AI Risk · Insurance 7 October 2026

Does My Business Insurance
Cover AI Mistakes?

Possibly — but only if you can show you used AI responsibly. Insurers have started writing to their business customers about exactly this, and the advice is the same each time: write an AI usage policy, train your staff, keep track of the AI tools you use, and have a plan for when something goes wrong. Behind that advice sits one question that will decide AI-related claims: did you take reasonable care?

Most businesses now use AI every day, often without a single written rule about how. If something goes wrong, “we were careful” is a claim. This article explains which policy usually responds to which AI risk, what an AI exclusion is, and what reasonable care looks like on paper.

This is general information, not insurance advice. Your broker is the right person to confirm what your own policy covers.

1. What can actually go wrong?

Two risks account for most of the exposure, and both happen in ordinary businesses using ordinary tools.

Wrong output reaches a client

A report, proposal or piece of advice is drafted with help from AI. Someone reviews it, but a fabricated figure or a misread table gets through. The client acts on it and loses money. The client does not care which tool produced the error. They care that your work was wrong.

Sensitive data goes where it should not

An employee pastes customer records, financial figures or a confidential contract into an AI assistant to save time. What happens to that data depends on the tool and the account. The consumer versions of some AI assistants may use conversations to train future models unless the setting is switched off; business and enterprise accounts usually commit not to, by contract. If your staff use personal accounts for work, you may not know which applies — and under the data protection law of almost every country we work in, you remain responsible for the personal data either way.

2. Which insurance policy would respond?

Usually professional indemnity for bad output, and cyber for data incidents. In practice:

  • Professional indemnity is designed for claims that negligent advice or work caused a client financial loss. Whether AI drafted the work does not change the basic question an insurer will ask: was it done with reasonable care?
  • Cyber insurance typically covers data breaches and the cost of dealing with them. Personal data pasted into an unapproved AI tool could become a data incident.

Both depend entirely on your policy wording, and neither is designed to reward a business that had no rules at all.

3. What is an AI exclusion?

It is a clause that removes or limits cover for losses involving AI. As AI use has grown, some insurers have begun adding them, while others have moved the opposite way and now offer cover that names AI explicitly. The market is not settled, which is exactly why you cannot assume.

Ask your broker two direct questions, and get the answers in writing:

  • Does my professional indemnity or cyber policy exclude or limit claims involving AI?
  • If something goes wrong, what will the insurer expect me to show about how we used AI?

4. What does reasonable care look like on paper?

Four documents, kept up to date. They are the same four things insurers are now recommending, and each one turns good intentions into evidence.

  1. An AI usage policy. Which tools are approved, what data can never go into them, and who checks AI-assisted work before it leaves the business.
  2. A staff training record. A policy nobody has read protects no one. Record who was trained, on what, and when.
  3. A record of the AI tools you use. Every tool in use, who uses it, why, and what data it touches. Most businesses that write this list find tools they did not know about.
  4. An AI incident response plan. What staff do in the first hour when AI output is wrong or data goes astray: who to tell, what to preserve, when the insurer needs to hear, and when a regulator has to be told about a personal data breach. That deadline depends on where you operate, and in some countries it is a matter of days.

Without these, “we were careful” is something you say. With them, it is something you can show.

5. What this means where you operate

The insurance question is the same everywhere: can you show reasonable care? What changes from country to country is the law sitting underneath it, and in several markets that law already expects some of these four documents.

  • United Kingdom. Under UK GDPR, a personal data breach that is likely to put people at risk must be reported to the ICO within 72 hours of becoming aware of it. UK AI compliance →
  • European Union. GDPR sets the same 72-hour deadline for reporting to the national data protection authority. Separately, Article 4 of the EU AI Act asks businesses that use AI to take measures to support AI literacy among their staff — and a training record is how you show you did. EU AI Act compliance →
  • United States. There is no single federal AI law, but every state has a data breach notification law with its own deadlines, and a growing number of states regulate specific uses of AI. US AI compliance →
  • Canada. Under PIPEDA, a breach that creates a real risk of significant harm must be reported to the Privacy Commissioner as soon as feasible. Canada AI compliance →
  • Australia and New Zealand. Australia's Notifiable Data Breaches scheme gives you 30 days to assess a suspected breach; New Zealand's Privacy Act requires a notifiable breach to be reported to the Privacy Commissioner as soon as practicable. Australasia AI compliance →
  • The Middle East and the Far East. Singapore requires notification within three calendar days of deciding a breach is notifiable, and the UAE, Saudi Arabia, Japan and South Korea each have data protection laws with reporting rules of their own. Middle East · Far East →

Operating somewhere else, or in several places at once? See every market we cover →

6. Is this just paperwork?

No. The documents change behaviour, and that is what reduces the risk. A clear rule that client data never goes into a free AI tool prevents the data leak. A clear rule that AI-drafted figures are checked against their source prevents the wrong report. The record matters if something goes wrong; the rules matter every working day before then.

What to do this week

  • Ask your broker whether your professional indemnity and cyber policies cover AI-related claims, and whether either has an AI exclusion.
  • Ask your team which AI tools they use for work, including free ones on their phones. Write the list down.
  • Decide what data must never go into any AI tool, and tell everyone.
  • Put the four documents in place, or have them prepared for you.

This article is general information. It is not insurance or legal advice, and what a particular policy covers depends on its wording and on facts specific to that business.

The documents that show reasonable care, written for your business

Every AI Policy pack includes a usage policy tailored to how your business actually uses AI, an AI incident response plan, and a staff training record. The Compliance Review adds a full audit and risk register of the AI tools you use.

See the AI Policy packs →
Call Now See prices