Is Your General Liability Policy Adequately Covering Digital Risks?
As businesses increasingly rely on digital technologies, the exclusion of cyber-related risks from general liability policies is raising alarms. Here's what you need to know to protect your business.

In an era where digital technologies underpin nearly every aspect of business, the importance of understanding your general liability (GL) policy cannot be overstated. Traditionally viewed as a safety net for physical consequences stemming from cyber events, many companies are now finding themselves exposed due to a significant shift in insurance coverage. Since 2014, the insurance landscape has evolved, leading to the removal of what was once considered 'silent cyber' coverage. As we delve into these changes, it’s essential for business leaders to grasp how these exclusions can impact their operations and what steps they can take to secure their interests.
The Evolution of Cyber Coverage in General Liability Policies
Historically, GL policies provided a limited scope of coverage for physical harm resulting from cyber incidents. Insurers would often 'carve back' coverage to include certain situations where a data breach or cyber failure led to actual bodily injury or property damage. This meant that if a cyber attack on a manufacturing system resulted in physical injury to a worker, the GL policy might still respond, offering a form of protection that many businesses relied upon.
However, the tides have turned dramatically in recent years. The introduction of exclusionary provisions has fundamentally altered the landscape. Insurers are now largely adopting standardized exclusions from the Insurance Services Office (ISO), stripping away the remaining safety net for businesses. The most notable of these is the CG 40 35 12 23 exclusion, which explicitly excludes coverage for any claims related to cyber incidents. This includes unauthorized access, malware attacks, and denial-of-service incidents, effectively leaving businesses vulnerable to losses they once thought were covered.

Understanding the Current Landscape: The 2023 Exclusions
As of 2023, the insurance industry has seen a definitive shift toward explicit exclusions for cyber incidents. The implications of this are profound. The CG 40 35 exclusion does not merely limit coverage for data breach expenses; it actively removes any potential for coverage related to bodily injury, property damage, or personal injury claims that arise from cyber events.
This exclusion is particularly concerning for industries where technology is integral to operations, such as manufacturing, healthcare, and utilities. A failure in an industrial control system due to a cyber attack, for instance, could lead to catastrophic injuries or property damage. Under the new exclusions, businesses would have no recourse through their GL policy if such an event were to occur.
Anticipating Future Risks: Generative AI and New Exclusions
The digital risk landscape does not stop with cyber incidents. As businesses adopt generative AI technologies, insurers are quickly adapting to address new liabilities associated with these innovations. The ISO has introduced several new endorsements in 2026 that specifically target the exclusions around generative AI. These include:
- CG 40 47 01 26 (The Broad Exclusion): This endorsement precludes coverage for claims arising from any aspect of AI, including generative AI and large language models.
- CG 40 48 01 26 (The Coverage B Exclusion): This narrower exclusion focuses on Coverage B, removing protection for claims such as defamation or copyright infringement arising from AI-generated content.
- CG 35 08 01 26 (The Products-Completed Operations Exclusion): This exclusion targets bodily injury and property damage arising out of generative AI in relation to finished products.
This shift indicates that underwriters are prioritizing sectors with high exposure profiles, including technology firms, media outlets, and software developers. However, as these exclusions become commonplace, businesses across all sectors must prepare for the implications.

Identifying Coverage Gaps: Take Action Now
With the removal of silent cyber coverage and the introduction of broad exclusions for generative AI, businesses are left with significant coverage gaps. Here are critical steps that business leaders must take:
1. Review Your Operations Thoroughly
Conduct a comprehensive assessment of your operations to identify scenarios where cyber incidents or AI errors could lead to physical harm, property damage, or financial loss. For example, consider how a hacked system might impact your production lines or customer safety.
2. Analyze Your Insurance Policies
Your insurance portfolio should be reviewed in light of these new exclusions. Examine your GL, Property, Technology Errors & Omissions, and standalone Cyber policies to determine how each one is affected by recent changes.
3. Engage Your Insurance Broker
This is not a time for complacency. Consult with your insurance broker to discuss your unique exposures and explore tailored underwriting solutions. Your broker can guide you in securing coverage that adequately addresses the evolving risk landscape.
Bridging the Gap: The Rise of Standalone AI Liability Markets
Recognizing the growing gap in coverage, the insurance industry is beginning to innovate. Standalone AI liability products are emerging, designed specifically to cover the unique risks associated with AI technologies. These new products aim to address:
- Financial loss and negligent misrepresentation stemming from AI errors
- Defamation and reputational harm
- Intellectual property infringement
- Unauthorized data disclosure
- Bodily injury or property damage related to AI outputs
As businesses navigate this shifting terrain, it is crucial to stay informed about these emerging products and consider them in your risk management strategy.

Key Takeaways
- The removal of silent cyber coverage from GL policies leaves businesses exposed to digital risks.
- New exclusions targeting generative AI are being rapidly adopted across the insurance industry.
- Proactive assessments of operations and insurance policies are essential to identify gaps in coverage.
- Engaging with insurance brokers can help secure tailored solutions for emerging risks.
- Standalone AI liability markets are developing to address the unique exposures associated with AI technologies.
Frequently Asked Questions
What is 'silent cyber' coverage?
Silent cyber coverage refers to the implicit coverage that businesses believed existed within their general liability policies for losses related to cyber incidents. Insurers previously ‘carved back’ this coverage to include certain physical damages resulting from cyber events. However, this coverage is now being actively excluded in most GL policies, leaving businesses with potential gaps in protection.
How can I identify if my business is exposed to these new risks?
Identifying exposure to new digital risks involves a comprehensive review of your operations. Consider how technology and AI are integrated into your business processes and how failures could lead to bodily injury or property damage. Conducting risk assessments and scenario planning can help illuminate potential vulnerabilities.
What steps should I take if I discover coverage gaps?
If you identify coverage gaps, the first step is to consult with your insurance broker. Discuss your specific needs and explore tailored solutions that may involve standalone policies or endorsements that cover emerging digital risks, including those related to AI technologies.
Are standalone AI liability policies widely available?
While standalone AI liability policies are still emerging, their availability is growing as insurers recognize the need for coverage tailored to the unique risks posed by AI technologies. Businesses should keep an eye on the market for new products and consider these options when reviewing their risk management strategies.
Comments
Harnessing AI in Insurance: From Document Processing to Revenue Growth
The insurance industry is evolving its approach to AI, transitioning from basic document extraction to focusing on productivity and revenue growth. This article dives into the ongoing discussions among industry leaders about the future of AI in insurance and the potential for transformative gains.

Related articles
Popular in Business Insurance
- Surging War-Risk Insurance Rates in the Strait of Hormuz: What It Means for Shipping
- Ross & Yerger Insurance Faces Class Action Over Data Breach Allegations
- Indiana Court Ruling: Insurers Can Deny Fire Claims Without Proving Harm
- WTW's Strategic AI Investment: A Game Changer for Insurance Brokerage
- How AI is Transforming Excess and Surplus Lines Underwriting






