AI insurance is still a stack of policies
AI insurance in 2026 spans E&O, cyber, media and specialty cover. Learn which losses trigger each policy and which exclusions create gaps.

Table of Contents
Buying a policy with "AI" in the name does not mean every loss involving a model is insured. In 2026, most companies still transfer AI risk through several policies, each tied to a type of injury, claimant, and legal theory. A false answer that costs a client money points toward technology errors and omissions. A prompt injection that exposes customer records points toward cyber. Copied campaign art may point toward media liability. The same incident can touch all three.
That fragmentation is manageable if you map coverage to real deployments before renewal. It becomes expensive when a founder asks only, "Are we covered for AI?" and accepts a yes. Policy language, endorsements, sublimits, retentions, and the facts in the application decide whether the insurer pays. This article explains the buying logic, but a broker and coverage lawyer must apply it to your wording and jurisdiction.
AI is a cause, not a coverage line
Treat AI as one cause of loss, then identify what was damaged and who alleges harm. Chubb's 2026 guide, Insurance Purchasing in the Age of AI, describes AI as a risk multiplier rather than a standalone peril. That is the right mental model for conventional insurance even though dedicated AI products now exist.
A simple coverage map starts with the claimant. If a customer says your AI service gave negligent advice and caused financial loss, inspect technology E&O or professional liability. If a person says you disclosed personal data, inspect cyber privacy liability and breach response. If a rights owner alleges copyright infringement or defamation, inspect media liability and the IP grant inside E&O. If an employee alleges automated hiring discrimination, inspect employment practices liability. If shareholders allege that directors concealed a material AI failure, inspect D&O.
Do not confuse a model error with an insured loss. A hallucination that an employee catches before publication may create rework, but no third party claim. Most liability policies do not reimburse the ordinary cost of fixing your own bad output. Coverage usually needs a defined claim alleging a defined wrongful act during the covered period, plus damages or defense costs that the policy recognizes.
The date mechanism matters too. E&O, cyber liability, media, D&O, and employment policies commonly use claims made wording. The policy in force when a claim arrives may respond, subject to its retroactive date, prior knowledge terms, and notice rules. A model can fail in March, a customer can discover the loss in October, and counsel can send a demand after renewal. Keep continuity and report circumstances when the contract permits it.
One event can also start parallel claims. Suppose a support bot reveals a customer record, invents a refund promise, and then refuses service based on a protected trait. Privacy, professional negligence, contract, consumer protection, and discrimination allegations may follow. Ask in advance which policy is primary, whether defense costs erode each limit, and how "other insurance" clauses coordinate. Three carriers pointing at one another is not a coverage plan.
E&O covers harmful output only inside defined services
Technology E&O is usually the first policy to test when customers rely on AI output and lose money. It can cover defense and damages arising from an error, omission, negligent act, or failure in an insured technology product or professional service. The exact definitions matter more than the marketing page.
Read the schedule of services as if you were an unfriendly claims examiner. A company described only as "software development consulting" may have trouble when a claim arises from an autonomous procurement agent sold after the application was signed. The schedule should match what customers receive: hosted software, generated recommendations, automated decisions, model integration, data processing, or managed operations. Include material beta products and internal models whose output reaches customers.
Then inspect who or what can commit the wrongful act. Some forms refer to acts by the insured, employees, or people for whom the insured is legally responsible. An insurer may argue that a model is neither a person nor an employee. Better wording ties coverage to an error in the insured product or service regardless of whether a human or model produced the immediate output. Marsh has identified this definition problem in professional indemnity wording, and buyers should resolve it by endorsement rather than by optimism.
Contract language creates another trap. A client contract may promise output accuracy, regulatory compliance, noninfringement, or a service credit. E&O often excludes liability assumed solely by contract, while preserving liability you would have under common law without that promise. If the customer can recover only because your contract offered a broad guarantee, the insurer may reject that part. Compare every material warranty and indemnity with the insurance grant before sales signs it.
E&O also does not equal performance insurance. If your model misses its internal accuracy target and nobody makes a covered claim, ordinary E&O may pay nothing. Munich Re's aiSure products illustrate a different structure: defined model underperformance can be insured after technical review. That is a specific performance transfer, not proof that generic liability wording covers drift, rework, refunds, or lost revenue.
