Insights · Governance

The underwriter's question: insurance has started pricing the difference between auditable and unauditable AI.

Insurers have begun declining to cover automation whose decisions cannot be inspected after a loss. The question an underwriter asks in a claim file is the one a fund already answers for its auditor, its regulator and its allocators, and it now arrives with a price attached. What follows is what a system has to be built like to answer it.

Working drawing: three compartmented coverage bars running the sheet, each drawn broken where one solid red vertical member stands across them at the renewal station, the dimension chain beneath measuring on past the break to a datum triangle.
Makoto TominagaPublished 2026-08-156 min
01·2026

three ISO generative-AI exclusions took effect

80%+

of major-carrier AI-exclusion filings approved by state regulators

Four

askers of the same question; the newest asks with a price attached

One

append-only record that answers all of them

The renewal

The default changed on the first of January.

On 1 January 2026, three generative-AI exclusion endorsements took effect for commercial general liability. They come from ISO, the Verisk unit whose standard forms are the base most American commercial general liability policies are written from. CG 40 47 removes bodily injury, property damage and personal and advertising injury arising from generative AI across Coverages A and B. CG 40 48 is confined to personal and advertising injury. CG 35 08 covers products and completed operations.

Carriers were already moving on their own. Subsidiaries of Berkshire Hathaway, Chubb, Travelers and AIG filed proprietary AI exclusions with state regulators through the autumn, and a Wolfe Research analysis of those filings, reported in April 2026, put the approval rate above 80 percent, with Florida, Connecticut and Maryland processing the most. W.R. Berkley went further, writing an absolute AI exclusion into directors and officers, errors and omissions, and fiduciary liability.

The mechanism matters more than the headline. These are endorsements, and an endorsement arrives when a policy is written or renewed. A firm meets the new default when it reads its renewal papers, or when it files a claim.

Four askers

The same question, now with a price attached.

A fund has heard this question before, from three directions at once.

The auditor asks at year end: show me the decisions and the approvals. The regulator asks after an incident: demonstrate that your controls operated. The allocator’s operational due diligence team asks before the subscription: walk me through how work is supervised here. The underwriter has now joined them, and asks with a price attached.

All four want the same artifact. A record, made at the time, of what was raised, what was decided, what was blocked, and who approved what, complete enough that reconstruction is a query rather than an archaeology project.

Fig. 1 — one record, four readingsentries this asker needs
The recordappend-only
  1. 01Obligation raised
  2. 02Owner and date attached
  3. 03Authority it ran under
  4. 04Material it drew on
  5. 05Constraint that bounded it
  6. 06Escalations that ran
  7. 07Result produced
  8. 08Approval that released it
  9. 09Named human sender
Decisions and approvals, as made.

The claim file

Every element turns on placing the action.

To pay or deny a claim, an insurer has to establish the elements. Proximate cause: which act produced the loss. The standard of care: whether the insured ran the controls a prudent operator would have run. The state of those controls at the moment of loss, as distinct from the day of the last audit. And the recurrence exposure: whether tomorrow carries the same risk at the same size.

Where the work was done by an agentic system, every element turns on whether the record can place the action. Placing it means the record shows which obligation the action served, what authority it ran under, what material it drew on, which constraint bounded it, and whose approval released the result. A placed action makes the loss ordinary: cause can be traced, care can be judged, the exposure can be bounded, and bounded risk has a price. An unplaced action leaves every element open, and an open element is what an underwriter is professionally obliged to walk away from. The exclusion is that refusal, printed as a standard form.

The record

Evidence deposited, not written up.

An inspectable system deposits its evidence as it works. Every step of the job leaves its own trace, at the time, without anyone writing anything up.

Genba’s operating model puts every obligation through one lifecycle, and each step leaves evidence: the item raised, the owner and date attached, the escalations that ran, the draft produced and the sources it drew on, the approval that released it, and the control decisions in between, all on Shuin, Genba’s append-only record. The send boundary is part of the same evidence. No agent has a send path to a third party, so finished work is held at distribution for a named human sender, and the record carries every one of those approvals. “What happened, and who authorised it?” is answerable months later, with the context intact.

None of this is a compliance layer bolted onto the automation. It is the shape of the automation. A system built this way answers the underwriter’s question the same way it answers the auditor’s, because it was never able to work off the record in the first place.

Repricing

The market is sorting automation on evidence.

Exclusions of this kind do not stay still. Insurers have begun writing affirmative AI cover alongside them, underwritten on representations about a firm’s AI capabilities, governance and controls, which get scrutinised at application. The market is sorting automation into what can be inspected and what cannot, and attaching a cost to the second.

For a regulated firm the sorting started earlier, because auditors and allocators were already doing it. What the exclusion adds is a price, printed on the renewal.

Q&A

Questions, answered

Direct answers to the questions this architecture raises.

01

What changed for AI liability coverage on 1 January 2026?

Three ISO endorsements took effect for commercial general liability: CG 40 47, excluding bodily injury, property damage and personal and advertising injury arising from generative AI; CG 40 48, confined to personal and advertising injury; and CG 35 08, for products and completed operations. Carriers have also filed their own AI exclusions, and several have written absolute versions into directors and officers, errors and omissions, and fiduciary lines.

02

Does the generative-AI exclusion reach investment firms?

The ISO endorsements amend commercial general liability forms, and carrier-specific AI exclusions have already appeared in directors and officers, errors and omissions, and fiduciary liability. What any individual policy does is a question of its own wording and its own carrier. The pattern across the market is the part that generalises: insurers are distinguishing automation they can inspect from automation they cannot, and coverage is following that line.

03

What must an agentic system's record establish after an incident?

Enough to place every action: the obligation it served, the authority and permissions it ran under, the material it drew on, the constraints that bounded it, what it produced, and the person whose approval released it, held so the sequence can be reconstructed. A loss that can be placed is an operational-risk event. A loss that cannot is unbounded.

04

Is logging enough to make a system auditable?

Logs record that software ran. An evidentiary record ties each action to an obligation, an owner, a constraint and an approval, in a form that cannot be edited afterwards. The difference is what a reviewer can conclude from it: activity in the first case, accountability in the second.

05

Why does the send boundary matter to insurability?

Because the largest loss scenarios begin with an autonomous external action. Where no agent has a send path to a third party, and a named person releases every outbound artifact, that scenario is removed rather than mitigated, and the approval record shows the boundary held.

06

Where does the evidence come from in practice?

From the work itself. Each step of the obligation lifecycle deposits its own record as a by-product: items, escalations, drafts, approvals, control decisions, all on Shuin, Genba's append-only record. Nothing is written up after the fact.

Cite this articleTominaga, M. (2026). The underwriter's question: insurance has started pricing the difference between auditable and unauditable AI. Genba Labs Insights. https://genbalabs.com/insights/ai-exclusion-underwriters-question/

Ask the underwriter's question about your own automation, and see what answers.

Scope the thirty-day proof