←
AI for Government
Proficient · M32 · lesson 32 of 50 · queued
Preview — browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll →
Insurance and Liability for Government AI
📖
now learning

Insurance and Liability for Government AI

15 min

Dolores Vance, deputy director of risk and procurement for a mid-sized city, thought she had the AI question covered. The city had bought an AI tool to help triage permit applications, the vendor had a slick demo, and the contract had a signature. Then the city attorney walked into her office holding a claim letter. A contractor whose permit was wrongly rejected by the AI was suing for $400,000 in lost work. Dolores pulled the contract. The vendor's liability was capped at the fees the city had paid them: $25,000. The city's own general liability insurance had an exclusion she had never noticed for "automated decision-making systems." And sovereign immunity, the doctrine that limits when a government can be sued, did not fully apply, because the contractor argued the city had acted negligently in deploying a system it never properly validated.

Dolores was exposed on three sides at once, and the time to fix it had been before signing, not after the claim. This lesson is for senior managers, procurement officers, and program directors who decide whether and how to field AI. We will follow her claim through the three layers of protection a government must understand, contracts, insurance, and immunity, and then work the harder question underneath them: which legal theories actually put an agency on the hook, and what a jurisdiction's own law does to the answer. Nothing here is legal advice. Every conclusion in this lesson depends on the law of your jurisdiction, and the correct next step after reading it is a conversation with your own counsel.

The Three-Layer Shield, and Why Each Has Holes

When AI causes harm, someone is liable. The question is who, and what financial consequence follows. The answer depends on three overlapping shields. Government leaders often assume one of them will hold. Dolores assumed all three would. None did, on its own.

The first shield is the vendor contract, which assigns responsibility between the agency and the company. The second is insurance, which pays claims when responsibility lands on the agency. The third is sovereign immunity, the legal principle that governments cannot be sued without their permission. Each shield has a specific, predictable hole. Liability for government AI is not a single wall; it is three overlapping shields, each with a known gap, and harm flows straight through any gap you forgot to close. Knowing where the holes are is the entire job.

It helps to be honest about what a liability framework can achieve. Perfect protection is not available and never was. What a framework can do is narrower and more useful: allocate risk appropriately among the government, its vendors and the citizens who bear the consequences; create incentives for responsible development and deployment; make sure that people harmed by a system can actually obtain redress; and give the agency a realistic picture of its own financial exposure. An agency that understands its potential liability invests in governance, testing and monitoring. An agency that believes itself protected tends to be careless.

The Legal Theories That Put an Agency on the Hook

AI liability is still an emerging area of law. Most legal frameworks were written before AI became pervasive, so there is genuine uncertainty about how existing doctrines apply, and different jurisdictions are developing different approaches. That uncertainty is not a reason to wait. Several established theories already reach AI systems, and the source material for this lesson sets out six of them. Counting them is the easy part; recognising which one a plaintiff will reach for is the skill.

Negligence is the most common route. If the government failed to exercise reasonable care in developing, testing or deploying a system, it can be liable for the harms that follow. An agency that fields a hiring model without testing it for bias, and then discovers the model is biased, is squarely in this territory. What counts as reasonable care for AI is still being defined by courts and legislators, which is precisely why the working definition matters so much to anyone deploying today.

On current understanding, reasonable care for an AI system likely includes appropriate planning and scoping before deployment; testing for known risks, meaning bias, robustness and security; monitoring and maintenance after deployment; transparency about the model's limitations; and procedures for detecting and remediating problems when they appear. That list is not a safe harbour and no court has certified it as sufficient. It is the current best account of what a reasonable operator does, and its five elements map almost exactly onto what a well-run governance programme produces anyway.

Strict liability attaches in some contexts even where a party exercised reasonable care, typically for activities treated as high-risk. It is possible that future laws will impose strict liability for certain categories of AI harm. Product liability reaches the vendor rather than the agency: where a government uses a third-party model, traditional product liability law may apply, and the vendor may be liable for a defective product even if the agency failed to catch the defect in testing.

Discrimination and civil rights violations deserve their own paragraph. Where an AI system produces outcomes that violate civil rights law, in employment, in race, in any protected category, the source material for this lesson states plainly that the government is liable regardless of intent, and that a claimant does not have to establish that the system was negligently built, only that discrimination occurred. Carry that as stated. It errs on the side of exposure and citizen protection, and an agency that plans around it will not be surprised. Whether a particular claim in a particular jurisdiction actually works that way is a question for counsel, not for a lesson.

