Assurance des entreprises et des particuliers · chaque devis vérifié par un producteur agréé
Toutes les publications
RISK MANAGEMENT10 min

The New Business Risks AI Creates — and Who Covers Them

Most small businesses now use AI somewhere in their workflow, and most policies were written before that was true. Here are the five exposures that show up in claims, and where each one lands in your coverage.

Affordable Insurance Center
Producteur agréé
Points clés
  • AI does not create a new category of liability — it creates faster, higher-volume versions of existing ones: professional negligence, IP infringement, discrimination and data breach.
  • Professional liability is the policy most likely to respond when AI-assisted work product is wrong, but only if your professional services definition covers how you actually work.
  • AI-generated content carries real copyright and right-of-publicity exposure, which lives in personal and advertising injury and in media liability.
  • Using AI in hiring or pricing decisions creates discrimination exposure under existing law, covered by employment practices liability — with exclusions worth checking.
  • Deepfake-enabled social engineering is the fastest-growing fraud; check your cyber policy’s funds transfer and social engineering sublimits.

1. Wrong output presented as your work

The core exposure is simple: an AI tool produced something inaccurate, you delivered it to a client, and they relied on it. A miscalculated estimate, a flawed analysis, a contract clause that does not say what you thought, a citation that does not exist.

Legally this is ordinary professional negligence. You are responsible for your work product regardless of the tool that produced it, and "the model generated it" is not a defense to anyone.

Professional liability is the policy that responds — provided your declared professional services match what you are doing. If your E&O describes bookkeeping and you are now delivering AI-generated financial analysis, that is a conversation to have with your broker before a claim, not after.

The control is review. A documented human review step before delivery is both the risk mitigation and the evidence that you had one.

2. Intellectual property in AI-generated content

Two distinct problems. First, output that resembles protected work — images, copy, code — can draw an infringement claim, and the law here is unsettled enough that being sued is realistic even where liability is uncertain. Second, purely AI-generated work may not be protectable by you, which matters when you are selling deliverables a client expects to own.

General liability’s personal and advertising injury covers copyright infringement in your advertising, which is narrower than most people assume. Media liability or a technology E&O policy covers the broader content exposure.

Practical controls: keep records of prompts and human modification, avoid prompting in the style of a named living artist or brand, run reverse image checks on anything you publish commercially, and tell clients in writing what is AI-assisted when the deliverable is content they will register or defend.

3. Discrimination through automated decisions

If you use AI in screening applicants, setting prices, scheduling shifts or evaluating customers, existing anti-discrimination law applies fully. A model that produces disparate outcomes creates the same liability as a manager who does — and several jurisdictions now have specific rules requiring notice and bias auditing for automated employment decision tools.

Employment practices liability is the responsive policy for hiring and employment decisions. Read it for any exclusion around automated decision-making, which some carriers have begun adding.

The mitigation is documentation: know what the tool considers, keep a human decision-maker in the loop with authority to override, and retain records showing the human made the call.

4. Data leakage into tools you do not control

Pasting client data, employee records or confidential material into a consumer AI tool can be a contractual breach and, depending on the data, a regulatory one. Many client agreements and nearly all healthcare, financial and government contracts restrict where data may be processed.

Cyber liability covers breach response and notification; it does not neatly cover a contractual breach you committed voluntarily. This exposure is managed by policy, not by insurance.

Write a short, real AI use policy: which tools are approved, what data may never be entered, and who to ask. One page, acknowledged in writing, beats a prohibition nobody follows.

5. Deepfake-enabled fraud

The fastest-growing loss. Voice cloning and synthetic video have made impersonation of an owner or executive cheap and convincing, and the target is always the same: a wire transfer or a change of payment instructions.

Cyber policies cover this unevenly. Social engineering fraud and funds transfer fraud are frequently sublimited well below the policy limit — $25,000 or $50,000 on a $1 million policy is common. Ask what the sublimit is and buy it up.

The control that actually works costs nothing: a mandatory call-back to a known number for any change to payment details, applied without exception, including when the CEO is on the line and says it is urgent.

What to ask your broker this year

Three questions. Does any policy contain an AI or algorithmic decision exclusion — several carriers have begun adding them. Does my professional liability definition of services cover how the work is now produced. And what are the actual sublimits on social engineering and funds transfer fraud.

The insurance market is moving quickly here. Renewal is the moment to ask, because exclusions get added quietly at renewal and are much harder to remove after a claim.