Research archive

Useful research, without pretending it is the current offer.

Gridex previously published extensively on AI regulation, insurance, exclusions, governance, compliance, and earlier operating directions. Valuable URLs keep their history and remain available here. They no longer define Gridex's homepage, services, or primary internal-link path. The current growth line is Managed Voice Operations.

11states tracked
4carrier forms
48published answers
16research articles
Archive map

Browse by the subject the page actually supports.

Research links to a current service only when it genuinely helps that buyer decide. Old authority is not redirected into Voice merely to transfer traffic.

Browse by state

View all state regulations

Browse by industry

View all industries
4 use cases Education & EdTech Schools, universities, EdTech platforms, and learning management providers that deploy AI for admissions screening, student assessment, academic proctoring, and personalized learning. These firms face regulatory scrutiny because AI in education affects access to educational opportunities — education is explicitly listed as a consequential decision domain in multiple state AI laws alongside employment, healthcare, and housing. E&O, Cyber, D&O, CGL 4 use cases Financial Services & Fintech Banks, credit unions, investment firms, fintech companies, and financial advisors that deploy AI for credit decisioning, underwriting, portfolio management, fraud detection, and customer engagement. These firms face overlapping state AI obligations and federal financial regulations (ECOA, FCRA, Dodd-Frank), creating a layered compliance environment where state AI laws add requirements on top of — not in place of — existing federal frameworks. D&O, E&O, Cyber, Fiduciary 4 use cases Healthcare Providers & Health Tech Hospitals, physician practices, telemedicine platforms, and health technology companies that deploy AI for clinical decision support, patient triage, diagnostic assistance, and patient communication. These firms operate under heightened regulatory scrutiny because AI errors can directly affect patient safety and health outcomes, and because healthcare is explicitly listed as a high-risk decision domain in multiple state AI laws. Medical Malpractice, E&O, Cyber, D&O 4 use cases HR & Recruiting Firms Staffing agencies, recruiting firms, and HR technology providers that use AI for candidate sourcing, resume screening, interview analysis, and employment decision support. These firms face heightened regulatory scrutiny because AI in hiring directly affects individuals' economic opportunities. EPL, E&O, Cyber, D&O 4 use cases Insurance Brokers Insurance brokers and agents increasingly use AI for underwriting support, client risk assessment, claims triage, and policy recommendation — work that sits squarely inside their professional duty of care. The exposure runs two ways. First, the brokerage's own AI use creates errors-and-omissions (E&O) risk: an AI-suggested coverage gap, a misclassified risk, or a chatbot that misstates policy terms can become a negligence claim. Second, brokers must understand the AI exclusion endorsements now appearing in the policies they place — Verisk's CG 40 47 and Berkley's PC 51380 both apply broadly to AI-related claims, including unsanctioned "shadow AI" use that the insured may not even know about. The NAIC Model Bulletin on the Use of Artificial Intelligence Systems by Insurers (adopted December 2023 and issued by many states since) sets the expectation of a documented AI governance program, while state unfair-trade-practices and rating laws constrain how AI may influence pricing, eligibility, and claims decisions. E&O, CGL, Cyber, D&O 4 use cases Law Firms Law firms use AI for legal research, document review, contract analysis, drafting, and client intake — uses that intersect directly with the rules of professional conduct. ABA Formal Opinion 512 (July 2024) confirms that the duty of competence (Model Rule 1.1, Comment 8) requires lawyers to understand the benefits and risks of the generative AI tools they use, while the duty of confidentiality (Model Rule 1.6) constrains submitting client information to AI systems that may retain it or train on it. The risk is not theoretical: in Mata v. Avianca, a federal court sanctioned lawyers who filed AI-hallucinated case citations, and a growing list of courts now require disclosure or certification of AI use in filings. Beyond the ethics rules, AI errors in research or drafting create direct malpractice exposure — and most lawyers' professional liability policies do not yet contemplate AI-specific risk. E&O, Cyber, D&O 4 use cases Marketing Agencies Marketing and creative agencies use AI across content creation, image and video generation, client-facing chatbots, and audience targeting — often embedding AI output directly into client deliverables. That creates layered exposure. The FTC has made clear under Section 5 of the FTC Act that deceptive AI claims and undisclosed AI-generated endorsements are enforceable "unfair or deceptive practices," and its 2024 "Operation AI Comply" sweep signals active scrutiny of AI-washing. Generative output carries IP risk: under Thaler v. Perlmutter, a purely AI-generated work is not copyrightable, so a deliverable the agency believes it "owns" may carry no protectable rights for the client, and image models can reproduce protected material from training data. Client-facing chatbots add contractual risk — in Moffatt v. Air Canada, a tribunal held the company liable for its chatbot's misstatements. Most agency E&O and CGL policies were never priced for these exposures, and AI exclusion endorsements are now narrowing what they cover. E&O, CGL, Cyber 4 use cases Real Estate & Property Management Real estate brokerages, property management firms, proptech platforms, and real estate investment companies that deploy AI for property valuation, tenant screening, listing optimization, and client engagement. These firms face regulatory scrutiny because AI in housing directly intersects with fair housing obligations, and algorithmic bias in property valuations or tenant screening can produce discriminatory outcomes at scale. E&O, CGL, Cyber, D&O

