Businesses are deploying generative AI tools, large language models (“LLMs”) and, increasingly, “agentic” systems across customer service, investment analysis and other many core functions. However, their insurance programmes have not kept pace — and this has widened the gap between the liabilities that organisations are assuming and the coverage they believe they hold.
Many businesses rely on some combination of cyber liability, technology errors and omissions (“TE&O”), directors’ and officers’ (“D&O”), and general commercial liability cover. But none of these products were designed with AI in mind — and the extent to which they cover AI-related losses varies from policy to policy and, in some cases, from insurer to insurer within the same line of business.
Cyber insurance policies are typically triggered by security incidents or personal data breaches, but losses caused by an AI system producing an erroneous output (such as a chatbot that invents a fact and exposes the business to a defamation or misrepresentation claim) will not usually engage these triggers. This is because the loss is not a cyber incident or personal data breach in the conventional sense; rather, it is an operational error generated by a still nascent technology.
TE&O policies are more relevant, as they are designed to cover losses arising from errors in the provision of technology services or products. But coverage is not assured, given that (1) existing professional indemnity wording was not drafted with the probabilistic nature of LLM outputs in mind, and (2) insurers are increasingly introducing carve-outs and exclusions aimed at those outputs.
Emerging insurer responses
Over the past 18 months, US insurers have been repositioning their books. For example, carriers including AIG and WR Berkley have sought regulatory approval for policy forms containing broad AI exclusions — in some cases, barring cover for any claim involving “any actual or alleged use” of AI, or any product or service “incorporating” it. If deployed, such language could risk rendering parts of a modern business’s operations effectively uninsurable.
Regulatory approval for an exclusion does not mean an insurer will use it, and several carriers have said publicly that they have no current plans to implement the exclusions they have filed. That said, filing an exclusion with a state insurance regulator is a prerequisite to using it, and carriers often file broader language than they intend to deploy immediately in order to preserve future flexibility. The filing gives them the option to deploy the exclusion at a future renewal, and this creates a risk for policyholders that cover which exists today may be withdrawn at short notice — potentially with little warning and limited opportunity to source replacement cover.
Some insurers are also applying sub-limits that cap AI-related payouts below the overall policy limit, or introducing endorsements that require policyholders to disclose their AI use and governance frameworks as a condition of cover. These disclosure-based endorsements are important in their own right, as they make the adequacy of a business’s AI governance a consideration in whether cover responds at all, rather than merely a factor in pricing. And although specialty insurers, particularly at Lloyd’s in London, have shown some appetite for AI-enhanced software, they often continue to decline to underwrite risks associated with LLMs, which they regard as too unpredictable to price with confidence.
A more significant near-term concern may be so-called silent AI risk — namely, the possibility that AI-related losses end up covered, or uncovered, under legacy wording that did not contemplate the technology. For insurers, silent AI exposure is unquantified and unpriced risk on their books. For insureds, it creates uncertainty in both directions: a business may assume that it has coverage for an AI-related loss, only to find at the point of claim that the insurer disputes that interpretation, or it may assume no coverage exists and forgo a claim that it was entitled to make.
AI-specific liabilities
The AI-driven liabilities relevant to our clients are varied and continue to expand, and include the following.
Hallucination and output errors. LLMs generate plausible but sometimes entirely false content, and businesses that deploy them in customer-facing or advisory contexts run the risk that a confident-sounding but fabricated answer is treated by a court, regulator or counterparty as a representation by which the business is bound. In Moffatt v Air Canada, for example, a tribunal ordered Air Canada to honour a discount that its customer-facing chatbot had invented. The case — which is certainly not unique — illustrates the broader point that companies may not be able to rely on the argument that an AI-generated statement was not made by the company, since the AI system is treated, for liability purposes, as an extension of the business that deployed it.
Notably, this category of loss sits between existing policy lines; it is not a cyber incident, and whether it falls within TE&O, general liability or no cover at all will often depend on wording that pre-dates the type of AI technology in question.
Deepfake-enabled fraud. Synthetic voice and video technology has made business email compromise considerably more convincing. In one case, fraudsters used a deepfake technology to impersonate the chief financial officer of UK engineering firm Arup and authorise transfers totalling US$25 million. As the quality of deepfakes improves and the cost of producing them falls, this type of fraud is likely to become more common.
For insurance purposes, losses of this kind often sit at the intersection of crime/fidelity cover, cyber cover and social engineering endorsements, and organisations should not assume that any one of these lines will respond in full — particularly where the fraud is instigated by a deepfake rather than a compromised email account or network intrusion, which is the scenario that more conventional social engineering wording was written to address.
Agentic AI errors. As organisations deploy AI systems capable of taking autonomous actions (such as executing trades and approving transactions), the potential for an error to generate significant losses increases correspondingly. These risks are compounded by the fact that (1) attributing responsibility between the technology vendor, the business deploying the system and the AI system is often more complex than in a typical errors-and-omissions scenario, and (2) most TE&O and general liability wording was drafted with a human decision-maker in mind and may not clearly extend to a loss caused by a system acting without direct human input at the time of the error.
