By the time procurement sends a marked-up MSA, security addendum, and certificate request, the startup has already described its product, data use, and the customer’s reliance on its output. That is often when founders discover that those promises were made in separate documents by separate teams.
An enterprise insurance review is where those documents have to reconcile. The MSA says what the company will stand behind; the application needs to give underwriters the same account of the business.
What insurance does a California AI startup need for an enterprise deal?
An enterprise deal does not create one “AI insurance” requirement. It creates specific requests: a cyber limit, perhaps technology E&O or D&O, and certificate wording. Whether they work depends on the services definition, exclusions, retention, endorsements, and the actual customer agreement.
Our job as a broker is to put the customer request, policy, and application beside one another and identify where they describe the same exposure. Counsel decides legal applicability and product compliance.
The MSA sets the insurance question
Read the MSA, statement of work, data-processing addendum, and public product claims together. Look for promises about accuracy, uptime, security, indemnity, intellectual property, and the customer’s permitted use of an output. A company may have a well-built product and still accept a contractual obligation that sits outside the insurance it has bought.
This is especially important where an enterprise customer will use an output to make a significant decision. The question is not whether the product is called AI. It is what the company has said about the output, who controls it, and what happens when the customer says the promise was not met.
California rules belong in the factual record
The California AI Transparency Act, SB 942, became operative on January 1, 2026. It applies to a defined covered provider: a person producing a publicly accessible generative AI system with more than one million monthly visitors or users in California. Its requirements concern tools and disclosures for certain image, video, and audio content. That is a narrower question than “is this an AI startup?” and it belongs with counsel.
The California Privacy Protection Agency also finalized regulations effective January 1, 2026 covering, among other things, cybersecurity audits, risk assessments, and automated decisionmaking technology. The legal analysis should produce a clear operational record: data types, vendors, user rights, security controls, and any product feature that creates a disclosure or assessment obligation. That record is what belongs in the insurance conversation.
Build the file before the redline becomes final
Bring the current customer papers, a plain-language product description, and a diagram of the data flow to the review. The broker should be able to see what the customer is asking for, what the startup actually does, and what each policy is intended to address.
Cyber may be relevant to a privacy or security event. Technology E&O may be relevant when a customer alleges the service failed to perform. D&O may be relevant to a management claim. Those are starting points, not coverage conclusions. The form and claim facts control.
That gives the founder a concrete choice before signing: change the promise, negotiate the requirement, or obtain coverage that supports it.