AI Security, Privacy and Compliance

Does Business Insurance Cover Mistakes Made by an AI Tool or AI Agent?

Last updated 23 July 2026 · 5 min read

Direct Answer

Often not automatically, and the gap is widening rather than closing. As of 2026, a growing number of insurers have added explicit AI exclusions to general liability, directors and officers, and traditional errors and omissions (E&O) policies — meaning a claim arising from an AI agent's bad decision, a chatbot's incorrect advice, or an automation sending a wrong invoice can fall outside coverage a business assumed it had. Where affirmative coverage for AI-related mistakes does exist, it's typically found in a technology E&O policy, a cyber policy with AI-related coverage explicitly written in, or a dedicated AI-liability endorsement, not a standard policy by default. This is fast-moving and carrier-specific — ask your broker or insurer directly, in writing, whether your current policies respond to an AI-caused loss, and if not, whether an endorsement or a separate technology E&O policy can close the gap.

Detailed Explanation

A business that has used AI tools or automation for a while without an incident can reasonably assume its existing insurance would respond if something did go wrong — an AI agent sends a wrong invoice, a chatbot gives a customer bad advice that leads to a loss, an automated decision turns out to be discriminatory or incorrect. As of 2026, that assumption is increasingly unsafe.

The core issue is that most general liability, directors and officers, and traditional errors and omissions policies were written well before AI-driven automation became common, and were never designed with this risk in mind. Rather than leaving it ambiguous (what the industry calls "silent AI" coverage — AI risk that's neither explicitly included nor excluded), a growing number of major carriers have moved to add explicit AI exclusions to these policy types, closing the ambiguity in the insurer's favor. The practical effect is that a business relying on a standard general liability or traditional E&O policy may find a claim caused by an AI tool's error falls outside coverage entirely, even if a very similar claim caused by human error would have been covered.

Where affirmative coverage for AI-related mistakes actually exists, it's typically one of a few specific places:

  • A technology errors and omissions (tech E&O) policy — designed around professional and product failures, including software and systems that don't perform as promised, and currently the line most likely to respond to an AI-caused financial loss.
  • A cyber policy with AI coverage explicitly written in — not every cyber policy includes this by default; it depends on the specific carrier and policy language.
  • A dedicated AI-liability endorsement or rider — a growing but still-developing product category, added on top of an existing policy rather than assumed to be included.

None of these are universal or standardized across carriers, and terms are changing quickly as insurers respond to real claims experience. The only way to know what a specific business is actually covered for is to ask the broker or insurer directly, in writing, and get a specific answer about AI-related exposure — not to infer coverage from a policy's general language.

What to Ask Your Broker or Insurer

  • Does our current general liability, D&O, or E&O policy contain an AI exclusion? Ask for the specific exclusion language, not just a yes/no — some exclusions are broader than others, and some apply only to certain types of AI use (e.g., generative AI specifically) rather than automation generally.
  • Would a claim caused by an AI agent's autonomous action be treated differently from a claim caused by a human using an AI tool as an assistant? Some emerging exclusions distinguish between AI as a decision-support tool and AI acting with more autonomy — a distinction worth understanding for how your business actually uses these tools.
  • Is there an affirmative AI-coverage option available — an endorsement, a technology E&O policy, or a cyber policy extension — and what would it cost? Treat the answer as time-sensitive and specific to your carrier; get it in writing and revisit it at each renewal rather than assuming last year's answer still holds.
  • Does our current governance (an employee AI usage policy, vendor DPA review, human review steps) affect underwriting or claims outcomes? Some insurers factor documented AI governance into pricing or claims handling the same way they do general security controls.

Things to Consider

  • This is a fast-moving area — treat any specific coverage detail as time-sensitive. Insurers are actively revising policy language and introducing new AI-specific products; a coverage gap confirmed at last year's renewal may have changed by this year's, in either direction.
  • A confirmed coverage gap is a reason to close it deliberately, not just note it. If your broker confirms your current policies exclude AI-related claims, treat sourcing an endorsement or a technology E&O policy as an active decision, not something to revisit only after a loss occurs.
  • This complements vendor-side risk management, but it's a different layer. Evaluating an AI vendor's data processing agreement and having an employee AI usage policy manage the risk of something going wrong; this page is about what happens financially if it does anyway.
  • Documentation strengthens both governance and any eventual claim. A written AI usage policy, a record of vendor vetting, and evidence of human review steps around consequential AI-assisted decisions all support a claim if one is ever needed, on top of being good practice regardless.

Common Mistakes

  • Assuming an existing general liability or E&O policy automatically covers AI-related mistakes because it covered ordinary human error before. As of 2026, this is exactly the assumption a growing number of policies no longer support — confirm it explicitly rather than inferring it from past coverage.
  • Treating "we have cyber insurance" as equivalent to "we're covered for AI mistakes." Cyber policies are built around data breaches and security incidents; AI-related coverage is a separate question that depends on the specific policy's language, not something a cyber policy automatically includes.
  • Waiting until after an incident to ask what's covered. Confirming coverage — and closing a gap with an endorsement or additional policy if needed — only works before a loss occurs; asking after the fact means finding out the hard way.
  • Assuming the answer from one insurer, one policy type, or one country applies universally. Coverage details vary by carrier, policy wording, and insurance market — get a specific answer for your actual policies rather than relying on a general industry pattern.

Frequently Asked Questions

What's the difference between general liability, cyber, and technology E&O for AI-related mistakes?
General liability covers bodily injury and property damage from a business's operations, and is where insurers have moved fastest to add explicit AI exclusions since it was never designed to cover software errors. A cyber policy is built around data breaches and security incidents, and only some carriers have extended it to cover AI-driven errors specifically. Technology errors and omissions (tech E&O) covers financial loss caused by a professional or product failure — a wrong recommendation, a bad calculation, a system that didn't perform as promised — and, as of 2026, is where affirmative AI-related coverage is most likely to actually exist, though this varies by carrier and by policy wording.
Does APRA or ASIC regulate what AI-related exclusions an Australian insurer can add?
Not directly at the level of individual policy wording — that's a commercial and contractual matter between insurer and insured, and general liability and E&O exclusions aren't something APRA or ASIC pre-approves. What APRA and ASIC do regulate is how APRA-regulated insurers themselves manage AI risk internally: APRA's 2026 Letter to Industry on Artificial Intelligence sets clear expectations for governance, risk management, and board oversight of AI use by banks, insurers, and superannuation trustees, and both regulators have signalled AI-related risk as a supervisory priority. That regulatory pressure on insurers is part of why AI exclusions and new AI-specific products are appearing in the Australian market — but the exclusion itself is still something to confirm policy-by-policy with your broker or insurer, not something a regulator guarantees or forbids.
Does having good AI governance (an employee usage policy, vendor vetting) affect insurance coverage or pricing?
It can, in the same way that general security controls affect cyber-insurance pricing and claims outcomes. An insurer assessing risk — or an adjuster assessing a claim — is likely to look favorably on a business that can show a documented employee AI usage policy (see what should an employee AI usage policy include), a vendor-vetting process, and human review steps around AI-assisted decisions, versus a business with no governance at all. Good governance doesn't substitute for confirming actual coverage, but it can support a claim and may affect underwriting terms.

References

Related Questions