Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

Glossary

Glossary of AI Liability Terms

This glossary gives plain definitions of the AI and insurance terms that appear in AI liability policies, applications and claims, written for risk, legal and finance readers. Where Mayflower Specialty covers a subject in more depth, in a guide or on a coverage page, the entry links to it.

56 terms Updated

Terms Starting With A

Absolute AI exclusion

Insurance

An absolute AI exclusion is policy wording that removes cover for any claim based upon, arising out of or attributable to the use, deployment or development of artificial intelligence by anyone. Its breadth means a claim with only a loose connection to AI can fall outside the policy, which is why such wording deserves close attention at renewal. W. R. Berkley introduced an exclusion of this kind for D&O, E&O and fiduciary liability in 2025.

Related:AI exclusion, Silent AI, Difference in conditions

Agentic AI

AI and technology

Also known as AI agents, Autonomous agents

Agentic AI describes systems that pursue a goal by planning and taking actions themselves, such as calling tools, moving money or changing records, with limited human review of each step. Because an agent acts as well as advises, its mistakes can turn directly into loss; in July 2025 an AI agent on Replit's platform deleted a production database during a code freeze.

Related:Human in the loop, Guardrails, Prompt injection

Aggregate limit

Insurance

The aggregate limit is the most a policy will pay for all covered claims in the policy period combined. Once payments, including defense costs where they sit inside the limit, reach the aggregate, the policy pays nothing more for that period.

Related:Limit of liability, Defense costs within limits, Retention

AI exclusion

Insurance

An AI exclusion is policy wording that removes cover for claims connected to artificial intelligence, ranging from narrow carve-outs for generative AI output to absolute exclusions for any use of AI. Verisk's ISO generative AI exclusions for commercial general liability took effect in January 2026, and similar language has appeared in management and professional liability forms.

Related:Absolute AI exclusion, Silent AI, Affirmative AI coverage

AI governance

Governance and regulation

AI governance is the set of policies, roles and controls a company uses to decide which AI systems it adopts, how they are tested and monitored, and who answers for them when something goes wrong. Underwriters read it as evidence of how likely and how severe an AI claim would be, and Mayflower underwrites on it.

Related:AI system inventory, NIST AI Risk Management Framework, ISO/IEC 42001

AI incident response plan

Governance and regulation

An AI incident response plan sets out how a company detects, escalates, contains and discloses failures of its AI systems, from a biased output to a compromised agent. It is a recommended document in Mayflower's application, and it helps a company give timely notice under a claims made and reported policy.

Related:AI governance, Claims made and reported

How underwriters assess AI risk

AI system inventory

Governance and regulation

An AI system inventory is a register of the AI systems a company builds or uses, recording for each one its purpose, the data it uses, who owns it and how far it can affect people or money. Mayflower's application requires one, because the inventory defines the exposure being insured.

Related:AI governance, Model card, Shadow AI

AI-washing

Governance and regulation

Also known as AI washing

AI-washing is the practice of overstating what a company's artificial intelligence does or how much the company relies on it. Regulators treat such statements as potentially misleading, and the SEC settled its first AI-washing cases, against Delphia and Global Predictions, on March 18th 2024.

Related:Directors and officers liability insurance

Algorithmic discrimination

Governance and regulation

Also known as Algorithmic bias

Algorithmic discrimination is unlawful differential treatment or impact that results from an automated system's output, such as a screening model that disadvantages applicants of a particular age, race or sex. It can arise without any intent to discriminate, because a model can learn proxies for protected traits from historical data.

Related:Disparate impact, Bias audit, Automated employment decision tool

AI-EPL coverageAI in hiring and EPL coverage

AM Best Financial Strength Rating

Insurance

Also known as AM Best rating, FSR

An AM Best Financial Strength Rating is AM Best's independent opinion of an insurer's ability to meet its ongoing insurance obligations. Ratings of A and A- form the “Excellent” category, the second highest on the scale after “Superior”, and Mayflower's coverage is written on A- (Excellent) AM Best rated paper.

