Traditional insurance policies are failing to cover losses from AI systems, leaving companies exposed to millions in liability. Insurers have added broad exclusions to E&O, Cyber, General Liability, and even D&O policies specifically targeting algorithm-driven failures, while most organizations still assume standard coverage will respond.
The gap exists because standard insurance architecture relies on clear distinctions between human error, system breaches, and physical damage. Generative AI blurs all three categories. When a model generates factually incorrect financial advice or surfaces proprietary data through a public prompt, underwriters can argue that output isn't a covered software defect, a system intrusion, or property damage-it's an unvetted algorithmic output.
Why standard policies break down
Technology Errors & Omissions
Traditional Tech E&O covers financial loss from a technology failure or professional service negligence. It assumes a human developer made a coding error or missed a deliverable. "When an independent model 'hallucinates' inaccurate financial advice or generates faulty logic that costs a client millions, underwriters may argue the output isn't a covered software defect or a covered professional service-it's an unvetted algorithmic output," wrote Kyle Jeziorski, managing director at Founder Shield, the innovation practice of The Baldwin Group.
Cyber Liability
Cyber policies cover third-party hacks, ransomware, and unauthorized network intrusion. They struggle when an employee pastes confidential customer data into a public prompt or an internal chatbot surfaces trade secrets to an unauthorized user. Standard definitions of a "data breach" or "malicious attack" often fail to apply in those scenarios.
General Liability
General Liability covers bodily injury and tangible property damage-broken bones, smashed equipment. Intangible digital assets are outside its scope. But as real-world operations and AI systems intermingle, the line between digital and physical blurs. An algorithm's bad advice can trigger a physical crisis, leading to the same multi-million-dollar blame game.
The five core liability exposure areas
Generative AI creates new pathways for third-party liability. The article outlines five categories:
- Financial loss from hallucinated promises. A customer-facing bot misquotes a contract rate or offers flawed technical advice. The client loses money and the firm is held responsible.
- IP theft and reputation damage. A marketing tool produces copy or images that mirror copyrighted work or generates false statements about a competitor. That invites copyright or defamation lawsuits.
- Data leaks via model inputs. Employees feed sensitive client data into a model. One tailored prompt from an external user can spill that proprietary data.
- Physical harm driven by bad advice. A flight safety or medical triage system gives bad guidance. Someone gets hurt-personal injury liability, not a glitch.
- Property damage via automated actions. An AI agent controls infrastructure machinery. A bad decision can break equipment, facilities, or inventory.
Closing the coverage gap
The article recommends three steps to address the gap. First, comb through E&O, Cyber, GL, and D&O policies for language such as "algorithm failure" or "unsupervised machine learning" in recent renewal endorsements. Identifying those exclusions before a loss empowers negotiation on modified terms.
Second, formalize internal AI governance. Underwriters evaluate risk based on the company control framework. Human-in-the-loop requirements for high-stakes decisions, strict policies against inputting customer PII or its code into public LLMs, and vetting procedures for third-party AI vendors all improve insurability.
Third, align coverage with actual operations. If the company builds AI tools, its Tech E&O policy must account for algorithmic output and model training. If the company consumes third-party AI tools internally, its Cyber and E&O policies must account for vendor failure and data exposure from automated systems.
Why this matters for insurance professionals
The speed of AI adoption has outpaced insurance drafting. The greatest risk factor is assumption-that policies will pay out when the underlying technology operates in ways the policy was never designed to cover. Insurance professionals must audit existing language for AI exclusions, push for clear coverage terms tied to specific operational use cases, and educate clients on what their policies actually exclude. Companies that want to work with AI for Insurance need to consider Generative AI and LLM and related risks.
Your membership also unlocks: