Est.

Munich Re AI Exclusion Stance in Autonomous Vehicle Liability Placements

Munich Re backs AI exclusions as a reinsurer while insuring AI performance failures through aiSure.

Senior Correspondent · · 10 min read
Cover illustration for “Munich Re AI Exclusion Stance in Autonomous Vehicle Liability Placements”
AI Exclusion Filings · October 9, 2026 · 10 min read · 2,277 words

Munich Re sits on both sides of the ledger in autonomous vehicle liability, so any AV operator needs to read its own insurance program with that in mind. As a reinsurer, Munich Re backs the capital, so primary carriers can staple AI exclusions onto standard commercial policies. As the underwriter behind aiSure, the same company affirmatively insures AI performance risk, paying out when a defined AI system fails to meet contracted benchmarks. Most operators, if they think about Munich Re at all, picture a remote institution several layers removed from their certificate of insurance, with no bearing on how a claim gets paid. That assumption does not hold: the two functions serve different buyers, demand different submissions, and produce opposite outcomes for an operator who does not know which side of Munich Re it is actually dealing with.

The 2026 Exclusion Wave and Munich Re's Reinsurance Role

The exclusion wave that reshaped commercial general liability coverage in 2026 was not the product of scattered, carrier-by-carrier caution. ISO filed three generative AI exclusion endorsements effective January 1, 2026, moving through the market as a coordinated package of underwriting decisions. CG 40 47 is the primary Commercial General Liability exclusion, removing coverage for bodily injury, property damage, and personal and advertising injury arising from generative AI; the endorsement applies across both Coverage A and Coverage B. CG 40 48 is a narrower endorsement limited to Coverage B, excluding personal and advertising injury, a category that reaches into intellectual property, copyright, and privacy claims. CG 35 08 excludes bodily injury and property damage arising out of generative artificial intelligence under the Products and Completed Operations section, and of the three, it lands most directly on autonomous vehicle deployments. More than 60 property and casualty groups filed during the 2026 wave to adopt the ISO forms or to delay adoption. That scale of adoption means these endorsements are not edge-case language a handful of carriers chose to add. They are the new baseline for how general liability policies treat AI exposure.

A shift of this size cannot come from primary carrier capital on its own. Reinsurance treaties set the boundaries of what a primary carrier can write, so when reinsurers decline to back AI-related liability on standard terms, primary carriers lose the support they need to keep that exposure on their own books. Munich Re's reinsurance role in this wave should be understood as structural logic rather than a direct, documented order to exclude: the capital standing behind commercial lines makes broad exclusion the rational, supportable choice for primary carriers operating in large numbers, at the same time. The practical result for an AV operator is the same regardless of the precise mechanism. The exclusion that shows up on a renewal policy did not originate in a single underwriter's judgment about one fleet. What you see instead is a market-wide reallocation of risk appetite, and the capital that made it possible sits, at least in part, behind Munich Re.

The "Silent AI" Problem in Autonomous Vehicle Policies Already in Force

AV operators holding coverage today face a more urgent exposure than the exclusion endorsements attaching at renewal. The more dangerous exposure is the coverage that was never explicitly priced in the first place, sitting silently in policies written before January 2026, available to be disputed the moment a claim arrives. If you bought a standard commercial auto and general liability program two years ago, you likely assumed autonomous operations fell under the vehicle coverage you already had, but now you carry two separate problems. The existing policy may hold silent AI coverage that the carrier never underwrote for autonomous risk, so if a large claim lands, the carrier has every reason to argue after the fact that the risk was never priced and so was never truly bound. At the same renewal where that dispute becomes live, the replacement policy likely attaches CG 35 08, and that closes off any ambiguity for good, in the carrier's favor.

