In Depth
CGL is the workhorse policy underneath most businesses. It answers for the physical-world harms a company can inflict on outsiders: a customer slips in your office, your work damages a client's property, your advertising defames a competitor. The form has been refined over decades, its triggers are well understood, and procurement teams treat a CGL certificate as table stakes. It was written for a world where harm meant something tangible, an injury or a broken thing or a libelous statement, caused by people and equipment.
Generative AI introduced harms that CGL drafters never contemplated and that don't map cleanly to "bodily injury" or "property damage." So the standardizing body for U.S. commercial insurance forms responded the way insurers respond to unpriced risk: they excluded it. ISO published generative-AI exclusionary endorsements for CGL, effective January 2026, which strip AI-related claims out of the standard form. What was previously a gray area, whether an AI-caused harm is covered under CGL, became an explicit "no" across the bulk of the market in a single renewal cycle.
The shift matters beyond the literal text because CGL is so widely held and so rarely re-read. Most businesses renew it on autopilot. The GenAI CGL exclusion arrived as an endorsement bolted onto otherwise-familiar policies, so the coverage changed for millions of buyers who never registered that anything had. For an AI vendor, it means the most foundational policy on the stack now points away from exactly the risk the business runs.
What It Looks Like
Picture a vendor whose AI agent supports a hospital's non-clinical operations: scheduling, intake, patient messaging. The agent sends a batch of patients the wrong pre-procedure instructions, and one follows them, leading to a physical injury and a claim that names the vendor. In a pre-2026 world, the vendor's lawyer might have argued the bodily-injury harm fell under CGL. After January 2026, the carrier points to the generative-AI exclusion on the renewed form: the harm traces to AI output, and the endorsement removes it. The baseline policy the vendor has carried for years, for this fact pattern, now reads as a denial.
Why It Matters For AI Vendors
CGL is the policy a customer's procurement team almost always requires, and the one vendors least expect to have an AI problem; it's "general liability," after all. That's what makes the 2026 exclusion so consequential: it converts the broadest, most-assumed coverage on the certificate into one that explicitly won't respond to AI-caused harm. A vendor can present a clean stack of certificates and still be uninsured for the agent that is its entire business, because every form in the stack now carries a version of the same carve-out.