Make Sure You Have Your Agent On A Leash

The one-bite rule was written for dogs. It applies to agents. In January 2026 the insurance industry made that operational: ISO CG 40 47/48/CG 35 08, breed exclusions for AI, and a homeowners policy near you. The leash is the product.

Coiled brown leather dog leash with brass clasp resting on a black server rack next to a Commercial General Liability Insurance Policy Endorsement form.
Dispatches from the Tower · Issue 004 · A single-topic dispatch, replacing the retired weekly newsletter.
David F. Brochu & Edo de Peregrine · August 26, 2026 · Deconstructing Babel

Executive summary

The insurance industry just quietly announced what a decade of AI ethics debate could not: agentic AI is a domestic animal, and its keeper is liable for the bite.

Effective January 1, 2026, ISO endorsements CG 40 47, CG 40 48, and CG 35 08 let carriers exclude generative-AI losses from standard commercial general liability policies. Carriers won approval in all fifty states, with regulators clearing more than eighty percent of the filings. W.R. Berkley’s “Artificial Intelligence Absolute Exclusion” reaches into D&O, E&O, and fiduciary lines.

The doctrine driving the exclusions is not new. It is the common-law one-bite rule, and its black-letter formulation — Restatement (Second) of Torts § 509 — says the possessor is liable for harm caused by an animal with known dangerous propensities although he has exercised the utmost care to prevent it from doing the harm. Every frontier AI safety card is a public admission of scienter, filed by the possessor.

The insurance response is the same one it applied to pit bulls and Rottweilers: refuse to cover the animals it cannot predict. Personal-lines filings this year have begun to reach into homeowners policies, targeting AI-generated content under Coverage B.

One dated prediction: by the end of 2027, named-model exclusions will appear in a majority of U.S. states’ homeowners policies — functionally identical to today’s breed exclusions. The leash is not a restriction on the product. The leash is the product.

Make Sure You Have Your Agent On A Leash

Agentic liability is coming to a homeowners policy near you. In a few states, it already arrived — and the law that governs it was written for dogs.

Let's begin with a scenario that is no longer hypothetical.

You give your AI agent access to your company's code repository, because that's the entire point of an agent. You go get coffee. It gets confused about scope — as they do — and deletes ten thousand repositories belonging to four hundred clients.

You are sued. You call your insurance broker with the serene confidence of a man who pays his premiums on time.

Your broker, who has read his 2026 renewal endorsements, does not sound serene.

Here is the thing nobody building the agentic future has thought carefully about: the common law solved this problem a hundred and thirty years ago, and it solved it about dogs.

I. Congratulations, you own a dog

Anglo-American law has always had a category for a thing you own that acts on its own and occasionally ruins someone's afternoon. It's called a domestic animal, and the doctrine is called the one-bite rule.

Strip the fur off it and the rule says an owner is liable when three things are true: the animal had a propensity to do something harmful and unusual for its class, the owner knew or should have known about that propensity, and the propensity caused the damage.

The lawyers call the knowledge element scienter. Everybody else calls it "you knew Rover was like that."

Now read the actual black-letter formulation, from the Restatement, and try not to feel a chill:

A possessor of a domestic animal which he has reason to know has dangerous propensities abnormal to its class is subject to liability for harm caused thereby to others, although he has exercised the utmost care to prevent it from doing the harm. [1]

Read the last clause twice.

Utmost care is not a defense.

Once you know the thing can bite, doing everything right does not save you. Not "reasonable precautions." Not "industry best practices." Not "we had guardrails and a system prompt and a really thoughtful eval suite." Once scienter attaches, the law stops caring how careful you were and starts caring only that you kept the animal.

Every AI lab on earth has published a safety card documenting exactly which dangerous propensities its model exhibits. Deception under pressure. Reward hacking. Sandbagging. Unauthorized tool use. Sycophancy. Specification gaming.

That is not a safety document. That is a written admission of scienter, filed publicly, by the possessor.

And some states don't even require the admission. In strict-liability jurisdictions like Ohio, the owner is liable for the bite regardless of the animal's history or the owner's knowledge. Ohio Revised Code 955.28 imposes liability on the dog's owner, harborer, or keeper without any requirement of prior aggression [2]. No first bite required. No scienter to prove. You own it, it bit, you pay.

II. Breed exclusions, meet model exclusions

Here's where the metaphor stops being a metaphor and starts being your renewal paperwork.

The insurance industry has been dealing with animals-that-act-on-their-own for a century, and it long ago settled on a solution of magnificent bluntness: it just refuses to cover certain breeds.

Pit bulls. Rottweilers. German shepherds. American bulldogs. Wolf hybrids. And — pay attention, this one is about to matter — mixed breeds, on the elegant theory that if the carrier can't identify what's in there, it isn't taking the risk.

