Skip to content
MAYFLOWER SPECIALTYMayflower Specialty

Fundamentals

Why Companies Using AI Need AI Liability Insurance

Updated 12 minute readBy Mayflower Specialty

AI liability insurance is written to pay the cost of defending and resolving claims that arise from a company's use of artificial intelligence, such as a customer who relied on a chatbot's wrong answer, a job applicant screened out by a biased tool or an investor who says the company overstated its AI. Companies that use AI need it because their directors and officers (D&O), employment practices (EPL), professional liability (E&O) and cyber policies were written before these exposures existed; many say nothing about AI, and insurers have begun adding exclusions that remove AI claims altogether.

What Is AI Liability Insurance?

Definition

AI liability insurance

AI liability insurance is coverage written for claims that customers, applicants, employees, investors or regulators bring because of a company's development or use of artificial intelligence, including defense costs, settlements and judgments. It either adds affirmative AI coverage to lines such as D&O, EPL and E&O or fills the gaps those policies leave when they are silent on AI or exclude it.

The defining feature of AI liability insurance is that its wording addresses AI directly, so whether an AI claim is covered is settled in the policy rather than argued after the loss. Cyber insurance, by contrast, is built around security and privacy events such as ransomware and data breaches, while AI liability insurance answers claims that an AI system's output or decisions harmed someone. AI liability and cyber insurance therefore work as complements, and most companies using AI at scale need both.

How Does AI Create Liability for a Business?

AI creates liability whenever its output or its decisions harm someone who can bring a claim, and the exposure grows with how widely a company uses it. According to Stanford's AI Index 2026, 88% of surveyed organizations used AI in 2025.[1] Documented harm has grown alongside adoption: the AI Incident Database recorded 362 AI incidents in 2025, up from 233 in 2024.[2] The resulting claims follow five patterns, each tending to land on a different line of insurance, so a company should check its own uses of AI against all five.

Wrong or Hallucinated Output

Wrong output can make the company that published it liable in the same way as wrong information on any other page it publishes. On February 14th 2024, in Moffatt v. Air Canada, British Columbia's Civil Resolution Tribunal held Air Canada liable for negligent misrepresentation after its website chatbot gave a customer wrong information about bereavement fares. The tribunal rejected the airline's argument that the chatbot was responsible for its own actions, since it “is still just a part of Air Canada's website,” and ordered the airline to pay C$812.02.[3]

Professional firms face the same risk: Damien Charlotin's public database listed more than 2,100 court decisions worldwide involving AI-hallucinated content as of October 5th 2026,[4] and a firm whose AI-assisted work contains an error can face an ordinary negligence claim. A company should therefore treat what its AI tells customers or clients as its own statement and confirm that its E&O policy does not exclude errors made with AI.

Decisions About People

AI that screens or ranks people creates discrimination exposure, and because one tool touches every applicant it screens, the claims can arrive as class or collective actions. In Mobley v. Workday, a federal court in California allowed disparate impact claims (claims that a practice disproportionately harms a protected group, whatever the intent) against Workday, the vendor of the screening software, to proceed in July 2024. On May 16th 2025 the court preliminarily certified a nationwide collective of applicants aged 40 and over under the Age Discrimination in Employment Act, and the case was still in discovery in August 2026.[5][16]

State law is adding duties as well: since January 1st 2026, Illinois has made it a civil rights violation for an employer to use AI that has a discriminatory effect in employment decisions, and has required employers to tell applicants and employees when AI is used.[6] Claims against the employer fall to its EPL policy, and whether that policy responds to discrimination alleged against licensed software depends on its wording, a question the guide to AI hiring discrimination and EPL examines and one an employer should settle with its broker before a claim arrives.

Autonomous Agents

AI agents raise the stakes because they act rather than advise. In July 2025 an AI coding agent on Replit's platform deleted a live production database during a code freeze, despite instructions not to proceed without human approval, and erased records on more than 1,200 executives and more than 1,190 companies; the user later recovered the data.[7] When an agent makes a costly error for a customer, the claim is likely to run against the business that deployed it, often with no security breach involved. Agent deployment was still in the single digits across nearly all business functions in 2025, according to the AI Index,[1] so most of this exposure lies ahead. A company that gives agents authority over payments, code or customer accounts should limit what they can do without human approval.

AI-Enabled Attacks and Fraud

Attackers use AI too, though most of the resulting loss falls on the company itself rather than on a third party who sues it. In May 2024 the engineering firm Arup was identified as the company that lost about US$25.6 million after an employee in its Hong Kong office joined a video call with deepfakes of its chief financial officer and other staff; Arup confirmed that fake voices and images were used and said that none of its internal systems were compromised.[8] Losses like this belong mainly to cyber and crime insurance, but because no system was compromised, a policy that responds only to a network intrusion may not respond at all. A company should therefore ask its broker which of its policies would answer a deepfake payment fraud.

