Thought Leadership

Insurance Won't Cover the AI Mistakes You Can't Reconstruct

When autonomous agents alter records or mislead clients, insurance claims hinge on auditability. Here is how to prove what happened.

Insurance is a reconstruction business. A claim is a story with documents: what was promised, what was done, who authorised it, what the policy said would be excluded if the story cannot be told. Artificial intelligence has not repealed that structure. It has made the story harder to tell, because the “person” who drafted the promise or proposed the change may be a system nobody logged.

Boards are asking brokers whether AI is covered. Brokers are asking what AI the company runs. The second question is the one that decides the first. A manuscript endorsement cannot insure a workflow you cannot describe.

The claim you will actually file

Picture two files.

In the first, a customer relied on a website answer and bought the wrong fare, the wrong cover, or the wrong delivery promise. You know this file. Moffatt v. Air Canada is the public miniature: a chatbot contradicted a policy page, the airline argued the bot was a separate entity, and the tribunal held the company responsible for its own website. CBC’s report is short enough to attach to a risk-committee pack. The damages were small. The evidentiary point is not. The passenger had a screenshot. The company had an argument. Screenshot beat argument.

In the second file, an internal assistant proposed a journal, a price, or a customer-record change, and it posted. Weeks later the number is wrong. The operator who clicked has left. The prompt was in a personal tool. The enterprise system shows the new value and not the proposed value. There is no refusal log because refusal was not a state the software could represent. You have an error. You do not have a claim narrative. Insurers are not hostile to errors. They are hostile to voids where a narrative should be.

IBM’s 2025 breach study is the security cousin of the same void. Among organisations that reported an AI-related breach, 97 percent lacked proper AI access controls. One in five reported a shadow-AI breach, associated with hundreds of thousands of dollars in extra average cost — about $670,000 where shadow-AI use was high. A carrier reading that report will not be reassured by a sentence in your submission that says “we have an AI policy.” The underwriter will ask whether access control and logging exist for the systems in scope. If the answer is a steering-committee charter, expect an exclusion, a sublimit, or a question you answer by paying more.

File one: the customer promiseFile two: the internal write
What went outA fare, a cover, a delivery promiseA journal, a price, a customer-record change
The public miniatureAir Canada: screenshot versus “the bot is a separate entity”No famous case. A variance, weeks later, and an operator who has left
What you can produceThe sentence, if you kept itOften only the new value. Not the proposal, not the prompt, not a refusal
What the carrier hearsA story with a documentA void where the narrative should be

What policies already do

Most cyber and professional-liability forms were not drafted with a generative assistant as a named peril. They respond, if they respond, through existing grants: privacy liability, system damage, business interruption, errors and omissions, media liability. Each grant has conditions. Notice. Reasonable security. Sometimes a requirement that the insured maintain backups, access control, or a written information-security programme. An AI system that employees use through personal accounts may sit outside the definition of “computer system” the form uses. A loss caused by a deliberate bypass of your own policy — staff told not to paste client data, staff paste client data — will attract an argument about whether the conduct was authorised.

None of this means “AI is uninsurable.” It means the application is now part of the control environment. Misstatements on applications are their own problem, as the SEC’s AI-washing cases illustrated in a different legal costume: describe a capability you do not have, and the description becomes the exhibit. An insurance application that says AI decisions are human-approved, when the human sees a digest the next day, is a description. Treat it with the same care as a customer claim.

The FTC’s 2023 warning on AI marketing claims is aimed at advertisers. Risk managers should read it as a drafting guide for submissions. Do not say the system prevents errors if it drafts them. Do not say data never leaves the tenant if personal accounts are common. Microsoft’s Work Trend Index found that 78 percent of AI users bring their own tools. If that is roughly true in your workforce, the application must not pretend otherwise.

Grant you might be counting onThe condition that usually sits underneath itWhere an assistant breaks the sentence
Privacy liabilityA computer system you control; reasonable securityThe paste was on a personal account outside the definition
Errors and omissionsA professional service you can describeThe “decision” was a draft nobody approved, described on the application as human-approved
Media liabilityContent you publishedYou cannot produce the sentence, only a paraphrase
Business interruption or system damageA system, a backup, an access-control programmeThe token was a shared administrator with no owner
A new “AI” endorsementWhatever the manuscript actually saysNobody has mapped the endorsement to a grant. It is a brochure

The reconstruction pack

Before the renewal, assemble one incident that did not happen and write it up as if it had. Pick a customer promise and an internal write. For each, produce:

  • The exact output, not a summary.
  • The sources the system was allowed to use, and the version of the policy or price list.
  • The identity of the person who approved, and what they saw.
  • The identity of anyone who could have approved and did not need to.
  • The log retention period.
  • The vendor’s role, and the contract clause that says whether the vendor is a processor, a co-author of the error, or a bystander.

If a page is missing, that page is your real renewal project. ISO/IEC 42001, the AI management-system standard, is one way to organise the work. It will not pay a claim. It will make the exhibit list shorter. NIST’s framework likewise. Standards impress brokers only when the artefacts exist.

Then talk to the broker with the pack, not with a slogan. Ask which grant would respond, which exclusion is the live one, and which wording they have seen carriers add in the last year. The market’s exclusions are moving. Your description should move with evidence, not with anxiety.

