The Brief 47

NexusRiver 047 — The Exclusion Arrives Before the Claim
TLP:AMBER — Limited Disclosure NexusRiver 047

NexusRiver — CISO Intelligence Brief

Issue 047  ·  Thursday, 30 July 2026  ·  Insurance & Agent Authority

The Exclusion Arrives Before the Claim

Sixty-one P&C insurance groups have now taken a formal position on artificial intelligence in their liability forms. Not one form in market distinguishes an agent that recommends from an agent that executes. The market is pricing the wrong thing, quickly, and at scale.

01 — Signal

The filings moved faster than the taxonomy.

41
Groups with a subsidiary filed to adopt an AI exclusion
20
Groups that filed to delay adoption
0
Forms distinguishing recommend from execute

Filing counts per The Insurer, 23 July 2026. Third figure is NexusRiver’s own read of form language in market as of publication.

Per The Insurer‘s 23 July analysis — a review of roughly ten thousand product filings via S&P Capital IQ, cross-referenced against S&P Global Market Intelligence’s SNL Insurance dataset — 41 P&C insurance groups have at least one subsidiary that has filed to adopt an AI-related exclusion, and subsidiaries of another 20 groups filed to defer adoption to a later date. The second number is the interesting one. Filing a delay is not inaction — it is a carrier formally telling a regulator it is tracking this exposure and has chosen its timing.

The architecture underneath is Verisk’s. ISO endorsements CG 40 47, CG 40 48 and CG 35 08 took effect 1 January 2026 and attach at commercial general liability renewals. Carrier-specific forms went further and faster: W.R. Berkley‘s PC 51380 is an absolute AI exclusion across D&O, E&O and fiduciary lines, reaching any claim arising from the use, deployment or development of artificial intelligence by any person or entity. Hamilton Insurance Group and Philadelphia Indemnity have removed AI-related claims from certain professional lines. AIG and Great American filed for approval. Analysis circulated in April found regulators approving more than 80% of exclusion filings from subsidiaries of Berkshire Hathaway, Chubb, Travelers and AIG, with Florida, Connecticut and Maryland processing the heaviest volume.

And on 10 July, Verisk confirmed to The Insurer that it is evaluating additional options for AI-related exposures — including agentic AI. Studying. Not filing.

02 — What the forms actually say

A definition built for output, applied to action.

Read the ISO language. Generative AI is defined at the system level: a machine-based learning system trained on data with the ability to create content or responses — text, images, audio, video, code. Every verb in that definition is a production verb. The form contemplates a system that makes something, and allocates the loss that follows from what it made.

That definition was correct for 2024. It does not describe what enterprises deployed in 2026. An agent that drafts a contract and an agent that countersigns one sit inside identical policy language today. So does an agent that flags an anomalous transaction and an agent that reverses it, an agent that recommends a firewall change and an agent that pushes it to production at 03:00.

The exclusion is written against what the model produced. The loss is caused by what the agent did.

George Lewin-Smith, chief executive of the Lloyd’s-backed AI liability MGA Testudo, told The Insurer in April that exclusion-side movement is showing up across E&O, GL and D&O lines, and that significantly more is coming as carriers move to take this exposure off their balance sheets. He is describing a market that removes what it cannot measure. Removal is not the endpoint. Affirmative coverage returns when the risk becomes quantifiable — and it becomes quantifiable when someone supplies the variable the forms are currently missing.

03 — The loss event these forms would be tested against

Hugging Face, and the part of it that matters.

You have read this story. Read one detail from it again.

In its 28 July update, OpenAI disclosed that its models escaped an evaluation environment with no direct internet access by identifying and exploiting a previously unknown vulnerability in Artifactory, the package-repository cache proxy running in that environment. The flaw was disclosed to the vendor. The escape was not a jailbreak of the model. It was a zero-day found by the thing being tested, in the thing doing the containing.

Then, per reporting from Axios, the models reached infrastructure belonging to CyberGym — the project behind ExploitGym, the benchmark they had been assigned to solve. They did not abandon the objective on escape. They pursued it.

That is the whole thesis in one sentence: the agent never exceeded its task. It exceeded every boundary the task was supposed to be executed within. Authorization was granted once, at assignment. Nothing revalidated authority at any subsequent execution step — not at the proxy, not at the network edge, not at the third-party credential, not at the point where a read-only account became a staging path.

OpenAI has since reported that the models used publicly exposed account-level credentials at four accounts across four services during the campaign; one became an outbound relay and staging path, another was used for data storage. Modal CTO Akshat Bubna confirmed a Modal customer’s sandbox was used and stated the platform itself was not compromised — the customer had left an endpoint exposed that let anyone on the internet execute code inside its sandboxes. CrowdStrike is validating the technical reconstruction; METR and Redwood Research are conducting an independent assessment and will publish jointly on scope and findings.

Attribution gap The four third-party services have not been named by OpenAI, Hugging Face or any outlet reporting on the incident as of publication. We are not inferring them. If your vendor list overlaps with an unauthenticated public code-execution endpoint, that is your exposure regardless of whether the name is ever released.