The structural reason this problem compounds rather than resolves on its own has to do with how liability moves through an AV incident. Standard auto and general liability forms were built around a single human driver as the responsible party, so you can assign fault cleanly and one policy can respond. Autonomous vehicle operations break that model by distributing responsibility across vehicle owners, operators, manufacturers, system suppliers, and network providers, all of whom may hold a piece of the causal chain in a single incident. When the single-driver assumption fails, the coverage gap does not stay contained to one layer of the program. It compounds across every party in that chain, and each one may be relying on a policy that was never written with a multi-party, software-mediated liability structure in mind.

Over-the-air software updates turn this into a moving target. A vehicle's autonomy profile can look nothing like it did when the policy was priced, because several software updates since then have changed how the system perceives, decides, and acts. The policy sitting in the operator's file reflects the risk profile from binding, not the risk profile on the road today, and nothing in a standard annual renewal cycle forces that documentation to catch up in real time.

aiSure's coverage and its structural difference from a GL policy with an AI carve-back

Munich Re's aiSure product addresses a different question than the one a general liability policy with an AI carve-back is built to answer. aiSure is a performance-contingent product: it pays when a defined AI system fails to meet measurable, contracted benchmarks, with a trigger built around quantified performance. Munich Re launched the product in 2018, with its first policy written for an anti-fraud AI model, and describes it as model-agnostic, covering machine learning, deep learning, reinforcement learning, ensemble models, and generative AI, on the premise that any type of model is insurable under the right benchmarks. The FAQ lists a range of losses that AI underperformance can cause, including property damage and bodily injury, compliance fines and penalties, privacy violations, data leaks, intellectual property infringement, pure financial losses, and discrimination, offered as illustrations of the liabilities underperforming AI can create rather than an exhaustive list of what the policy pays for. The current 2026 version of the product covers algorithmic bias, privacy failures, intellectual property infringement, and performance shortfalls, while explicitly excluding regulatory penalty exposure and losses that fall below a contracted threshold. Partnered with Mosaic, the 2026 version offers substantial per-developer or per-vendor limits against defined performance failures. Munich Re has written aiSure policies across agriculture, banking, climate and earthquake forecasting, cyber security, insurance, and retail, and the FAQ states confidence in covering any industry use case where the accuracy and reliability of AI performance is critical to financial results.

The distinction that matters for an AV operator lives in the trigger itself. A GL claim requires proof of tort causation, which in an AV context often means litigating whether a sensor misread, a perception failure, or a planning error was the proximate cause of a downstream injury or property loss. aiSure replaces that causation fight with a measurable question: did the system perform within the accuracy thresholds, latency floors, and drift bands set out in the contract. That shift does not make aiSure a substitute for general liability coverage. It makes aiSure a policy for a different layer of the exposure stack, one that responds to performance failure against a benchmark rather than to bodily injury or property damage arising from an incident. An AV operator cannot use aiSure in place of a GL program, because the two products are not answering the same question. Treating them as interchangeable is the single most common error an operator can make in reading Munich Re's position.

The Coverage Triangle, GL, Tech E&O, and Cyber, Leaves AV Operators With No Center

The exclusion problem in AV liability is not confined to general liability. Three standard commercial lines, general liability, technology errors and omissions, and cyber, are each written to exclude the territory the other two are supposed to cover, and an AV incident routinely generates a claim that touches all three at once. General liability policies now carry CG 35 08, which excludes property damage from autonomous systems, the core exposure most AV operators are trying to insure. Technology errors and omissions policies systematically exclude bodily injury and property damage claims, which happen to be the exact claims that physical AI deployments most commonly produce. Cyber policies typically exclude contractual liabilities, and the standard cyber form still has a documented gap for physical damage caused by a compromised autonomous system, so if a cyberattack on an AV system leads to a physical accident, it falls squarely into that unaddressed space.

