Skip to content

Deal economics

Generative AI insurance exclusions in 2026: what data suppliers should check

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Data suppliers should check every liability policy, not only cyber, for generative AI exclusions: endorsements or wording that remove coverage for claims arising from AI. Broad wording can reach privacy, IP and contract claims tied to a buyer's model. Pull complete policies, list each endorsement and get your broker's answers in writing before signing.

Key takeaways

  • Generative AI exclusions can appear in general liability, cyber, technology E&O, media and D&O policies, often added by endorsement at renewal.
  • Broad arising-out-of wording can reach a data supplier even though the supplier never builds or runs a model.
  • Indemnities given in a data license may fall outside coverage under contractual liability exclusions, before any AI exclusion applies.
  • Set the license's liability cap and insurance requirements against what your policies actually cover.
  • Get written answers from your broker before signing, and check whether the policy requires notice of a material new activity.

What is changing in AI exclusions at 2026 renewals?#

AI exclusions are appearing on more commercial insurance renewals in 2026, sometimes as standard endorsements and sometimes as carrier-specific wording. Insurers are uncertain how AI-related claims will develop, and some have responded by excluding them, narrowing them or offering separate affirmative coverage instead.

The scope varies widely. Some exclusions target claims caused by content a generative AI system produced. Others reach any claim arising out of the development, training, provision or use of artificial intelligence, which is broad enough to touch a company that only supplied records. Some are written as absolute exclusions that apply regardless of other policy provisions.

Because the changes often arrive as endorsements, they are easy to miss. The declarations page can look the same as last year while the forms schedule has a new line.

Why a data supplier is exposed without building a model#

A data supplier is exposed because claims can follow the records, not just the model. If a buyer's model produces something harmful and a claimant traces it back to licensed records, the supplier may be named alongside the developer, even with good defenses.

None of these exposures is unique to AI. The risk is that an AI exclusion carves them out of policies that would otherwise respond.

  • Privacy claims if personal details survived preparation and later appear in outputs or a breach.
  • Confidentiality or IP claims from customers, vendors or former partners whose material was in the records.
  • Contract claims from the buyer under the warranties and indemnities in the license.
  • Regulatory inquiries into how personal data was handled before delivery.
  • Governance or securities claims if statements to investors about AI activity prove inaccurate.

Which policies to pull and what to check#

The policies to pull are every liability policy the company holds, not only cyber. The table shows where a data license can create exposure and what to read in each policy.

Which policies to pull and what to check
PolicyExposure from a data licenseWhat to check
Commercial general liabilityPersonal and advertising injury allegations, such as privacy or publicity claimsAI or generative AI endorsements; data-related and personal injury exclusions
Cyber and privacy liabilityPersonal data in delivered records; regulatory response costsExclusions for unauthorized collection or use of data, AI training or AI output
Technology or professional E&OClaims that delivered records or services were defective or misdescribedDefinition of professional services; AI exclusions; contractual liability exclusion
Media liabilityIP and defamation claims from content in the recordsWhether licensed content counts as covered media; AI-generated content exclusions
Directors and officersClaims about board decisions or investor statements on AI activityAbsolute AI exclusions; entity coverage; disclosure-related exclusions

Phrases and form numbers to search for#

Searching the full policy text for specific phrases is the fastest way to find AI language. Ask your broker for complete policies with every endorsement, not summaries or certificates, and search each document.

Then list every endorsement by form number and edition date from the forms schedule, and ask the broker which ones address artificial intelligence. Standard forms, such as those published by the insurance advisory organization ISO, show a form number followed by an edition date in month and year, while carrier endorsements use the carrier's own numbering. A number or edition date that was not on last year's schedule is the clearest sign something changed, so compare the two schedules line by line.

  • artificial intelligence, AI, generative, machine learning, large language model
  • algorithm, automated decision, automated system
  • training data, data mining, model training, synthetic content
  • arising out of, based upon, attributable to, in any way involving
  • absolute exclusion, notwithstanding any other provision
  • unauthorized collection, wrongful collection, use of data
  • contractual liability, insured contract, assumed liability

How the license contract interacts with coverage#

The license contract decides how much of the supplier's exposure insurance even needs to cover. Warranties, indemnities and the liability cap set the size of the contractual promise; the policy decides whether any of it is insured.