Administrative law violations are the theory agencies forget. Many jurisdictions require an agency to follow specific procedures before making decisions that affect citizens, from public notice and comment through impact assessments. Deploying an AI system without following those procedures can create liability entirely independent of whether the system caused any harm at all. Breach of contract runs the other direction: when a vendor delivers a model that does not meet specification, the agency's claim against the vendor is how it recovers.

Shield One: The Contract and the Indemnification Trap

The most important liability term in an AI contract is indemnification, a contractual promise by one party to cover the other's losses. A clause might read that the vendor will indemnify the government for all losses arising from defects in the model. Dolores's contract had the allocation backwards from the city's perspective. The vendor's total liability was capped at fees paid, $25,000, a common vendor position. So when a $400,000 claim arrived, the vendor's maximum exposure covered about six cents on the dollar and the rest fell on the city.

Indemnification is valuable, and it is also weaker than it reads. Four limits recur. Vendor solvency: if the company goes out of business, the promise is worthless. Scope: a clause may cover direct damages but not reputational harm or lost revenue. Caps: indemnification is frequently capped, often at the contract value, and once damages exceed the cap the vendor's obligation ends. Exclusions: many clauses carve out whole classes of harm, and a carve-out for damages to third parties removes exactly the harm a government most fears, the injury to a resident.

The practical fix is specific. Push for the vendor to indemnify the agency for harms caused by the AI's defects, bias or failure to perform as represented. Resist liability caps set at contract value; for a rights-impacting system the potential harm dwarfs the fee. Require the vendor to carry its own insurance, with the agency named as an additional insured. And read the exclusions before you read the promise, because the exclusions are where the promise actually ends.

Indemnification is only one of the instruments available. A warranty commits the vendor to specifications for accuracy, fairness and security, and gives the agency the right to reject or demand repair when the model misses them. A limitation of liability clause caps exposure for either party and is the term to negotiate hardest. Insurance requirements obligate the vendor to maintain cover for defined risks. Escrow holds back a percentage of payments and releases them only if the model performs over a stated period. A performance bond can be claimed if the vendor fails to deliver a quality system. Each is a lever, and none of them can be added after award.

Who Should Bear the Risk, and What Each Choice Does

How risk is allocated between government and vendor is not a legal detail. It shapes behaviour on both sides, and the two extremes both fail in predictable ways.

AllocationGovernment behaviourVendor behaviourEffect on citizens
Government bears all riskStrong incentive to test and monitorWeak incentive to invest in quality, since it is not liable; models offered at lower costProtected only by government diligence
Vendor bears all riskRisk of complacency, assuming the vendor has handled itStrong incentive to invest in quality; prices rise to cover liabilityProtected by vendor incentives, but only while the vendor is solvent
Shared, the workable middleCommits to reasonable due diligence: testing, monitoring, governanceIndemnifies for defects that reasonable diligence would not have caughtProtected by two parties who both have something to lose

The middle row is the target. Note what it asks of the agency: the government's side of the bargain is not a signature, it is the diligence itself. An agency that negotiates a strong indemnity and then skips testing has bought a clause it may not be able to rely on, because the vendor's obligation was scoped to defects that diligence would have missed, and diligence that never happened misses everything.

Shield Two: Insurance and the Exclusion You Did Not Read

Dolores's second surprise was the exclusion. Many traditional government policies, general liability, errors and omissions, and cyber, were written before AI was common. Some now carry explicit exclusions for automated or algorithmic decision-making, and others simply do not contemplate AI harms at all. A policy you assumed covered this may quietly not, and you will find out at the worst possible moment.

There is a structural reason insurance fits AI badly. Insurance works by pooling risk across many similar entities and pricing premiums from actuarial data. AI harms are novel, hard to predict and potentially catastrophic, and insurers struggle to price risks they do not yet understand. That is not a reason to skip the conversation. It is the reason to have it early, in writing, and with specifics.