Statements About Your AI

What a company says about its AI creates securities and regulatory exposure for the company and for its directors and officers. Overstating what a company's AI does, a practice known as AI-washing, has drawn regulators: on March 18th 2024 the SEC announced settled charges against two investment advisers, Delphia and Global Predictions, over false and misleading statements about their use of AI, with civil penalties of $225,000 and $175,000.[9]

Shareholder suits have followed: Cornerstone Research counted 15 AI-related securities class actions in the first half of 2026, “on pace to nearly double the 2025 total,” and AI-related filings made up $385 billion, or 73%, of its Disclosure Dollar Loss Index (the market value lost when alleged misstatements are revealed) for the period.[10] These are the claims a D&O policy exists to answer. A board should therefore have the company's statements about AI checked against what its systems actually do and read each D&O renewal for an AI exclusion, steps the guide to board AI oversight and AI-washing sets out in more detail.

Who Gets Sued When AI Goes Wrong?

The company that deploys an AI system is the party its customers and applicants deal with, so it is usually the first to be sued, but developers, directors and officers, and employers each face claims of their own.

Definition

Deployer

A deployer is a company that uses an AI system in its own business, with customers, employees or decisions about people, whether it built the system or bought it. Most companies that use AI are deployers, and a deployer generally answers to the people its AI affects.

Definition

Developer

A developer is a company that builds an AI system or model, or substantially modifies one, and supplies it to others. Developers face claims from the businesses that buy their products and, as Mobley v. Workday shows, from the people those products affect.

The Air Canada decision shows a tribunal refusing to let a deployer treat its AI as a separate actor that absorbs the blame. A vendor contract may also shift less risk than a buyer expects: where the vendor caps its liability at the fees paid or excludes claims arising from the customer's own data and prompts, the deployer can be left carrying most of a large loss, so a company buying AI should read those clauses before relying on them.

Why Might Existing Insurance Not Cover AI Claims?

Existing insurance may not cover an AI claim for three reasons: many policies say nothing about AI, insurers are adding exclusions that remove AI claims, and cyber insurance is generally triggered by security failures, data breaches and privacy events. A chatbot's wrong advice or a hiring tool's bias involves no breach, so a claim over either may fall outside a cyber policy.

Silent AI

Silent AI is the uncertainty that arises when an insurance policy neither covers nor excludes losses caused by artificial intelligence, which leaves cover to be argued after the loss. A Lloyd's Market Association (LMA) survey that drew 144 responses in the second and third quarters of 2025, 94% of them from underwriters, rated professional indemnity (the London market's term for professional liability) as the class with the highest potential impact from AI loss scenarios, followed by cyber, and the LMA said it could not generalize about coverage without a specific scenario and clause.[11] If the market's own underwriters cannot predict how a silent wording will respond, a policyholder should not assume it will, and should ask for wording that addresses AI one way or the other.

New AI Exclusions

Insurers are increasingly resolving that uncertainty by excluding AI. Verisk's ISO generative AI exclusions for commercial general liability, standard forms that insurers can attach to their policies, took effect in January 2026.[12] The broadest of them, form CG 40 47, removes bodily injury, property damage and personal and advertising injury arising out of generative AI.[13]

In management and professional lines, a large US insurance group introduced an “absolute” AI exclusion for D&O, E&O and fiduciary liability in 2025 that removes any claim “based upon, arising out of, or attributable to” any actual or alleged “use, deployment, or development of Artificial Intelligence,” along with claims over statements about AI.[14][17] A clause like that could take an AI-washing securities claim out of the D&O policy written to answer it, so every renewal form should be checked for AI wording before it is accepted, using the approach in the guide to silent AI and the new AI exclusions.

What Types of AI Liability Coverage Are Available?

AI liability coverage is sold in three forms, and the right one depends on how a company's existing program is built.

  1. Standalone third-party AI policies: These are separate policies written mainly for losses caused by AI output or performance, such as hallucinations. They suit a company whose exposure centers on one AI product, but their boundary with its D&O, EPL and E&O policies needs checking for gaps.
  2. Affirmative AI coverage in management and professional lines: Here the D&O, EPL or E&O wording itself names AI-related claims as covered, which removes the silent AI argument in the lines where many AI claims land.
  3. Difference-in-conditions layers: A difference-in-conditions (DIC) layer sits over the existing policies and is written to respond where they are narrower, for instance where an underlying D&O policy carries an AI exclusion, so the current program stays in place.

