Insurance, Indemnity, and AI Disclosure to Owners
A mid-size GC settled a $1.8M defect claim, then sent the demand to its professional-liability carrier expecting the policy to respond. The loss traced to a slab-edge dimension that an AI takeoff tool had read off a superseded drawing revision, and the contractor's preconstruction team had submitted the number into the GMP without catching it. The carrier's coverage counsel found the answer in the 2026 renewal endorsement nobody at the firm had read: a new exclusion barring claims "arising out of or in connection with the use of artificial intelligence, machine learning, or automated decision systems" in the performance of professional services. The claim was denied. The firm carried the loss on its own balance sheet, and the renewal it had treated as a formality had quietly rewritten what its coverage protected. This is not a legal-advice lesson, and it is not insurance advice: it is the strategist's reading of where AI-assisted work meets the firm's policies, what the 2026 exclusions do, and the questions to take to your broker and your counsel. By the end you will be able to read your firm's policy tower for AI exclusions and produce a policy review with the recommended riders and endorsements before a claim, not after.
The Denied Claim and the Analogy That Governs It
Insurance is the firm's transfer of risk to a carrier in exchange for a premium, and the transfer is only as good as the policy language on the day the loss occurs. The strategist who treats the renewal as a paperwork chore is like a builder who orders a critical material without reading the submittal: what arrives may not be what the spec called for, and you discover the gap at the worst moment, when the work is in place or the claim is filed. The firm had coverage, paid premium, and assumed the policy would respond, and it did not, because the language had changed and the firm had adopted a workflow the new language excluded.
The controlling analogy is the submittal. A policy is a submittal from the carrier: its statement of what it will and will not cover, issued for the firm's review, which the firm either checks against what it actually does or accepts on the carrier's word. A builder would never accept a 60-page mechanical submittal without checking it against the basis of design, because a deviation buried on page 40 becomes the firm's problem at installation. A policy is the same: an exclusion buried in a renewal endorsement becomes the firm's problem at the claim. So the strategist reads the policy the way a project engineer reads a submittal, against what the firm actually does, looking for the deviation the carrier has quietly introduced, which in 2026 is the AI exclusion. The seal is binary, and so is coverage: a claim is either inside the policy or outside it, with no partial credit for having paid the premium in good faith.
This connects to the spine of the program. AI-assisted work creates new liability exposure, and the firm's verification gates (design intent, code, contract authority, dollars, life-safety) exist precisely because AI output can be wrong in ways that produce a loss. When a gate fails (an AI takeoff reads the wrong revision, an AI code narrative cites a fabricated section, an AI schedule analysis understates an impact), the loss has to land somewhere, and the firm's whole risk posture assumes some losses land on the insurance tower. The 2026 question is whether the tower still catches the losses that now involve AI, and the firm protects its coverage before a claim, because after the claim the language is fixed and the negotiation is over.
The Policy Tower a Firm Actually Carries
An AEC firm does not carry one policy. It carries a tower of distinct coverages, each written for a distinct exposure, and AI-assisted work touches several of them differently. The strategist has to know which policy responds to which loss before asking which policy now excludes AI, because an exclusion only matters where the coverage would otherwise have responded.