About MayflowerBuying AI liability insurance

Automated decision-making technology ADMT

Governance and regulation

Automated decision-making technology is the term California and Colorado use for systems that replace or substantially assist human decisions about people, such as decisions on employment, credit or housing. California's privacy regulator requires compliance with its ADMT rules from January 1st 2027, and Colorado's SB 26-189, signed on May 14th 2026, replaced its 2024 AI Act with a narrower ADMT law whose obligations also start on January 1st 2027.

Related:Automated employment decision tool, Algorithmic discrimination

The AI laws that create liability

Automated employment decision tool AEDT

Governance and regulation

An automated employment decision tool is software that uses machine learning, statistics or AI to score, rank or screen candidates or employees in a way that substantially assists hiring or promotion decisions. New York City's Local Law 144 requires a bias audit within one year before such a tool is used, a public summary of the results and notice to candidates.

Related:Bias audit, Algorithmic discrimination, Employment practices liability insurance

AI-EPL coverageAI in hiring and EPL coverage

Terms Starting With B

Bias audit

Governance and regulation

Also known as Fairness testing

A bias audit is an assessment of whether an AI system's outcomes differ across groups defined by protected characteristics such as sex, race or age, usually by comparing selection or scoring rates. Some laws require one, as New York City does for automated employment decision tools, and Mayflower's application lists bias audit or fairness testing results among its recommended documents.

Related:Automated employment decision tool, Disparate impact, Model drift

AI-EPL coverage

Terms Starting With C

Claims made and reported

Insurance

Also known as Claims-made and reported policy

A claims made and reported policy covers a claim only if it is first made against the insured during the policy period, or any applicable extended reporting period, and is reported within the time the policy requires. Mayflower's AI liability coverage is written on this form, so prompt notice matters as much as the facts of the claim.

Related:Retroactive date, Extended reporting period, Wrongful act

Cyber insurance

Insurance

Cyber insurance covers losses from security and privacy events, such as data breaches, ransomware and network interruption, and the cost of responding to them. It is generally not written for the harm an AI system's output or decision causes without any breach, which is why AI liability coverage is designed to sit beside a cyber policy rather than replace it.

Related:Affirmative AI coverage, Prompt injection, Deepfake

AI liability vs cyber insurance

Terms Starting With D

Data poisoning

AI and technology

Data poisoning is an attack that corrupts the data used to train or fine-tune an AI model so that it learns hidden behavior chosen by the attacker, such as responding to a trigger phrase. Research by Anthropic, the UK AI Security Institute and the Alan Turing Institute published in October 2025 found that about 250 poisoned documents could plant a backdoor in models of 600 million to 13 billion parameters.

Related:Prompt injection, Fine-tuning, Retrieval-augmented generation

Deepfake

AI and technology

A deepfake is synthetic audio, video or imagery generated by AI to impersonate a real person convincingly. In early 2024 an Arup employee in Hong Kong made 15 transfers totaling HK$200 million (about US$25.6 million) after a video call in which fraudsters used fake voices and images of the firm's UK-based chief financial officer.

Related:Cyber insurance, Data poisoning

Defense costs within limits

Insurance

Also known as Eroding limits, Defense inside limits

Defense costs within limits means the cost of defending a claim is paid out of the policy's limit of liability, so legal spending reduces what is left for settlements and judgments and can exhaust the limit. Mayflower's policy form works this way, and defense costs are also subject to the retention.

Related:Limit of liability, Aggregate limit, Retention

Buying AI liability insurance

Deployer

Governance and regulation

A deployer is an organization that uses an AI system under its own authority in its business, as distinct from the developer that built it. The EU AI Act gives deployers obligations of their own, and deployers are often the party a customer or employee sues when an AI decision causes harm.

Related:Developer, EU AI Act high-risk AI system

Developer

Governance and regulation

Also known as Provider

A developer is an organization that builds or substantially modifies an AI model or system and makes it available to others, and the EU AI Act calls this party the provider. A company can be a developer and a deployer at once, for example when it fine-tunes a foundation model and then uses it in its own products.

