Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022
Back to BlogBoard Advisory
Your D&O Policy Has a Hidden AI Gap: What Every Board Member Must Know in 2026

Your D&O Policy Has a Hidden AI Gap: What Every Board Member Must Know in 2026

AI exclusions are quietly stripping D&O coverage at renewal—and most boards have no idea. Learn what the CG 40 47 endorsement means for your liability protection in 2026.

August 24, 202611 min readBy Adil Karam

Your directors and officers insurance policy may already have a gap in it. Not a hypothetical gap, not a future risk to monitor. An actual exclusion, written into your last renewal's endorsement schedule, that strips coverage for losses arising from AI. Most boards never saw it. Most brokers never flagged it. And most executives will only discover it when they file a claim and the insurer points to three letters buried in the fine print: CG 40 47.

This is the defining liability story of 2026 for corporate boards, and it has nothing to do with being hacked. It has everything to do with the intersection of a hardening insurance market, an expanding regulatory accountability regime, and a governance gap that plaintiffs' attorneys are now actively studying. Directors who cannot document active AI oversight face a double exposure: personal liability with no insurance backstop. That combination has the potential to reach personal assets, not just corporate indemnification. Forward this to your general counsel and your risk committee before your next renewal.

The Structural Break That Changed Everything at Renewal

January 2026 marked a structural break in the commercial insurance market. Verisk's ISO Form CG 40 47 01 26, a generative AI exclusion underpinning 82% of global property and casualty policies, took effect.

The timing was not accidental.

Simultaneously, W.R. Berkley introduced an "absolute" AI exclusion across D&O, E&O, and fiduciary liability lines. AIG and Great American Insurance followed with their own exclusion filings.

A review of nearly 10,000 filings through S&P Capital IQ's product filings search found that 41 P&C insurance groups tracked in S&P Global Market Intelligence's SNL Insurance dataset had at least one subsidiary that filed to adopt an AI exclusion. Subsidiaries of a further 20 groups filed to delay adoption of exclusions until a later date.

This is not a niche market movement. This is a systemic repricing of AI risk away from insurer balance sheets and onto yours.

What makes the mechanism particularly dangerous is how quietly it operates.

The exclusions did not require policyholders to affirmatively opt in. They were added at renewal, in endorsement form, as standard policy modifications. An organization whose broker did not specifically flag the AI exclusion language may be unaware that their coverage changed, until a claim is filed.

According to Alana McMullin, a partner at Lathrop GPM whose practice focuses on complex insurance disputes, "there's been a major shift in the insurance industry's treatment of AI-related risks and insurers are moving very quickly to limit this exposure."

The Agentic AI Exposure Is the Next Wave

Generative AI exclusions are only the first chapter. The chapter your board needs to read now concerns agentic AI, the systems that do not merely generate content but take autonomous actions: executing transactions, sending communications, modifying databases, and making consequential decisions without human approval at each step.

Verisk, the largest provider of data and standardized policy language for the U.S. insurance sector through its ISO unit, has confirmed that it is studying new specific exclusions for risks arising from agentic AI. According to the company, it is a matter of "evaluating additional options" in the face of an exposure that grows as these tools become embedded in companies' operations.

Most cyber and E&O policies were written for breaches and bugs, not agents acting under your credentials. The coverage gap shows up at claim time, when nobody planned for it.

An agentic AI system that executes a flawed pricing strategy, autonomously sends discriminatory communications, or initiates unauthorized transactions operates with legitimate credentials.

Traditional cyber policy triggers depend on intent and identity: an external actor obtained unauthorized access, a phishing email tricked a user, ransomware encrypted a system. Agent incidents fail every one of these tests. The agent had legitimate credentials. The agent was authorized to call the tool. The agent's action was logged, attributed, and within its declared scope. There was no intruder, no deception, no malware.

The insurer denies. The board is exposed. The company self-insures an existential loss.

Carriers are not refusing to cover AI altogether. They are refusing to cover AI they cannot evaluate. The underwriting conversation has shifted from "do you have an AI policy?" to "show us the evidence."

Boards that cannot produce documented evidence of AI governance, specifically meeting minutes, risk committee charters, AI system inventories, and board-level risk reporting, are simultaneously more liable and less insured than at any prior point in their tenure.