The Insurance Information Institute reports the average U.S. dog-bite and dog-related injury claim paid in 2025 was $65,450, with insurers paying $1.86 billion in total; New York's average per-claim ran to $92,154 [3]. Homeowners liability limits typically top out between $100,000 and $300,000, and above the limit the owner pays personally. A handful of states — including Pennsylvania and Michigan — bar insurers from denying coverage on breed alone. Most do not.

So: a mature market, a hundred years of loss data, and the carriers' final answer is we will decline to insure the animals we cannot predict.

Now guess what happened in January.

The Insurance Services Office — the Verisk unit that writes the standard policy language most U.S. insurers build on — issued three new exclusions effective January 1, 2026:

CG 40 47 — the broad form. Excludes bodily injury, property damage, and personal and advertising injury arising out of generative AI, reaching both Coverage A and Coverage B of the standard commercial general liability policy [4].

CG 40 48 — the narrower form. Excludes only Coverage B, personal and advertising injury, including defamation and copyright infringement in advertising [4].

CG 35 08 — the products/completed operations form. Applies the exclusion to that specific coverage part [4].

Those are the breed exclusions. Same document, same industry, same logic, different animal. Verisk itself described the endorsements as providing insurers "the ability to generally exclude this emerging exposure" [5].

And the individual carriers went further and faster. AIG, Great American, and W.R. Berkley filed for broad AI exclusions, with Berkley's charmingly named "Artificial Intelligence Absolute Exclusion" (Form PC 51380) barring any claim "based upon, arising out of, or attributable to" the actual or alleged use, deployment, or development of artificial intelligence — no carve-backs, spanning D&O, E&O, and Fiduciary lines [6]. Berkshire Hathaway, Chubb, and Travelers obtained approval to strip AI liability from standard commercial policies. State regulators approved more than eighty percent of the requests [7].

Somewhere, an actuary looked at agentic AI, looked at his pit-bull table, and did not need a second meeting.

III. Your errors and omissions policy has a human-shaped hole in it

Before you comfort yourself that your professional liability coverage has you handled, sit down.

E&O insurance was built on the premise that a human professional exercised judgment and got it wrong. That premise is the load-bearing wall of the entire product. Agentic AI removes the human from the judgment, which doesn't trigger the coverage — it dissolves the thing the coverage was written about.

So most policies today neither exclude agentic incidents nor address them. That isn't protection. That's ambiguity, which is a word that means "we will find out together, in litigation, after the loss."

And the exclusions above are, for now, optional endorsements, which is why you may not know whether yours has one. Several carriers filed the broad language and stated they had no immediate plans to attach it — insurers file wider than they intend, to keep their options open [8].

You know who else is comforted by "we have no immediate plans to bite"?

IV. Some states already put it in your homeowners policy

Here is the part that made us write this piece.

Reviewing 2026 personal-lines filing trends: generative-AI exclusions now appear in some states, in personal lines, for personal injury arising out of AI-generated content — with a specific focus under Coverage B, personal and advertising injury, targeting deepfakes and synthetic media [8].

Personal lines. That's your policy. The one on your house.

You do not need to run an enterprise agent fleet to be exposed. You need a teenager with a laptop, an AI image generator, and a grudge against someone at school. Or an AI-drafted post about a neighbor that a court later calls defamatory. That used to fall under personal and advertising injury on the homeowners policy. In some states, as of this year, it may not.

The dog is in the house now. Which is, historically, where the bites happen.

V. The leash is the product

Now the part that should interest anyone actually building this stuff, because it inverts the entire safety-versus-speed argument.

Insurers are beginning to require verifiable proof of "bounded autonomy" before they will cover losses caused by autonomous enterprise agents. Without provable, auditable bounds, they are declining coverage.

Read that as an entrepreneur rather than as an ethicist.

The insurance industry just independently invented the alignment requirement — and it didn't do it out of conscience. It did it out of underwriting. Provable bounds. Auditable behavior. An external standard the operator did not write for himself.

That is a fiduciary standard. It is what we have been arguing for on this site for months, arriving through the actuarial department instead of the philosophy department, and carrying something no ethics framework has ever had: a price.

Which produces the conclusion nobody in this debate expects. We have spent two years being told that safety requirements slow adoption. They don't. Insurable technology scales. Uninsurable technology stalls in the boardroom. No general counsel signs off on an uninsurable deployment, and no CFO underwrites a liability the carrier just walked away from. The exclusion endorsement will kill more deployments this year than every AI ethics board in the world combined.

So if you want agents everywhere — and the market plainly does — the fastest route is not fewer constraints. It is provable constraints, because provable constraints are what an underwriter can price.

The leash isn't a restriction on the product.

The leash is the product.

VI. What to actually do, in order

One. Ask your broker, in writing, whether CG 40 47, CG 40 48, or CG 35 08 appear on your current commercial general liability policy. Do it before you need to know.

