Your Insurance Policy Is the New AI Regulation
Randy Hall, CEO

The sharpest new AI rule hitting MSPs in 2026 did not come from a legislature. It came from insurance carriers. Since January 1, 2026, the industry's standard-setting body has been stripping generative AI out of the general liability and professional liability policies your business and your clients carry, and that limits what you can safely promise about AI work.
Why Are Insurers Moving Faster Than Lawmakers?
Insurers move on loss data and renewal cycles, not committee votes. Once underwriters saw AI-driven claims start to surface with no clear precedent for pricing them, they had a strong incentive to act before the next renewal season rather than wait years for legislative clarity. That is exactly what happened. Verisk's ISO Core Lines Services filed three new endorsements, CG 40 47, CG 40 48, and CG 35 08, making them available to member carriers nationwide with a January 2026 edition date, and dozens of individual carrier groups have layered their own versions on top.
What Exactly Changed in January 2026?
The core change is a new exclusion built directly into commercial general liability forms for bodily injury, property damage, and personal or advertising injury "arising out of, or attributable to" generative AI. CG 40 47 applies broadly across the policy, CG 40 48 narrows it to advertising and personal injury coverage, and CG 35 08 targets products and completed operations. Coverage tracking by S&P Global's SNL Insurance data, reported by The Insurer, shows 41 property and casualty groups have already filed to adopt some version of an AI exclusion, with another 20 groups filing instead to delay it, more than 60 in total. Several major carriers have gone further and applied similarly broad exclusions to errors and omissions, directors and officers, and employment practices liability lines, the exact coverage most MSPs and their clients depend on.
The Coverage Gap You're Walking Into
This is not an abstract insurance-industry story. If a client's business is harmed by an AI tool your team deployed, configured, or recommended, and generative AI sits anywhere in the causal chain, your general liability policy may no longer respond, and your technology E&O policy may carry its own carve-out on top of that. Several carriers, including AIG, W.R. Berkley, and Great American, have already filed or received clearance for broad AI exclusions spanning D&O, E&O, employment practices, and general liability lines at once.
That layering matters because a single AI-related incident can now hit multiple policies with none of them paying out. The practical effect is a widening gap between what MSPs are now selling and what their existing coverage actually pays for, and that gap does not show up until a claim is already in front of an adjuster.
| Coverage line | Typical AI exposure today |
|---|---|
| General liability | New ISO exclusion in effect since January 2026 |
| Technology E&O | Increasingly excludes hallucination and output-related losses |
| D&O and EPLI | Some carriers filing "absolute" AI exclusions |
| Standalone AI liability | A small but growing market, mostly unproven at scale |
Does This Mean You Should Stop Selling AI Tools?
No, and trying to sit this out is its own risk. Clients are asking for AI-powered services whether or not their MSP offers them, and stepping back just hands that revenue and that relationship to whoever says yes. The right response is not retreat, it is precision: know exactly where your coverage stops, and stop making promises that outrun it.
Two things belong on every MSP owner's desk this quarter. First, an actual read of your current general liability and E&O policies, line by line, to see whether an AI exclusion has already been added at your last renewal without much fanfare. Second, a conversation with your broker about what an affirmative AI endorsement or a standalone policy would cost against the revenue you are already booking from AI-powered offerings.
Rewriting Client Contracts Before Insurers Force the Issue
Your contracts are the other half of this problem, and most of them were written before generative AI was part of the conversation. Vague indemnification language that once felt safe now has to answer a harder question: who owns the liability when an AI recommendation, output, or automated decision causes measurable harm to a client's business. Clean allocation matters here. Define what you control, what the client controls after delivery, and what happens when a vendor's own AI model produces the bad output in the first place, since most AI vendor agreements already cap their liability far below what a serious claim would cost.
This is also where AI disclosure earns its keep. Telling a client, in writing, where and how AI is involved in the service you deliver protects you two ways at once. It gives you a documented basis to argue the exclusion should not apply, and it gives the client informed consent that closes off a whole category of dispute before it starts.
Turning Governance Into a Competitive Edge
Here is the strategic piece most MSPs are missing. Every carrier tightening its AI language and every enterprise client adding AI questions to their vendor questionnaires is creating demand for MSPs who can document how they actually manage AI risk. The NIST AI Risk Management Framework remains voluntary for private companies, but it is already showing up as a reference point in procurement conversations at larger clients and in regulated industries where a client's own compliance obligations pass straight through to you.
An MSP that can hand a client a written AI risk process, tied to how tools get vetted, deployed, and monitored, is answering a question competitors cannot. That process has to live somewhere other than a slide deck. Building it into how you onboard and provision every AI-powered engagement, the way Catalyst is built to handle onboarding overhead for AI tools generally, turns a compliance chore into something you can point to in a sales conversation.
This only works if the tools underneath that process were chosen deliberately in the first place. A patchwork of AI point solutions picked up deal by deal is much harder to document, insure, or defend than a curated set of tools with consistent vetting behind them. That is the case for treating the Actiforge product catalog as a governance decision, not just a shopping list.
What This Looks Like in Practice
Start by mapping every AI-powered tool currently touching a client environment, from the obvious ones to the automation quietly running inside a ticketing or monitoring platform. Then match that map against your actual coverage and your actual contract language, not what you assumed either one said. The gaps you find are not theoretical, they are the specific claims an insurer or a client's lawyer will point to first, and they are far cheaper to close now than after a client's business has already been harmed. Set a recurring review, twice a year at minimum, since both the exclusion language and the vendor landscape are still moving fast enough that a policy read in January can be stale by the next renewal.
If you are still deciding which AI tools belong in your stack at all, working through that decision with a clear view of what you can defend contractually and what you can insure changes the calculus. The stack builder walks through exactly that tradeoff, tool by tool, before you commit a client relationship to something you have not stress-tested.
The Bigger Picture for 2026
Legislatures will keep arguing over AI bills, and those fights matter over a longer horizon. But the rules actually shaping what you can sell, sign, and insure this year are being written by carriers and drafted into contracts right now, months ahead of any statute taking effect. The MSPs who read their own policies, fix their contract language, and can document a real AI risk process will close deals the ones who wait cannot.
That is the whole point of building a deliberate, white-labeled stack instead of bolting on whatever tool a client asks for this week. See the full stack and decide with your eyes open, not after a claim gets denied.
Sources: Verisk / ISO generative AI exclusion endorsements CG 40 47, CG 40 48, CG 35 08 | The Insurer, "More than 60 P&C insurance groups file to adopt AI exclusions" | Claims Journal, "Insurer Interest in AI Exclusions Growing as Risk Becomes Omnipresent" | Fenwick, "The End of Silent AI" | Arthur J. Gallagher & Co., "ISO Introduces Generative AI Exclusion in Commercial General Liability Policies" | ChannelE2E, "MSPs Have a Bigger Role in SMB Cyber Insurance Readiness" | NIST AI Risk Management Framework.