Professional liability (errors and omissions, E&O) covers claims arising from negligent professional services: a defective design, a missed code requirement, a flawed estimate, an erroneous schedule analysis. For a design firm this is the core policy; for a GC it covers the design-assist, constructability, and preconstruction services the firm increasingly performs. It is the policy most exposed to AI, because AI is most embedded in professional-services work: the AI-drafted code narrative, the AI takeoff that feeds a GMP, the AI routing that becomes a basis-of-design input. When an AI-assisted professional service produces a negligent result, E&O is the policy that would respond, which is why the 2026 AI exclusions are appearing in E&O forms first. Builder's risk is first-party property coverage for the work in place and materials during construction: it responds to physical loss or damage (fire, wind, water, collapse) to the project itself, not to professional negligence. AI touches it less directly, but a loss caused by an AI-driven decision (a sequencing or means-and-methods choice that contributes to a collapse) can raise the question of whether the loss is an excluded design or workmanship defect rather than a covered fortuitous event. Cyber liability covers data breach, ransomware, network interruption, and increasingly the failure of AI systems the firm deploys: a compromised model, a prompt-injection incident that leaks an owner's confidential program data, an AI agent that takes an unauthorized action. As firms run AI agents against project data, cyber grows in relevance, and AI-specific cyber endorsements are appearing alongside the AI exclusions on the liability side. Contractor's pollution liability (CPL) covers pollution conditions arising from the contractor's operations: a spill, a release, contaminated soil, mold from a water intrusion. AI touches CPL where an AI-assisted decision (an AI-flagged-but-overridden moisture reading, an AI environmental-monitoring system that missed an exceedance) is alleged to have caused or failed to prevent a pollution condition.
The tower matters because a single AI-related loss can implicate more than one policy and fall into the gap between them. A model that leaks owner data and also produces a defective design touches both cyber and E&O; if the cyber policy excludes professional services and the E&O policy excludes AI, the loss falls through the tower entirely. The strategist maps the firm's AI use against the tower so the gaps are visible before a claim finds them, the same gap-mapping discipline the program applied to subcontractor scope and the verification gates: the dangerous loss is the one that lands in the seam nobody owns.
A policy is a submittal from the carrier, and the 2026 AI exclusion is the deviation buried on page 40. The firm that does not read its tower against what it actually does discovers the gap at the claim, when the language is fixed and the premium is already spent. Read the policy before the loss, because coverage, like the seal, is binary.
The 2026 AI Exclusions and Why Carriers Wrote Them
Carriers underwrite by pricing known, bounded risk, and AI-assisted professional work is, from the underwriter's seat, unknown and unbounded. The carrier cannot yet price the frequency or severity of AI-driven losses, the case law on AI negligence is unformed, and the carrier does not want to fund the industry's experiment. So in the 2026 renewal cycle, carriers began attaching AI exclusion endorsements to professional-liability and, in some cases, general-liability and CPL forms. The strategist should expect several patterns and read for the exact one on the firm's form rather than assuming.
The patterns differ sharply in their bite. A broad absolute exclusion bars any claim "arising out of, based upon, or in any way involving" the use of AI, machine learning, or automated systems in the firm's services, and because almost any modern professional service now touches AI somewhere, this exclusion can swallow most of the coverage the firm thought it bought. A negligent-reliance or failure-to-supervise exclusion is narrower: it bars claims arising from the firm's reliance on AI output without adequate human review, which effectively ties coverage to the firm's verification discipline and is far more survivable for a firm that documents its gates. A carve-back or affirmative-coverage endorsement goes the other way: it confirms that AI-assisted services remain covered provided the firm maintains stated controls (a human-in-the-loop, a documented review process, disclosure to the client), turning the firm's governance into a coverage condition. And a silent-AI posture, where the policy says nothing about AI at all, is its own risk, because the carrier may later argue the exclusion was implied or may add it at the next renewal, and silence is not the same as affirmative coverage.
The reading discipline is to find the AI language, classify which pattern it follows, and trace what it does to each policy, because the same exclusion has different consequences on E&O than on cyber. An AI exclusion on the E&O policy that also leaks into the cyber policy can leave an AI-system failure uncovered on both fronts. The strategist does not negotiate the policy alone: the reading produces the questions for the broker (what AI language is on the form, what carve-backs are available in this market, what the carrier requires to grant affirmative coverage) and for coverage counsel (how broadly the exclusion reads, how it interacts with the other policies, what controls satisfy a carve-back). This is informational; the binding interpretation is counsel's and the broker's.
Indemnity, Disclosure, and the Owner Relationship
Coverage is only half the risk transfer. The other half is the indemnity the firm gives and receives in its contracts, and AI disclosure to owners interacts with both. An indemnity clause shifts liability for defined losses from one party to another, and the firm's insurance is what makes its indemnity meaningful: an indemnity the firm cannot fund is a promise, not a protection. So if the firm indemnifies the owner against losses arising from its services, and the firm's E&O policy now excludes AI-related losses, the firm has given an indemnity its insurance will not back, and an AI-driven loss it indemnified comes straight out of its own capital. The exclusion does not just deny a defense, it strands an indemnity obligation.