Businesses deploying agentic AI should therefore expect this category of exposure to be the focus of attention from insurers, and potentially further exclusionary language, as agentic technology becomes more widely adopted.
LLMjacking. This involves unauthorised parties gaining access to and exploiting an organisation's LLM credentials or infrastructure, and it sits at the intersection of traditional cyber risk and AI-specific exposure. This hybrid character creates a coverage difficulty: although a cyber policy may respond to the unauthorised access (because it resembles a conventional network intrusion), it may be less likely to respond to losses flowing from the misuse that follows, such as reputational harm from harmful content generated in the organisation’s name or third-party claims arising from exfiltrated training data.
As with the categories above, businesses should not assume that authorisation of access to a system is the same as authorisation of everything that an intruder subsequently does with that access, and they should review policy wording for how it treats consequential misuse as distinct from the initial breach.
Regulatory fines and enforcement. The EU AI Act imposes onerous obligations on providers and deployers of AI systems, with penalties for non-compliance reaching up to the greater of €35 million or 7% of global annual turnover. Whether regulatory fines are insurable varies by jurisdiction, and where a jurisdiction treats those fines as uninsurable on public policy grounds, that position will not change simply because a business holds a D&O or liability policy that would otherwise appear broad enough to respond. However, the defence costs and remediation expenses associated with an enforcement action can be significant in their own right and, unlike the fines, are more commonly capable of being insured, making the distinction between the two components of exposure important for businesses assessing their coverage.
Going forward, organisations’ compliance postures under the AI Act are likely to factor into insurers’ underwriting and pricing decisions in the same way that GDPR compliance has become relevant to cyber insurance underwriting. Businesses that can demonstrate robust AI governance may be able to secure more favourable terms and, conversely, those that cannot evidence a coherent compliance programme may find that this becomes a pricing or coverage disadvantage in its own right.
Guidance for legal and compliance counsel
We recommend that businesses take the following steps.
- Audit your insurance programme. Map existing cyber, TE&O, D&O and general liability policies against your current and planned AI use cases — and identify where coverage is clear, where it is ambiguous and where exclusions have already been introduced. This audit should not be treated as a one-off exercise, given how quickly insurer positions on AI exclusions and endorsements are developing, and should be cross-referenced against the AI use inventory described below so that the audit reflects the organisation’s current deployment rather than a historical snapshot.
- Scrutinise renewal terms. Closely review new AI-specific exclusions, sub-limits or endorsements introduced at renewal, and negotiate their scope where possible. In particular, a blanket exclusion for “any use of AI” will often be disproportionate to the underlying risk profile, and businesses should press insurers to narrow this language to the specific AI-related risks that the insurer is seeking to exclude. Businesses should also confirm whether an exclusion has been filed with regulators but not yet implemented, since, as discussed above, this distinction affects how much runway the organisation may have before the exclusion is deployed against it.
- Align AI governance with underwriting expectations. Insurers increasingly want to understand how AI is governed before they will price risk, so it is important that organisations document governance frameworks, vendor due diligence, model risk management and use case inventories in a form that can support an underwriting submission. Indeed, businesses should treat the underwriting submission as a discipline that improves the underlying governance record, given that documentation capable of withstanding underwriter scrutiny is also more likely to withstand regulatory or litigation scrutiny if a loss occurs.
- Monitor the standalone AI liability product market. Dedicated AI liability policies are beginning to emerge, and although the market remains relatively immature, these products may start to fill gaps that traditional policies exclude. Businesses should track this market rather than assuming that traditional lines will eventually be amended to cover the gap.
- Maintain an AI use inventory and incident response plan. Document where and how AI is deployed across the business and ensure that your incident response plan addresses AI-specific failures (e.g., hallucination events and model compromises) in addition to traditional cyber incidents. The inventory should be updated as new use cases are adopted or existing ones are expanded, given that the insurance audit referenced above and the underwriting submission both depend on the inventory being an accurate reflection of AI deployment rather than a static record compiled at a single point in time.
- Coordinate with broader compliance functions. Insurance programme management should not operate separately from AI governance and regulatory compliance teams, particularly where EU AI Act obligations are in scope. A coordinated approach helps to ensure that risk mitigation measures serve regulatory and insurance objectives, and can avoid a scenario where steps taken to satisfy a regulator are not captured or communicated in a way that also strengthens the business’s position with its insurers, or vice versa.
Subscribe to Ropes & Gray Viewpoints by topic here.
Authors
Stay Up To Date with Ropes & Gray
Ropes & Gray attorneys provide timely analysis on legal developments, court decisions and changes in legislation and regulations.
Stay in the loop with all things Ropes & Gray, and find out more about our people, culture, initiatives and everything that’s happening.
We regularly notify our clients and contacts of significant legal developments, news, webinars and teleconferences that affect their industries.