Several routes exist, with real limits on each. Cyber liability policies sometimes cover AI harms, particularly where the harm flows from a security breach or data manipulation. Errors and omissions cover claims that the organisation made mistakes that caused harm, and some governments are obtaining errors and omissions cover that reaches AI system failures. Specialised AI liability insurance is beginning to appear from a small number of insurers, covering harms from bias, discrimination or malfunction; availability is limited and premiums are high. Self-insurance, setting aside reserves rather than buying a policy, works only for an organisation large enough to absorb a significant loss. Consortium purchasing, where several governments buy collectively, reduces cost through scale.

The practical step is a coverage review with your insurer or risk pool before deploying, built around one blunt question: if our AI system causes a wrongful decision that harms a person, does this policy pay? Get the answer in writing. Where coverage is missing, the options are an endorsement that adds AI cover, a specialised technology errors-and-omissions policy, or shifting the risk to the vendor's insurance. Insurance also does something contracts cannot: insurers have real expertise in assessing risk, they provide a reliable source of funds when a claim lands, and they have their own incentive to reduce risk, which usually shows up as better pricing for better governance.

Shield Three: Sovereign Immunity Is Not a Force Field

Sovereign immunity holds that the government, or the Crown in Commonwealth countries, cannot be sued without permission. The theory is that the government's authority derives from the people's sovereignty and a sovereign cannot be sued in its own courts. It varies enormously by jurisdiction and by context: nearly absolute in some places, narrowly limited in others. Government leaders often treat it as a complete defence. It is not.

Most jurisdictions have carved out exceptions, and four recur. Waiver: a government can waive immunity for specific claims or specific counterparties, which is routine in procurement, where a contract may provide that both parties can be sued for breach. Tort claims acts: many jurisdictions have passed statutes waiving immunity for tort claims such as negligence, usually up to a cap set by that statute. The cap is a number you must read out of your own jurisdiction's act; there is no general figure and this lesson will not supply one. Constitutional rights violations: in many jurisdictions a person whose constitutional rights were violated can sue despite immunity, which frequently covers discrimination claims. Non-sovereign functions: when a government acts in a proprietary capacity, more like a business than a government, immunity may not apply to claims arising from that activity.

Immunity typically protects discretionary policy decisions, and it often does not protect operational negligence, meaning the failure to do a basic job competently. The contractor's lawyer in Dolores's case did not argue that the city had no right to use AI. He argued that the city had deployed a decision-making system without validating it, monitoring it or providing human review, and that this was negligence rather than protected discretion. The distinction is where most government AI claims will be fought.

What that means in practice is that immunity rewards diligence and thins out around carelessness. An agency that tests its AI, documents the testing, monitors performance and keeps a human in the loop on consequential decisions stands on firmer ground. Records of responsible deployment strengthen the agency's position in both immunity and insurance arguments. They are evidence of diligence, not a guarantee of any outcome, and no court is obliged to be persuaded by a well-kept file. The agency that deploys a black box and hopes converts a discretionary choice into an operational failure, and immunity is thinnest exactly there.

Working out how immunity applies in your jurisdiction is not academic. It determines whether citizens can sue your agency for AI harms, whether vendors can sue you over contract disputes, what insurance is available and what it will cover, and therefore which contractual protections you actually need. Those four answers change the whole design of your programme, and only your legal team can give them to you.

Disclosure as a Liability Instrument

Governments are increasingly requiring vendors to disclose information about their models, and the requirement does more than satisfy curiosity. Disclosure lets the agency assess whether a model is suitable for its intended use. It fixes who knew what, which is often decisive when harm occurs and liability has to be apportioned. It creates accountability, because a vendor whose documentation is public has a reason to keep quality up. And it lets citizens and advocates see how the systems that affect them actually work.

The disclosures that carry weight are concrete: model documentation covering what the system does, what it was trained on and what its limitations are; performance metrics, including how the model performs across different populations rather than only in aggregate; training data documentation describing provenance and likely biases; risk assessments setting out what could go wrong and how likely harm is; the mitigation measures in place; and the monitoring and maintenance plan for after deployment. Each of these is also, not coincidentally, a document you would want in hand if a claim ever arrived.

Three Claims and Where They Land

Abstract doctrine gets clearer when a claim is actually working its way through it. Three scenarios, drawn from the recurring patterns in government AI, show how the theories and shields interact.

A benefits system with a regional skew. A social benefits agency deployed a model to flag which applicants needed additional verification, trained on the agency's own historical decisions. An audit later showed the model rejecting applications from one region far more often than legitimate factors justified. Citizens sued, claiming discrimination.

The liability questions then run in sequence. Was the agency negligent? There was no evidence it had ever tested for regional bias, which strengthens the negligence claim considerably. Did the model discriminate? Statistically, yes, and discrimination liability does not turn on intent or care. Could the agency claim immunity? In most jurisdictions, the source material states, no: immunity is waived for discrimination claims or for torts generally. Who pays? The government, which means taxpayers. Could the vendor be liable? That depends on what the vendor knew. A vendor that tested for bias, found it and did not disclose it may be exposed under product liability or fraud; a vendor that never tested may be exposed for negligence.

Two further points make that case worth sitting with. Neither government insolvency nor sovereign immunity protects citizens from seeking damages, because courts have mechanisms to compel a government to pay, including budget allocations. And vendor indemnification only helps if the vendor is solvent and if the clause actually covers discrimination claims, which many do not. The real lesson is that the investment belongs before deployment, not after harm.

A vendor that missed its own specification. An immigration agency contracted for a model to help officers prioritise visa applications, with a contractual specification of 90 percent accuracy. The delivered model appeared to meet it. Six months after deployment, independent testing found significant performance gaps for applications from certain countries, where actual accuracy was 72 percent.

Did the vendor breach its warranty? It promised 90 percent and did not achieve it for all populations. The contract did not require accuracy to be uniform across populations, which is itself the drafting lesson. The source material argues that the implied warranty of merchantability, the expectation that a product will do what it is supposed to do, is breached here. Treat that as a claim the agency may be able to make rather than one it can count on: implied warranties vary by jurisdiction and can be disclaimed by contract, and an express, measurable performance term is worth more than an implied one.

Could the agency claim indemnification? Yes, if the contract contains a broad enough clause, and it could then demand that the vendor cover retraining and reprocessing costs. Is the vendor liable to the visa applicants themselves? Probably not directly, unless they can show the vendor knew of the defect and concealed it; the vendor's obligation runs to the government under the contract, not to the applicants. Who compensates the applicants? The government, most likely, which may then seek reimbursement from the vendor. Notice what made the difference: a specific, measurable performance guarantee created a clear liability path, and an indemnification provision that named the actual harms, reprocessing and remediation costs, would have made that path collectible.

An innovation the agency genuinely wants. A health ministry wants to deploy a model predicting which patients are at high risk of complications. It could improve outcomes, and it rests on novel techniques not extensively tested in similar contexts, so the uncertainty is real rather than rhetorical. The approach that manages both: run a controlled pilot with limited deployment, tell affected patients explicitly that they are in a pilot, and obtain informed consent. Before any full deployment, validate extensively, red-team the system, obtain approval from the appropriate oversight bodies, whether ethics committees or clinicians, and document the due diligence as you go.

If harm occurs during the pilot, an agency that tested the model, warned users and monitored carefully is less likely to be found negligent, and informed consent helps because patients knowingly accepted a disclosed risk. Insurance cuts both ways here: a government liability policy may exclude experimental treatments, and this is exactly the question to put to your insurer before the pilot starts rather than after. Properly informed, supervised pilots are generally more insurable than full deployments without due diligence. Liability frameworks can support innovation when they are designed to, and the design is safeguards plus transparency rather than caution alone.

The AI Liability Readiness Checklist

Run this before deploying any AI that affects a person's benefits, permits, employment or rights. Every "no" is a hole in a shield.

  1. Indemnification. Does the vendor agree to cover the agency's losses from the AI's defects, bias or misrepresented performance, and have you read the exclusions as carefully as the promise?
  2. Liability cap. Is the vendor's liability cap realistic against potential harm, rather than set at the contract fee?
  3. Vendor solvency. Have you assessed whether the vendor could actually pay on its indemnity, and does the contract require insurance as the backstop if it cannot?
  4. Vendor insurance. Does the vendor carry adequate technology and professional liability cover, with the agency named as additional insured?
  5. Coverage review. Has your insurer or risk pool confirmed in writing that AI-caused harms are covered, with no automated-decision exclusion?
  6. Performance terms. Are acceptable performance levels stated as measurable warranties, including performance across affected groups and not only in aggregate?
  7. Validation record. Did the agency test the system for accuracy and bias before deployment, and is the testing documented and dated?
  8. Human review. Is there a human in the loop with authority to override the AI on consequential decisions, with that review logged?
  9. Monitoring. Is performance monitored over time, with records showing the agency caught and corrected problems?
  10. Procedural compliance. Have the procedural steps your jurisdiction requires before an automated decision affects citizens actually been completed?
  11. Named owner. Is there an accountable official responsible for the system's safe operation?
  12. Appeal path. Can an affected person contest an AI-influenced decision and reach a human?