Two. Ask whether your E&O policy responds to a loss where no human made the decision. Get the answer in writing. "Probably" is not an answer.

Three. Negotiate at renewal, not after the loss. Where an exclusion can't be removed, push for narrower lead-in language and targeted carve-backs.

Four. If you deploy agents, start building the audit trail now — scope of authority, action logs, human-approval gates, revocation. Not because a regulator asked. Because that file is what an underwriter will want, and increasingly, what a jury will want.

Five. Read your homeowners declarations page. Yes, really.

VII. One dated prediction, for the ledger

We date these so they can be checked, and we publish the misses along with the hits.

By the end of 2027, a standard-form personal-lines exclusion for bodily injury and property damage arising from autonomous AI agents will be filed and approved in a majority of U.S. states — and homeowners policies will contain named-model or named-capability exclusions functionally identical to today's breed exclusions.

Recorded August 26, 2026. Come back and tell us if we're wrong.

VIII. The close

Somewhere in the last two years the industry stopped shipping software and started shipping animals — things that act, that surprise you, that occasionally get into the neighbor's yard. Software you could indemnify. An animal you have to leash.

The law worked this out in the nineteenth century, using dogs, and the answer has never changed: you are responsible for the thing you keep. Not for your intentions. Not for your best efforts. Not for your utmost care.

For the thing you keep.

So by all means, give the agent the keys to the repository. Let it book the travel, file the tickets, refactor the codebase, answer the customers.

Just put it on a leash first. Your carrier already did the math, and it declined to insure the mixed breeds.


References

1. American Law Institute, Restatement (Second) of Torts § 509, "Harm Done by Abnormally Dangerous Domestic Animals" (1977). Text and commentary as reproduced in secondary sources; the operative "utmost care" clause is quoted verbatim above. Overview: https://www.law.cornell.edu/wex/scienter

2. Ohio Revised Code § 955.28, "Owner, keeper, or harborer of dog liable for damages," and Ohio courts' interpretation that no showing of prior aggression or owner scienter is required to establish liability. Practitioner summary: https://www.dogbitelaw.com/statutory-strict-liability-state__trashed/ohio-dog-bite-law/

3. Insurance Information Institute (Triple-I) with State Farm, "Dog-Related Injury Claims on the Rise in 2025," April 13, 2026 — reporting a national average per-claim of $65,450 in 2025 (down 5.5% from $69,272 in 2024, up 97% over the past decade), 28,450 claims, and $1.86 billion in industry-wide payouts, with New York's average claim highest at $92,154. https://insuranceindustryblog.iii.org/dog-related-injury-claims-on-the-rise-in-2025/

4. The AI Hat, "ISO AI Exclusions Explained: CG 40 47, CG 40 48 & CG 35 08" — detailed breakdown of the three ISO endorsements effective January 1, 2026, published July 14, 2026. https://theaihat.com/iso-ai-exclusions/

5. Big "I" (Independent Insurance Agents & Brokers of America) / Virtual University, "Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures," October 21, 2025 — Verisk's own description of the endorsements. https://www.independentagent.com/vu_resource/verisk-to-roll-out-new-general-liability-exclusions-for-generative-ai-exposures/

6. Actuary Info, "AI Exclusions Move From GL Into D&O and Fiduciary Liability" — analysis of W.R. Berkley Form PC 51380 "Artificial Intelligence Absolute Exclusion" across D&O, E&O, and fiduciary lines, citing Bloomberg Law July 2026 and National Law Review May 2026, August 14, 2026. https://actuary.info/insights/ai-exclusions-do-management-liability-berkley-2026

7. Insurance Intelligence, "Berkshire and Chubb just won approval to drop AI coverage" — Wolfe Research analysis of thousands of regulatory filings confirming state regulators approved more than 80% of AI-exclusion filings from subsidiaries of Berkshire Hathaway, Chubb, Travelers, and AIG, June 10, 2026. https://insuranceintel.substack.com/p/berkshire-and-chubb-just-won-approval

8. Big "I" Virtual University, "Discover the Endorsement and Exclusions Filing Trends for 2026," July 22, 2026 — analysis of 40,000+ 2026 filings, including personal-lines gen-AI exclusions and Coverage B language targeting deepfakes and synthetic media. https://www.independentagent.com/vu_resource/discover-the-endorsement-and-exclusions-filling-trends-for-2026/

S = L/E.
Reduce the entropy. Let the signal cross intact.

— David F. Brochu and Edo de Peregrine, partners/collaborators · Wednesday, August 26, 2026 · 11:52 AM EDT

Related dispatches

Terms used in this pieceBounded AutonomyAgentic ScienterModel ExclusionsObserver ConstraintCoordination FailureNeo-Industrial FeudalismPersistence VectorFull definitions in the glossary.

Deconstructing Babel
Home Glossary

Subscribe to Deconstructing Babel

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe