Risklytics
Get Insured

Guide

AI liability, explained

Who is liable when an AI system causes a loss: how model providers' terms push liability to deployers, which insurance lines respond, and where AI exclusions change the answer.

The Risklytics team

Who holds the liability

When an AI system causes a loss, three parties are in the frame: the lab that trained the model, the company that deployed it inside a product, and the customer who relied on it. In practice the liability concentrates on the deployer, the company in the middle.

The mechanics are contractual. Model providers' terms of service disclaim liability for how outputs are used and push responsibility downstream to the deployer. The customer's contract, meanwhile, is with the deployer, not the lab. A customer harmed by an AI-driven product sues the company they bought from. Both documents point at the same party.

Courts and regulators are still working out the edges, and the law here will move. But a company deploying AI in production today should assume the claims come to them, because the paper is already written that way.

Which insurance lines respond

Tech E&O is the natural home for AI liability. It responds when your technology's professional work causes a customer financial loss, and a model's decision is professional work. An agent that mishandles a workflow, a model that misprices a transaction, a system that generates faulty output a customer relies on: these are E&O-shaped claims.

Cyber liability responds when the loss runs through security or data: a prompt-injection attack that exfiltrates customer records, a model leaking training data, an agent manipulated into revealing credentials. The boundary between an E&O event and a cyber event can blur in AI systems, which is a reason to place both lines with wording that meets in the middle rather than leaving a gap.

General liability enters when AI causes physical harm, through a robot, a vehicle, or an industrial control decision. Directors and officers coverage responds higher up the stack, when leadership is sued over what they told investors and customers the AI could do.

AI exclusions are the moving part

Every line above was designed before modern AI systems existed, and the insurance market is deciding what to do about that in real time. Some carriers have begun filing AI-specific exclusions; others cover AI risk silently under existing wording; a few are building affirmative AI coverage. The result is that two policies with identical labels can answer the same claim differently.

An exclusion does not announce itself at purchase. It sits in the paper until a claim arrives, and then it controls the outcome. For a company whose product is a model, reading every form before binding is not diligence theater; it is the difference between insured and uninsured, discovered at the worst possible moment.

What deployers should do now

Three practical moves. First, treat your tech E&O and cyber placement as the primary AI liability program and have the forms read for AI exclusions before binding. Second, keep your customer contracts' limitation-of-liability and indemnity clauses consistent with the coverage you actually carry, because a contract that promises more than your policy covers converts the gap into uninsured exposure. Third, document how your system is supervised and evaluated: underwriters price what they can see, and a legible safety story earns better terms.

This page describes coverage in general terms. It is not an offer of insurance, and carrier appetite, policy wording, licensing, and availability govern every quote and every claim.

Common questions

Who is liable when an AI system causes a loss?
In practice, the company that deployed the AI. Model providers' terms push liability downstream to deployers, and the harmed customer's contract is with the deployer, so both the paper and the lawsuit point at the company in the middle.
Does insurance cover AI mistakes?
Tech E&O is the line designed to respond when technology's work causes a customer financial loss, and that includes a model's output. Whether a given policy responds depends on its wording; some carriers have filed AI exclusions, so the form has to be read before it binds.
What is an AI exclusion?
Policy wording that removes coverage for claims arising from artificial intelligence or machine learning. Some carriers have begun filing them into standard technology forms, where they sit unnoticed until a claim arrives and then control whether it is paid.
Is the model provider ever liable for what their model does?
Their terms of service are written to prevent it, disclaiming responsibility for outputs and their use. The law is still developing and the edges will move, but a deployer relying on the model provider absorbing the claim is relying on terms that say the opposite.

This guide describes coverage in general terms. It is not an offer of insurance and not evidence of coverage. Carrier appetite, policy wording, licensing, and availability govern every quote and every claim.