The short answer
When an AI system causes a loss, the claim lands on the company that deployed it. The model provider's terms disclaim responsibility for outputs, and the harmed customer's contract is with the deployer, so both documents point at the company in the middle. Tech E&O is the line that responds to that claim, cyber responds when the loss runs through a breach, and the policy wording, including any AI exclusion added since January 2026, decides whether either one pays.
Who holds the liability
When an AI system causes a loss, three parties are in the frame: the lab that trained the model, the company that deployed it inside a product, and the customer who relied on it. In practice the liability concentrates on the deployer, the company in the middle.
The mechanics are contractual. Model providers' terms of service disclaim liability for how outputs are used and push responsibility downstream to the deployer. The customer's contract, meanwhile, is with the deployer, not the lab. A customer harmed by an AI-driven product sues the company they bought from. Both documents point at the same party.
Courts and regulators are still working out the edges, and the law here will move. But a company deploying AI in production today should assume the claims come to them, because the paper is already written that way.
Which insurance lines respond
Tech E&O is the natural home for AI liability. It responds when your technology's professional work causes a customer financial loss, and a model's decision is professional work. An agent that mishandles a workflow and a model that misprices a transaction both produce E&O-shaped claims.
Cyber liability responds when the loss runs through security or data: a prompt-injection attack that exfiltrates customer records, a model leaking training data, an agent manipulated into revealing credentials. The boundary between an E&O event and a cyber event can blur in AI systems, which is a reason to place both lines with wording that meets in the middle, so a claim cannot fall between them.
General liability enters when AI causes physical harm, through a robot, a vehicle, or an industrial control decision. Directors and officers coverage responds higher up the stack, when leadership is sued over what they told investors and customers the AI could do.
AI exclusions are the moving part
Every line above was designed before modern AI systems existed. The standard-forms bureau's generative AI exclusions for general liability took effect in January 2026 (Independent Agent magazine, 2025-10-21), and a global reinsurer's research note counted more than 80% of the resulting filings approved (2026-08-26). Other policies still cover AI risk silently, and a few insurers now write affirmative AI coverage. Two policies with identical labels can answer the same claim differently.
An exclusion does not announce itself at purchase. It sits in the paper until a claim arrives, and then it controls the outcome. For a company whose product is a model, the form read before binding is the one that decides whether the claim is paid.
What deployers should do now
Treat your tech E&O and cyber placement as the primary AI liability program, and have the forms read for AI exclusions before binding. Keep your customer contracts' limitation-of-liability and indemnity clauses consistent with the coverage you actually carry, because a contract that promises more than your policy covers converts the gap into uninsured exposure. Document how your system is supervised and evaluated, because underwriters price what they can see and a legible safety story earns better terms.
This page describes coverage in general terms. It is not an offer of insurance, and carrier appetite, policy wording, licensing, and availability govern every quote and every claim.
Common questions
Who is liable when an AI system causes a loss?
In practice, the company that deployed the AI. Model providers' terms push liability downstream to deployers, and the harmed customer's contract is with the deployer, so both the paper and the lawsuit point at the company in the middle.
What is an AI exclusion?
Policy wording that removes coverage for claims arising from artificial intelligence or machine learning. Insurers began adopting them on general liability in 2026, and some management and professional forms carry their own. They sit unnoticed until a claim arrives and then control whether it is paid.
Is the model provider ever liable for what their model does?
Their terms of service are written to prevent it, disclaiming responsibility for outputs and their use. The law is still developing and the edges will move, but a deployer relying on the model provider absorbing the claim is relying on terms that say the opposite.
Terms in this guide
Sources
Read next
- Insurance for AI agentsHow to insure an AI agent that takes actions inside customer systems: which lines respond to a wrong action at scale, what tech E&O does and does not do for agents, and what to document before you apply.
- Your renewal added an AI exclusion. Now what?How to read a generative or absolute AI exclusion on a renewal, the steps to take before the renewal date, what a buy-back costs, and where affirmative AI coverage comes from.