Endorsement tracker

View full tracker

Common questions

View all answers
  • Do AI-driven adverse actions require fair lending notices? Yes. Federal fair lending laws require adverse action notices regardless of whether the decision was made by AI. Under ECOA and Regulation B, lenders must provide written adverse action notices with specific reasons for credit denials — regulators have clarified this applies even when an AI model is the proximate decision-maker. FCRA similarly requires adverse action notices when a consumer report influences a credit or employment decision. Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205) adds a state-level layer: financial services is a consequential decision, so lenders using an automated decision-making technology (ADMT) must give interaction notice, explain an adverse decision within 30 days, allow correction of inaccurate personal data, and provide meaningful human review — creating overlapping obligations for Colorado lenders.
  • Who is liable when an AI agent causes harm? Liability for an AI agent's actions tends to resolve in layers. Default — deployer or operator: the business that puts the agent into operation is generally answerable for the harm it causes, much as it would be for an employee or a tool it chose to use, under established agency, vicarious-liability, and negligence principles. Vendor or developer: responsibility can extend upstream through product-liability, professional-liability (E&O), or misrepresentation theories where the harm traces to a defect or an overstated capability rather than the deployer's own setup. Contract and indemnity: master service agreements, warranties, limitation-of-liability clauses, and indemnities reallocate that risk between the parties and often decide who actually bears a loss. Insurance and exclusions: a policy may respond, but AI-specific exclusions such as Verisk's CG 40 47 can strip coverage a deployer assumed it had — changing who pays without changing who is legally liable. Human review and audit trail: where a person reviews the agent's decisions and every action is logged, that record shapes whether the deployer is found negligent and whether coverage responds. Outcomes vary by jurisdiction and the agent's degree of autonomy, and newer rules such as Colorado's AI Act (SB 26-189, deployer and developer duties effective January 1, 2027) can add obligations whose breach supports a claim. This is general business and insurance-risk analysis, not legal advice.
  • What AI compliance requirements apply to insurance brokers? Insurance brokers using AI for quoting, risk assessment, or client recommendations fall under Colorado's AI Act (SB 26-189, which repealed and reenacted SB 24-205), which treats insurance as a consequential decision: brokers must give interaction notice, explain adverse AI-driven decisions within 30 days, allow data corrections, and provide meaningful human review — plus potential E&O exposure if AI exclusion endorsements affect their own coverage.
  • Which states require AI disclosure to consumers? Several states require AI disclosure, but the scope differs sharply. Colorado's AI Act (SB 26-189, obligations from January 1, 2027) requires deployers to give consumers notice when automated decision-making technology is used in a consequential decision, plus a plain-language explanation after an adverse outcome. California's AI Transparency Act (SB 942, operative January 1, 2026) requires large generative-AI providers to offer an AI-detection tool and to watermark AI-generated content. Illinois HB-3773, effective January 1, 2026, requires notice to an employee when an employer uses AI for covered employment decisions; the enacted provision does not state a general applicant-notice duty. Separately, the Artificial Intelligence Video Interview Act requires notice, explanation, and consent before AI analyzes an applicant video interview. Connecticut SB-1103 governs state agencies' own AI use rather than private-sector consumer disclosure.
  • Which states actively regulate AI in employment as of 2026? Illinois and Colorado have the most direct state-level AI employment regimes as of 2026. Illinois HB-3773 prohibits discriminatory AI and zip-code proxies in covered employment decisions and requires notice to an employee; the separate AI Video Interview Act governs AI-analyzed applicant video interviews. Colorado's SB 26-189 obligations begin January 1, 2027. Texas TRAIGA applies prohibited-practice rules, including intentional discrimination and certain biometric identification, but does not create a general private-employer hiring disclosure rule. Connecticut SB-1103 governs state agencies, while Connecticut's private-controller privacy amendments and Minnesota's consumer privacy act exclude data used solely within ordinary job-applicant or employment roles; neither should be presented as a general private-employer AI hiring law.
  • Are D&O and E&O policies affected by AI endorsements? Yes. Berkley PC 51380 specifically targets D&O, E&O, and Fiduciary liability policies with an absolute AI exclusion. Any claim arising from AI use, including board-level AI governance decisions, can be excluded.
  • How do AI endorsements affect EPL policies? Berkley PC 51380 can attach to EPL policies, excluding claims where AI contributed to employment decisions. This is critical for companies using AI in hiring, performance reviews, or termination decisions.
  • How do I know if my policy has an AI exclusion endorsement? Check your policy's endorsement schedule or declarations page for forms CG 40 47 (Verisk/CGL), PC 51380 (Berkley/Professional), or similar AI-specific endorsements. Your broker can run an endorsement audit across all your policies.
Research Library

Current analysis for AI work, coverage, and governance.

