The 2027 policy year will arrive with a commercial insurance landscape materially different from the one that existed when most mid-market businesses last had a complete program review. Two developments are driving that change. First: the Insurance Services Office introduced new AI-related exclusions at the start of 2026, and a significant number of major underwriters have followed with their own AI exclusion provisions embedded in commercial policies that renewed throughout the year. Second: cyber underwriting standards, which softened slightly in 2025 as competition among cyber carriers increased, are tightening again for the 2027 policy year as ransomware severity trends resumed their upward trajectory in mid-2026.
The businesses that are best positioned for 2027 are the ones that address these developments in Q4 2026 — before renewal, before a claim, and before the AI exclusion language in a renewed policy becomes the reason a claim is declined. What follows is a planning framework for what to evaluate before December 31.
Step One: Find the AI Exclusions in Your Current Policies
The ISO AI exclusion, introduced at the start of 2026, excludes bodily injury, property damage, and personal and advertising injury arising from AI systems — broadly defined to include machine learning, algorithmic decision-making, and automated systems that generate outputs influencing decisions. Several major underwriters have introduced their own AI-related exclusions with different scope, different definitions of what constitutes an AI system, and different carve-backs for certain uses.
The practical implication is that a business that uses AI in any customer-facing, employment, or operational decision process may have GL policy language that excludes claims arising from those uses. The exclusion does not require that the AI system caused harm through a sophisticated failure mode. A recommendation engine that influences a purchase decision, a screening tool that filters applicants, a chatbot that provides information that proves incorrect — each of these is a potential AI exclusion trigger under some policy forms.
The first action item for Q4 is requesting a copy of the AI exclusion language in every commercial policy that renewed in 2026 and having your broker provide a written explanation of what each exclusion covers and what coverage, if any, responds to AI-related claims that the GL policy now excludes. This is not a hypothetical exercise. ISO exclusions are being applied in claims today.
Step Two: Evaluate the Gaps the AI Exclusions Create
Three coverage products may respond to AI-related liability exposure that GL excludes.
Technology errors and omissions (Tech E&O) covers claims arising from professional services rendered through or with technology, including AI-enabled tools. For businesses that provide AI-enabled services or advice to clients, Tech E&O may cover the professional services component of an AI-related claim that GL’s professional services exclusion and AI exclusion together would otherwise leave uninsured.
Cyber liability coverage, depending on policy language, may respond to certain AI-related claims — particularly those involving data privacy, unauthorized processing of personal information, or AI-enabled social engineering fraud. The intersection of AI and cyber claims is where policy language matters most and where gaps are most likely to exist between what a business owner assumes is covered and what the policy actually provides.
D&O insurance, as noted in the September issue, responds to claims arising from governance and management decisions — including the decision to adopt and deploy AI tools without adequate oversight. As the EEOC, FTC, and state regulators intensify scrutiny of AI governance, and as class-action plaintiffs develop viable theories for algorithmic harm claims, D&O becomes an increasingly relevant coverage for any business that has approved AI tool deployment at the management level.

Step Three: Reassess Cyber Coverage Against 2027 Underwriting Requirements
Cyber underwriting requirements are tightening for the 2027 policy year. Ransomware severity — the total cost of a ransomware incident including downtime, remediation, ransom payments, and regulatory response — resumed its upward trajectory in mid-2026 after a brief period of relative stability. Carriers are responding by strengthening underwriting requirements, particularly around three areas.
Backup architecture validation is the first. Carriers are no longer accepting a yes/no answer on whether backups exist. For 2027 renewals, underwriters are requiring documentation that backups are tested, that they are stored in locations not reachable from the primary network, and that recovery time objectives have been validated through actual restore testing. A business that maintains backups but has not tested restoration in twelve months will face harder underwriting questions than one that can show a tested recovery procedure.
Multi-factor authentication scope is the second. The requirement for MFA has been in place for several years. The 2027 underwriting expectation is moving beyond MFA on email to MFA on all privileged accounts, all remote access pathways, all cloud service administrative consoles, and all financial transaction systems. Partial MFA implementation — covering email but not RDP, covering employee accounts but not service accounts — is now specifically flagged in underwriting questionnaires.
AI-powered threat detection is the third. Carriers are beginning to differentiate between businesses that use legacy antivirus and businesses that have deployed endpoint detection and response (EDR) systems with AI-powered behavioral analysis. EDR is already a standard underwriting requirement at most carriers. For 2027, the question is likely to expand to whether the EDR system has been configured to detect AI-assisted attack patterns — deepfake-enabled social engineering, AI-generated phishing, and automated credential stuffing — that signature-based detection cannot identify.
Step Four: Review the Deepfake Fraud Exposure Specifically
A convincing voice or video call can now be part of a business email compromise (BEC) attempt. A fraudster may impersonate an executive or trusted counterparty to pressure an employee into sending a wire transfer or changing payment instructions. The FBI has warned that criminals use generative AI to make financial fraud more believable. Its 2025 Internet Crime Report puts reported BEC losses at roughly $3 billion. That figure covers BEC generally; it does not measure deepfake-related BEC losses separately. ic3.gov
A cyber policy with social engineering coverage may respond to a fraudulent transfer, but the label alone does not establish coverage. Businesses should confirm how the policy defines a covered event, whether BEC has a separate sublimit and what verification procedures the policy requires. The answers may be especially consequential when an employee authorized the transfer after receiving a convincing fraudulent request.
Before year end, take two practical steps. First, ask your broker to review the policy’s specific treatment of BEC, social engineering and AI-assisted impersonation. Second, require independent verification of wire requests and account changes. A callback to a number already on file is more reliable than calling a number supplied in the request. The FBI’s guidance on AI-enabled financial fraud likewise advises people to independently verify a caller’s identity. ic3.gov
Tooher-Ferraris works with businesses to assess cyber coverage as part of their broader commercial insurance program and evaluate options through its specialty programs. A policy review can clarify the applicable limits and conditions before a fraudulent payment request tests them.

Frequently Asked Questions
What does the ISO AI exclusion exclude from my general liability policy?
The ISO AI exclusion, introduced in 2026, excludes coverage for bodily injury, property damage, and personal and advertising injury arising from AI systems, which the exclusion defines broadly to include machine learning, algorithmic decision-making, and automated systems that generate outputs influencing decisions. The specific scope varies by carrier and by the edition of the exclusion in each policy. Reviewing your specific policy language with your broker is the only reliable way to understand what the exclusion in your policy covers.
What coverage responds to AI-related claims that my GL policy now excludes?
Depending on the nature of the AI-related claim, Technology E&O, cyber liability, and D&O insurance may each provide partial or full coverage for claims the GL AI exclusion bars. The coverage that responds depends on whether the claim arises from professional services rendered with AI tools (Tech E&O), from a data privacy or social engineering event enabled by AI (cyber), or from a governance decision to adopt and deploy AI without adequate oversight (D&O).
How are cyber underwriting requirements changing for 2027?
Cyber underwriters are tightening requirements in three specific areas for the 2027 policy year: backup architecture validation (requiring documented restore testing, not just backup existence), MFA scope (expanding from email to all privileged accounts, remote access, and cloud consoles), and AI-powered threat detection (evaluating whether EDR systems are configured to detect AI-assisted attack patterns). Businesses that address these requirements proactively before renewal are better positioned for favorable terms.
Ready to review your cyber and AI coverage before the 2027 policy year begins? The team at Tooher-Ferraris has been helping businesses navigate commercial insurance since 1932.
Contact us today to schedule a no-obligation consultation.






