Skip to main content

Who's Liable When Your AI Agent Makes a Bad Call?

7 min readMike ThriftMike Thrift
Who's Liable When Your AI Agent Makes a Bad Call?

A car dealership's chatbot once agreed to sell a brand-new Chevrolet Tahoe for one dollar. A customer talked another retailer's AI assistant into an 80 percent discount, then placed an order worth thousands. And in the case that started it all, a tribunal ordered Air Canada to honor a bereavement-fare discount its chatbot invented out of thin air — the airline's argument that the bot was "a separate legal entity" didn't survive first contact with a judge.

None of those companies wrote a line of the bad code, the false promise, or the discount that never should have existed. They just owned the AI that said it. And in 2026, that's exactly how courts, regulators, and — increasingly — insurers are treating it: if your AI said it, you own it.

That last part is the twist small business owners haven't caught up to yet. Just as agentic AI tools have gotten good enough to actually run parts of a business — quoting prices, answering support tickets, screening job applicants, drafting contracts — the insurance industry has quietly started carving AI-related claims out of the policies business owners assumed would catch them.

The Coverage You Thought You Had Is Changing

For years, most small businesses operated on "silent AI coverage": nothing in a general liability (GL), errors & omissions (E&O), or professional liability policy explicitly mentioned artificial intelligence, so claims involving AI tools were handled like any other claim. If your software made a mistake, your policy generally responded.

That silent era ended in January 2026. The Insurance Services Office (ISO) — the industry body that drafts standard policy language most U.S. carriers build from — introduced two new optional endorsements specifically for generative AI:

  • CG 40 47 is the broad version. It excludes claims under both Coverage A (bodily injury and property damage) and Coverage B (personal and advertising injury) tied to generative AI outputs — defamatory content, IP infringement from AI-generated material, even physical harm if it traces back to an AI-driven error.
  • CG 40 48 is narrower, excluding only Coverage B. It leaves the door open for bodily injury and property damage claims, but still shuts out the advertising- and reputation-related harms that AI mistakes most often cause.

By early 2026, major carriers — including Chubb, Travelers, and Berkshire Hathaway — had already gotten state regulatory approval to add explicit AI exclusions to GL, directors and officers (D&O), and E&O policies. Over 80 percent of carrier requests for these exclusions were approved. That means a policy renewing today may look identical to last year's on the surface while quietly dropping AI-related claims from what it covers.

The timing is the uncomfortable part: roughly 74 percent of small businesses now use AI tools in some capacity, and adoption keeps climbing. Most owners have no idea their renewal already excludes the exact risk they're accumulating the fastest.

What's Actually Falling Into the Gap

The exclusions aren't just about chatbots going viral for the wrong reasons. The liability gap shows up anywhere an AI tool takes an action — or makes a statement — that a customer, employee, or regulator can point back to your business:

  • Pricing and quotes. An AI agent that quotes a price below cost, offers an unauthorized discount, or misstates a policy term. Courts have already ruled a company must honor what its bot promised, even when the promise was wrong.
  • Hiring decisions. An AI resume screener or scheduling agent that produces a biased or discriminatory outcome, exposing the business to an employment claim the underlying policy never priced in.
  • Customer communications. Support agents that give incorrect legal, medical, or financial guidance, or that make representations no human ever approved.
  • Vendor and supply actions. An AI purchasing or routing agent that places an incorrect order, mismanages inventory commitments, or triggers a contract the business didn't intend to enter.
  • Data handling. AI tools that pull in, retain, or expose customer data in ways that violate privacy law — a fast-growing regulatory category on its own.

The common thread: these are consequential damages — lost profits, reputational harm, regulatory fines, data loss — not just the cost of the software subscription. Standard technology contracts typically exclude exactly those categories, and the vendor terms most businesses clicked "accept" on disclaim responsibility for accuracy or fitness for purpose in the first place. That leaves the business holding a risk it didn't fully choose and now can't fully insure through the policy it already has.

What to Do Before Your Next Renewal

You don't need to rip out your AI tools or panic before your policy expires. You do need to stop assuming your existing coverage still says what it said last year.

1. Request a policy audit. Ask your broker to review your current GL, E&O, D&O, and professional liability policies specifically for AI-related endorsements or exclusionary language. If your policy renewed after October 2025, treat that as the point where this needs a second look — that's roughly when the exclusion language started showing up in real renewals.

2. Map where AI actually touches your business. Most owners underestimate this. Go tool by tool: customer service bots, AI-assisted hiring or scheduling, financial modeling or forecasting tools, marketing content generation, AI-driven pricing or inventory systems. Each one is a place a claim could originate.

3. Ask about standalone AI liability coverage. A new market segment is forming specifically to plug this gap. HSB (a Munich Re company) launched an AI Liability Insurance product for small and mid-sized businesses in March 2026, distributed through existing insurance packages, with coverage extending to scenarios like a mispriced AI quote the business has to honor. Standalone products from carriers including Munich Re now offer limits ranging from $2 million to $50 million, with pricing shaped heavily by industry, how intensively you use AI, and how much governance you can document.

4. Put a human in the loop for material decisions. Insurers increasingly price coverage based on governance, not just AI usage. Structured oversight — a human review step before an AI-generated price, contract term, or hiring decision becomes final — is both good risk management and a factor that can meaningfully improve your terms and premium.

5. Document your controls. Bias testing, monitoring logs, an incident escalation policy, and a written AI usage policy all become evidence that you're managing the risk rather than ignoring it — which matters both for underwriting and if a claim ever goes to litigation.

The market itself is still young. As one underwriter put it, there's a lot of people talking about AI insurance and not that many people actually writing the coverage yet. That's an argument for starting the conversation with your broker now, while there's still room to shop terms, rather than after a renewal notice arrives with an exclusion already baked in.

Keep the Financial Record Straight, Whatever the AI Did

When an AI-related dispute does land — a disputed price, a chargeback, a settlement, a new insurance line item — the first thing an insurer, accountant, or lawyer will ask for is a clean paper trail: what was billed, what was refunded, what the policy premium was, and when each entry hit the books. Beancount.io gives you plain-text accounting that keeps that record transparent and version-controlled from day one, so if you ever need to reconstruct exactly what happened financially, the answer isn't buried in a black-box tool. Get started for free and keep your books as auditable as the AI tools you're now trying to insure against.

Share this article