Does Your Business Insurance Cover AI Mistakes?
General liability and cyber cover the wrong things. Most AI errors are professional service errors, which is the one policy a lot of small firms and freelancers never bought.
Probably not the way you assume. Business insurance covers AI mistakes only where the mistake fits a policy you already hold, and the fit is narrower than most owners expect. If AI produces bad work that a client relies on and loses money, that is a professional service failure, and it belongs to professional indemnity cover, also sold as errors and omissions. General liability does not touch it. Cyber cover usually does not either. Professional indemnity is also the policy that small consultancies, agencies and freelancers most often decide they can skip.
This is not legal or insurance advice, and policy wordings vary enormously by insurer and country. What follows is a map of which question to ask about which scenario, so a fifteen minute call with a broker produces a real answer instead of a reassuring one.
Which business insurance policy covers which AI mistakes
Policy | Covers, broadly | Typical AI relevance |
|---|---|---|
General liability | Bodily injury and property damage to third parties | Rarely relevant to a software error |
Professional indemnity / E&O | Financial loss from negligent professional work | Where most AI output failures land |
Cyber | Breach response, extortion, data loss, some interruption | Relevant when data leaks, not when advice is wrong |
Media liability | Defamation, IP infringement in published material | Relevant to generated content and images |
Directors and officers | Claims against individuals for management decisions | Relevant to how you governed AI use, not the output |
The distinction that catches people is between a data problem and an advice problem. Cyber policies are built around incidents: something was accessed, exfiltrated, encrypted. An AI that confidently produced a wrong number in a report is not an incident, it is bad work product, and it goes down a different corridor entirely.
Three scenarios and where they land
Concrete cases make the mapping obvious.
An AI assistant drafts a client deliverable containing a fabricated regulatory citation. The client acts on it and incurs a penalty. This is a professional negligence claim. Professional indemnity is the relevant policy, and the question is whether the wording excludes work produced or assisted by automated systems.
A support chatbot pastes one customer's details into another customer's conversation. This is a data incident. Cyber is the relevant policy, and the question is whether an internal configuration error counts as a covered event or whether the policy requires an external attack.
A generated marketing image reproduces a protected work closely enough to draw a claim. This is media liability or the IP section of your professional indemnity, and the question is whether AI generated material is included in the definition of your content.
On who ends up carrying the cost when it is not clean, the reasoning is set out in who is responsible when AI makes a mistake. Insurance sits downstream of that: it responds to a liability you already have.
Four questions to put to your broker, verbatim
Send these in writing and keep the reply. A written answer from a broker is worth substantially more than a phone reassurance if it ever matters.
1. Does our professional indemnity policy exclude, limit, or treat
differently any work produced or assisted by artificial intelligence
or automated systems? Please quote the relevant wording.
2. If a client suffers financial loss because of an error in output
generated by an AI tool we used, is that a covered claim under the
current policy as written?
3. Does our cyber policy respond to a data exposure caused by our own
misconfiguration of an AI tool, with no external attacker involved?
4. Are AI generated images, text, or code included in the definition of
content for the intellectual property and media sections?Question one is the one that surprises people. Some insurers have added AI exclusions, some have added affirmative AI wording, and a good number have neither and will tell you it is simply untested. All three are useful answers. Not asking is the only bad outcome.
What to fix in contracts, which you control
Insurance is the last line. The cheaper move is not being liable in the first place, and that is a drafting exercise.
Say in the engagement letter that AI tools are used in your process, and what human review is applied before delivery. Disclosed and reviewed is a very different position from discovered later.
Cap liability at fees paid, or a multiple of them, and make sure the cap survives whatever the client's procurement template does to it.
Define the deliverable as reviewed work product, not as raw tool output, so the standard you are held to is the review you actually perform.
Push back on client contracts that warrant output is free of third-party IP claims, which is a warranty nobody can honestly give about generated material.
The mirror image applies upstream, to the terms your AI vendor offers you. Indemnities, liability caps and IP assurances vary widely between providers and are more negotiable than the self-serve signup page implies, which we went through in negotiating a contract with an AI vendor.
The paperwork that helps a claim
If a claim ever happens, the difference between a defensible position and an expensive one is usually evidence that you had a process and followed it.
A written AI usage policy, dated, saying which tools are approved for which work. The template and the decisions behind it are in our guide to writing one.
Review records showing a human checked the output before it went to the client, at whatever level of detail you actually do.
Version history for deliverables, so you can show what was changed and when.
A record of which tool and model produced what, which sounds excessive until the first time someone asks.
The policy document is the cheapest of these and the one that most changes how a claim is framed. Writing an AI usage policy covers what to put in it without turning it into an unread PDF. If a customer-facing tool is in scope, the failure mode to plan for specifically is the one in when an AI chatbot gives a customer wrong information.
Questions
Do I need a special AI insurance policy?
Standalone AI products exist but are early and thinly tested. For most small businesses the practical step is confirming how existing professional indemnity, cyber and media cover respond, and fixing gaps in those, before shopping for something new.
Does my AI vendor's insurance protect me?
Assume not. Vendor terms typically cap liability at a small multiple of fees paid and disclaim responsibility for output. Some offer IP indemnities for generated content, with conditions. Read the specific terms rather than assuming either way.
Will disclosing AI use raise my premium?
It might, and it is still the right call. Non-disclosure of a material change in how you deliver work is the reliable way to have a claim declined later, which is a worse outcome than a higher premium.
What about a solo freelancer with no policy at all?
Then your entire exposure is your contract and your personal assets. Start with a liability cap in your engagement terms, which costs nothing, and price professional indemnity before assuming it is out of reach. It is often less than one project's fee.
Where do I start if I run a small business generally?
Confirm what you already hold, ask the four questions above, and fix the contract terms in parallel since those do not depend on an insurer answering. Our broader guide to AI for small business covers where this sits among the other decisions worth making early.
How did this land?
About the author

Growth & SEO Lead
Manuele covers distribution: SEO, content strategy, and how AI-built products find their first thousand users. He tests everything he recommends.