Why This Matters for Government

Government AI lives in high-stakes territory, denying benefits, rejecting permits, screening for fraud, where a wrong decision is not an inconvenience but a financial or legal harm to a resident. Government agencies are powerful entities with significant resources, and when their systems harm citizens the harm can be severe and widespread. Citizens have a moral and political right to seek redress, and the government has a corresponding obligation to make sure its systems do not harm people unjustly. Insurance, where it exists, spreads that cost across many stakeholders rather than letting it fall catastrophically on one, which is what allows an agency to take a calculated risk at all.

Federal guidance reinforces the diligence theme. Office of Management and Budget direction on federal AI use expects agencies to assess and monitor rights-impacting AI, and the National Institute of Standards and Technology's AI Risk Management Framework, which is voluntary rather than binding, treats governance and measurement as core. These are not just compliance boxes. They are the documented diligence that holds your immunity and insurance shields together, and they are the evidence you will reach for if a claim ever arrives.

Dolores's city settled the claim, then rebuilt its process. Every AI procurement now runs through the readiness checklist before signing. The contracts carry real indemnification with the exclusions negotiated down. The insurance was reviewed and endorsed. And no rights-affecting AI deploys without documented validation and human review. The cost of all that diligence was a fraction of one $400,000 claim.

Anti-Patterns

  • Assuming sovereign immunity covers everything. Immunity is a real protection in many jurisdictions, which is exactly why it gets treated as absolute. An agency that fields a hiring model without bias testing on the theory that it cannot be sued discovers, when women bring a claim, that the jurisdiction waived immunity for civil rights violations. Understand the limits of immunity where you operate, ask your legal team directly, and govern as though you will be held liable, because you might be.
  • Transferring all liability to the vendor and relaxing. A contract can allocate liability; it cannot conjure money. A generous indemnity from a startup with no assets is worth nothing the day the startup dissolves, and the agency is left with no recourse and a harmed resident. Assess financial stability, require insurance as the reliable funding source, avoid vendors without financial backing for critical systems, and keep your own testing running as a backstop rather than assuming the vendor will catch everything.
  • Skipping insurance because we are the government. Insurance reads as a cost, and a government feels large and resilient. Then a catastrophic failure produces discriminatory outcomes at scale, litigation runs into millions, and the liability eats a budget that was meant for services. Treat insurance as risk management rather than overhead, work the question with your finance and legal teams, and if traditional cover is unavailable, price out reserves or a consortium approach rather than doing nothing.
  • Treating the documentation as the defence. Records of validation, monitoring and human review strengthen your position materially. They do not decide the case. An agency that produces a thick file describing a test it ran badly has documented a bad test, and offering the file as proof of diligence invites the other side to read what is in it. Do the work first; the file is the byproduct.
  • Reading the indemnity and not the exclusions. The clause that promises to cover all losses arising from defects is frequently followed by one excluding damages to third parties, which is the only category a government genuinely fears. The promise ends where the carve-outs begin, and the carve-outs are where vendors do their real negotiating.
  • Letting a cap set at contract value stand for a rights-impacting system. A cap equal to fees paid is defensible for a piece of office software. For a system that decides who receives a benefit, it prices the vendor's exposure at a small fraction of the harm the system can cause, and it silently transfers the rest to the public treasury.
  • Waiting for the claim to ask the coverage question. The blunt question to your insurer costs an email today and is unanswerable after a loss. A verbal reassurance from a broker is not a coverage position; get it in writing, and get it before deployment.

