Skip to content
Go to homepageDrova logo
AI & Innovation

AI risk #55/99: Insured, until the cause is AI

Dozens of lines on a risk register say "insured". Those policies were written when the cause of a loss did not matter. Insurers in Australia, London, the US and Europe are now deciding whether AI changes that.

Rachel Riley portrait
Rachel RileyCFO & Co-founder
1 Oct
A supercell storm over open farmland, with the series marker #55/99 and the words Uninsured AI losses

Open a risk register and count how many lines end on the same word. A professional mistake that costs a client money: insured. A director sued over a decision: insured. Fraud, a supplier failing, a system going down: insured. On most registers it is the reason a line scores low and nobody loses sleep over it.

For decades that was a safe word. A policy paid when something went wrong, and it did not much matter why. The cause could be a tired employee, a bad spreadsheet or a contractor's error. Cover was written around the type of loss, and the cause was the insurer's problem.

AI is now behind more of those losses, and insurers have noticed that they never priced for it. So they are deciding, market by market, whether they will still pay when AI was the cause. The decisions are landing at different speeds in different places, and almost none of them are landing on anyone's register.

 

Four markets, four different answers

 

Australia has not decided. Nick Bezwick, who runs professional indemnity for Newline Australia, told Insurance Business in September that "at the moment we're not seeing a widespread introduction of AI-related exclusions into PI policies". Austin Rosier of OmniShore said much the same in June: "We haven't seen an AI-specific endorsement or standard-form wording emerge yet." That sounds like good news. What it means is that the policy almost certainly says nothing about AI at all, so the question of whether it pays gets asked for the first time on your claim. Lander & Rogers put it to insuranceNEWS in April: insurers are "increasingly signalling that AI-related losses may be foreseeable and avoidable or expressly excluded". Underwriters have started asking at renewal whether a business uses AI or sells it, what the oversight looks like, and whether a person is still the one making the decision.

London is writing the rules now. The Lloyd's Market Association asked 144 people at Lloyd's managing agents, almost all of them underwriters, to rate AI loss scenarios across their lines. Professional indemnity came out on top. The scenario was "AI produces erroneous advice/service to clients, causing a loss", and 58% of the PI underwriters thought such a loss could reach the full policy limit. The same body is now consulting its members on a standard definition of AI that could be written into policies. Lockton's head of cyber and technology insurance, Carlo Ramadoro, expects regulators "sooner or later" to force insurers to say plainly whether AI is covered, the way Lloyd's forced that clarity on cyber from 2020, because AI "could touch every single line of insurance". The International Underwriting Association's director of underwriting, Tom Hughes, said in August: "We're certainly talking about the risk of silent AI." That is the market's own name for cover nobody has decided on. Airmic, the UK body for risk managers, said last October that AI exclusions are "not currently market standard" and told members to check their policies for AI gaps at renewal, before they are.

In the US, some insurers have already said no. The standard US general liability form picked up a generative AI exclusion in January 2026, and some US insurers' wordings now set out to exclude any claim "arising out of any use, development, or deployment of artificial intelligence".

In Europe, from December, you can be sued as if you built it. The EU's revised Product Liability Directive applies to products put on the market after 9 December 2026. Software, including AI, counts as a product. Liability is strict, so the claimant does not have to prove fault. And a business that substantially modifies a product can be treated as its manufacturer. If you build AI into what you sell, or change how it behaves, a new way to be sued arrives in ten weeks, while the cover that would respond to it is being narrowed.

 

Where this lands in your business

 

The register would file all of this under insurance. It belongs under everything the insurance protects. Advice to clients, decisions by directors, payments going out, suppliers you depend on, the service your customers get. Each of those is now partly drafted, checked or decided by software, and each has "insured" written beside it by someone who had no reason to ask about the cause.

Lander & Rogers gave Australian boards the useful version of the question: map where AI "influences decisions and outcomes rather than merely supporting workflow". A tool that drafts an email is workflow. A tool that sets a price, approves a refund, writes the advice a client pays for or decides which complaint gets escalated is making a decision, and a decision is what a policy responds to, or does not.

Aon's September paper on AI in consulting has a line that travels well beyond consulting: "AI risk is outpacing insurance." Insurers will ask harder questions about how AI is governed at the next renewal. The register should have asked them first.

 

Treat "insured" like any other safeguard

 

Every other safeguard on the register has an owner, a check and a date it was last tested. "Insured" usually has none of those. It was written down once and has carried the score ever since.

So give it the same treatment. For each line that scores low because a policy sits behind it, record which policy, and whether anyone has confirmed it responds when AI is involved. There are only three honest answers: yes and the wording says so, no and the exclusion says so, or nobody has checked. Most lines in most businesses would get the third answer today, in Australia and in London alike, and a line nobody has checked is not a low score. It is an unknown one.

As the person who signs the renewals, I would want that third column filled in before "insured" stayed on a single line, and I suspect most CFOs would feel the same once it is put that plainly.

Two things follow. Where the answer is no, the line needs a safeguard that is not a policy: the person who checks AI output before it reaches a client, the limit on what software may decide on its own, the record of who approved what. Where the answer is nobody knows, the broker gets the job of finding out, and the question goes on the agenda for the next review rather than the next claim.

There is a sample report on the Index page if you want to see what it produces before you run your own.

If you want to see which of your objectives those lines sit under, the AI Disruption Index is free and takes about ten minutes. It starts from what the business is trying to achieve, scores the risks AI is driving against each objective, ranks them and drafts a safeguard for every one. It does not read your policies. It will show you which objectives are leaning on them.

Which of your objectives is AI hitting hardest? Free, in about ten minutes.

See which objectives are leaning on a policy