Insurance Structure for an Autonomous System Pilot With an Enterprise Customer
Enterprise pilots need custom insurance built before deployment starts, not after incidents happen.

An autonomous system pilot with an enterprise customer creates a distinct insurance problem because it combines three things a standard deployment does not: liability mechanics nobody has fully worked out, contract terms the vendor did not write, and coverage built for neither. A warehouse robot running on a company's own floor, under its own operating rules, is a contained risk. A pilot at a customer's site is something else entirely: the hardware runs on someone else's property, under someone else's contract, and often alongside someone else's staff.
Physical AI systems, robots, autonomous vehicles, and comparable hardware, use sensors, software, and AI models to decide how to act as conditions change on the ground. That decision-making is what breaks the liability framework traditional policies were built around, because fault rarely sits with a single party when something goes wrong. A robot maker may have built the hardware. A separate firm may have supplied the AI model running on it. The operator at the customer site may have failed to enforce the procedures the vendor specified. When the incident happens, all three parties end up arguing over which failure actually caused the loss, and that argument plays out at the pilot customer's facility, under the pilot customer's contract terms, not in some neutral venue.
The insurance market has already responded to this ambiguity, and it has responded by pulling back. Carriers including Berkshire Hathaway, Chubb, and Travelers sought state regulatory approval to exclude AI-related damages from general liability policies, and regulators approved more than four-fifths of those requests. Some carriers went further and put absolute exclusions across multiple lines at once. Autonomy is being sold and deployed faster than insurance products are being rewritten to cover it, and an enterprise pilot is the exact point where that lag turns into a live financial risk sitting on the vendor's books. None of it can be fixed after the fact. The coverage structure has to be decided before the pilot starts, because once an incident happens, the question of what responds becomes a dispute rather than a plan, with no room left for negotiation.
How Standard Policies Fail at Each Layer of an Autonomous System Pilot
The failure is not confined to one line of coverage. Nearly every policy a standard broker would place for a technology company runs through it, and each line fails for its own reason once autonomous hardware is running at a customer site.
General liability and product liability are the first casualties. A standard business policy may not respond to a robot incident at all if it carries an AI exclusion, or if the loss simply doesn't fit the policy's definition of an accident. Even where a standard GL policy does respond, it typically pays for physical damage alone, leaving the production losses that follow a robot failure, the shutdown of a customer's line, outside what the policy pays for. Verisk's ISO Form CG 40 47 01 26 takes effect in January 2026 and lets carriers exclude generative AI claims from commercial general liability policies outright, and policies renewing in the first and second quarters of 2026 are the first group likely to carry that exclusion. A defect in a third-party sensor or component adds another trap: the claim often lands on the company that integrated the part, not the company that made it.
Technology E&O fails differently. It is built to cover financial loss from professional errors, not bodily injury or property damage. Once an AI model is controlling physical equipment and someone gets hurt or something gets damaged, product liability or casualty coverage is what needs to respond, not Tech E&O. A software error in a robot control platform can cascade into equipment damage, defective output, or a shutdown across an entire facility. Tech E&O might pay for the financial wrongful-act piece of that loss. It leaves the physical-damage tail completely uncovered.
Cyber coverage runs into its own wall. A smart factory or autonomous deployment ties together IoT sensors, AI platforms, robotics controllers, and cloud systems, so a single vulnerability can spread across the whole operation. A cyberattack or an act of data poisoning can corrupt an AI model, disable the robots it controls, halt production, and trigger business interruption claims and third-party liability claims at the same time. Standard cyber policies hold a line at the digital boundary: a pure AI performance failure, one with no security incident and no media component behind it, often sits outside what the cyber policy covers.
Commercial property fails for a simpler reason: the hardware has left the building. When autonomous equipment deploys at a pilot customer's site, it sits exactly where a standard commercial property policy stops paying. Off-premises sub-limits on most commercial property policies run far below the value of a deployed robot fleet, so the moment equipment ships to the customer, the vendor is underinsured on day one. IMA Financial Group's analysis of liability exposure in advanced manufacturing makes the same point from the insurer's side: standard frameworks were never built for the fragmented fault and new liability forms that AI-driven robotics produces. The pattern across every line is the same. Each policy was written around an assumption the autonomous pilot violates, and no single rider fixes that. The fix has to be a stack built for the purpose. That is where the contract pressure comes in next.
