Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

Risk

Who Is Liable When AI Hallucinates? Cases, Exposure and Insurance

Updated 11 minute readBy Mayflower Specialty

When an AI system gives a customer or client wrong information, the company that deployed it is usually held responsible, because the ordinary rules on misrepresentation and negligence can apply to an AI's answers as they do to a website or an employee. A Canadian tribunal applied that reasoning when it held Air Canada liable for its chatbot's advice on February 14th 2024 [1], and a public database now lists more than 2,100 court decisions in which a party relied on AI-hallucinated content, usually fabricated citations [3]. Professional liability (E&O) insurance is the line most likely to respond to these claims, but many E&O wordings are silent on AI and some now exclude it, so the policy wording decides whether a hallucination becomes an insured claim.

What Is an AI Hallucination?

An AI hallucination is content that a generative AI system states with confidence but that is false, such as an invented court case, a misquoted judgment or a refund policy that does not exist. It matters to a business because a hallucinated answer looks as authoritative as a correct one, so customers and staff act on it before anyone notices the error.

Definition

AI hallucination

An AI hallucination is false or fabricated content that a generative AI system presents as fact. The US National Institute of Standards and Technology (NIST) calls the risk “confabulation” and defines it as the production of confidently stated but erroneous or false content by which users may be misled or deceived.

NIST's Generative AI Profile, NIST AI 600-1 (July 2024), describes confabulation as a natural result of how generative models work, since they approximate the patterns in their training data, and warns that systems can also produce “confabulated logic or citations” that make a wrong answer look justified [4]. NIST adds that the problem is particularly relevant to long, open-ended answers and to specialist fields, which are where companies most want AI to save expert time. It is best to treat hallucination as a known characteristic of the technology, to be managed and insured like the other AI risks, rather than as a defect the next model will remove.

Who Is Liable for AI Hallucinations?

The company that deploys an AI system is likely to be held liable for what the system tells its customers, just as it answers for its website and its staff, because the customer dealt with that company and relied on its representations.

In Moffatt v. Air Canada, the airline's website chatbot told a customer that he could claim a bereavement fare retroactively after travel, contradicting the airline's actual policy [2]. Air Canada argued that it could not be held liable for its chatbot's information and that the customer could have found the correct policy elsewhere on its website. The British Columbia Civil Resolution Tribunal rejected both arguments and ordered C$812.02 in damages, interest and fees for negligent misrepresentation, observing that the chatbot “is still just a part of Air Canada's website” and that “It should be obvious to Air Canada that it is responsible for all the information on its website” [1].

Disclaimers can reduce this exposure but are unlikely to remove it. In Walters v. OpenAI, a Georgia trial court granted OpenAI summary judgment (a ruling without a trial) on May 19th 2025; according to OpenAI's counsel, the court accepted that OpenAI warns users about hallucinations and that the user's session was full of signs that the output was unreliable [5].

On July 24th 2026, by contrast, a Delaware court refused to dismiss the commentator Robby Starbuck's AI defamation suit against Google, saying that “A more robust record is necessary to resolve issues regarding the disclaimers” [6]. A disclaimer is therefore best treated as evidence rather than a shield, and it is likely to carry least weight where an ordinary customer relied on the company's answer.

Marketing can create exposure of its own, as DoNotPay found when the Federal Trade Commission finalized an order on January 17th 2025 requiring it to pay $193,000 over allegations that its AI service did not live up to claims that it could substitute for a human lawyer [7].

The recommended course of action for a company deploying AI is to treat every statement an AI system makes to a customer as the company's own, to keep accuracy claims in line with tested performance and to read the indemnity and limitation-of-liability clauses in AI vendor contracts, since they decide whether any loss can be passed back to the vendor.

How Do AI Hallucinations Turn Into Lawsuits and Claims?

AI hallucinations have become lawsuits, court sanctions and refunds by four main routes (customer-facing chatbots, court filings, professional deliverables and defamation), and each route lands on a different part of a company's insurance program.

Customer-Facing Chatbots

The C$812.02 award in Moffatt was small, and a small-claims tribunal's decision does not bind other courts, but the same reasoning could apply to a bank or retailer whose chatbot misstated fees to thousands of customers.

Public bodies have met the same problem: in March 2024 The Markup found that New York City's MyCity chatbot told business owners they could take a cut of workers' tips and that landlords need not accept Section 8 housing vouchers, both contrary to city law [8]. In early 2026 Mayor Zohran Mamdani called the tool “functionally unusable”, said it was “costing the administration around half a million dollars” and announced that it would be taken down [9].