The Coverage Fragmentation Map

When reviewing coverage for 2026 renewals, policyholders should expect more AI risk to be expressly allocated, or quietly removed, from policies that previously may have responded. The result is not clarity but fragmentation. Policyholders now face heightened risk of AI-related claims falling between traditional coverage lines or being subject to competing exclusions across the insurance tower.

The table below maps how AI exclusions are spreading across the policy lines most relevant to directors and officers:

Policy LineCurrent AI Exclusion StatusDirector Exposure
Commercial General LiabilityISO CG 40 47/48 effective Jan 2026; adopted by 41+ P&C groupsThird-party bodily injury, property damage from AI systems
D&O (Management Liability)W.R. Berkley absolute exclusion; Berkshire Hathaway, AIG, Travelers filed exclusionsPersonal liability for AI-related securities claims, derivative suits
Errors & Omissions / Tech E&OParallel AI exclusion language spreading from CGL formsProfessional liability for AI-driven advice or automated decisions
Cyber LiabilityAI-adjacent gaps; agentic AI incidents fail standard trigger testsAutonomous agent actions, AI-enabled fraud, agentic data misuse
Fiduciary LiabilityW.R. Berkley absolute exclusion applies across fiduciary linesERISA liability for AI-assisted benefit or investment decisions

The Insurance Services Office introduced standard general-liability AI exclusion forms effective January 2026, and Berkshire Hathaway, Chubb, Travelers, and AIG have filed AI exclusions across general liability, E&O, and D&O lines.

A single AI-related incident can now trigger denial across every relevant policy in your insurance tower simultaneously.

The Caremark Problem: Personal Liability Without a Safe Harbor

While insurers narrow coverage, courts and regulators are simultaneously expanding what boards owe. The governing legal doctrine is Caremark, and its application to AI governance is now settled enough to create real personal exposure.

Corporate oversight under Delaware law rests on two bases for liability identified in In re Caremark International Inc. Derivative Litigation and reaffirmed in Stone v. Ritter. The first is a failure to implement any reporting or information system or controls, and the second is, having implemented such a system, a conscious failure to monitor or oversee it. In either case, liability requires a showing of bad faith, that is, a sustained or systematic failure to exercise oversight, or a conscious disregard of red flags signaling that the corporation was exposed to material risk.

For boards and the officers who advise them, the decision to deploy or build AI is a Caremark event. The Delaware oversight chain from Caremark to McDonald's explains why personal, loyalty-based exposure attaches before the tool is ever switched on.

The governance gap in practice is alarming.

66% of directors use AI tools but only 22% report having formal governance frameworks, according to the What Directors Think 2026 survey.

Meanwhile,

the Conference Board reports that the share of large-cap public companies disclosing AI as a material risk jumped from 12% in 2023 to 83% in 2025, while only 23% of directors describe themselves as fluent in AI.

The liability ratchet works in both directions simultaneously: more surface area for claims, less insurance to absorb them.

By embedding oversight functions in opaque and probabilistic systems, AI increases the difficulty of demonstrating good faith while simultaneously generating richer records through which courts may evaluate fiduciary engagement.

The regulatory dimension compounds the personal exposure.

The EU AI Act imposes fines of up to €35 million or 7% of global turnover for serious violations, and the U.S. Securities and Exchange Commission has designated AI as a systemic market risk in its 2026 examination priorities.

State-level law adds further pressure:

Texas's Responsible AI Governance Act, effective January 1, 2026, imposes risk assessment and transparency obligations on deployers of high-risk AI systems and provides an affirmative defense for organizations demonstrating alignment with a recognized governance framework such as the NIST AI RMF.

That affirmative defense is the key insight. Documentation of governance process, not perfect AI outcomes, is what protects directors.

Agentic AI Exclusions Are Coming to Renewals After 2026

New policy exclusions for agentic AI could be on the horizon, as Verisk's Insurance Services Office explores options to address additional AI exposures.

The pattern is predictable: generative AI exclusions arrived in July 2025 filings and took effect January 2026. Agentic AI exclusions are in development now. Boards that deploy autonomous agent systems before establishing documented governance oversight will face the same coverage gap on a compressed timeline, with higher potential loss severity.