What the enterprise customer's contract actually requires, and where that diverges from what the vendor assumed
While the insurer-side gaps are opening up, the pressure from the other direction is building at the same time. The enterprise customer's contract spells out the coverage it expects the vendor to carry, and that list is usually written for a mature vendor with a full commercial insurance program already in place, not a robotics company running its first enterprise pilot.
The moment this becomes real is when the insurance exhibit arrives attached to the pilot agreement. A typical exhibit asks for Commercial General Liability, Technology E&O or Cyber, and Workers' Compensation, and frequently adds Auto Liability, Umbrella or Excess coverage, and Crime or Fidelity coverage on top. Workers' Compensation is sometimes conditioned on whether the vendor has employees. Enterprise customers in healthcare, finance, or government routinely push for higher Tech E&O limits and sometimes require D&O coverage as a further condition, though D&O tends to get demanded more often by investors and financing counterparties than by the pilot customer itself. Government contracts raise the bar again: FAR-driven terms typically add higher per-occurrence limits, require that the government entity be named as an additional insured, and require a waiver of subrogation, terms laid out in the GSAM clause governing insurance and in FAR 28.306, which lets contracting officers demand coverage and limits above the regulatory floor.
The indemnification clause is where this turns from a paperwork exercise into personal exposure. Enterprise contracts routinely ask vendors to accept broad indemnities and performance guarantees, sometimes with no cap. When the contract carries no liability cap and the policy limit runs out first, the vendor is on the hook personally for whatever sits above that limit. Most standard AI vendor agreements cap total liability, indemnification included, at 12 months of fees paid, but negotiation often carves indemnification out of that cap. Set against damages that could run into the hundreds of millions, a 12-month-fees ceiling is not a serious number. The fix is to cap liability at a multiple of contract value, or tie it directly to the insurance limits actually in place, before the contract gets signed, not after.
A certificate of insurance sitting in the deal folder proves nothing by itself. Both sides need to confirm the coverage actually applies to AI-related claims and carries no exclusions for hallucinations, IP infringement, or bias, because a carrier may have added such exclusions quietly at the vendor's last renewal and no one on the vendor's side noticed. A vendor can be fully compliant with the letter of the exhibit and still be exposed, because the policy technically exists but doesn't respond to the claim that actually happens.
The coverage stack that actually responds to an autonomous system pilot
Closing this gap takes a coordinated stack built for the purpose, not a handful of riders bolted onto a generic tech policy. Each line covers a different kind of failure, and the lines need to be checked against each other for overlaps and exclusions before the pilot ever launches.
Commercial General Liability with explicit autonomous-operations language is the foundation. It covers bodily injury and property damage at the customer site, but only if it comes from a carrier whose form doesn't exclude AI-related claims. With the Verisk ISO Form CG 40 47 01 26 exclusion now in play, picking the right carrier matters as much as picking the right limit.
Technology E&O, or professional liability, covers the financial loss that follows a wrongful act or a performance failure in the software and AI model layer, the exact gap that GL and cyber leave open for technology-mediated failures. The policy has to be written around the specific AI system being deployed. A generic Tech E&O form that excludes AI outputs or autonomous decision errors doesn't do the job it's bought to do.
Cyber coverage, with a cyber-physical extension where a carrier offers one, addresses the fact that a cyberattack corrupting an AI model or disabling a robot is a cyber event and a physical loss at the same time. Standard cyber policies stop at the digital boundary, so the extension is what carries the coverage across it.
When autonomous hardware leaves the insured's own premises and the commercial property policy stops responding, an inland marine policy, or a scheduled equipment floater, covers that gap. Inland marine coverage is built for business equipment in transit or temporarily located away from the main business address, which is exactly the situation a deployed robot fleet sits in at a customer's facility. Each unit needs to be scheduled at full replacement value, because the standard property policy's off-premises sub-limit runs far below what most pilot deployments are worth.