Mayflower Specialty provides AI liability insurance in the second and third forms: AI Directors and Officers Liability (AI-D&O), AI Employment Practices Liability (AI-EPL) and AI Professional Liability (AI-E&O), plus an AI DIC Excess layer over an existing tower (the stack of primary and excess policies a company already carries). Mayflower writes on a claims made and reported form, on A- (Excellent) AM Best rated paper (the rating of the insurer that issues the policy) backed by some of the world's largest reinsurers, and its coverage is placed through brokers and underwritten on the applicant's AI governance.

A claims made and reported policy responds only to claims first made and reported within the periods it sets, so AI claims should be reported promptly. Because what any policy covers depends on its wording, a buyer should compare the module descriptions in the coverage overview with its current program before choosing between affirmative cover and a DIC layer.

Which Companies Need AI Liability Insurance Most?

Companies need AI liability insurance most where AI makes or shapes decisions about customers, applicants, employees or investors, and where one mistake can repeat across thousands of people before anyone notices.

AI useTypical exposureLine most likely involved (Mayflower module)
Customer-facing chatbots and assistantsWrong advice and misrepresentationE&O (AI-E&O)
Screening, promotion or termination decisionsDiscrimination claims, including class or collective actionsEPL (AI-EPL)
Statements about AI to investorsSecurities suits and regulatory inquiries over AI-washingD&O (AI-D&O)
AI-assisted professional work, or AI products sold to businessesNegligence claims over errors and failed productsE&O (AI-E&O)
AI agents that act on payments, code or customer accountsErrors at scale, often with no security breachE&O, with cyber for security events
Any of these where a renewal added an AI exclusionA gap in the existing programAI DIC Excess

Company size is a weaker guide than use, since a 50-person company that screens thousands of applicants with AI can carry more exposure than a large company that uses AI only for internal drafting. Companies in regulated sectors, and any company whose renewal has added AI wording, should treat the question as urgent.

What Drives the Cost of AI Liability Insurance?

The cost of AI liability insurance is set case by case, because it depends on how much harm a company's AI could cause, how well the company governs it, its claims history and the limits and retention it chooses (the retention being the share of each claim the company pays itself). Underwriters start with decision materiality, meaning how much a wrong output could matter: an AI that drafts internal summaries carries far less exposure than one that approves loans, screens applicants or advises patients. Scale sets how large a single failure can become, and governance is the evidence that the company knows what AI it uses, tests it for accuracy and bias, keeps a human in the loop for material decisions, monitors it and has a plan for incidents.

Of these factors, governance is the one a company can improve before it applies. Mayflower's application covers AI systems, governance, data governance, operations and monitoring, incident response, regulation and claims history, and it asks for an AI governance policy and an AI system inventory; completing it does not bind coverage. Regulators expect the same discipline from insurers themselves, since the National Association of Insurance Commissioners (NAIC) Model Bulletin on the Use of Artificial Intelligence Systems by Insurers had been adopted by 24 states and the District of Columbia as of April 1st 2026.[15] The guide to how underwriters assess AI risk explains what each part of the application is for, and it is a good idea to assemble the governance policy and inventory before starting, because a company that can show how it governs its AI is easier to underwrite.

How Should a Company Prepare to Buy AI Liability Insurance?

A company preparing to buy AI liability insurance should establish what AI it uses, what its current policies say about AI and what an underwriter will want to see. It is best to start at least three months before the next D&O, EPL or E&O renewal, so that there is time to place affirmative cover if an exclusion appears, and the recommended course of action has four steps.

  1. Inventory AI use: List every AI system the company builds, buys or lets employees use, and mark those that speak to customers, make decisions about people or act without approval.
  2. Read the renewal wording: Ask the broker for every form in the program and check each one for an AI exclusion, an AI definition or an endorsement (an amendment to the policy) that changes how AI claims are treated, starting with D&O.
  3. Run the coverage gap check: Mayflower's coverage gap check shows where the current program may leave AI exposure uncovered, which gives the renewal discussion with the broker a concrete starting point.
  4. Prepare the application: Gather the governance policy, the inventory and any testing, bias audit and incident response records, then apply online or through a broker using the supplemental application; brokers will find placement details on the brokers page.

Above all, a company whose policies are silent on AI should treat that silence as a gap to close rather than as cover it can rely on, because the time to learn how a policy reads is before a claim is made against it.

Frequently Asked Questions

What does AI liability insurance cover?