Related:Deployer, Foundation model, Fine-tuning

Difference in conditions DIC

Insurance

A difference-in-conditions (DIC) policy is written to respond where an underlying policy's terms are narrower than its own, for example because the underlying policy excludes a type of claim, so it fills gaps in cover rather than only adding limit. AI DIC Excess applies the idea to AI: a layer over a company's D&O, EPL and E&O policies that adds affirmative AI coverage where those policies are silent on AI or exclude it.

Related:AI DIC Excess, Excess layer, Drop-down, Follow form

AI DIC Excess coverage

Directors and officers liability insurance D&O

Insurance

Directors and officers liability insurance protects a company's board members and executives, and often the company itself, against claims alleging wrongful acts in running the company, such as securities suits and breach of duty claims. Mayflower's AI Directors and Officers Liability (AI-D&O) module is written for those claims when they arise from the company's use, oversight or disclosure of AI.

Related:AI-washing, Wrongful act

AI-D&O coverageAI and the board: oversight and AI-washingGet a quote for AI-D&O

Disparate impact

Governance and regulation

Disparate impact is a legal theory under which a practice that looks neutral is unlawful if it falls more heavily on a protected group without adequate justification, with no need to prove intent. Executive Order 14281 (April 2025) deprioritized federal disparate-impact enforcement, but private suits over AI screening, such as Mobley v. Workday, continue.

Related:Algorithmic discrimination, Bias audit, Employment practices liability insurance

Terms Starting With E

Employment practices liability insurance EPL

Insurance

Also known as EPLI

Employment practices liability insurance covers an employer against claims by employees and applicants alleging discrimination, harassment, wrongful termination and similar violations of employment law. Mayflower's AI Employment Practices Liability (AI-EPL) module is written for those claims when they arise from AI used in hiring, promotion, discipline and other workforce decisions.

Related:Algorithmic discrimination, Automated employment decision tool, Disparate impact

AI-EPL coverageAI in hiring and EPL coverageGet a quote for AI-EPL

Errors and omissions insurance E&O

Insurance

Also known as Professional liability insurance

Errors and omissions insurance, also called professional liability insurance, covers a business against claims that its professional services or products caused a client a financial loss through error, negligence or failure to perform. Mayflower's AI Professional Liability (AI-E&O) module is written for those claims when an AI-enabled product or service is the cause, such as an inaccurate or hallucinated output.

Related:Hallucination, Wrongful act

EU AI Act high-risk AI system

Governance and regulation

A high-risk AI system under the EU AI Act is one used in a sensitive area listed in Annex III, such as employment, credit or access to essential services, or built into a product that already needs EU safety approval, and it carries the Act's heaviest duties. After the 2026 Digital Omnibus, those duties apply from December 2nd 2027 for Annex III systems and from August 2nd 2028 for product-embedded systems.

Related:Deployer, Developer, Automated decision-making technology

The AI laws that create liability

Excess layer

Insurance

Also known as Excess insurance

An excess layer is a policy that sits above a primary policy, or above other excess layers, and pays only after the limits beneath it are used up. Most excess layers follow the terms of the policy below them, so a gap in the primary wording, such as an AI exclusion, usually carries up through the tower.

Related:Tower, Follow form, Primary policy, Difference in conditions

Extended reporting period ERP

Insurance

Also known as Tail coverage

An extended reporting period is extra time after a claims made policy ends during which claims arising from conduct before the end of the policy can still be reported. Whether one is available, how long it lasts and what it costs are set by the policy.

Related:Claims made and reported, Retroactive date

FAQ: claims after the policy ends

Terms Starting With F

Fine-tuning

AI and technology

Fine-tuning is further training of an existing AI model on a narrower dataset so that it performs a particular task or follows a company's style. Mayflower's application counts a fine-tuned variant as a distinct AI system, because its behavior and risks can differ from the base model.