Ask for a written answer to one concrete scenario: "Our model gives a customer a false recommendation; the customer relies on it and demands $750,000 for economic loss. Which insuring agreement responds, and what exclusion could remove it?" Keep the carrier's answer with the submission. It cannot amend the policy, but ambiguity surfaced before binding is easier to negotiate.
Cyber covers a breach mechanism, not every data dispute
Cyber insurance is the natural home for security events, privacy liability, incident response, restoration, and business interruption, but an AI connection does not automatically trigger it. The event still must meet definitions such as security failure, privacy event, unauthorized access, or wrongful disclosure.
Prompt injection provides a clean example. An attacker instructs a customer service agent to ignore its rules and reveal conversation history. If the agent exposes personal information, the event may trigger forensic work, notification, privacy defense, regulatory response, and third party liability under cyber coverage. If the agent merely produces a false price quote, cyber may not respond because no security or privacy trigger occurred. E&O may be the better fit.
Employee use of public models is less clean. An engineer pastes source code and customer data into a public assistant. Whether that is a covered privacy event can turn on what left your control, whether the model provider retained it, whether anyone gained unauthorized access, and how the policy treats voluntary disclosure. Trade secrets and confidential corporate information may sit outside a definition limited to personal information. A cyber policy can be broad on breach response yet silent on the commercial value of leaked code.
Look closely at system definitions. Does "computer system" include cloud models, vendor hosted agents, vector databases, and software as a service used under contract? Does dependent business interruption cover an outage at the model provider you actually use? Does contingent coverage require a complete shutdown, or can severe degradation qualify? AI deployments add vendors quickly, while the application may still describe last year's architecture.
Security conditions can narrow payment after an incident. A policy or endorsement may reduce coverage when the insured failed to maintain controls stated in the application. An absolute promise such as "all sensitive data is blocked from public AI tools" is dangerous if one team has an exception. Answer applications accurately, qualify scope, and document compensating controls. A mistaken warranty can become more damaging than the original missing control.
Cyber also has its own AI enabled threats. Voice cloning can support fraudulent transfer, and synthetic media can damage a company's reputation without breaching its network. In late 2025, Coalition announced a deepfake response endorsement that adds technical, legal, and reputation support. Its existence shows why buyers must separate response expense from indemnity: help authenticating and removing a fake is different from reimbursement for transferred funds or lost sales.
IP wording decides whether defense exists
Intellectual property risk is where broad talk about "AI coverage" becomes most misleading. Copyright, trademark, trade secret, patent, right of publicity, and contract claims do not receive the same treatment. One policy can cover some copyright allegations while excluding patent and trade secret disputes entirely.
Media liability is often the best starting point when the company publishes text, images, audio, advertising, or other content. A media grant may cover copyright infringement, trademark use, defamation, privacy invasion, or misappropriation in defined media activities. Technology E&O sometimes includes a narrower IP grant. General liability once carried more advertising injury exposure, but exclusions and digital activity limits often make it unreliable for a company whose product creates content.
Read the IP exclusion line by line and then read every exception. "Any actual or alleged infringement of intellectual property rights" can erase the apparent promise unless an exception restores copyright or trademark coverage. Patent claims are commonly excluded. Trade secret allegations may be excluded or confined to acts by particular people. Contractual indemnities owed to a model provider or enterprise customer may fall outside the restored coverage.
The U.S. Copyright Office's 2025 report on copyrightability answers a different question. It says AI output can receive copyright protection when a human author determines sufficient expressive elements, while prompts alone usually do not supply enough control. That concerns whether you own protection in an output. It does not decide whether an output infringes somebody else's work, and it does not make an insurer defend that allegation. Ownership and infringement are separate questions.
Vendor indemnity is not a substitute for insurance either. Check whether your model vendor indemnifies output claims, which services and settings qualify, whether you must use filters, and whether caps or exclusions apply. Then check whether your own policy lets the insurer pursue the vendor and whether contractual risk transfer reduces your retention. A promise buried in vendor terms may disappear when a team uses an unsupported model or disables a required control.