The articles below connect operational AI decisions to the risk, documentation, and insurance questions that show up once the work reaches production.

Resources Architecture & Engineering 10 min

Can Contractors Use AI in Federal Proposals?

The AI proposal rules as of June 2026: Section K, pricing certifications, past-performance claims, professional seals, and what humans must sign.

June 2026 Read
Resources Architecture & Engineering 9 min

The RFP Response Process: A Working Checklist From Solicitation to Submission

The RFP response process as a working checklist — Section L/M/C extraction, compliance matrix, past-performance verification, amendment tracking, reviews, and sign-off — and which steps can be prepared for your team.

June 2026 Read
Resources Architecture & Engineering 7 min

Proposal Content Library Maintenance: Why SF-330 Materials Go Stale

Why proposal content libraries go stale — and what it takes to keep SF-330 Section E resumes, Section F project descriptions, and past-performance entries review-ready between pursuits.

June 2026 Read
Resources Accounting 8 min

Can CPA Firms Use AI?

Can CPA firms use AI? Yes — AICPA tax standards and IRS Circular 230 permit it, with judgment and sign-off staying with the practitioner. What AI can prepare, and what it must never decide.

June 2026 Read
Resources Accounting 9 min

Client Document Collection for CPA Firms

Why tax portals and organizers still leave CPA staff chasing documents, and how review-ready intake packets change client document collection.

June 2026 Read
Resources Regulatory 13 min

Candidate Notice Is Not Enough: The Operating Controls Behind AI Hiring Compliance

AI hiring laws in Illinois, Colorado, Texas, and NYC require more than a disclosure email. The real obligations — vendor intake, bias monitoring, human review, record retention — are workflow controls, not notice.

June 2026 Read
Resources Analysis 7 min

AI Agents, Shadow AI, and Insurance Readiness: What Companies Need to Know in 2026

AI agents and shadow AI are creating uninsured liability across enterprises. A comprehensive analysis of how these technologies affect insurance coverage, carrier exclusions, and what companies should do before their next renewal.

March 2026 Read
Resources Market Analysis 7 min

Every Company Needs an AI Agent Strategy. Who Insures It?

As AI agents become standard enterprise infrastructure, the gap between what's deployed and what's insured is widening. Analysis of three critical insurance gaps and emerging coverage options.

March 2026 Read
Resources Commentary 10 min

The AI Insurance Market Is Splitting in Two

The AI insurance market is bifurcating: companies with documented, governed AI deployments are insurable. Those without are facing exclusions, sublimits, and declining coverage. Here's what's driving the split — and what it means.

March 2026 Read
Resources Risk Framework 7 min

Security Controls vs. Insurance Readiness for AI Agents

Security controls and insurance readiness are not the same thing for AI agents. Analysis of where they overlap, where they diverge, and how to bridge the documentation gap.

March 2026 Read
Resources Broker Briefing 6 min

How Brokers Should Review AI Agent Exposure Before Renewal

A practical guide for insurance brokers: how to assess AI agent exposure in client portfolios, audit policies for AI exclusions, and negotiate better terms at renewal.

March 2026 Read
Resources Commentary 9 min

Shadow AI Is Becoming an Insurance Problem, Not Just a Security Problem

Shadow AI is typically framed as a security concern. But the real exposure is on the insurance side: undocumented AI tools create liability that carriers can't see, can't price, and increasingly won't cover. Here's why the framing matters.

March 2026 Read
Tools & Checklists Practical Guide 7 min

Shadow AI Discovery Checklist for Mid-Market Companies

Step-by-step shadow AI discovery checklist for mid-market companies. Department-by-department guide to finding unsanctioned AI tools, classifying risk, and building an insurance-ready inventory.

March 2026 Read
Resources Commentary 11 min

What Carrier Filings Actually Tell You (That the Headlines Don't)

Most coverage of AI insurance exclusions oversimplifies the story. We've read every major filing — Verisk CG 40 47, Berkley PC 51380, Hamilton Select's platform-naming exclusion. Here's what the actual form language tells you that the headlines don't.

March 2026 Read
Resources Risk Framework 8 min

AI Workflow Risk Classification: A Framework for Brokers and Risk Managers

How to categorize enterprise AI deployments by risk level — from internal knowledge queries to autonomous business execution — and what each category means for coverage.

February 2026 Read
Resources Broker Briefing 8 min

Verisk AI Exclusions: CG 40 47, CG 40 48, and CG 35 08

Compare Verisk CG 40 47, CG 40 48, and CG 35 08, including affected coverage, form scope, policy verification steps, and practical renewal implications.

February 2026 Read