A single scenario shows how this plays out in practice. A cyberattack compromises an autonomous vehicle's control system, causing it to behave erratically and strike a pedestrian. That incident is a cyber event, since it began with a network compromise. The same incident is also a technology errors and omissions event, since the system performed outside its contracted specification. And it is a general liability event too, because a third party suffered bodily injury on the operator's watch. Three policies, each theoretically relevant, each point to one of the other two as the line that should respond, leaving the operator holding three declination letters.

This gap appears in contracting long before it appears in a claim. Inland marine and equipment coverage follows hardware out to a customer's site, but if you want to deploy on a site owner's premises, they typically require proof of general liability first. Even when a hardware-focused AV operator can produce a certificate, this is often the first contract term it cannot actually satisfy in substance. When the underlying GL policy carries CG 35 08, the certificate handed to the site owner does not reflect coverage that would actually respond to an autonomous-system incident on that property. The paperwork clears the contract requirement, but the coverage behind it does not clear the risk.

Diagram: The Coverage Triangle: Three Policies, Zero Center. Visualizes: Visualize a triangle where each corner is labeled with one of the three coverage lines — General Liability (GL), Technology E&O, and Cyber — and each side of the triangle…

What a submission to Munich Re's aiSure underwriters requires

Getting access to Munich Re's affirmative AI capacity is not primarily a matter of finding the right contact or the right broker relationship. What it depends on is whether you can produce the technical documentation that Munich Re's own underwriting process demands, and most AV operators cannot produce it without dedicated preparation. The published process runs on a two-step technical assessment: underwriters evaluate the model development pipeline and identify specific risk scenarios, including unrepresentative training data, data drift, and the operator's processes for updating and monitoring the model, and they derive a risk estimator from historical performance data. That second step depends on a thorough, quantitative analysis of data inputs and outputs sufficient to establish a performance baseline. If you have no telemetry, no performance logs, and no documented testing history, you have nothing to feed into that process, no matter how sound the underlying autonomous system actually is.

If you run AV systems, underwriters now expect continuous telemetry tracking, automated intervention mechanisms, and audit logs just so you can make a baseline submission. If an autonomous agent causes physical damage in a cyber-physical system, the burden of proof for that claim rests on those logs. Without them, the claim cannot be substantiated, and the underwriting cannot be completed. The submission also needs to specify the autonomy level, the operational domain, and the human override architecture of the system in explicit terms. A submission that describes "autonomous vehicle operations" in general language, without naming these parameters, routes into decline queues or specialist desks that are already long under the AI-assisted triage systems now running at primary carriers.

Closing this gap is a documentation problem before it is a relationship problem. A specialist broker who understands both the technical material Munich Re's underwriters require and the operational reality of how AV systems actually run can translate what an operator already has, telemetry, safety cases, testing logs, into the format underwriters need to price the risk. The broker commission is already embedded in the premium whether or not a specialist ends up placing the policy, so the cost of getting that preparation right is a cost the operator is paying either way, not an additional expense layered on top of the placement.

Steps AV operators should take at their next renewal given Munich Re's dual position

All of this comes down to a single choice an AV operator makes at every renewal. Show up with a generic submission, and Munich Re appears on the other side of the transaction as the reinsurer backstopping the exclusions written into the primary policy. Show up with a purpose-built technical submission, documenting telemetry, autonomy level, override architecture, and performance history, and Munich Re appears instead as the underwriter capable of binding the affirmative AI performance coverage the operation actually needs.

Before the next renewal, every AV operator should take two concrete steps. Audit the existing general liability policy for CG 35 08 or any proprietary AI exclusion endorsement, because these can attach at a prior renewal with no corresponding premium adjustment and no explicit notice calling attention to the change. Review any policy written before January 2026 that covers AV operations for silent AI exposure, and check whether the carrier ever priced the autonomous operations risk or just left it unaddressed in the underwriting file. Those two checks determine which version of Munich Re an operator is going to meet at the next renewal: the reinsurer standing behind the exclusions closing in on the policy, or the underwriter sitting behind the one product built to actually pay when the AI system fails.

More in AI Exclusion Filings