California has also legislated: AB 1609, signed on September 28th 2026 and operative from January 1st 2027, requires businesses with more than $500 million in gross annual revenue nationally to disclose that a customer-service chatbot is not human where a reasonable person is likely to be misled into thinking it is, and to offer a way to reach a human representative [10]. A route to a human is also a useful control against hallucination losses, so it is worth offering one whether or not the law applies.

Court Sanctions for Fabricated Citations

On June 22nd 2023, in Mata v. Avianca, Judge P. Kevin Castel of the Southern District of New York imposed a $5,000 penalty on two lawyers and their firm for a brief citing six cases that ChatGPT had invented [11]. As of October 5th 2026, Damien Charlotin's AI Hallucination Cases database listed 2,149 decisions worldwide in which a party relied on hallucinated content, 1,473 of them in the United States [3].

A company whose outside counsel files invented case law can bear the cost in its own case, so it is a good idea to ask counsel how they check AI-assisted research and to apply the same rule in-house.

Professional Deliverables

In October 2025 Deloitte Australia agreed to partially refund the A$440,000 (about US$290,000) that Australia's Department of Employment and Workplace Relations had paid for a report, after a University of Sydney researcher flagged fabricated references in it [12]. The revised report removed quotes attributed to a federal court judge and references to nonexistent reports, and it disclosed that Azure OpenAI had been used in writing it; Deloitte did not respond when asked whether the errors were generated by AI.

The larger risk for consultants, accountants, lawyers and technology firms is a client who relies on a flawed deliverable and suffers a loss. In a Lloyd's Market Association survey that drew 144 responses in mid-2025, 94% of them from underwriters, professional indemnity (the London market's term for professional liability) was rated the class with the highest potential impact from AI loss scenarios, in a scenario where AI gives clients erroneous advice or service, followed by cyber [13]. A firm that sells advice or reports should therefore check its professional liability wording first.

Defamation by AI

The best-known defamation suits over AI output have targeted AI developers, with mixed results. Walters v. OpenAI, over a ChatGPT answer falsely saying that the radio host Mark Walters had been sued over embezzlement allegations, resulted in summary judgment for OpenAI [5]. Robby Starbuck's suit against Meta settled in August 2025 [14], while his suit against Google survived a motion to dismiss [6].

Wolf River Electric, a Minnesota solar contractor, alleges that Google's AI Overview falsely said it was facing a lawsuit from the state's attorney general [19]. The company has claimed $110 million to $210 million in damages in its initial disclosures [15], and a federal court returned the case to state court in January 2026 [16]. A company that publishes AI-drafted content about real people or businesses is likely to be treated as its publisher and could face the same kind of claim, so a person should check that content before it goes out.

Which Insurance Covers AI Hallucination Claims?

Professional liability (E&O) insurance is the policy most likely to respond when a hallucination causes a client or customer a financial loss, because the claim alleges an error in a service the company provided. The table below sets out the other routes and the obstacles in each.

ScenarioPolicy that usually respondsCommon obstacles
A chatbot gives a customer wrong terms, prices or adviceProfessional liability (E&O), including technology E&ONarrow definition of professional services; AI and chatbot exclusions
AI-assisted advice or a report causes a client lossProfessional liability (E&O)AI exclusions; refunded fees are often not covered loss
A court filing contains fabricated citationsLawyers' professional liabilityFines and sanctions are often excluded from loss
AI-generated content defames a person or businessGeneral liability (personal and advertising injury) or media liabilityISO generative AI exclusions, available from January 2026
A major AI failure leads to claims against directorsDirectors and officers (D&O)Broad AI exclusions in some D&O forms
A hallucination causes loss with no security breachCyber rarely respondsCyber cover is usually triggered by a security failure or data event

Many of these policies were written before generative AI and say nothing about it, a gap known as silent AI (explained in the guide to silent AI and the new AI exclusions), and insurers are now closing that gap with exclusions. In 2025 one large US insurer introduced an “absolute” AI exclusion for D&O, E&O and fiduciary liability that removes cover for claims based on “the generation, creation, or dissemination of any content or communications using Artificial Intelligence” and on “any alleged representations, warranties, promises, or agreements actually or allegedly made by a chatbot or virtual customer service agent”, clauses that match the Deloitte and Moffatt facts closely [17].

Verisk's ISO unit, which drafts standard policy forms used across the US market, has also issued generative AI exclusions for general liability that insurers can attach from January 2026, including forms that remove personal and advertising injury cover, where defamation claims normally sit [18].