Many liability policies exclude liability the insured assumes by contract unless it falls within a defined insured contract or would exist without the contract. An indemnity to an AI buyer for third-party claims may therefore be uninsured before any AI exclusion applies. Ask counsel and the broker to read the indemnity and the policies together.

Buyers sometimes require suppliers to carry specified coverage and name the buyer as an additional insured. Do not accept that requirement until the broker confirms the coverage is available without an AI exclusion that defeats it.

Questions for your broker before signing#

Questions for your broker should be written and specific, and the answers should come back in writing. The table lists the ones that matter most for a company licensing records to AI developers.

Questions for your broker before signing
QuestionWhy it matters
Do any current or renewal endorsements exclude claims involving artificial intelligence?Finds the exclusion before a claim does
Would a claim arising from records we licensed for AI training fall within that exclusion?Tests broad arising-out-of wording against your actual activity
Is the indemnity in this license an insured contract under our policies?Shows whether contractual promises are insured at all
Do we need to notify carriers of the license or update our applications?Avoids a coverage dispute over undisclosed activity
Is affirmative AI coverage or a buyback of the exclusion available?Shows whether the gap can be closed or must be managed by contract
Does the timing of signature or delivery affect which claims-made policy responds?Decides which policy year and which wording apply to a later claim

Illustrative: an HVAC contractor reads its renewal#

Illustrative: a fictional HVAC and plumbing contractor with several branches plans to license years of ServiceTitan job notes, transcribed call notes and estimate revisions to a model developer. Its insurance renewal arrives during contract negotiation.

The forms schedule shows a new endorsement on the cyber policy excluding claims arising from the use of data to train or operate artificial intelligence. Meanwhile the license draft asks the contractor to indemnify the buyer for privacy claims without a cap.

The owner and counsel narrow the indemnity to claims caused by a breach of the contractor's preparation warranty, cap it at a stated amount and carve commercial customers with restrictive contracts out of scope. The broker provides a written explanation of how the exclusion applies, and the owner accepts the remaining risk before signing.

How SourceX approaches insurance questions#

SourceX does not give insurance advice, but the SourceX five-step transaction is built to reduce the facts that drive claims. In the Preparation step, personal and confidential details are removed before release, and the supplier approves each step from Supply and Rights through Approval and Delivery.

The privacy record and permitted use in the SourceX Evidence Packet document what was removed and what the buyer may do with the records. Brokers can review that record when assessing the license, and counsel can align warranties with it.

Frequently asked questions

Does cyber insurance cover a data license?

Not by default. Cyber policies typically respond to breaches and privacy incidents, and a license is a deliberate disclosure under contract. Some wording may respond to a privacy claim tied to licensed records, while AI or data-use exclusions may remove that coverage. Only the policy text and your broker's written answer settle it.

Should we tell our insurer about a data license?

Check the application, the policy's notice and change-in-risk provisions and any application answers about AI activity. Some policies require notice of material changes, and inaccurate renewal answers can lead to coverage disputes. Your broker can advise how and when to disclose.

Can we buy coverage for AI-related claims?

Some markets offer affirmative AI coverage or buybacks of AI exclusions, usually with underwriting questions about your activity. Availability and terms vary by carrier and change often, so ask what is offered for a data supplier specifically rather than for an AI developer.

Does the buyer's insurance protect us?

Only if you are an additional insured, or the buyer indemnifies you and has coverage that responds. Many AI developers carry their own policies, but the license should say whether you get the benefit of them. Without that, assume the buyer's coverage protects the buyer.

Do occurrence and claims-made policies treat this differently?

Yes. An occurrence policy generally responds based on when the injury happened, while a claims-made policy responds based on when the claim is made and reported. AI-related claims may surface long after delivery, so the wording in force at that later time can matter more than today's.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify