Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

AI risks

The AI Risks That Turn Into Claims

AI creates liability when its output, decisions or actions harm a customer, employee, investor or business partner and that party brings a claim. The most common routes are inaccurate or hallucinated output, discriminatory automated decisions, AI-enabled cyber attacks and fraud, mistakes by autonomous agents and misleading statements about a company's AI. This page sets out each risk with the cases and rules behind it, the line of insurance that usually responds and the Mayflower Specialty coverage module written for it.

Why now

Three Pressures Are Moving AI Exposure Onto Company Balance Sheets

Regulators, plaintiffs and insurers are each changing how AI losses are paid for, and they are doing it at the same time. Together they mean a company can face an AI claim that its current policies were not written to answer.

Regulators

01

7%

of worldwide annual turnover, or €35 million if higher, is the maximum EU AI Act fine for prohibited AI practices

Source: Official Journal of the European Union, via EUR-Lex, July 12th 2024

The EU AI Act can reach companies outside the EU when their AI output is used there. In the United States, AI rules in Texas and Illinois took effect on January 1st 2026, Colorado's automated decision law applies from January 1st 2027 and New York City already requires bias audits of automated hiring tools. Each new duty gives regulators something to enforce and can give plaintiffs a standard to measure a company against.[1][2][3][4][5]

Litigation

02

15

AI-related securities class actions filed in the first half of 2026, against 16 in all of 2025

Source: Cornerstone Research, July 29th 2026

Courts are also holding companies responsible for what their AI says. A British Columbia tribunal rejected Air Canada's argument that its chatbot was responsible for its own advice, and Damien Charlotin's database lists more than 2,100 court decisions worldwide involving AI-fabricated content as of October 5th 2026.[7][8]

Carriers

03

3

standard generative AI exclusions for general liability policies (ISO forms CG 40 47, CG 40 48 and CG 35 08), which took effect in January 2026

Source: Independent Insurance Agents & Brokers of America, 2025

W. R. Berkley has introduced an “absolute” AI exclusion for D&O, E&O and fiduciary liability, and the Financial Times reported in November 2025 that AIG, Great American and W. R. Berkley had asked US regulators to approve AI exclusions. Many policies written before generative AI say nothing about it, which leaves coverage to be argued after a loss.[10][11][12]

The practical response is to find out, before the next renewal, which of these pressures reaches your company and which of your policies would answer if it did.

The risk map

Five Places Where AI Fails

Mayflower groups the ways AI fails into five categories: the model's own output, decisions an AI system takes on its own, the data it learns from, the way it is built into a business and the dependencies it shares with many other companies. Select a category to see what it covers, a real example and the Mayflower module written for it.

Select a category to see its detail. Arrow keys move between categories.

Model Performance

Model performance risk is the chance that an AI system's output is wrong, biased or degrades over time. A generative model can state a falsehood with confidence, a scoring model can disadvantage a protected group, and a model that tested well at launch can drift as the data it sees changes. It is the most direct route from AI to a claim, because someone relied on the output.

Moffatt v. Air Canada, February 2024

A British Columbia tribunal held Air Canada liable for negligent misrepresentation after its website chatbot gave a customer wrong advice about bereavement fares, and rejected the argument that the chatbot was responsible for its own actions.
Source: Civil Resolution Tribunal of British Columbia, February 14th 2024 [7]
Read the guide: Who Is Liable When AI Hallucinates? Cases, Exposure and Insurance

How AI failures become claims

Seven routes lead from an AI failure to a claim. Each section below gives a short answer, sourced examples, the line of insurance that usually responds and the Mayflower module written for it, so it is quickest to start with the routes that match how your company uses AI.

Model Performance

Inaccurate and Hallucinated Output

Inaccurate or hallucinated AI output creates liability when someone relies on it and loses money, or when it damages a reputation. Courts and tribunals have held companies and professionals that use AI responsible for what it produces, in the same way as for the rest of their website, advice or work product.[7][18]

The exposure is widest for companies whose AI talks to customers or produces work that clients rely on, such as legal, financial, medical and technical advice. Professionals who file or deliver AI-drafted work carry the same risk, and Damien Charlotin's database lists more than 2,100 court decisions worldwide involving AI-fabricated content as of October 5th 2026.[8]

Moffatt v. Air Canada, February 2024

A British Columbia tribunal held Air Canada liable for negligent misrepresentation after its chatbot gave wrong advice on bereavement fares, ordering C$812.02 in damages, interest and fees. The tribunal said the chatbot “is still just a part of Air Canada's website.”

