Est.

ISO AI Exclusion Endorsement CG 21 06 Language Analysis

Insurance carriers are quietly excluding AI risks from standard policies through January 2026.

Senior Correspondent · · 10 min read
Cover illustration for “ISO AI Exclusion Endorsement CG 21 06 Language Analysis”
AI Exclusion Filings · October 7, 2026 · 10 min read · 2,211 words

The commercial insurance market has moved from ambiguity to explicit exclusion on AI risk, and the shift happened fast enough that most autonomous hardware operators have not caught up with what their policies now say. Until January 1, 2026, AI risk mostly lived inside existing cyber, Tech E&O, and CGL policies without ever being named directly. Insurers called this "silent AI," coverage that left AI exposure unresolved until a claim forced the question to be fought out after the fact. That era is ending, and it is ending the way these things tend to end in insurance, through standardized language that regulators approve and carriers attach at renewal, not through a single dramatic announcement. For a robot maker, a drone operator, or an autonomous vehicle company, where physical harm and AI-directed decision-making sit on top of each other, the change in wording is the clause that decides whether a bodily injury claim gets paid.

The Definition of "Generative AI" in CG 21 06 and Its Breadth for Physical Systems

Three new exclusion endorsements from the Insurance Services Office, effective January 1, 2026, give carriers standard language to remove generative AI losses from commercial general liability coverage: CG 40 47, CG 40 48, and CG 35 08 [1][2][3]. All three rely on one shared definition, and that definition is doing the heavy lifting. Generative AI, under this language, means "a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code." Read that sentence slowly, because it is written at the level of the system, not the product category, and it does not say chatbot or content tool. It describes any trained model that produces outputs, and that description covers a lot of ground that has nothing to do with marketing copy or customer service bots.

A delivery robot's vision model, if it identifies and steers around obstacles, fits this description. A drone's planning model that re-routes mid-flight in response to new sensor data fits it. An autonomous vehicle's control model that generates real-time steering and braking outputs fits it too. None of these systems look like generative AI in the popular sense of the term, the sense tied to image generators and text chatbots, but the ISO definition does not test for popular usage. It tests for a trained model that creates content or responses, and none of the three forms require that the model be central to the product. A qualifying model only needs to be part of the system that produced the loss. That is a much lower bar than most operators assume when they read "generative AI" on a declarations page and picture a tool they don't use.

Why "Arising Out Of" Does More Work Than Operators Expect

The definition tells a carrier what counts as generative AI. The trigger phrase tells a carrier how close that AI has to be to the loss before the exclusion applies, and the standard phrase used across all three forms is "arising out of." CG 40 47 goes further, adding "or attributable to" on top of "arising out of," which makes its trigger broader than the language in CG 40 48 or CG 35 08. Under established insurance law, "arising out of" does not require that the AI be the direct or dominant cause of the harm. A causal connection is enough. The AI does not need to be the proximate cause of the loss, and it does not need to be the main reason the loss happened. It only needs to be somewhere in the chain of events that led to it.

Walk through what that means for an actual incident. Picture a delivery robot that collides with a pedestrian. The investigation finds three contributing factors: a sensor that misread distance, an operator who failed to intervene in time, and a path-planning model that chose a route through a crowded area it should have avoided. Under a policy carrying CG 40 47, the presence of that third factor, the AI model, is enough to put the exclusion in play, even though the sensor failure and the operator's inaction were also part of the story. The carrier does not need to prove the AI caused most of the harm. It needs only to show the AI was part of the causal chain, and "arising out of" lets it make that argument.

The same low bar reaches other claim types, and hardware operators tend to underweight them. A defamation or advertising injury claim tied to AI-drafted marketing copy, an intellectual property claim over AI-generated product imagery, or a bodily injury claim where an AI recommendation contributed even marginally: all of these fall inside the exclusion through the same trigger language. Operators sometimes say their product isn't an AI product, that AI is just a feature buried somewhere in the stack, not the thing they sell. That argument does not defeat the trigger. The question a carrier asks is whether a qualifying model sits in the causal chain of the specific loss being claimed, not how the company describes itself in its marketing or its pitch deck. A company that has never once called itself an AI company can still discover, at the moment of a claim, that its CGL policy treats it like one. The exclusion follows the model that caused the harm, not the label the company put on its own product.

The three ISO forms are not interchangeable

Diagram: Three ISO Forms, Three Different Coverage Holes. Visualizes: Show how the three 2026 ISO endorsements each carve out a distinct slice of CGL coverage, so operators can see at a glance which claims remain payable and which do not.

Knowing that the definition is broad and the trigger is low tells an operator that exposure exists. It does not tell them how much of their coverage is actually gone, because the three ISO forms do not remove the same protections. Each one targets a different part of the CGL policy, and the form a carrier attaches determines which claims still get paid and which do not.

| Form | Scope removed | What it hits hardest | |---|---|---| | CG 40 47 | Coverage A (bodily injury, property damage) and Coverage B (personal and advertising injury) | Broadest form. Works with occurrence and claims-made policies. Closes coverage completely on AI-adjacent claims. | | CG 40 48 | Coverage B only (personal and advertising injury) | Leaves Coverage A intact. Targets defamation, IP infringement, and advertising injury claims tied to content generation. | | CG 35 08 | Products/Completed Operations Liability Coverage Part | Excludes bodily injury and property damage from generative AI in delivered products or completed work. |

For an autonomous hardware operator, CG 40 47 is the form that does the most damage: a robot collision causing bodily injury is a Coverage A claim, and if a qualifying AI model is anywhere in the causal chain, that claim may not be paid. CG 40 48 matters less for a company whose primary exposure is physical harm rather than content, though it still strips protection from marketing material, software outputs, and AI-generated communications, none of which disappear just because a company builds hardware.

CG 35 08 deserves more attention than its narrow scope suggests. It applies only to the Products/Completed Operations coverage part, separate from Coverage A, and it excludes bodily injury and property damage if they arise from generative AI in products you already delivered or work you already completed. For a company that ships an autonomous robot, a drone, or a vehicle, that is where the largest bodily injury and property damage exposure actually lives: in the field, after the product has left the factory and started operating on its own. Treating CG 35 08 as a minor form because its scope is narrow misreads where hardware risk concentrates.

Carriers can attach one of these forms, two, or all three, and the combination changes what the policy actually covers. A policy carrying only CG 40 48 looks different from one carrying CG 40 47 and CG 35 08 together, and a policy with no AI endorsement looks different from both. Finding out which forms sit on a given policy means opening the endorsement schedule and checking each form number by name. A broker's summary of the declarations page will not surface this distinction reliably.

Where CG 21 06 sits relative to the 2026 forms

CG 21 06 predates the 2026 forms, and it has not been retired or absorbed by them. It works as its own exclusion mechanism, and it addresses a scope of AI-related coverage that remains contested in ways the newer forms were drafted specifically to avoid. CG 40 47, CG 40 48, and CG 35 08 represent a more aggressive and more precisely targeted successor architecture, built explicitly around generative AI as a named, defined category. CG 21 06 was not.

An operator whose policy carries both CG 21 06 and one of the 2026 forms faces layered exclusions written under two different definitional regimes, not one unified AI exclusion. What counts as "AI" under CG 21 06 may not match what counts as "generative AI" under the 2026 language, and that mismatch does not resolve itself cleanly. It creates two separate clauses that a court would have to interpret on their own terms in relation to the specific facts of a claim. A coverage dispute on a policy carrying both forms is a matter of working through two clauses, two definitions, and how each might be read against the loss in question, a task that calls for a broker who has actually read the policy language before the policy binds, rather than one working from a declarations-page summary.

How carriers are adopting these forms in practice

None of this happens automatically. ISO writes the standard language, but each carrier decides on its own whether to attach a given endorsement, to which policies, and under what terms. The forms did not strip AI coverage from every CGL policy in the country on January 1, 2026. For most policies already in force before that date, the exclusion is not attached yet. It arrives at renewal, one carrier and one policy at a time. A company whose policy renewed in early 2026 may already be carrying one of these endorsements while a company whose policy renews in the fourth quarter of 2026 may still be operating without it. The exclusion does not raise the premium in a way that draws attention. It appears instead as a new line item in the endorsement schedule, a part of the renewal packet that most operators do not read line by line.

Some carriers are moving well past ISO's optional framework. Berkley has filed an "absolute" AI exclusion that reaches across directors and officers, errors and omissions, and fiduciary liability lines, excluding claims "based upon, arising out of, or attributable to" the actual or alleged use, deployment, or development of artificial intelligence. That language extends even to claims tied to a company's failure to detect AI-generated content or to inadequate AI policies, practices, or training, a scope considerably wider than the CGL-specific ISO forms. Other carriers are applying exclusions selectively, tied to how a company disclosed its AI use on the original application. An operator that did not disclose AI involvement at underwriting can face a retroactive dispute later, with the carrier arguing the exposure was material and should have been disclosed. None of this is theoretical for a policy renewing this year. It is a live decision a specific underwriter is making about a specific account, and the only way to know where a given policy stands is to check it.

Autonomous Hardware Operators Face a Worse Coverage Outcome Than Software-Only AI Companies

The same exclusion language does not land the same way on every kind of AI company, and hardware operators come out worse than software-only vendors when these forms attach. A company selling a generative AI writing tool or an image generator faces its sharpest exposure in Coverage B: defamation claims, IP infringement claims, advertising injury claims tied to the content its product produces. That is where litigation friction concentrates for content-generating software, and it is the coverage CG 40 48 is built to strip away.

Autonomous hardware operators carry a different risk profile. Their greatest exposure is in Coverage A, bodily injury and property damage, because their products are physical machines operating in the world without a person at the controls: a delivery robot that collides with a pedestrian, a drone that crashes into a parked car, an autonomous vehicle that causes an injury on a public road. CG 40 47, the broadest of the three forms, removes both Coverage A and Coverage B for losses that arise out of generative AI. For a software company, losing Coverage B is a serious problem. If you're a hardware operator and you lose Coverage A, you lose the part of the CGL policy that exists specifically to pay for physical harm and property damage, the core reason a general liability policy exists. A standard CGL policy was built around a world where the thing causing harm was a person, a product defect, or a structure. It was not built around a trained model making a real-time decision inside a machine operating on its own, and the 2026 ISO forms make that mismatch explicit rather than leaving it to argue over later.

Sources

  1. New Generative AI Insurance Exclusion: What the Construction Industry Needs to Know - Cohen Seglias
  2. Commercial General Liability (CGL) Policy Guides
  3. The End of Silent AI Coverage: Exclusions Outrun Risk Transfer
  4. From Control Boundary to Insurance Claim: Reconstructing AI-Mediated Losses Through the CER Framework
  5. The Insurability Frontier of AI Risk: Mapping Threats to Affirmative Coverage, Silent Exposures, and Exclusions

More in AI Exclusion Filings