Mayflower Specialty writes affirmative AI coverage so that these claims are addressed in the wording rather than argued over after a loss. Its AI Professional Liability (AI-E&O) module is written for claims alleging that AI-assisted services or AI output caused a client or customer loss, which is usually what buyers mean by AI hallucination insurance. The AI DIC Excess layer (DIC means difference in conditions) is written to sit over an existing tower of D&O, EPL and E&O policies and may respond where they exclude or do not address AI. Mayflower's coverage is written on a claims made and reported form on A- (Excellent) AM Best rated paper backed by global reinsurers, placed through brokers and underwritten on the applicant's AI governance.

Whether a particular claim is covered depends on the wording and the facts, so it is best to have a broker compare the current E&O wording with an affirmative AI form before the next renewal.

How Can a Company Reduce AI Hallucination Risk?

A company can reduce its hallucination exposure with four controls: grounded retrieval, factuality checks, human review before output reaches a customer or a court, and prompt and output logging. Underwriters ask about each because together they make errors rarer and the resulting claims easier to defend.

Grounded Retrieval With Citations

Definition

Grounded retrieval

Grounded retrieval is a design in which an AI system answers from a defined set of approved documents, such as a company's policies or product terms, and cites the passage it relied on. It reduces hallucinations because the system draws on checked material rather than generating an answer from its general training data.

In Moffatt the correct policy was published on Air Canada's own website, yet the chatbot contradicted it, and the tribunal found that the airline had not taken reasonable care to ensure its chatbot was accurate [1]. Grounding a chatbot in the company's published terms is the most direct answer to that finding, and it should be the first control behind any customer-facing system.

Factuality Checks

Automated factuality checks compare an answer against its sources and flag claims, figures or citations that cannot be found, so that a fabricated case is caught before it leaves the company. Confirming that every cited authority exists was the step missing in Mata v. Avianca, and any team using AI for legal or research work should make it mandatory.

Human Review Before Output Reaches Customers

Reviewing every chatbot answer is impractical, so review should match the stakes, with a qualified person signing off on anything filed in court or delivered as professional advice. In the Deloitte case an outside researcher found the errors after publication, which is the most expensive point at which to find them.

Definition

Human in the loop

Human in the loop is a control in which a qualified person reviews and approves AI output before it is acted on or reaches a customer, client or court. It places professional accountability for the output on a named reviewer rather than on the system.

Prompt and Output Logging

A record of what the system was asked and what it answered lets a company show exactly what a customer was told and notify its insurer promptly. That matters under a claims made and reported policy, which covers a claim only if it is made and reported within the periods the policy sets, so late reporting can defeat cover.

The guide to how underwriters assess AI risk explains how applications test these controls, and systems that take actions rather than only answer questions need the further safeguards described in agentic AI liability. The recommended approach is to document all four controls before applying, since an underwriter can give more credit to a control that is written down and tested than to one that is only described.

What Should a Company Do About AI Hallucination Liability?

A company that uses generative AI in customer-facing or client-facing work should plan on hallucinations occurring and prepare its operations, contracts and insurance for them before its next renewal.

  1. Map where AI output reaches outsiders: List every chatbot, drafting tool and report workflow, who receives its output and whether a person checks it first, since underwriters will ask for this inventory.
  2. Match controls to the stakes: Put grounded retrieval and logging behind every customer-facing system, and require human sign-off on court filings and professional advice.
  3. Review contracts and marketing: Keep disclaimers accurate without relying on them, align accuracy claims with tested performance and check the indemnity and liability cap in each AI vendor agreement.
  4. Read the insurance wording: Ask your broker to check each policy for AI exclusions, chatbot clauses and the ISO generative AI forms, and to explain how it would treat a claim like Moffatt's or Deloitte's.
  5. Decide on affirmative cover: If the review finds exclusions or silence, consider AI-E&O cover or an AI DIC Excess layer, and assemble the governance documents underwriters will request.

The recommended course of action is to complete the inventory and the insurance review together, because the inventory shows which hallucination claims are realistic and the wording shows which of them are uninsured. It is best to start both well ahead of renewal, while there is still time to arrange affirmative cover if an AI exclusion appears.

Frequently Asked Questions

Can you insure against AI hallucinations?

Claims caused by AI hallucinations can often be insured, but whether a given policy responds depends on its wording. Claims that a hallucination caused a client or customer a financial loss usually fall to professional liability (E&O) insurance, yet many E&O policies say nothing about AI and some now exclude it. Affirmative AI coverage, such as an AI-E&O policy or a DIC layer over an existing program, is written to address these claims expressly.

Is a company liable for what its chatbot says?