Page in the packCustomer promiseInternal writeIf the page is blank
Exact outputThe sentence the customer sawThe payload that postedYou have a summary. Summaries do not win arguments
Source and versionPolicy or price list in force that hourRule the assistant was allowed to useYou cannot show which version spoke
Who approved, and what they sawThe outbound words, or “nobody”The payload, or “nobody”“Human in the loop” is a misstatement if they saw a digest the next day
Who could have approved and did not need toThe design, honestlyThe design, honestlyThis is the segregation-of-duties gap
RetentionHow long the log is keptHow long the log is keptA retention you cannot name is a retention you do not have
Vendor’s roleProcessor, co-author, or bystander, from the contractThe same, for the system that postedA click-through accepted by someone without authority is still a fact

Rehearsing the renewal conversation

Walk into the renewal with a story you can finish, because the alternative is a story the carrier finishes for you.

Start with scope, in plain words. Which jobs may draft. Which jobs may send, post, or pay. Which data is in bounds. If personal accounts are common — and survey evidence says bring-your-own use is the norm among AI users — say so, and describe the substitute you are funding. An application that says “employees use approved tools only” while the help desk tickets say otherwise is a misstatement. Misstatements are how coverage arguments start, before anyone debates an exclusion. Public cases about overstated AI capability are a different forum and the same discipline: describe what is true.

Then show one reconstructed customer promise and one reconstructed internal write, even if both are drills. The output. The source version. The person who saw it before it left, or the honest statement that nobody did. The retention of that record. If the second sentence is “nobody did,” do not hide it behind a project name. Put a date on the fix and assume the grant is narrower until the date. Carriers insure a control environment they can recognise. They do not insure a roadmap.

Ask the questions in writing. Which grant would respond if a customer relied on an assistant’s answer and you made them whole? Which exclusion is the one the claims team would actually reach for? Does the definition of computer system include a vendor you do not host? What happens if the loss flowed through an employee’s personal account after you forbade it? You will not love every answer. You will know which risks are retained, which is the point of buying insurance. A headline endorsement that nobody has mapped to a grant is not a transfer of risk. It is a brochure.

Price the residual on purpose. A refund reserve for the channel that can still speak without a log. A higher retention where access control is immature. The breach data is specific enough to justify the conversation: AI-related compromises were overwhelmingly associated with missing access controls, shadow AI featured in a meaningful share of incidents, and incidents involving heavy shadow use correlated with higher breach cost. You do not need to adopt the vendor’s dollar figure as your number. You need to stop treating the exposure as hypothetical.

A management standard and a risk framework help you organise the exhibit. They are not the exhibit. The exhibit is the log, the approver, and the policy version.

Ask the broker, in writingWhy the answer changes what you buy
Which grant responds if a customer relied on an assistant and you made them whole?Tells you whether the customer-promise file is transferred or retained
Which exclusion would the claims team actually reach for?The live exclusion, not the one in the brochure
Does “computer system” include a vendor you do not host?Personal accounts and unsanctioned tools may sit outside the definition
What if staff pasted data after you forbade it?Authorisation will be argued. The substitute path is part of the answer
What wording have carriers added in the last year?The market is moving. Your description should move with evidence

The page you hand the underwriter

One customer promise and one internal write, reconstructed as if they had gone wrong: the output, the rule version, the person who saw the sentence, the retention, the vendor’s role. Where a page is blank, the blank is the disclosure, with a date you will fill it. Do not let a headline endorsement sit on top of a blank. Personal-account use has to be described as it is, because an application that denies it becomes the exhibit later. Ask which grant responds and which exclusion the claims team would actually pick. Price what remains with you. That price is the honest premium. The rest is stationery. Pay for the story you can finish, and reserve for the one you cannot.

A call to risk officers and chief financial officers

Do not buy a headline endorsement and consider the matter closed. Buy the ability to tell the story. Log the sanctioned assistant. Attribute writes to a named person. Keep the customer-facing answer. Prohibit the paths you cannot reconstruct, and mean it by giving people a path you can.

When the loss comes — a refund wave, a leaked file, a corrupted ledger — the coverage conversation will last as long as the documents do. Companies that kept the documents will argue about policy language. Companies that kept a vibe will argue about whether they were negligent in a way the form does not cover. Only one of those arguments is worth having.


References

About Nimbus

Nimbus is a Collaborative AI Operating System built around four core pillars that bring human teams and autonomous AI together into a single, unified workspace.

Communication: Keep context tied to the job. Unify emails, meeting recordings, transcripts, and operational files directly within active projects—ending knowledge silos buried in private inboxes, scattered Slack threads, or unrecorded calls.

Collaboration: Work alongside AI in real time. Bring people and AI agents onto the exact same brief, visual canvas, or initiative. Query company-wide data, invite agents into live calls, and co-create in one shared space—eliminating the split between human group chats and isolated AI sidebars.

Automation: Put routine workflows on autopilot. Connect more than 2,000 enterprise tools and standardize repetitive operations. Background loops run on schedules or data triggers with full execution logs, ensuring operational knowledge is shared across the team rather than trapped in one person’s head.

Governance: Deploy AI with absolute control. Enforce strict role-based access controls across workspaces. AI agents can analyze, summarize, and draft—but no live system changes or external communications occur without explicit, verified human sign-off.

Short answers

The claim starts with what happened

Why would a policy not respond?

Because the claim file starts with what happened. A chat scroll is not a reconstruction of a changed record or a misleading customer answer.

What do we need on file?

The output, the data it used, the person or rule that approved it, and the system change that followed.

Is this only a legal problem?

It becomes a coverage problem the moment you cannot show the sequence. The apology does not replace the record.

See what governed AI looks like on your stack.

Connect your tools, run a workstream, and keep every decision on your ledger. Start on Free.