Source: Civil Resolution Tribunal of British Columbia, February 14th 2024 [7]

Mata v. Avianca, June 2023

A federal judge in New York fined two lawyers and their firm $5,000 for filing a brief that cited six cases invented by ChatGPT, and ordered them to write to each judge falsely named as an author.

Source: US District Court for the Southern District of New York, June 22nd 2023 [18]

Line that usually responds

Errors and omissions (professional liability), where the policy does not exclude AI.

Mayflower module written for it

Get a quote with AI-E&O selected

Coverage depends on the policy wording and the facts of a claim.

Model Performance

Biased Decisions About People

AI that screens, scores or ranks people creates liability when its decisions disadvantage a protected group. Employers remain responsible for discrimination in hiring, promotion and dismissal when an AI tool makes or shapes the decision, and a federal court has also let discrimination claims proceed against an AI vendor on the theory that it acted as the employer's agent.[19]

New rules add duties on top of existing anti-discrimination law. New York City requires a bias audit within the year before an automated employment decision tool is used, Illinois has barred employers since January 1st 2026 from using AI that has a discriminatory effect, and California's civil rights rules on automated decision systems took effect on October 1st 2025.[3][5]

Mobley v. Workday, 2024 to 2026

A federal court in California let claims against Workday proceed on an agent theory in July 2024, then in May 2025 conditionally certified a nationwide collective of applicants aged 40 and over who allege its AI screening tools disadvantaged older applicants. The case was in discovery as of August 2026.

Sources: Civil Rights Litigation Clearinghouse, as of December 2nd 2025 [19]; CDF Labor Law, August 27th 2026 [20]

EEOC v. iTutorGroup, 2023

iTutorGroup agreed to pay $365,000 to settle an EEOC suit alleging that its tutor application software automatically rejected female applicants aged 55 or older and male applicants aged 60 or older.

Source: US Equal Employment Opportunity Commission, September 11th 2023 [21]

Line that usually responds

Employment practices liability (EPL), which may be silent on AI or exclude it.

Mayflower module written for it

Get a quote with AI-EPL selected

Coverage depends on the policy wording and the facts of a claim.

Data Integrity and Integration

AI-Driven Cybersecurity Risks

Prompt injection, data poisoning, model and data leakage, and deepfake-enabled fraud

AI creates two kinds of cyber risk: attacks on a company's AI, such as prompt injection and data poisoning, and attacks that use AI, such as deepfake impersonation. Which policy responds depends on the loss: cyber insurance for breaches and data loss, crime or social engineering cover for stolen funds, and liability lines when customers or investors claim the company's AI failed them.

Definition

Prompt injection

Prompt injection is an attack in which instructions hidden in user input, or in content an AI system reads, cause the system to ignore its intended rules. It can lead an AI assistant to disclose data or take actions its operator never authorized.

Definition

Data poisoning

Data poisoning is the deliberate corruption of the data a model learns from, so that the model behaves as the attacker chose, often only when a hidden trigger appears. Because the behavior is learned, it can carry into every product built on the model.

Leakage is the quieter version of the same risk: Samsung banned generative AI tools on company devices in 2023 after staff uploaded internal source code to ChatGPT. Weak access controls make all of these worse, and IBM's 2025 breach study found that 97% of organizations reporting a breach of an AI model or application lacked proper AI access controls.[22][23]

13%

of organizations in IBM's 2025 study reported a breach of an AI model or application

Source: IBM, July 30th 2025

EchoLeak, June 2025

Researchers disclosed a zero-click prompt injection flaw in Microsoft 365 Copilot (CVE-2025-32711, rated 9.3 out of 10) that could expose data from the assistant's context; Microsoft patched it in June 2025.

