There's a quiet development in enterprise risk that most AI programs haven't noticed, and it could leave a company exposed at exactly the wrong moment. The insurance industry is splitting in two on AI. On one side, a new market for AI-specific coverage is forming fast. On the other, traditional insurers are quietly carving AI out of the policies companies already hold.
Gartner put the urgency in plain terms this spring, advising general counsel to actively assess AI insurance and forecasting more than 2,000 AI-related legal claims filed worldwide by the end of 2026. The claims are coming. The question every GC and CFO should be asking is whether the coverage they think they have will actually respond when one lands.
The new market: affirmative AI insurance
The optimistic half of the story is that real products now exist. In April 2025, Armilla launched what it billed as the first standalone AI liability policy, backed by a Lloyd's of London underwriter, covering AI that underperforms, hallucinates, or fails to do what it was built to do; by early 2026 its limits had climbed past $25 million per organization. Munich Re's aiSure, offered through Mosaic Insurance, insures against AI model errors and hallucinations up to $15 million, and a startup called AIUC has begun writing policies covering losses from AI agents, including data leakage and IP infringement, up to $50 million.
Read together, these are proof the market has decided AI risk is real and can be priced, enough that serious underwriters will now take it on. That's genuinely useful for a company that wants to transfer some of its AI exposure instead of carrying all of it.
The quiet half: exclusions
The half that catches companies off guard is happening inside the policies they already renew every year. Verisk's ISO, whose standard forms underpin the vast majority of US property-and-casualty policies, introduced generative-AI exclusion endorsements that became available to insurers on January 1, 2026. Carriers including W.R. Berkley and Hamilton have begun adding AI exclusions and limitations, and some are writing "absolute" AI exclusions into directors-and-officers and errors-and-omissions policies, wiping out coverage for any claim arising from the use or development of AI.
That's the trap. A company can be building its AI program on the assumption that its existing liability, D&O, and E&O policies have it covered, while at renewal those exact policies are being amended to exclude the thing it's now doing more of every quarter.
What this means for a $100M+ company
The two halves combine into a single, uncomfortable message: AI risk is being priced and separated out, and silence is not coverage. A GC who hasn't read the AI language in this year's renewals doesn't actually know whether the company is insured for its fastest-growing source of risk. And a CFO signing off on AI initiatives may be taking on liability that used to be transferable and quietly isn't anymore.
Gartner's own forecast is that by 2030, insurers will require organizations to demonstrate strong AI risk controls before granting AI coverage at all. In other words, the ability to buy AI insurance is going to depend on being able to show real governance, which turns AI controls from a nice-to-have into a prerequisite for being insurable.
How True Horizon does it
Insurance responds to risk you can demonstrate you're managing, and that's the part we build. We put the controls, documentation, and oversight around an enterprise AI program that both reduce the odds of a claim and give a GC something concrete to show an underwriter: what's deployed, who owns it, how it's monitored, and what happens when it fails. We're not selling insurance. We're making a company safer and insurable, which are increasingly the same thing.
What to do now
Start with a reading exercise, not a purchase. Have your GC pull this year's liability, D&O, and E&O renewals and find the AI language, because that's where the coverage is quietly changing. Map where AI actually creates exposure in the business. Then decide, deliberately, which of that risk you're keeping, which you're insuring, and which you're reducing with controls. The companies that get caught out will be the ones that assumed old policies still covered a new kind of risk.
If you want to know whether your AI program is defensible to an underwriter, take our AI assessment and we'll map the controls an underwriter will actually want to see.