D&O coverage protects company leadership when someone sues them personally over management decisions. For an AI company, public statements about what a system can actually do are statements made to investors, and overstated capability claims are an active target for lawsuits and regulatory scrutiny right now.
The specialist market has started building products that stitch these pieces together rather than leaving the vendor to assemble them line by line. Chaucer's Vanguard AI product, for one, combines cyber and tech E&O coverage with standalone AI liability coverage and a separate AI aggregate, under predefined allocation rules that govern mixed scenarios spanning cyber events, technology failures, and AI system behavior. That structure addresses the coverage friction in mixed-cause events, where a breach, a service failure, and AI behavior all contribute to the same loss. No single product in this stack covers the whole chain of liability by itself. Assembling the stack correctly is what closes the gap, not finding one policy that claims to do it all.
Why the underwriting submission determines whether the coverage actually responds
Buying the right lines is not the same as getting them to actually pay out. A policy that names every right coverage but was placed on a thin, generic submission will likely carry exclusions or sub-limits that strip the coverage away at the exact moment a pilot incident happens.
Underwriters evaluating autonomous AI systems now dig into specific technical detail before they will quote a risk. They want to know what AI systems the organization runs and which underlying models power them. They want to know whether those models have been customized, fine-tuned, or retrained on proprietary data. They ask what data gets processed and where it comes from, what kind of outputs the system produces, whether those outputs go out externally without a human reviewing them first, and what safeguards and monitoring controls sit on top of all of it. A submission that leaves these questions unanswered doesn't read as neutral to an underwriter. It reads as higher risk, and gets priced or excluded accordingly.
Policyholders need to show continuous telemetry tracking and automated intervention mechanisms as part of that submission. If an autonomous agent causes physical damage in a cyber-physical system, proving what happened rests heavily on audit logs, so underwriters want proof of deterministic safeguards before they will stand behind the risk.
Accumulation risk compounds the problem. Gallagher Re has found that as robots and autonomous vehicles increasingly run on AI, product liability coverage may only respond to injury and property damage in jurisdictions that treat AI software as a product, and that a flaw in one widely used AI model can spread rapidly to every business running it, across every industry and country at once. Underwriters pricing that kind of accumulation risk will look closely at which models the system in front of them runs on. A submission built specifically for autonomous hardware operating in the field, one that documents the operational controls, the AI model stack, the telemetry architecture, and the safety intervention mechanisms, produces materially better terms than a generic tech-company submission dropped into the same carrier's intake queue. The coverage stack only works if the submission behind it gives the underwriter a reason to let it work.
Sequencing the Coverage
The sequence in which these decisions get made matters as much as the decisions themselves. If a founder waits until the enterprise customer sends over the signed pilot agreement, insurance exhibit attached, the room to shape the contract's liability caps and insurance requirements has already closed. The exhibit should be requested and reviewed during the term sheet or early contract conversation, not after signature, so that the liability cap, the indemnification carve-outs, and the required limits can still be negotiated against what the vendor's actual program covers.
Coverage placement has its own sequencing risk. A policy bound after the pilot hardware has already shipped to the customer site leaves a window, however short, where the equipment sits uninsured at full replacement value under an inland marine floater that doesn't yet exist. Carriers that have added AI exclusions at renewal, the kind enabled by the Verisk ISO Form CG 40 47 01 26, make the renewal date itself a risk event: a policy that covered autonomous operations last year may not cover them after the next renewal unless someone checks the form language line by line.
Parametric-style products built around measurable performance data offer one way to shorten the time between an AI failure and a claim payment, since they settle based on defined performance thresholds. That speed matters most precisely when a pilot is running, when a vendor's cash position and customer relationship are both most exposed to a drawn-out claims process. The sequencing principle holds across every piece of this: insurance exhibits need review before signature, coverage needs to be bound before equipment ships, and submissions need to be built for the specific autonomous system in the field before the first renewal cycle hits. Assembled in that order, the stack holds. Assembled after the fact, the stack becomes a negotiation with a claims adjuster.