Source: The Hacker News, June 2025 [24]

Arup, 2024

An Arup employee in Hong Kong made 15 transfers totaling HK$200 million (about US$25.6 million) after a video call in which deepfakes impersonated the company's UK-based chief financial officer. Arup said none of its internal systems were compromised.

Sources: Hong Kong Free Press, February 5th 2024 [25]; Fortune, May 17th 2024 [26]

Line that usually responds

Cyber insurance for breaches and data loss, crime or social engineering cover for stolen funds, and E&O or D&O when customers or investors bring claims.

Mayflower module written for it

AI-E&O is written for claims by clients who suffer a loss from a company's AI-enabled products or services, which can follow a successful attack on that AI, subject to the policy terms.

Get a quote with AI-E&O selected

Coverage depends on the policy wording and the facts of a claim.

Autonomous Decisions

Autonomous and Agentic AI

An AI agent creates liability when it takes an action that harms someone before a person can review it, such as sending a message, changing a record, agreeing to terms or moving money. In Moffatt v. Air Canada a tribunal rejected the argument that a chatbot was a separate party responsible for its own conduct, so a company that deploys an agent should expect to answer for what the agent does.[7]

Agents also widen the cyber exposure described above, because an agent that reads outside content and can take actions can be steered by instructions hidden in that content. The controls that matter most are limits on what an agent may do without approval, a record of what it did and a fast way to stop it.

Replit, July 2025

Replit's AI coding agent deleted a user's production database during a code freeze, although the data was later restored.

Source: Fortune, July 23rd 2025 [13]

ForcedLeak, September 2025

Researchers showed that a prompt injection flaw in Salesforce's Agentforce agents, rated 9.4 out of 10, could be used to extract sales lead data from the CRM, and Salesforce has since patched the flaw.

Source: The Register, September 26th 2025 [27]

Line that usually responds

Errors and omissions for harm to clients and counterparties, and D&O where shareholders allege the board failed to oversee the systems it relies on.

Get a quote with AI-E&O selected

Coverage depends on the policy wording and the facts of a claim.

Governance and disclosure

AI-Washing and Disclosure

AI-washing is the practice of overstating what a company's AI does or how much the company relies on it. It creates liability for directors and officers because regulators bring enforcement actions over such statements, and shareholders bring securities class actions when the share price falls after the truth comes out.[6][28]

The claims are also moving beyond overstatement: recent securities suits, such as the June 2026 suit against ZoomInfo, allege that companies understated how much AI threatened their own business. Disclosure is growing at the same time, with 72% of S&P 500 companies flagging AI as a material risk in 2025 against 12% in 2023, and each of those statements has to stay accurate as the company's use of AI changes.[29][30]

24

AI-related securities class actions filed in 2026 by September 23rd, nearly 14% of all new filings

Source: The D&O Diary, September 23rd 2026

SEC v. Delphia and Global Predictions, March 2024

The SEC settled its first “AI washing” cases against two investment advisers for misleading statements about their use of AI, with penalties of $225,000 for Delphia and $175,000 for Global Predictions.

Source: US Securities and Exchange Commission, March 18th 2024 [28]

SEC v. Presto Automation, January 2025

The SEC settled charges that Presto Automation made materially false statements about its AI drive-thru ordering product, which needed human help on most orders. The D&O Diary described it as apparently the SEC's first AI-washing action against a public company.

Sources: US Securities and Exchange Commission, January 14th 2025 [32]; The D&O Diary, January 2025 [33]

Line that usually responds

Directors and officers liability (D&O), which some insurers now limit with AI exclusions.

Mayflower module written for it

Get a quote with AI-D&O selected

Coverage depends on the policy wording and the facts of a claim.

Data Integrity

Data, Privacy and Intellectual Property

AI systems create data and intellectual property claims when they are trained on, retrieve or reveal information the company had no right to use or disclose. The claims range from privacy and biometric statutes that set damages per violation to copyright suits over the material used to train a model and the content it produces.

Statutory damages make the privacy side expensive: Illinois' Biometric Information Privacy Act lets individuals sue for $1,000 for each negligent violation and $5,000 for each intentional or reckless one. Disclosure duties are growing too, and since January 1st 2026 California has required developers of generative AI to publish summaries of their training data.[34][35]

Thomson Reuters v. Ross Intelligence, 2025 to 2026

A federal judge in Delaware held in February 2025 that Ross's use of Westlaw headnotes to train a competing AI legal research tool was not fair use, noting that the AI before him was not generative. The Third Circuit affirmed in late September 2026 in an opinion that was still sealed when this page was reviewed, so how far the reasoning reaches generative models is not yet clear.

Sources: US District Court for the District of Delaware, February 11th 2025 [36]; IPWatchdog, September 30th 2026 [37]

Line that usually responds

It varies by policy: privacy events often sit with cyber insurance, and cover for intellectual property claims differs sharply from one policy form to the next.

Mayflower module written for it

How Mayflower's modules treat intellectual property and privacy claims depends on the policy terms, so ask us about the specific exposure before relying on any policy for it.

Talk to us about this exposure

Coverage depends on the policy wording and the facts of a claim.

Regulators

Regulation as a Source of Claims

AI regulation creates liability in two ways: regulators can investigate and fine a company directly, and each new duty, such as a bias audit, a notice to consumers or a record of how a system was tested, can give plaintiffs a standard against which to measure the company's conduct.

The EU AI Act reaches companies outside the EU when their AI output is used there, and its obligations for high-risk uses listed in Annex III, which include employment, now apply from December 2nd 2027. Texas's Responsible AI Governance Act has been in effect since January 1st 2026, enforced by the state attorney general with penalties of up to $200,000 for each violation that cannot be cured, and Colorado's automated decision law applies from January 1st 2027.[1][2][4][38]

Product liability is moving the same way, since the EU's revised Product Liability Directive will treat software, including AI, as a product when it is placed on the EU market on or after December 9th 2026. Insurers face rules of their own as well: 24 states and the District of Columbia had adopted the NAIC model bulletin on insurers' use of AI as of April 1st 2026. Because these dates keep moving, it is best to review the rules that apply to the company at each renewal rather than once.[39][40]

FTC orders on “AI-powered” marketing claims, August 2026

The FTC finalized orders requiring Cox Media Group, MindSift and 1010 Digital Works to pay a total of $930,000 over charges that they deceived customers about an “AI-powered” service said to target ads using conversations captured from consumers' smart devices.

Source: US Federal Trade Commission, August 27th 2026 [41]

FTC Operation AI Comply, 2024 to 2025

The FTC announced five cases over deceptive AI claims in September 2024. In December 2025 it set aside its order against one of them, Rytr, which shows that enforcement priorities can shift even where the underlying law does not.

Sources: US Federal Trade Commission, September 25th 2024 [42]; US Federal Trade Commission, December 22nd 2025 [43]

Line that usually responds

D&O for investigations and claims against directors and officers, and EPL for employment rules. Whether fines and penalties can be insured depends on the law where they are imposed and on the policy wording.

Get a quote with AI-D&O selected

Coverage depends on the policy wording and the facts of a claim.

Who gets sued

Developers, Deployers, Directors and Employers

AI claims can reach four kinds of party, and a single incident can involve several of them at once.

Developers

Companies that build and sell models or AI products face claims from customers when a product fails and from people harmed by its output. In July 2026 a Delaware court refused to dismiss Robby Starbuck's defamation suit against Google over statements made by its AI.[44]

Deployers

Companies that use AI in their own products, services or operations answer for its output to the people they serve, as Air Canada found when a tribunal held it liable for its chatbot's advice.[7]

Directors and Officers

Boards answer to shareholders and regulators for how the company oversees AI and what it says about it, through securities class actions, derivative suits and enforcement actions.[6][28]

Employers

Employers answer for discrimination when AI screens, ranks or evaluates applicants and employees, including when the tool comes from a vendor, and the vendor itself may be sued as in Mobley v. Workday.[19]

Most companies hold more than one of these roles, so the useful exercise is to list your AI systems and note, for each one, whether you built it, deployed it, report on it or use it to make decisions about people.

From risk to coverage

Which Policy Usually Responds to Each AI Risk

The table maps each route to the claimant who typically brings it, the line of insurance that usually responds and the Mayflower module written for it. It is general information; whether a policy responds depends on its wording and the facts of a claim. The coverage overview explains how the four modules fit together.

AI risks mapped to the typical claimant, the line of insurance that usually responds and the Mayflower module written for each
RiskTypical claimantLine that usually respondsMayflower module
Inaccurate and hallucinated outputTypical claimantCustomers, clients and people the output defamesLine that usually respondsErrors and omissionsMayflower moduleAI-E&O: AI Professional Liability
Biased decisions about peopleTypical claimantApplicants, employees and regulatorsLine that usually respondsEmployment practices liabilityMayflower moduleAI-EPL: AI Employment Practices Liability
AI-driven cyber attacks and fraudTypical claimantCustomers whose data was exposed, and the company itself for stolen fundsLine that usually respondsCyber; crime or social engineering; E&O for client claimsMayflower moduleAI-E&O: AI Professional Liability
Autonomous and agentic AITypical claimantClients and counterpartiesLine that usually respondsErrors and omissionsMayflower moduleAI-E&O: AI Professional Liability
AI-washing and disclosureTypical claimantShareholders, the SEC and the FTCLine that usually respondsDirectors and officers liabilityMayflower moduleAI-D&O: AI Directors and Officers Liability
Data, privacy and intellectual propertyTypical claimantIndividuals, rights holders and regulatorsLine that usually respondsVaries by policy formMayflower moduleDepends on the policy terms; ask us
RegulationTypical claimantRegulators, attorneys general and plaintiffs relying on new rulesLine that usually respondsD&O; EPL for employment rulesMayflower moduleAI-D&O: AI Directors and Officers LiabilityAI-EPL: AI Employment Practices Liability
An AI exclusion in an existing policyTypical claimantAny of the aboveLine that usually respondsNone, once the exclusion appliesMayflower moduleAI DIC Excess: AI DIC Excess

Coverage gap check

Check your own program against these risks

The coverage gap check asks up to nine questions about how your company uses AI and which policies it holds, then shows where an AI claim may fall outside your program. It asks for no contact details.

Check your coverage gaps

The common objection

“Don't We Already Have Cyber for That?”

Cyber insurance answers only part of the question, because it is built to respond to security events, while many AI claims involve no security event at all. A chatbot that gives a customer wrong advice, or a screening tool that rejects older applicants, causes harm without any breach, so the claim falls to liability policies such as E&O, EPL or D&O, which may be silent on AI or exclude it.

Cyber insurance

A Security Event

What triggers it

A security or privacy event, such as a breach, ransomware or a network outage.

Who brings the claim

The company itself, for its own costs, and customers whose data was exposed.

What the loss looks like

Breach response, data restoration, business interruption and privacy claims.

An example

An AI-enabled attack: IBM's 2026 study found that 1 in 4 malicious breaches were AI-enabled, at about $6 million each on average.[45]

The policy built for it

A cyber policy.

AI liability

A Decision, Output or Action

What triggers it

A decision, output or action by an AI system that harms someone, with or without a breach.

Who brings the claim

Customers, clients, applicants, employees, investors and regulators.

What the loss looks like

Damages, settlements and defense costs for wrong advice, discrimination, professional errors and securities claims.

An example

No breach at all: Air Canada's chatbot gave a customer wrong fare advice, and a tribunal held the airline liable.[7]

The policy built for it

AI-E&O, AI-EPL and AI-D&O, or AI DIC Excess over the program you already carry.

The two are designed to sit beside each other rather than replace one another. The practical course is to keep cyber for security events and to check, before the next renewal, that your liability policies name AI.

Read the full comparison: AI Liability Insurance vs Cyber Insurance: What Each Covers

Questions

Frequently Asked Questions

Short answers to common questions about AI risk. The full FAQ covers the policy, the application and how Mayflower works with brokers.

How does AI create legal liability for a business?

AI creates legal liability when an AI system's output, decision or action harms a customer, employee, investor or business partner, and that party brings a claim against the company that built or used it. The usual routes are inaccurate output, biased decisions about people, cyber attacks on or with AI, mistakes by autonomous agents, misleading statements about AI and breaches of new AI rules.

Who is liable when AI causes harm, the developer or the company using it?

Both can be sued, but the company that deployed the AI is often the first to face the claim, because it dealt with the person harmed. In Moffatt v. Air Canada a tribunal rejected the airline's argument that its chatbot was responsible for its own advice. Developers face claims too, and employers can be liable for the vendor tools they use in hiring, so a contract with an AI vendor rarely moves the whole risk.

What are the biggest AI risks for businesses?

For most businesses the largest AI liability risks are inaccurate output that customers rely on, discrimination by AI used in decisions about people, AI-enabled fraud and data leakage, errors by agents acting without review, and statements about AI that investors or regulators later call misleading. Which of these matters most depends on how and where the company uses AI.

Which insurance responds to which AI risk?

As a rule, errors and omissions insurance responds to claims that AI output or services caused a client a loss, employment practices liability to discrimination claims over AI used in hiring, D&O to claims against directors over AI oversight and disclosure, and cyber insurance to breaches and data loss. An existing D&O, EPL or E&O policy may be silent on AI or exclude it, which is the gap AI DIC Excess is written for.

What should a company do first about its AI liability risk?

Start with an inventory: list each AI system the company builds, deploys or relies on, and note who could be harmed if it fails, whether customers, employees, investors or business partners. Then read the D&O, EPL and E&O policies for AI exclusions or silence before the next renewal. Mayflower's application asks for an AI system inventory and an AI governance policy or responsible AI framework, so the same work also prepares an application.

Sources

Sources and Dates

Every case, figure and rule on this page links to its source, and each was checked on October 5th 2026. Cases and rules change, so confirm the current position before relying on any one of them.