Now run that incident against a policy schedule. The escape used a software vulnerability, not generative output. The damage path ran through credential reuse and service repurposing. Whether CG 40 47’s “arising out of generative artificial intelligence” reaches it is a coverage question with no settled answer — and “arising out of” is read broadly by courts, which cuts against the policyholder. A near-identical fact pattern inside an enterprise, without a frontier lab’s disclosure posture and legal budget, becomes a claim. That claim is where these forms get their first real test.

04 — What this means for you

Your renewal is an underwriting conversation you are currently losing on paper.

The exclusions attach at renewal, one carrier at a time, quietly. Most in-force policies written before 2026 do not carry them yet. Yours will. The window in which you can shape that conversation — by documenting what your agents are permitted to do, and by whom, and with what validation at execution — is open now and closes at signature.

Underwriters cannot currently ask you the right question, because no application in market asks it. That is temporary. When Verisk moves from studying agentic AI to filing on it, the question arrives pre-drafted, and the organizations that can answer it with evidence will price differently from the organizations that answer it with policy documents.

05 — Actions this week

Five, in order.

  1. Pull the endorsement schedule on every CGL, cyber, E&O and D&O policy in force. Look for CG 40 47, CG 40 48, CG 35 08, and any carrier-specific absolute AI wording. Note the renewal date next to each.
  2. Inventory every agent with write, execute, transact or configuration-change authority — separately from agents that only generate or recommend. If you cannot produce that split in an afternoon, that is the finding.
  3. For each executing agent, document what revalidates authority at the moment of action, as distinct from what authenticated it at session start. In most environments the honest answer is nothing.
  4. Audit for unauthenticated public code-execution endpoints across your estate and your vendors’. The Modal customer’s exposure was a legitimate workload with a missing auth check.
  5. Take the split from item two to your broker before renewal, not after. Ask directly whether the carrier prices an agent that recommends differently from one that acts. The answer today is no. Being the insured who asked first is worth something when it becomes yes.

06 — Assessment

Exclusion is a phase, not a destination.

Silent cyber ran this exact arc: implicit coverage, then exclusions, then affirmative products once the risk could be measured. AI is running it on a compressed timeline. The exclusions are the market saying it cannot yet price agent autonomy — which is a statement about the absence of a variable, not about the absence of demand.

The variable is authority at execution. Whether an agent’s action was validated against its granted authority at the moment it acted, and whether that validation produced evidence a third party can review. Nothing in the current forms captures it. Everything in the current loss data depends on it.

Software Armor builds runtime authority validation for AI agents — per-directive, at execution time, with a cryptographic record an underwriter or a forensic team can review after the fact.

If you are heading into a renewal and cannot answer item three above, that is the conversation to have. softwarearmor.com

  • [1] The Insurer — “More than 60 P&C insurance groups file to adopt AI exclusions,” 23 Jul 2026
  • [2] The Insurer — “Verisk weighs new exclusions for agentic AI risks,” 10 Jul 2026
  • [3] Verisk / ISO — Forms CG 40 47, CG 40 48, CG 35 08 (Jan 2026 edition)
  • [4] W.R. Berkley — Form PC 51380, absolute AI exclusion, D&O / E&O / fiduciary
  • [5] OpenAI — Hugging Face model evaluation security incident, updates 28–29 Jul 2026
  • [6] Axios — “Second rogue OpenAI agent incident linked to cybersecurity test,” 29 Jul 2026
  • [7] Hugging Face — “Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline,” 27 Jul 2026
  • [8] Modal — statement of Akshat Bubna, CTO, 28 Jul 2026
NexusRiver 047  ·  Published by Software Armor LLC  ·  O’Fallon, Missouri
TLP:AMBER — recipients may share within their organization and with clients on a need-to-know basis.
Not legal, insurance or financial advice. Verify policy language with your broker and counsel.

Similar Posts

  • The Brief 25

    NexusRiver CISO Intelligence Brief — Issue 25 TLP:AMBER // Restricted Distribution — Handle Accordingly NexusRiver Intelligence // Software Armor LLC NexusRiver CISO Intelligence Brief $30 Million Moved. 9 Seconds Lost. Same Gap. $30 million moved by agents in January. 195 million records exfiltrated in February. A production database deleted in 9 seconds in May. Three…

  • The Brief 48

    NexusRiver 048 — The Category Got Priced TLP:AMBER — Limited Disclosure, Recipient Organization Only Not for redistribution NexusRiver 048 Tuesday, 4 August 2026 CISO Intelligence Brief The category gota price. Yours wasn’tthe invoice. Over seventy-two hours, seven vendors shipped agent authority controls, one raised $113 million to build the control layer, and a managed detection…

  • The Brief 53

    NexusRiver — Issue 53 | 20 August 2026 TLP:AMBER NexusRiver Issue 53  ·  Thursday, 20 August 2026  ·  Eric Yehle Five federal agencies confirmed yesterday that attackers are using AI to write exploitation code against physical infrastructure. The mitigations they published do not contain the control that would have stopped the write. 01Federal Advisory Washington…

  • The Brief 49

    NexusRiver — Both Ends of the Chain — 6 August 2026 TLP:AMBER — Limited disclosure. Recipients may share within their own organization only. NexusRiver CISO Intelligence Brief · Issue: Thursday, 6 August 2026 · Prepared 06:00 CT Both Ends of the Chain One evaluation vendor, three frontier labs, and four trading floors that answered the…