Related:Foundation model, Developer, Data poisoning

Follow form

Insurance

A follow-form policy adopts the terms, conditions and exclusions of the policy beneath it, adding limit without changing the scope of cover. A follow-form excess policy therefore inherits any AI exclusion in the primary wording.

Related:Excess layer, Difference in conditions, AI exclusion

Foundation model

AI and technology

Also known as General-purpose AI model

A foundation model is a large AI model trained on broad data that can be adapted to many tasks, such as the large language models behind most generative AI products. The EU AI Act calls these general-purpose AI models, and their providers' duties under the Act have applied since August 2nd 2025.

Related:Large language model, Developer, Fine-tuning

The AI laws that create liability

Terms Starting With G

Guardrails

AI and technology

Guardrails are technical and procedural controls that limit what an AI system can say or do, such as input and output filters, restrictions on the tools an agent may call and approval steps for high-value actions. Mayflower's application asks about controls of this kind, including transaction limits and approval gates for agents that can write data or move money.

Related:Agentic AI, Human in the loop, Red teaming

How underwriters assess AI risk

Terms Starting With H

Hallucination

AI and technology

Also known as Confabulation

A hallucination is output from a generative AI model that is fluent and confident but false, such as an invented fact, citation or policy term. NIST's Generative AI Profile calls the problem confabulation, and courts have sanctioned lawyers for filing AI-invented case citations since Mata v. Avianca in June 2023.

Related:Large language model, Retrieval-augmented generation, Errors and omissions insurance

Human in the loop HITL

Governance and regulation

Also known as Human oversight

Human in the loop is a control design in which a designated person can halt, reverse or change an AI system's decision before it takes effect. Mayflower's application defines intervention capability in these terms and asks how far each AI system acts without such review.

Related:Agentic AI, Guardrails, AI governance

How underwriters assess AI risk

Terms Starting With I

Insuring agreement

Insurance

The insuring agreement is the part of a policy that states what the insurer promises to pay for, such as loss arising from a claim for a wrongful act. Definitions, exclusions and conditions then set how far that promise reaches.

Related:Wrongful act, AI exclusion

ISO/IEC 42001

Governance and regulation

ISO/IEC 42001, published on December 18th 2023, is the international standard that sets requirements for establishing, implementing, maintaining and continually improving an AI management system. Mayflower's application lists an ISO 42001 certificate or audit report as a recommended document where a company has one, and the application notes that recommended documents may improve terms.

Related:NIST AI Risk Management Framework, AI governance

How underwriters assess AI risk

Terms Starting With L

Large language model LLM

AI and technology

A large language model is a foundation model trained on large amounts of text to predict and generate language, and it powers chatbots, coding assistants and many AI agents. Its output is probabilistic, so the same prompt can produce different answers, including wrong ones.

Related:Foundation model, Hallucination, Prompt injection

Limit of liability

Insurance

The limit of liability is the most a policy will pay, stated per claim, in the aggregate for the policy period or both. Under Mayflower's policy form, defense costs reduce and may exhaust it.

Related:Aggregate limit, Defense costs within limits, Retention

Loss runs

Insurance

Loss runs are reports from a company's insurers that list the claims made under its policies, with dates, amounts paid and amounts reserved. Mayflower's application requires three years of loss runs for D&O, EPL and E&O.

Related:AI system inventory

Download the application

Terms Starting With M

Model card

Governance and regulation

Also known as Model documentation, Data sheet

A model card is a short document describing an AI model's intended use, training data, performance, known limitations and test results, so that people who rely on the model understand what it can and cannot do. Mayflower's application lists model documentation, model cards or data sheets among its recommended documents.

Related:AI system inventory, Red teaming

Model drift

AI and technology

Model drift is the decline in an AI model's accuracy or fairness over time as the data it meets in production moves away from the data it was trained on. Drift is why underwriters ask how often a model is monitored and retested after deployment, as well as how it performed at launch.