A company is likely to be held responsible for what its chatbot tells customers. In Moffatt v. Air Canada (February 14th 2024), a British Columbia tribunal held Air Canada liable for negligent misrepresentation after its chatbot gave a customer wrong bereavement-fare advice, and rejected the airline's argument that it could not be held liable for the chatbot's information. The tribunal said the chatbot was “still just a part of Air Canada's website”.

Does E&O insurance cover AI mistakes?

E&O insurance may cover AI mistakes, depending on the wording. Professional liability is the line most likely to respond when AI-assisted work causes a client loss, but many policies were written before generative AI and say nothing about it, and some insurers have added exclusions for AI-generated content and chatbot statements. Ask your broker to check the definition of professional services and any AI exclusion before renewal.

Are lawyers sanctioned for AI hallucinations in court filings?

Lawyers are regularly sanctioned or reprimanded for filing AI-fabricated citations. In Mata v. Avianca (June 22nd 2023), a New York federal judge imposed a $5,000 penalty on two lawyers and their firm for a brief citing six cases invented by ChatGPT. As of October 5th 2026, Damien Charlotin's AI Hallucination Cases database listed 2,149 decisions worldwide in which a party relied on hallucinated content, 1,473 of them in the United States and 854 involving lawyers.

Can a disclaimer protect a company from liability for AI output?

A disclaimer can reduce liability for AI output but rarely removes it. In Walters v. OpenAI (May 2025), OpenAI's hallucination warnings helped it win summary judgment in a Georgia court, but in Moffatt v. Air Canada the tribunal held the airline responsible for its chatbot's advice and saw no reason customers should have to double-check the chatbot against other parts of the website. Courts weigh who the user was, what warnings they saw and whether their reliance was reasonable.

Sources

  1. [1]Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal of British Columbia, via CanLII, February 14th 2024
  2. [2]BC Tribunal Finds Air Canada Liable for Inaccurate Advice Given by Website Chatbot, Deeth Williams Wall LLP, March 6th 2024
  3. [3]AI Hallucination Cases database (2,149 decisions as of October 5th 2026), Damien Charlotin, October 5th 2026
  4. [4]NIST AI 600-1, Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, National Institute of Standards and Technology, July 26th 2024
  5. [5]Gibson Dunn Wins Significant Victory for Client OpenAI Defending Against Defamation Claim Based on Hallucinated Generative AI Output (Walters v. OpenAI), Gibson Dunn, May 21st 2025
  6. [6]Conservative Commentator Robby Starbuck's Lawsuit Alleging Google AI Had Defamed Him Can Go Forward, Reason, The Volokh Conspiracy, July 24th 2026
  7. [7]DoNotPay: case and proceedings, Federal Trade Commission, January 17th 2025
  8. [8]NYC's AI Chatbot Tells Businesses to Break the Law, The Markup, March 29th 2024
  9. [9]Mamdani to kill NYC AI chatbot that was caught telling businesses to break the law, Route Fifty, February 2nd 2026
  10. [10]AB 1609, customer service chatbots (Chapter 733, Statutes of 2026), California Legislative Information, September 28th 2026
  11. [11]Mata v. Avianca, Inc., No. 22-cv-1461 (S.D.N.Y.), Opinion and Order on Sanctions, U.S. District Court for the Southern District of New York, via CourtListener, June 22nd 2023
  12. [12]Deloitte to partially refund Australian government for report with apparent AI-generated errors, Associated Press, via News4JAX, October 7th 2025
  13. [13]Understanding AI exposures: AI loss scenarios survey results, Lloyd's Market Association
  14. [14]AI libel suit by conservative activist Robby Starbuck against Meta settles, Reason, The Volokh Conspiracy, August 8th 2025
  15. [15]LTL LED, LLC (Wolf River Electric) v. Google LLC, No. 25-cv-2394 (D. Minn.), Notice of Removal, U.S. District Court for the District of Minnesota, via CourtListener, June 9th 2025
  16. [16]LTL LED, LLC (Wolf River Electric) v. Google LLC, No. 25-cv-2394 (D. Minn.), Order granting remand, U.S. District Court for the District of Minnesota, via CourtListener, January 9th 2026
  17. [17]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, May 28th 2025
  18. [18]Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures, Independent Insurance Agents & Brokers of America, October 21st 2025
  19. [19]Minnesota Solar Company Sues Google Over AI Summary, Star Tribune, via Government Technology, June 13th 2025

Next step

Put Affirmative AI Coverage in Front of Your Board

Apply online and underwriting will respond within 48 hours, or send a short note if you would rather talk first.