This is where the lesson echoes the L1 accountability lesson and the AI-disclosure transmittal language the program built there. The L1 lesson framed disclosure as a professional-accountability act: the responsible licensed professional discloses that AI assisted the work because the professional, not the AI, owns the result. The strategist adds the coverage layer: disclosure may be the condition that preserves coverage under a carve-back endorsement, and non-disclosure of material AI use may give a carrier grounds to contest a claim or rescind. The same disclosure language the firm added to its transmittal cover sheets and sealed sheets (a statement that AI assisted the work and a licensed professional reviewed and verified it) does double duty: it documents the verification the negligent-reliance exclusion turns on, and it satisfies a disclosure-conditioned carve-back. The firm should align its standard owner disclosure with what its policy requires, so the language protecting the license also protects the coverage.
The owner relationship has its own dynamic. Sophisticated owners (healthcare systems, hyperscalers, institutional developers) are beginning to ask, in their owner-architect and owner-contractor agreements, whether and how AI is used on their projects, and some are adding their own AI-disclosure and AI-restriction clauses. The strategist reads the owner contract's insurance and indemnity provisions together with the firm's policy: if the owner requires the firm to carry E&O covering AI-assisted services and the firm's policy now excludes them, the firm is in breach of its insurance covenant the day it signs, a contractual exposure independent of any actual loss. Aligning the contract requirement, the firm's coverage, and the disclosure language is the strategist's reconciliation, and the gaps among the three are exactly the gaps a claim will find.
Reading the Policy: The Strategist's Method
Reading an insurance tower for AI exposure is a disciplined pass, not a skim, run the way a contract-review AI would surface a risk register: locate the relevant language, classify it, flag the consequence. The pass starts with the declarations and the schedule of forms and endorsements, because the exclusion that matters is usually an endorsement attached at renewal, not body text, and the schedule is where you find what changed this year. Pull the prior year's policy alongside the renewal and run the same drawing-comparison discipline the program taught, what is added, deleted, reworded, because the AI exclusion most often arrives as a quietly added endorsement the renewal summary does not foreground.
For each policy in the tower, the strategist answers a fixed set of questions. Does the policy mention AI, machine learning, or automated systems, and where (body, exclusion, endorsement, definitions)? If it excludes AI, which pattern is it (broad absolute, negligent-reliance, carve-back, silent)? What does the exclusion do to this specific policy's coverage given how the firm uses AI in the work this policy covers? Does the exclusion interact with another policy in the tower to create a gap (the E&O-cyber seam, the CPL-pollution seam)? What does the firm's indemnity in its standard contracts promise, and does the now-modified coverage still back it? What do the firm's owner contracts require for AI insurance, and is the firm in compliance? The answers populate the policy review, and the questions the firm cannot answer from the policy become the broker and counsel agenda.
The strategist resists two errors. The first is over-reading: treating every mention of "automated" or "software" as an AI exclusion when it is boilerplate, wasting the broker's negotiating capital on non-issues. The second is under-reading: assuming the firm's AI use is too minor to trigger an exclusion when, under a broad absolute exclusion, even incidental AI use in a service can be argued into the bar. The defense against both is the program's discipline: read the language against what the firm actually does, document the firm's AI footprint by service line, and let the specific facts (this policy, this exclusion, this firm's actual AI use) drive the classification rather than a general impression. The firm verifies its coverage before the loss the way it verifies an AI deliverable before the stamp.
The Applied Problem: A Policy Review With Recommended AI Riders and Endorsements
Here is the exercise. Take your firm's actual insurance tower (E&O, builder's risk, cyber, CPL, and the general-liability and umbrella forms above them) and produce a policy review with recommended AI riders and endorsements, framed as the firm's pre-claim coverage position and the agenda for the broker and counsel. The review is not a legal or insurance opinion; it is the strategist's structured reading that lets the broker and counsel work from facts rather than impressions.