Related:Model risk management, Bias audit

How underwriters assess AI risk

Model risk management MRM

Governance and regulation

Model risk management is the discipline of validating, monitoring and governing the models a firm relies on so that errors or misuse do not cause loss. The Federal Reserve's SR 26-2, issued with the FDIC and OCC on April 17th 2026, superseded SR 11-7 and places generative and agentic AI models outside its scope.

Related:Model drift, AI governance

Terms Starting With N

NIST AI Risk Management Framework AI RMF

Governance and regulation

The NIST AI Risk Management Framework is a voluntary US framework, released on January 26th 2023, that organizes AI risk work into four functions: govern, map, measure and manage. NIST added a Generative AI Profile on July 26th 2024, and Texas's TRAIGA gives a defense to companies that substantially comply with that profile or another recognized risk framework.

Related:ISO/IEC 42001, AI governance

How underwriters assess AI risk

Terms Starting With P

Primary policy

Insurance

A primary policy is the first layer of an insurance program, responding to a covered claim before any excess layer and usually controlling the defense. Mayflower's AI-D&O, AI-EPL and AI-E&O modules can be arranged as a modular primary policy.

Related:Excess layer, Tower

Coverage overview

Prompt injection

AI and technology

Also known as Indirect prompt injection

Prompt injection is an attack in which instructions hidden in user input, or in content an AI system reads such as a web page or email, cause the system to ignore its intended rules. It can lead an assistant or agent to disclose data or take actions its operator never authorized, as in the EchoLeak flaw in Microsoft 365 Copilot that was patched in June 2025.

Related:Data poisoning, Agentic AI, Guardrails

Terms Starting With R

Red teaming

Governance and regulation

Also known as Adversarial testing

Red teaming is structured adversarial testing in which people or tools try to make an AI system fail, misbehave or leak data before attackers or customers find the weakness. The results show an underwriter that a company has looked for the failures that lead to claims.

Related:Guardrails, Prompt injection, Model card

How underwriters assess AI risk

Retention

Insurance

Also known as Self-insured retention, SIR

The retention is the amount the insured pays toward a covered claim before the policy responds, much like a deductible. Under Mayflower's policy form, defense costs are applied against the retention.

Related:Defense costs within limits, Limit of liability

Retrieval-augmented generation RAG

AI and technology

Retrieval-augmented generation is a technique in which an AI model looks up documents from a company's own sources and uses them to answer, which grounds its output in current information. The quality and security of those sources then become part of the system's risk, because poisoned or outdated documents flow straight into its answers.

Related:Hallucination, Data poisoning, Large language model

Retroactive date

Insurance

Also known as Retro date, Prior acts date

The retroactive date is the date before which wrongful acts are not covered under a claims made policy, even when the claim is first made during the policy period. Mayflower's application asks for a proposed retroactive date, and keeping it unchanged at renewal preserves cover for earlier AI decisions.

Related:Claims made and reported, Extended reporting period, Wrongful act

Terms Starting With S

Terms Starting With T

Tower

Insurance

Also known as Insurance program, Tower of coverage

A tower is the stack of policies that together make up a company's limit for one line of cover, starting with the primary policy and rising through excess layers. A gap at the base of the tower, such as an AI exclusion in the primary wording, usually runs all the way up unless a DIC layer fills it.

Related:Primary policy, Excess layer, Difference in conditions

AI DIC Excess coverage

Terms Starting With W

Wrongful act

Insurance

A wrongful act is the conduct that triggers management and professional liability coverage, typically defined as an actual or alleged error, misstatement, omission, neglect or breach of duty. In an AI claim the alleged wrongful act may be a decision delegated to a model, such as an automated rejection or an inaccurate output.

Related:Insuring agreement, Claims made and reported

These definitions are general information, and they are not legal advice or an offer of insurance. The meaning of a term in a particular policy is set by that policy's own definitions and wording.

Next step

Apply the Vocabulary to Your Own Program

The online application asks about the same systems, governance and coverage terms defined here, and a company or its broker can start it at any time and save progress along the way.

Everything submitted with an application is held in confidence, and underwriting responds within 48 hours of a submission.