about: AI screening, ranking, or scheduling that disadvantages a protected group. Insurers will want to see: which HR tools use AI, bias testing records, your vendor's role.
Look on the schedule for: an AI exclusion attached onto the whole management liability package rather than this policy
OWNER TODAY:_______________

6. FIDUCIARY LIABILITY
Gets asked about: AI in benefit plan administration, participant communications, or investment monitoring. Insurers will want to see: whether AI touches plan decisions, and who oversees the provider running it.
Look on the schedule for: an absolute AI exclusion written across the D&O, E&O, and Fiduciary packages together, as W.R. Berkley has done, as well as one attached to this policy directly.
OWNER TODAY:_______________

Fill in the six owner lines first; six blanks, or six different names, is the finding.

Three things to watch for:

  1. On D&O, read the definition of AI before you read the exclusion. If it covers systems that infer outputs from inputs, it's already covering predictive models you've run for years.

  2. On employment practices, most policies say nothing about AI. Silent doesn’t mean covered.

  3. On cyber, your policy addresses when AI is the way into a security failure but not when nothing has been hacked and the model just produced a wrong answer.

If your head of risk management believes the broker already owns this, send them the six blocks above including the empty owner lines and let the blanks make the case.

When the stakes exceed your internal capacity:

  • AI Exposure Diagnostic: A 2-hour strategic evaluation for risk, compliance, and legal leaders to identify your highest-priority governance gaps and deliver a 90-day remediation roadmap.

  • 12-Week Governance Sprint: Translate regulatory requirements into audit-ready policies, control frameworks, and accountability structures.

  • Ongoing Advisory Retainer: Embedded judgment for policy updates, vendor assessments, and board prep as regulations and technology evolve.

  • Fractional Chief AI Officer: A standing officer seat with the authority to ship or stop AI deployments, and the accountability to answer for that decision to your board and regulators. You get the officer without the full-time hire.

Reply with "Diagnostic" or “Sprint” to schedule a conversation for next month.

Chris Cook writes Judgment Call weekly for compliance and risk officers navigating AI governance.

Former IBM Vice President and Deputy Chief Auditor. Published in the AI Journal, speaker at Yale.

Chris Cook

Managing Partner & Founder

Blackbox Zero

Forwarded this by a colleague? Subscribe to Judgment Call

Previous
Previous

Why Your AI Spending Needs the Same Authorization Controls as Travel and Procurement

Next
Next

Why Asking a Chatbot Legal Questions Can Waive Attorney-Client Privilege