Practice Prompts

  • Research the liability landscape in your own jurisdiction. Is sovereign immunity broad or narrow? What waivers exist, and does a tort claims act apply with a cap you can cite from the statute itself? Write the findings down with sources, because the next person will need them.
  • Pull an actual contract your government holds with an AI vendor. Does it include indemnification? Insurance requirements? Performance warranties? Then assess adequacy: read the exclusions and the cap, and write one sentence on what the agency would recover if the system caused a serious harm tomorrow.
  • Design a liability framework for one critical AI system, allocating risk deliberately among the government, the vendor and affected citizens. Include warranties, insurance requirements and indemnification provisions, and mark which of them you would trade away first under negotiating pressure.
  • Investigate insurance options for AI liability where you operate. What is actually available? What does it cost? What does it cover, and what does it exclude? Where are the gaps between your assumption and the policy language?
  • Build the due-diligence documentation process. What evidence would you need to produce to show that your agency exercised reasonable care in developing and deploying a system? Compare that list against what exists today for your highest-risk system.
  • Take the five elements of reasonable care from this lesson and mark each one present, partial or absent for one live system. The partials are usually where the real exposure sits.

Reflection

Think about the AI system in your agency that touches the most people. If a court found your government liable for harm caused by it tomorrow, what would the financial impact be, and can anyone in your organisation currently answer that question with a number? Then ask the version that is harder to dodge: for that same system, could you produce, today, the evidence that would demonstrate reasonable care, or would you be assembling it after the claim arrived? The gap between those two answers is your real exposure, and it is almost always larger than the gap you would have guessed.

Glossary

  • Indemnification: A contractual promise by one party to cover the other's losses. Its value depends entirely on the promising party's solvency, the scope of harms covered, any cap, and the exclusions.
  • Sovereign immunity: The doctrine that a government cannot be sued without its permission. It varies by jurisdiction and by context, from nearly absolute to narrowly limited.
  • Tort claims act: A statute waiving sovereign immunity for tort claims such as negligence, typically up to a cap stated in that jurisdiction's own act.
  • Negligence: Failure to exercise reasonable care in developing, testing or deploying a system, and the most common theory under which an agency is held liable for AI harms.
  • Strict liability: Liability that attaches even where the party exercised reasonable care, applied in some jurisdictions to certain high-risk activities and to discrimination claims.
  • Product liability: The theory that reaches a vendor whose product is defective, potentially even where the buying agency failed to detect the defect in testing.
  • Limitation of liability: A contract clause capping how much either party can be liable for, frequently set by vendors at the contract or annual contract value.
  • Additional insured: A party named on someone else's insurance policy so that it can claim under that policy directly, commonly required of AI vendors by the buying agency.
  • Errors and omissions insurance: Cover for claims that an organisation made mistakes that caused harm; some governments are obtaining it in forms that reach AI system failures.
  • Escrow: Withholding a percentage of contract payments and releasing them only if the system performs over a specified period, giving the vendor a financial stake in quality.
  • Performance bond: A bond posted by a vendor guaranteeing performance, claimable if the vendor fails to deliver a system of the promised quality.
  • Self-insurance: Setting aside financial reserves against potential claims instead of buying a policy, viable only for an organisation large enough to absorb a significant loss.

Closing

Liability and insurance frameworks for government AI are still evolving, and several principles are already clear. Assume you can be held liable rather than relying on immunity to absorb every claim. Invest in governance, because due diligence is the closest thing to insurance that is reliably available. Allocate risk explicitly in contracts, which creates incentives on both sides rather than hope on one. Seek insurance where it exists. And prioritise transparency, because disclosure creates accountability and lets citizens understand the risks being run on their behalf.

The organisations that manage this well are the ones that build governance from the beginning, allocate risk deliberately and maintain cover where they can. They are better protected against claims, and, less obviously, they are freer to act, because an agency that has genuinely bounded its downside can take a reasonable risk to improve a service. Liability planning for AI is not legal paperwork you complete after the fact. It is a decision you make before you sign, or a bill you pay after you are sued.