Preserve provenance for important output. Record the model and version, prompt context, source material, retrieval results, review decision, and final edits. This will not prevent a claim, but it helps counsel separate copied input, generated output, and human authorship. An insurer deciding whether to defend needs facts, not a screenshot with no history.
A hallucination must become a covered claim
Hallucination liability is not a single cause of action or a universal policy feature. NIST uses the term "confabulation" for confidently presented false content and warns that people may act on it, especially in decisions that demand context or domain expertise. Insurance responds to the legal consequence, not to the model behavior by itself.
Consider a startup that sells an AI assistant to summarize maintenance manuals. The assistant invents a torque value. A customer's technician follows it, a machine fails, production stops, and the customer demands repair cost and lost profit. The claim raises several separate questions: Was the assistant within the scheduled product? Does E&O cover financial loss? Does general liability address damaged tangible property? Does an impaired property exclusion apply? Did a contractual cap or warranty change the alleged liability? Did bodily injury occur?
Change one fact and the coverage changes. If the startup catches the false value in testing, the cost is quality control. If the customer spots it before acting, there may be a demand for a refund but no consequential damage. If the error harms a patient, professional liability and bodily injury exclusions become central. If a user republishes a false accusation about a person, media liability may matter. "Hallucination covered" is too vague to be useful.
Human review helps the risk, but it does not automatically settle coverage. A policy may still respond when a reviewer negligently approves output. Conversely, calling a reviewer "in the loop" on the application while that person approves hundreds of outputs without source access can look like a misrepresentation. Describe the actual authority, workload, escalation rule, and evidence available to reviewers.
Regulatory defense deserves its own question. The EU AI Act transparency duties apply to specified AI interactions and generated or manipulated content from 2 August 2026. Other obligations follow different dates and categories. A policy may cover defense expenses for a regulatory proceeding yet exclude fines, penalties, disgorgement, or the cost of bringing a system into compliance. Local law may also bar insurance for some penalties. Ask about each cost rather than accepting "regulatory cover" as one bucket.
In March 2026, HSB announced AI liability insurance for small businesses aimed at lawsuits involving AI use, including bodily injury, property damage, and advertising injury that some general liability policies exclude. That is evidence of a maturing specialty market. It is not evidence that every AI policy covers hallucination. The insuring agreement still needs a claimant, an alleged act, a loss category, and facts that avoid exclusions.
Other policies have narrow but important jobs
General liability, employment practices, crime, D&O, property, and product recall policies can matter, but none should become a dumping ground for an unmapped AI exposure. Give each policy a defined scenario and check its borders with adjacent coverage.
Commercial general liability can respond to bodily injury or property damage caused by an AI controlled product, subject to product, professional services, cyber, data, and impaired property exclusions. Pure economic loss usually points elsewhere. If software controls a physical device, coordinate the product liability and E&O towers so each carrier understands the full product.
Employment practices liability is the natural place for claims that an AI hiring, promotion, monitoring, or termination tool discriminated against an applicant or employee. Check whether applicants count as insured claimants, whether algorithmic decisions fall within employment acts, and whether regulatory investigations receive defense. The vendor's error does not remove the employer from the claim.
Crime and social engineering endorsements matter when synthetic voice or video persuades an employee to transfer money. Many crime forms distinguish computer fraud, funds transfer fraud, and social engineering. A voluntary transfer induced by deception may fall only under a social engineering endorsement with a smaller sublimit and a verification condition. Deepfake response expenses do not necessarily replace the stolen funds.
D&O can respond when shareholders or regulators allege that directors misrepresented AI capabilities, ignored known defects, or failed to disclose material risk. It does not insure the model's performance. Conduct exclusions, insured versus insured terms, entity coverage, and the point at which an exclusion applies can control the result.
Property and business interruption usually require covered physical loss under their wording. A model outage, bad forecast, or corrupted recommendation may cause revenue loss without that trigger. Cyber business interruption or specialty performance cover may fit better. Product recall policies may help with removal of a physical product but often exclude the cost of correcting software or improving an undamaged product.
Specialty AI cover solves only the named gap
Dedicated AI insurance is worth considering when conventional wording leaves a measurable exposure, but buy it for the gap it names. In 2026 the market includes products aimed at model underperformance, liability from AI use, and specific synthetic media response. These structures do different jobs.
Start by writing the uninsured loss in one sentence. Examples include, "The model falls below the contracted accuracy threshold and we owe service credits," or "A customer alleges bodily injury from advice generated by our internal assistant." A specialty underwriter can accept, narrow, price, or reject that scenario. "All AI risk" cannot be underwritten meaningfully.
Expect technical diligence. An underwriter may ask for model cards, evaluation results, data rights, monitoring, drift thresholds, human review, vendor contracts, incident history, and rollback procedures. Treat this as an engineering review with financial consequences. If nobody can identify the production model version or the person allowed to stop it, the insurance discussion has exposed an operating problem.
Compare specialty cover with the existing tower. Check whether it is primary or excess, whether another insurance clause delays payment, whether defense sits inside the limit, and whether one event can exhaust several sublimits. Confirm territorial scope and which legal entities, contractors, acquired companies, and customer deployments qualify.
Do not pay twice for the same narrow grant while leaving a larger gap untouched. A $250,000 synthetic media response sublimit may be useful, but it does not solve a $5 million E&O exposure from automated financial advice. Rank scenarios by plausible severity, contractual obligation, and ability to mitigate. Insurance belongs after prevention and contract allocation, not in place of them.
Read these exclusions twice
The most dangerous exclusions are ordinary clauses whose interaction removes the expected claim. An explicit AI exclusion is easy to spot. A professional services exclusion inside cyber, paired with a cyber exclusion inside E&O, can leave the same event between policies.
Review at least these provisions against written scenarios:
- The AI, algorithm, or automated decision exclusion, including broad language such as arising out of or related to.
- Intellectual property exclusions and their copyright, trademark, trade secret, patent, and contractual exceptions.
- Privacy, data, cyber, and access or disclosure exclusions in E&O, media, and general liability.
- Professional services, technology services, and product exclusions in cyber and general liability.
- Contractual liability, guarantees, refunds, service credits, liquidated damages, and performance warranties.
Then inspect conduct and compliance terms. Policies often exclude intentional acts, fraud, knowing violations, unlawful collection, or prior known circumstances. The timing of the exclusion matters. Wording that applies only after a final nonappealable adjudication protects defense better than wording triggered by an allegation. Severability determines whether one executive's knowledge affects innocent insureds.
Watch exclusions tied to regulated data, biometric information, employment decisions, consumer credit, health advice, or unapproved uses. If your highest risk deployment sits inside one of those categories, a broad policy elsewhere does not help. Ask for a carveback or a separate policy, and make the endorsement name the activity plainly.
Sublimits deserve the same attention as exclusions. Regulatory defense, social engineering, dependent interruption, reputational response, contractual penalties, and media claims may have smaller limits or separate retentions. Defense costs often reduce the available limit. Build the coverage map with the payable limit, not the number printed on the declarations page.
Finally, read notice, consent, cooperation, and mitigation clauses. Calling forensic counsel, admitting liability, issuing refunds, or signing a settlement before insurer consent can damage recovery. Build the notice path into the incident plan so the operating team does not discover it during a weekend crisis.
Your application must match production
An accurate application is part of coverage architecture. Insurers price the controls and deployments you describe. If production changes materially while the application remains frozen, a claim can turn into an argument about misrepresentation or a failure to notify.
Maintain one AI register that engineering, legal, security, finance, and the broker can all read. It should record customer reliance and potential harm, not just model names. This compact YAML structure is enough to force the right conversation:
use_case: customer support refund recommendations
owner: vp_support
model_provider: contracted_vendor
data: customer_identity_and_order_history
output_reaches_customer: true
customer_can_rely_without_review: false
human_review: required_above_500_usd
worst_plausible_loss: privacy_and_financial_loss
contracts: vendor_terms_and_customer_terms
controls: retrieval_allowlist_output_filter_audit_log
policy_candidate: cyber_and_technology_eo
last_reviewed: 2026_07_15
The register should link internally to evidence, but the insurance submission needs a controlled snapshot. Do not dump privileged legal analysis or security secrets into a broad broker email. Decide what the underwriter needs, answer exactly, and preserve the submitted version alongside the bound policy.
Reconcile the register quarterly and before renewal. New model providers, agents with transaction authority, changed data retention, removed human review, acquisitions, and new countries can alter the exposure. Define who tells risk management when a deployment crosses a threshold. A procurement approval without an insurance update is incomplete when the tool can make customer facing decisions.
At oleg.is, I use a Team & AI Audit to examine team design and AI operations, not to issue a coverage opinion. The insurance benefit is indirect but practical: a company that can name its workflows, owners, controls, and savings can give a broker a coherent risk story instead of vague claims about "using AI everywhere."
Test the claim before you bind
A claim scenario workshop is the fastest way to find gaps because it forces policy language, technical facts, and contracts into the same room. Run it with the founder or CFO, engineering owner, security lead, counsel, and broker. Bring the actual forms and endorsements, not a coverage summary.
Choose four events that reflect production: harmful advice causing customer loss, confidential data disclosed through a model, output accused of infringement, and synthetic media inducing a payment or reputation crisis. For each event, write the claimant, allegation, first known fact, demand, response expense, expected damage, affected entity, territory, and vendor role.
Record the answer in a small matrix with columns for scenario, first policy, trigger, main exclusion, payable limit, notice deadline, and owner. For false customer advice, test Tech E&O, a claim alleging a service error, and the contractual guarantee exclusion. Assign general counsel as owner.
For a prompt data leak, test cyber, the privacy or security event definition, and voluntary disclosure. The security lead should own notice. For a copied campaign image, test media coverage, the copyright grant, IP wording, and prior knowledge. For a cloned executive voice, test both crime and cyber, the deceptive transfer and response triggers, verification conditions, and all sublimits. The CFO should own the payment loss path.
Any cell that says "probably covered" remains open. Ask the broker to cite the insuring agreement, definition, exclusion, endorsement, and limit. Where two policies might respond, ask both carriers how they expect coordination to work. Where neither responds, choose deliberately among an endorsement, specialty cover, contract change, stronger control, lower deployment scope, or retained risk.
Run the same exercise after a material change and at least once before renewal. The goal is not a promise that every claim will be paid. The goal is to remove preventable ambiguity while you still have the power to change the contract, the system, or the insurance.
Frequently Asked Questions
Does general liability insurance cover AI mistakes?
Sometimes, when an AI related event causes bodily injury, property damage, or a covered advertising injury. Professional services, cyber, data, and impaired property exclusions often narrow that answer, while pure financial loss usually points to E&O.
What insurance covers an AI hallucination?
Insurance follows the harm caused by the false output. Technology E&O may address customer financial loss, media liability may address defamation, and general or professional liability may matter for physical or professional injury.
Do I need a standalone AI insurance policy?
Only when a material scenario falls outside your existing policies or when you need defined performance cover. Map the gap first, because a dedicated product can still cover only selected uses, losses, and entities.
Does cyber insurance cover data entered into a public AI tool?
It can, but the answer depends on privacy event, unauthorized disclosure, computer system, and confidential information definitions. Voluntary disclosure language and statements in the application can decide the claim.
Will insurance cover copyright claims from AI output?
Media liability or an IP grant in technology E&O may cover defense and damages for some copyright claims. Read the main IP exclusion and its exceptions because patent, trade secret, and contractual indemnity claims often receive different treatment.
Are AI regulatory fines insured?
Some policies cover defense expenses for regulatory proceedings and certain penalties where law permits insurance. Fines, disgorgement, compliance upgrades, and business changes may remain uninsured, so ask about each cost separately.
Does human review make an AI claim covered?
No. Human review can reduce risk, but coverage still depends on the claim trigger and wording. Describe the actual review process accurately because a nominal approval step can create an application dispute.
What should I disclose on an AI insurance application?
Disclose material uses, customer reliance, data types, model vendors, decision authority, controls, incidents, and planned changes that the questions request. Keep a dated copy and update the broker when the policy requires notice of material changes.
Can a model vendor's indemnity replace insurance?
No. Vendor indemnities have scope conditions, caps, exclusions, and collection risk, and they may not protect your company from every claimant. Coordinate the indemnity with your own policy and preserve the insurer's recovery rights.
How often should a company review AI coverage?
Review it before every renewal and after material deployment changes such as a new provider, sensitive data, transaction authority, or removal of human review. A quarterly register review keeps the insurance submission aligned with production.


