Your GL Policy May Not Cover AI-Generated Code

A DTC brand's checkout went down on a Saturday afternoon this summer. The root cause traced back to a caching change an AI coding assistant had written three sprints earlier β the kind of change that ships routinely when nobody has time to review it line by line. Six hours of downtime, a six-figure revenue hit, and an ops team that did the responsible thing: they filed a claim against the general liability policy they'd carried for years.
The claim was denied. Not because the loss wasn't real. Because since January 2026, a policy endorsement most brands never knew they were carrying was written specifically to deny it.
The Endorsement Quietly Changing Who Pays
The Insurance Services Office (ISO) β the body that drafts the standard policy language most U.S. commercial general liability (CGL) insurers build on β introduced endorsement CG 40 47 01 26, the "Generative Artificial Intelligence Exclusion," at the start of 2026. It removes coverage for bodily injury, property damage, and personal or advertising injury "arising out of, or attributable to, generative AI," across both Coverage A and Coverage B of a standard CGL policy. Companion forms CG 40 48 and CG 35 08 extend similar language into products and completed-operations coverage β the part of a policy that would normally respond to a defect in something you shipped.
ISO doesn't sell insurance directly, but when it publishes a standard exclusion, individual carriers adopt it fast. Berkley Insurance has gone further with an "Absolute" AI exclusion across its specialty liability lines, and several tech E&O and D&O/EPLI carriers are now declining coverage for AI-generated outputs and AI-related errors outright. None of this made headlines the way a rate hike would. It showed up as a paragraph added to a renewal packet.
Does insurance cover losses caused by AI-generated code?
Increasingly, no. ISO's CG 40 47 endorsement, appearing on U.S. commercial general liability policies since January 2026, lets insurers exclude coverage for losses "arising out of, or attributable to, generative AI" β even when AI is only a contributing cause. Berkley and other carriers have added broader exclusions to tech E&O and specialty lines.
"Attributable To" Is Doing a Lot of Work
The exclusion language is where this gets expensive to misread. It doesn't require generative AI to be the sole or even primary cause of a loss β "attributable to" is broad enough that a claims adjuster can point to any AI-generated component in the chain, whether you wrote it yourself, a contractor wrote it, or an agency's offshore team leaned on an AI assistant to hit a deadline. You don't have to have built with AI on purpose for the exclusion to apply. You just have to be unable to prove you didn't.
That's a different risk profile than "AI code has more bugs," which is a quality argument brands have been having for two years. This is a coverage argument: the safety net a business budgets for β the one that's supposed to absorb the cost of a bad outage or a security incident β may already have a hole cut in exactly the place a modern commerce stack is most exposed.
Most Commerce Stacks Can't Currently Answer the Question
Ask most engineering teams, in-house or agency, what share of their codebase went through a human reviewer before shipping, and you'll get a shrug, not a number. That's not a criticism of any one team β until this year, nobody needed the number. Now it's the first question a broker, an underwriter, or a claims adjuster is going to ask after an incident, and "we don't track that" is the answer that gets a claim denied rather than paid.
For a storefront running checkout, payments, and customer data, that gap matters more than it would for an internal tool. It's also exactly the gap that shows up first in stores built quickly with AI-assisted or no-code tooling and never re-reviewed once they started taking real traffic β the same unreviewed-code pattern MnT Future documented end to end in its own AI Cleanup Lab case study.
What Insurable Actually Requires Now
This is the part of the conversation that's changed fastest with the funded D2C and marketplace brands MnT Future works with. Insurability is turning into a due-diligence question about how a platform was built, not just how it performs β which is exactly why our custom, headless storefront engineering is scoped with a documented senior-review trail from day one, not bolted on after a claim gets contested. A senior-reviewed codebase with a documented review trail isn't just more stable β it's also the difference between a claim that gets paid and one that gets contested on page four of a renewal packet nobody read closely enough.
Practically, that means three things any brand running or commissioning a commerce platform should be able to produce today: a record of what percentage of the codebase received senior human review before deployment, documentation of who reviewed what and when, and a straight answer from any agency or contractor about how much of the build is unreviewed AI output. None of this is exotic. It's the same discipline good engineering teams already practiced before AI made it optional to skip.
The Practical Next Step
Two things are worth doing this quarter, regardless of who built your platform. First, ask your broker directly whether your current GL or tech E&O policy carries a generative-AI exclusion endorsement β most brands find out only at claim time. Second, get an honest read on how much of your storefront's codebase would survive that question with a real answer.
That second one is what MnT Future's free agent-readiness audit is built to surface β not just whether your store is ready for AI shopping agents, but whether the engineering behind it can stand up to the scrutiny insurers are now applying. If the honest answer is uncomfortable, that's useful information before a claim, not after one.