Key Takeaways

  • Three shields, three holes. Contracts, insurance and sovereign immunity each have a predictable gap, and harm flows through whichever one you forgot to close. No single shield was designed to carry the whole load.
  • Six theories can reach your agency. Negligence, strict liability, product liability, discrimination and civil rights, administrative law violations, and breach of contract. Administrative law is the one agencies forget, and it can create liability even where the system harmed nobody.
  • Reasonable care has a working definition. Planning and scoping, testing for bias, robustness and security, monitoring after deployment, transparency about limitations, and procedures for detecting and remediating problems. No court has certified it as sufficient, which is a reason to exceed it rather than to ignore it.
  • Indemnification is weaker than it reads. Vendor solvency, scope, caps and exclusions each hollow it out, and a carve-out for third-party damages removes the exact harm a government fears. Read the exclusions before the promise.
  • Your insurance may exclude AI. Some policies now carry explicit automated-decision exclusions and others simply never contemplated AI. Get written confirmation from your insurer or risk pool before you deploy, and treat a verbal reassurance as no answer at all.
  • Sovereign immunity rewards diligence. It typically protects discretionary policy choices, and it often does not protect operational negligence. An untested, unmonitored black box converts a protected choice into an unprotected failure.
  • Documentation strengthens your position; it does not decide the case. Records of validation, monitoring and human review are evidence of diligence, and evidence is not a guarantee. What the records say matters more than that they exist.
  • Discrimination claims do not turn on intent. Where an AI system produces outcomes that violate civil rights law, liability can attach regardless of whether anyone meant it to happen, and immunity is frequently waived for exactly these claims.
  • Liability is set at procurement, not at the claim. By the time a lawsuit arrives, the allocation of risk is already fixed in the contract you signed, and every lever, warranty, cap, escrow, bond, insurance requirement, is only available before award.
  • Keep a human and an appeal in the loop. Consequential decisions need a person who can override the AI and a path for affected residents to contest the outcome, which is both a governance control and a liability position.

Frequently Asked Questions

Does sovereign immunity mean our agency cannot be sued over an AI decision?

No, and planning on that basis is the single most expensive assumption in this lesson. Immunity varies by jurisdiction from nearly absolute to narrowly limited, and most jurisdictions have carved out exceptions: express waivers, tort claims acts, constitutional rights violations, and activities the government carries out in a proprietary rather than governmental capacity. It also tends to protect discretionary policy choices rather than operational negligence, which is where AI deployment failures usually sit. Ask your legal team how the doctrine works where you operate, and treat the answer as the design input it is.

The vendor's contract caps liability at what we paid them. Is that normal?

It is common and it is negotiable. A cap set at fees paid is defensible for low-stakes software and indefensible for a system that decides who receives a benefit, because it prices the vendor's exposure at a small fraction of the harm the system can cause and leaves the remainder with the public treasury. Push the cap up for rights-impacting systems, require insurance so there is a funding source behind the promise, and remember that the exclusions can matter more than the number.

If the vendor indemnifies us, are we covered?

Only to the extent the vendor can pay, the clause reaches the harm that actually occurred, and the cap has not been exhausted. A generous indemnity from a company with no assets is a piece of paper. Assess financial stability before award, require insurance as the backstop, check whether the clause covers discrimination claims and third-party damages rather than only direct damages, and keep your own testing and monitoring running regardless, because your diligence is usually the condition on which the indemnity was scoped in the first place.

Is a completed liability checklist enough to protect us?

No. The checklist finds the holes; it does not fill them. A checked box next to "validation record" means a document exists, not that the testing behind it was competent, and if a claim arrives the other side will read the document rather than the checkbox. Use the list to identify what is missing, then look hard at the quality of what you found, because that is the part a court, an insurer and an auditor will all examine.

Can insurance replace governance?

It cannot, and the market makes that explicit. Traditional insurance struggles with AI because it prices risk from actuarial history and AI harms are novel and potentially catastrophic, so cover is limited, expensive and full of conditions. Insurers also price on governance quality, which means the agency with real testing and monitoring gets the better terms. Insurance distributes a loss you could not otherwise absorb. It does not prevent the loss, and it will not pay for harm the policy excluded.

We are running a pilot rather than a full deployment. Does that reduce our exposure?

It can, if the pilot is genuinely controlled. Limiting deployment, telling affected people explicitly that they are in a pilot, obtaining informed consent, monitoring closely and documenting the diligence all make a negligence finding less likely, and a properly supervised pilot is generally more insurable than an undocumented full deployment. But check your policy first: government liability cover may exclude experimental activity, and that is a question to settle in writing before the pilot begins rather than after something goes wrong.