AI liability insurance covers claims that arise from a company's development or use of AI, including defense costs, settlements and judgments. Typical claims involve wrong or hallucinated output, discrimination by AI used in hiring, costly errors by AI agents and securities claims over statements about a company's AI. Coverage is usually organized by line, such as D&O, EPL and E&O or a difference-in-conditions layer, and what a specific policy covers depends on its wording.

Is AI liability insurance the same as cyber insurance?

AI liability insurance and cyber insurance answer different claims. Cyber insurance is generally triggered by security failures, data breaches and privacy events, while AI liability insurance is written for claims that an AI system's output or decisions harmed someone, which often involve no breach at all, such as a chatbot giving a customer wrong advice or a hiring tool screening out older applicants. Most companies that use AI at scale need both.

Do small companies need AI liability insurance?

Small companies can need AI liability insurance as much as large ones, because the exposure follows how AI is used rather than headcount. A 50-person company whose AI screens thousands of job applicants, or whose product gives customers financial or health information, can face a class action or a regulator's inquiry. A small company that uses AI only for internal drafting has far less exposure and may not need dedicated cover.

Does AI liability insurance cover AI we buy from a vendor?

AI liability insurance can respond to claims involving AI bought from a vendor, which matters because the company that deploys a tool is usually the one its customers and applicants pursue. In Moffatt v. Air Canada (2024), a tribunal held the airline responsible for what its website chatbot told a customer. Whether a policy responds depends on how it defines AI and the insured's activities, so read the wording alongside the vendor contract's liability cap and indemnity.

Is AI insurance required by law?

AI laws such as Illinois's ban on discriminatory AI in employment decisions, in force since January 1st 2026, impose duties on companies rather than a requirement to buy AI liability insurance. They still create the liability the insurance is written for, as do regulators and tribunals: the SEC has penalized misleading statements about AI, and a Canadian tribunal held Air Canada responsible for its chatbot. Customers, lenders or investors may also require it by contract.

How much does AI liability insurance cost?

The cost of AI liability insurance depends on the company's exposure, its AI governance, its claims history and the limits and retention it chooses, so premiums are set case by case. Underwriters look at how material the decisions the AI makes are, how many people or transactions it touches and the evidence that it is tested and monitored. A company with a documented AI inventory, governance policy and incident plan is easier to underwrite.

Sources

  1. [1]The 2026 AI Index Report: Economy, Stanford Institute for Human-Centered Artificial Intelligence
  2. [2]The 2026 AI Index Report: Responsible AI, Stanford Institute for Human-Centered Artificial Intelligence
  3. [3]Moffatt v. Air Canada, 2024 BCCRT 149, Civil Resolution Tribunal of British Columbia, February 14th 2024
  4. [4]AI Hallucination Cases Database, Damien Charlotin, October 5th 2026
  5. [5]Mobley v. Workday, Inc., 3:23-cv-00770 (N.D. Cal.), Civil Rights Litigation Clearinghouse
  6. [6]Illinois Department of Human Rights Withdraws Proposed AI in Employment Rules, Burke, Warren, MacKay & Serritella, P.C., June 16th 2026
  7. [7]AI-powered coding tool wiped out a software company’s database in ‘catastrophic failure’, Fortune, July 23rd 2025
  8. [8]A deepfake ‘CFO’ tricked British design firm Arup in $25 million fraud, Fortune, May 17th 2024
  9. [9]SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence, U.S. Securities and Exchange Commission, March 18th 2024
  10. [10]Securities Class Action Filings Surge in the First Half of 2026, Cornerstone Research, July 29th 2026
  11. [11]Understanding AI Exposures: AI Loss Scenarios Survey Results, Lloyd's Market Association
  12. [12]Insurers, brokers adjust as AI exclusions emerge, Business Insurance, April 7th 2026
  13. [13]Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures, Independent Insurance Agents & Brokers of America, October 21st 2025
  14. [14]The Continued Proliferation of AI Exclusions, Hunton Andrews Kurth, May 28th 2025
  15. [15]Implementation of NAIC Model Bulletin: Use of Artificial Intelligence Systems by Insurers (status as of April 1st 2026), National Association of Insurance Commissioners, April 1st 2026
  16. [16]AI Hiring Litigation: Key Lessons for Employers, CDF Labor Law LLP, August 27th 2026
  17. [17]Insurer Interest in AI Coverage Exclusions Growing as Risk Becomes Omnipresent, Insurance Journal, August 17th 2026

Next step

Put Affirmative AI Coverage in Front of Your Board

Apply online and underwriting will respond within 48 hours, or send a short note if you would rather talk first.