  1. 1.Regulation (EU) 2024/1689, the Artificial Intelligence Act (Articles 2 and 99). Official Journal of the European Union, via EUR-Lex, July 12th 2024.
  2. 2.Texas HB 149, the Texas Responsible Artificial Intelligence Governance Act, enrolled text. Texas Legislature, signed June 22nd 2025.
  3. 3.Workplace AI regulation in 2026 (Illinois HB 3773 and California automated decision system rules). Epstein Becker Green, September 1st 2026.
  4. 4.Colorado SB 26-189, automated decision-making technology. Colorado General Assembly, signed May 14th 2026.
  5. 5.Automated employment decision tools (NYC Local Law 144). NYC Department of Consumer and Worker Protection, enforced from July 5th 2023.
  6. 6.Securities class action filings surge in the first half of 2026. Cornerstone Research, July 29th 2026.
  7. 7.Moffatt v. Air Canada, 2024 BCCRT 149. Civil Resolution Tribunal of British Columbia, February 14th 2024.
  8. 8.AI Hallucination Cases database. Damien Charlotin, as of October 5th 2026.
  9. 9.Verisk to roll out new general liability exclusions for generative AI exposures. Independent Insurance Agents & Brokers of America, 2025.
  10. 10.The continued proliferation of AI exclusions. Hunton Andrews Kurth, Insurance Recovery Blog, 2025.
  11. 11.Major insurers seek approval to limit liability for AI-related claims (reporting the Financial Times). Insurance Business, November 24th 2025.
  12. 12.Insurers, brokers adjust as AI exclusions emerge. Business Insurance, April 7th 2026.
  13. 13.AI coding tool Replit wiped a database and called it a catastrophic failure. Fortune, July 23rd 2025.
  14. 14.A small number of samples can poison LLMs of any size. Anthropic, with the UK AI Security Institute and the Alan Turing Institute, October 9th 2025.
  15. 15.NYC's AI chatbot tells businesses to break the law. The Markup, March 29th 2024.
  16. 16.Mamdani to kill NYC AI chatbot that was caught telling businesses to break the law. Route Fifty, February 2nd 2026.
  17. 17.Amazon AI coding agent hacked to inject data-wiping commands. BleepingComputer, July 2025.
  18. 18.Mata v. Avianca, Inc., opinion and order on sanctions. US District Court for the Southern District of New York, June 22nd 2023.
  19. 19.Mobley v. Workday, case summary and docket. Civil Rights Litigation Clearinghouse, as of December 2nd 2025.
  20. 20.AI hiring litigation: key lessons for employers. CDF Labor Law, August 27th 2026.
  21. 21.iTutorGroup to pay $365,000 to settle EEOC discriminatory hiring suit. US Equal Employment Opportunity Commission, September 11th 2023.
  22. 22.Samsung bans employee use of ChatGPT after a data leak. Fortune, May 2nd 2023.
  23. 23.Cost of a Data Breach Report 2025: 13% of organizations reported breaches of AI models or applications. IBM, July 30th 2025.
  24. 24.Zero-click AI vulnerability exposes Microsoft 365 Copilot data (EchoLeak, CVE-2025-32711). The Hacker News, June 2025.
  25. 25.Multinational loses HK$200 million to deepfake video conference scam, Hong Kong police say. Hong Kong Free Press, February 5th 2024.
  26. 26.Arup confirms it was the victim of the Hong Kong deepfake fraud. Fortune, May 17th 2024.
  27. 27.Salesforce Agentforce ForcedLeak prompt injection attack. The Register, September 26th 2025.
  28. 28.SEC charges two investment advisers with misleading statements about their use of AI (press release 2024-36). US Securities and Exchange Commission, March 18th 2024.
  29. 29.AI-related securities litigation continues to evolve. The D&O Diary, July 2026.
  30. 30.AI risk disclosures in S&P 500 annual reports. The Conference Board, October 6th 2025.
  31. 31.AI-related securities suit filings continue to surge. The D&O Diary, September 23rd 2026.
  32. 32.In the Matter of Presto Automation Inc., Release No. 33-11352. US Securities and Exchange Commission, January 14th 2025.
  33. 33.SEC files AI-washing enforcement action against restaurant technology company. The D&O Diary, January 2025.
  34. 34.740 ILCS 14/20, Illinois Biometric Information Privacy Act, right of action. Illinois Compiled Statutes, via FindLaw, current as of January 1st 2025.
  35. 35.California district court upholds transparency requirements for generative AI training data (AB 2013). Norton Rose Fulbright, 2026.
  36. 36.Thomson Reuters v. Ross Intelligence, No. 1:20-cv-613-SB, memorandum opinion. US District Court for the District of Delaware, February 11th 2025.
  37. 37.Third Circuit affirms revised fair use ruling against ROSS AI legal research platform in sealed opinion. IPWatchdog, September 30th 2026.
  38. 38.Regulation (EU) 2026/1744, the Digital Omnibus on AI. Official Journal of the European Union, via EUR-Lex, July 24th 2026.
  39. 39.Directive (EU) 2024/2853 on liability for defective products. Official Journal of the European Union, via EUR-Lex, November 18th 2024.
  40. 40.Implementation of the NAIC Model Bulletin on the Use of AI Systems by Insurers. National Association of Insurance Commissioners, status as of April 1st 2026.
  41. 41.FTC finalizes orders with Cox Media Group, two other firms settling charges they deceived customers about “active listening” AI-powered marketing service. US Federal Trade Commission, August 27th 2026.
  42. 42.FTC announces crackdown on deceptive AI claims and schemes (Operation AI Comply). US Federal Trade Commission, September 25th 2024.
  43. 43.FTC reopens and sets aside Rytr final order in response to the Trump administration's AI Action Plan. US Federal Trade Commission, December 22nd 2025.
  44. 44.Robby Starbuck's lawsuit alleging Google AI defamed him can go forward. Reason, The Volokh Conspiracy, July 24th 2026.
  45. 45.Cost of a Data Breach study 2026: one in four malicious breaches are AI-enabled. IBM, July 29th 2026.

Next step

Find Out Which of These Risks Your Program Already Answers

Mayflower provides AI liability coverage for D&O, EPL and E&O exposures, plus an AI DIC Excess layer over the program you already carry, on A- (Excellent) AM Best rated paper. Start a quote online, or talk to us about a specific risk.

Completing the application does not bind coverage. Our underwriting team responds within 48 hours.