AI Litigation Is Accelerating the Claims Environment

Generative AI-related lawsuits in the U.S. surged by 978% from 2021 to 2025, according to a report from broker Gallagher Re.

Stanford's AI Index, drawing on the AI Incident Database, recorded 362 documented AI incidents in 2025, up from 233 in 2024. Those incidents span privacy violations, discriminatory outputs, misinformation, and consequential algorithmic errors, exactly the categories that turn into claims, regulatory inquiries, and lawsuits.

Underwriters are watching this data. Your premiums and your exclusions will reflect it.

"AI Washing" Shareholder Actions Are Targeting Directors Personally

D&O policies cover claims against directors, officers, and sometimes the company itself for alleged mismanagement, breach of fiduciary duty, or securities law violations. AI-related D&O claims are emerging. One example is so-called "AI washing," where a company publicly claims advanced AI capabilities that it has not actually developed. In response, shareholders may allege material misrepresentation claims against the company.

When coverage is also excluded, the personal exposure of individual directors becomes the primary recovery target for plaintiffs.

Documented Governance Is Now an Underwriting Requirement

Insurers and brokers are demanding documentation of AI system inventories

as a condition of favorable underwriting.

The language can be negotiated. Documented AI governance, narrower definitions, and alternative markets all change the outcome.

The board that arrives at renewal with a structured AI governance framework, board-level AI risk reporting, and evidence of active oversight is a materially different underwriting risk than the board that cannot answer the question.

Board AI Governance Readiness: Immediate Action Checklist

The following steps reflect alignment with the NIST AI Risk Management Framework, ISO 42001 (AI Management Systems), and CIS Controls for AI-adjacent risk. Use this as your starting point before your next renewal conversation:

Action ItemWho Owns ItUrgency
Pull every policy endorsement schedule and search for CG 40 47, CG 40 48, CG 35 08, and any AI exclusion languageRisk Committee + BrokerImmediate
Commission an AI system inventory documenting all deployed models and agentic toolsCISO / CTOImmediate
Establish a board-level AI risk reporting cadence (minimum quarterly)Board / Audit Committee30 days
Document board meeting minutes to reflect AI oversight discussionsCorporate SecretaryOngoing
Assign AI oversight to a specific board committee with a written charterBoard Chair60 days
Assess alignment with NIST AI RMF or ISO 42001 for regulatory affirmative defenseCISO / Legal60 days
Brief underwriters at renewal with documented AI governance evidenceCFO + Risk CommitteeAt next renewal
Conduct AI-specific tabletop exercise at board levelBoard + CISO90 days

The CISA AI Security guidance and the EU AI Act compliance portal provide additional regulatory alignment resources for organizations with international exposure. The SEC's 2026 examination priorities confirm AI disclosure as an active enforcement focus.

How I Help

My Board Advisory work is built specifically for the situation you are facing: translating complex AI risk into boardroom language that directors can act on, insurers can evaluate, and regulators can audit. I deliver executive-ready presentations that quantify AI liability exposure in financial terms, build governance frameworks that create documented oversight trails, and produce board reporting packages that function as evidence of fiduciary engagement, not just status updates. Boards I work with arrive at renewal conversations and regulatory inquiries with the documentation that changes outcomes.

For organizations deploying AI systems or evaluating agentic tools, my Secure AI Deployment service addresses the specific governance and technical controls needed to close the coverage gap before the next exclusion wave arrives. For organizations that need a fractional security executive to lead these conversations internally and with the board, my vCISO engagement provides that leadership without the full-time cost. I also help organizations build the compliance architecture that aligns with NIST AI RMF, ISO 42001, and state-level AI accountability statutes, and work directly with security architecture teams through Security Architecture engagements to ensure AI system design reflects the governance requirements boards are being held to.

See if I should be in the room

#D&O Insurance#AI Liability#Board Governance#Risk Management#Corporate Compliance#Executive Leadership
PDFShare:

Adil Karam

Security & AI Governance Advisor

Helping organizations navigate security leadership and AI governance challenges.

Ready to Put These Insights Into Action?

Whether you need secure AI deployment, security leadership, or compliance guidance, we can apply these strategies to your organization.