In Depth
ISO, the Insurance Services Office, writes the standardized policy language that most U.S. property and casualty insurers build their forms on. When ISO publishes a new endorsement, carriers across the country adopt it as renewals come up, so an ISO change doesn't move one insurer. It moves the market. That is what makes the generative-AI CGL exclusion a turning point rather than a footnote. It is a coordinated, industry-wide narrowing of a policy that nearly every company carries.
Commercial General Liability is the baseline business policy, covering bodily injury, property damage, and personal and advertising injury to third parties. For years, when an AI agent caused harm, a plausible argument existed that some piece of it might fall under CGL, because the form predated AI and said nothing about it. Silence read as ambiguity, and ambiguity sometimes read in the policyholder's favor. The generative-AI endorsement closes that door deliberately. By naming AI as an excluded cause, it replaces an arguable gray area with an explicit "not covered," and removes the line of argument vendors had been quietly relying on.
The reach of the change is what's underappreciated. The CGL exclusion didn't arrive alone. It landed in the same window as AI carve-outs spreading across Tech E&O and Cyber forms. Taken together, the three policies an AI vendor most likely carries now coordinate to exclude the same category of risk. A vendor can hold all three, pass its customers' insurance requirements, and be uncovered for the way its agent actually fails. The exclusion didn't create the AI risk. It made the absence of coverage for that risk explicit and near-universal.
What It Looks Like
A healthcare-adjacent AI vendor sells an agent that triages patient inquiries. The agent mishandles a case in a way that contributes to a physical harm, and the injured party's claim names the vendor. In the pre-2026 world, the vendor's broker might have tendered the claim to the CGL carrier and argued the bodily-injury coverage should respond. After the generative-AI endorsement, that argument is foreclosed at the form level. The policy now states that claims arising from generative AI are excluded, and the carrier declines on the language rather than on the facts. The vendor isn't fighting over interpretation anymore. The exclusion already answered the question.
Why It Matters For AI Vendors
This is the keystone fact behind why standalone AI coverage exists. The market didn't drift toward excluding AI. ISO made it the standard, on a known effective date, across the policy every business carries. For an AI vendor, that converts a vague worry into a concrete, dated coverage gap you can point to. It also reframes the conversation with enterprise buyers. Their own risk teams know the CGL forms changed, so "we're covered under our general liability policy" no longer satisfies a serious security review.
The right response isn't to argue with the exclusion. It's to carry coverage built for the risk the exclusion removed.