Produce the review in three parts. First, the tower map and AI footprint: each policy, what loss it responds to, and where the firm uses AI in the work that policy covers, so the exposure is mapped before the language is read. Second, the exclusion findings: for each policy, the AI language found (quoted with the endorsement number and the renewal date it was added), the pattern it follows (broad absolute, negligent-reliance, carve-back, or silent), what it does to coverage given the firm's AI use, and any tower gap it creates with another policy, with the prior-year-to-renewal comparison called out. Third, the recommended riders and endorsements with the broker and counsel agenda: the specific endorsements to pursue (an affirmative AI carve-back conditioned on the firm's verification and disclosure controls, an AI-specific cyber endorsement for model and agent failures, a clarification that the firm's documented human-in-the-loop satisfies the negligent-reliance language), the indemnity-coverage reconciliation (whether the firm's standard indemnity is still backed and where the owner contracts require AI coverage the firm lacks), and the questions only the broker and counsel can answer.
The deliverable is the three-part policy review, and the lasting product is a firm that knows where its tower covers AI-assisted work, where it does not, and what to ask for at renewal, rather than a firm that learns the answer from a denied claim. The strategist who masters this protects the firm's coverage before the loss, aligns the disclosure that protects the license with the disclosure that preserves the coverage, and turns the renewal from a formality into the firm's annual reading of its own risk transfer, because coverage is binary, the language is fixed at the claim, and the only leverage the firm has is the reading it does before the loss.
Key Takeaways
- AI-assisted work creates liability exposure the firm's existing policies may not cover, and the 2026 renewal cycle is introducing AI exclusions that can deny a claim the firm assumed was covered, which is why the firm reads its tower before the loss, not after, when the language is fixed and the premium is already spent.
- The controlling analogy is the submittal: a policy is the carrier's statement of what it will cover, issued for the firm's review, and the AI exclusion is the deviation buried in a renewal endorsement that becomes the firm's problem at the claim, so the strategist reads the policy against what the firm actually does, the way a PE checks a submittal against the basis of design.
- The firm carries a tower, not one policy: professional liability (E&O) is most exposed because AI is most embedded in professional services; builder's risk is first-party property and touches AI through the design-or-workmanship-defect question; cyber grows in relevance as firms run AI agents on project data; and contractor's pollution liability touches AI through AI-assisted environmental decisions.
- The dangerous loss is the one that falls into the seam between policies: an AI failure that leaks owner data and produces a defective design can fall through a cyber policy that excludes professional services and an E&O policy that excludes AI, the same gap-mapping discipline the program applied to subcontractor scope and the verification gates.
- The 2026 exclusions follow patterns the strategist must classify: a broad absolute exclusion can swallow most of the coverage; a negligent-reliance exclusion ties coverage to the firm's verification discipline; a carve-back endorsement preserves coverage if the firm maintains stated controls and disclosure; and a silent-AI policy is its own risk because silence is not affirmative coverage.
- Indemnity and coverage are linked: an indemnity the firm cannot fund is a promise, not a protection, so an AI exclusion that strands an indemnity obligation pushes an AI-driven loss straight onto the firm's own capital, and the strategist reconciles the firm's indemnity with its now-modified coverage.
- AI disclosure to owners does double duty: the same disclosure that the L1 accountability lesson built to protect the license (a statement that AI assisted and a licensed professional verified) also documents the verification a negligent-reliance exclusion turns on and can satisfy a disclosure-conditioned carve-back, so the firm aligns the license-protecting language with the coverage-preserving language.
- The deliverable is a policy review with recommended AI riders and endorsements: a tower map and AI footprint, exclusion findings classified by pattern with the prior-year comparison, and recommended endorsements plus the broker and counsel agenda, because this is informational and the binding interpretation belongs to counsel and the broker, while the reading that gives them facts belongs to the strategist.
Skill.re