Is Your General Liability Policy Adequately Covering Digital Risks?

As businesses increasingly rely on digital technologies, the exclusion of cyber-related risks from general liability policies is raising alarms. Here's what you need to know to protect your business.

0
Is Your General Liability Policy Adequately Covering Digital Risks?

In an era where digital technologies underpin nearly every aspect of business, the importance of understanding your general liability (GL) policy cannot be overstated. Traditionally viewed as a safety net for physical consequences stemming from cyber events, many companies are now finding themselves exposed due to a significant shift in insurance coverage. Since 2014, the insurance landscape has evolved, leading to the removal of what was once considered 'silent cyber' coverage. As we delve into these changes, it’s essential for business leaders to grasp how these exclusions can impact their operations and what steps they can take to secure their interests.

The Evolution of Cyber Coverage in General Liability Policies

Historically, GL policies provided a limited scope of coverage for physical harm resulting from cyber incidents. Insurers would often 'carve back' coverage to include certain situations where a data breach or cyber failure led to actual bodily injury or property damage. This meant that if a cyber attack on a manufacturing system resulted in physical injury to a worker, the GL policy might still respond, offering a form of protection that many businesses relied upon.

However, the tides have turned dramatically in recent years. The introduction of exclusionary provisions has fundamentally altered the landscape. Insurers are now largely adopting standardized exclusions from the Insurance Services Office (ISO), stripping away the remaining safety net for businesses. The most notable of these is the CG 40 35 12 23 exclusion, which explicitly excludes coverage for any claims related to cyber incidents. This includes unauthorized access, malware attacks, and denial-of-service incidents, effectively leaving businesses vulnerable to losses they once thought were covered.

digital risk exposure

Understanding the Current Landscape: The 2023 Exclusions

As of 2023, the insurance industry has seen a definitive shift toward explicit exclusions for cyber incidents. The implications of this are profound. The CG 40 35 exclusion does not merely limit coverage for data breach expenses; it actively removes any potential for coverage related to bodily injury, property damage, or personal injury claims that arise from cyber events.

This exclusion is particularly concerning for industries where technology is integral to operations, such as manufacturing, healthcare, and utilities. A failure in an industrial control system due to a cyber attack, for instance, could lead to catastrophic injuries or property damage. Under the new exclusions, businesses would have no recourse through their GL policy if such an event were to occur.

Anticipating Future Risks: Generative AI and New Exclusions

The digital risk landscape does not stop with cyber incidents. As businesses adopt generative AI technologies, insurers are quickly adapting to address new liabilities associated with these innovations. The ISO has introduced several new endorsements in 2026 that specifically target the exclusions around generative AI. These include:

  • CG 40 47 01 26 (The Broad Exclusion): This endorsement precludes coverage for claims arising from any aspect of AI, including generative AI and large language models.
  • CG 40 48 01 26 (The Coverage B Exclusion): This narrower exclusion focuses on Coverage B, removing protection for claims such as defamation or copyright infringement arising from AI-generated content.
  • CG 35 08 01 26 (The Products-Completed Operations Exclusion): This exclusion targets bodily injury and property damage arising out of generative AI in relation to finished products.

This shift indicates that underwriters are prioritizing sectors with high exposure profiles, including technology firms, media outlets, and software developers. However, as these exclusions become commonplace, businesses across all sectors must prepare for the implications.

insurance policy review

Identifying Coverage Gaps: Take Action Now

With the removal of silent cyber coverage and the introduction of broad exclusions for generative AI, businesses are left with significant coverage gaps. Here are critical steps that business leaders must take:

1. Review Your Operations Thoroughly

Conduct a comprehensive assessment of your operations to identify scenarios where cyber incidents or AI errors could lead to physical harm, property damage, or financial loss. For example, consider how a hacked system might impact your production lines or customer safety.

2. Analyze Your Insurance Policies

Your insurance portfolio should be reviewed in light of these new exclusions. Examine your GL, Property, Technology Errors & Omissions, and standalone Cyber policies to determine how each one is affected by recent changes.

3. Engage Your Insurance Broker

This is not a time for complacency. Consult with your insurance broker to discuss your unique exposures and explore tailored underwriting solutions. Your broker can guide you in securing coverage that adequately addresses the evolving risk landscape.

Bridging the Gap: The Rise of Standalone AI Liability Markets

Recognizing the growing gap in coverage, the insurance industry is beginning to innovate. Standalone AI liability products are emerging, designed specifically to cover the unique risks associated with AI technologies. These new products aim to address:

  • Financial loss and negligent misrepresentation stemming from AI errors
  • Defamation and reputational harm
  • Intellectual property infringement
  • Unauthorized data disclosure
  • Bodily injury or property damage related to AI outputs

As businesses navigate this shifting terrain, it is crucial to stay informed about these emerging products and consider them in your risk management strategy.

business risk management

Key Takeaways

  • The removal of silent cyber coverage from GL policies leaves businesses exposed to digital risks.
  • New exclusions targeting generative AI are being rapidly adopted across the insurance industry.
  • Proactive assessments of operations and insurance policies are essential to identify gaps in coverage.
  • Engaging with insurance brokers can help secure tailored solutions for emerging risks.
  • Standalone AI liability markets are developing to address the unique exposures associated with AI technologies.

Frequently Asked Questions

What is 'silent cyber' coverage?

Silent cyber coverage refers to the implicit coverage that businesses believed existed within their general liability policies for losses related to cyber incidents. Insurers previously ‘carved back’ this coverage to include certain physical damages resulting from cyber events. However, this coverage is now being actively excluded in most GL policies, leaving businesses with potential gaps in protection.

How can I identify if my business is exposed to these new risks?

Identifying exposure to new digital risks involves a comprehensive review of your operations. Consider how technology and AI are integrated into your business processes and how failures could lead to bodily injury or property damage. Conducting risk assessments and scenario planning can help illuminate potential vulnerabilities.

What steps should I take if I discover coverage gaps?

If you identify coverage gaps, the first step is to consult with your insurance broker. Discuss your specific needs and explore tailored solutions that may involve standalone policies or endorsements that cover emerging digital risks, including those related to AI technologies.

Are standalone AI liability policies widely available?

While standalone AI liability policies are still emerging, their availability is growing as insurers recognize the need for coverage tailored to the unique risks posed by AI technologies. Businesses should keep an eye on the market for new products and consider these options when reviewing their risk management strategies.

Comments

Read next

Harnessing AI in Insurance: From Document Processing to Revenue Growth

The insurance industry is evolving its approach to AI, transitioning from basic document extraction to focusing on productivity and revenue growth. This article dives into the ongoing discussions among industry leaders about the future of AI in insurance and the potential for transformative gains.

Harnessing AI in Insurance: From Document Processing to Revenue Growth

Related articles