AI Insurance and Liability
The claim arrived fourteen months after the AI system had been taken offline. The city's AI-powered pothole detection and repair prioritization system had been operational for 22 months. During that period, a section of Maple Street in a lower-income neighborhood, a section the system had consistently de-prioritized because its training data correlated property value with infrastructure maintenance need, had deteriorated to the point where a cyclist fell and sustained a fractured wrist and a broken collarbone. The cyclist's attorney filed a negligence claim against the city for $340,000, naming both the city and the AI system's vendor. The city's risk manager, Marco Espinoza, pulled the city's general liability policy and found three words that changed the conversation: "excluding automated systems." The city was self-insured for standard municipal liability, and the exclusion applied to automated decision-making systems, which the pothole prioritization tool unambiguously was. Marco had seventeen months of records showing the city had relied on the system's recommendations without human override. He had no insurance coverage for the claim. This lesson is about building the liability and insurance framework before an AI failure generates a claim, rather than after.
Before anything else: nothing in this lesson is legal advice. Insurance policy language, sovereign immunity, tort claims statutes and civil rights exposure all vary by jurisdiction and by the specific facts of a claim, and none of the general statements here survive contact with a particular policy or a particular state's law without review. The correct next step after reading is a conversation with your own counsel and your own insurer or risk pool, with the questions in this lesson in hand.
What This Lesson Adds to the Three Shields
Government AI liability rests on three overlapping shields: the vendor contract, which allocates responsibility between the agency and the company; insurance, which pays when responsibility lands on the agency; and sovereign immunity, the doctrine that a government cannot be sued without its permission. Each shield has a predictable hole. The companion lesson Insurance and Liability for Government AI works those three shields and the underlying legal theories in depth, and it is the place to start if you have not read it. This lesson picks up where that one leaves off, at the level a chief AI officer or agency risk manager operates: the insurance market as it actually exists, the policy review you can run this quarter, and the program that keeps both current.
Why Government AI Liability Is Different
Government AI liability operates differently from private sector AI liability in two important ways. First, sovereign immunity applies in some but not all AI-related harm scenarios. Most states have waived sovereign immunity for negligence claims involving property conditions, vehicle operations, and some categories of service delivery. Whether that waiver extends to AI-assisted decisions affecting service delivery is unsettled, and it is being litigated in multiple jurisdictions with inconsistent outcomes. Plan on the assumption that immunity will not absorb an AI claim, and let your counsel tell you where it might.
Second, government agencies cannot disclaim liability through terms of service the way private companies can. A citizen harmed by an AI-assisted government decision cannot be said to have agreed to accept that risk, because government service is not optional for many constituents. The source material for this lesson goes further and states that the constitutional due process requirements attaching to government AI decisions, meaning notice, an opportunity to challenge, and human review of adverse decisions, create a liability floor that does not exist in the private sector. Carry that as stated. It errs toward more protection for the citizen and more exposure for the agency, and an agency that designs to it will not be surprised. Whether a particular due process obligation attaches to a particular program is a question for counsel.
Those two differences point the same way. In the private sector, a company can shrink its exposure by writing a better contract with its users. A government cannot, because it has no users in that sense, only constituents who did not choose the relationship. The only lever an agency actually holds is the quality of the system and the record of how it was built, tested and supervised. Everything in this lesson is downstream of that fact.
The Equity Exposure Standard Policies Miss
The pothole claim illustrates a third government-specific exposure: equity-based liability under the Equal Protection Clause and statutes such as Title VI of the Civil Rights Act. An AI system that systematically de-prioritizes infrastructure maintenance in lower-income or minority neighborhoods creates potential civil rights liability distinct from ordinary negligence. This is the exposure standard municipal liability policies are least likely to cover, and it is the one government AI is most likely to create.
Look at how the Maple Street failure was built. The model correlated property value with infrastructure maintenance need. That correlation is genuinely present in historical maintenance records, because past spending followed past property values, so the model learned the pattern faithfully. Nobody wrote a rule that said deprioritize poor neighborhoods. The rule emerged from data that recorded decades of decisions and offered them back as a forecast. This is the ordinary shape of algorithmic disparate impact in government: the model is accurate about the past and the past was unequal, and the system then makes the inequality efficient and repeatable.
Two practical consequences follow. First, equity testing before deployment is not an ethics extra; it is the only place this failure is cheap to find. An equity impact assessment that compares outcomes across the populations a system touches would have surfaced the Maple Street pattern in its first months rather than after twenty-two months of operation. Second, an agency should assume its existing coverage does not reach a civil rights claim arising from an algorithm, and should ask the question specifically rather than reading a general liability grant optimistically. Algorithmic Impact Assessments and Rights-Impacting and Safety-Impacting AI Safeguards cover the testing and the category definition in detail.
The Insurance Market as It Actually Exists
The commercial insurance market for AI-specific liability is developing rapidly and is not yet mature. Insurance works by pooling risk across many similar entities and pricing premiums from actuarial history, and AI harms are novel, hard to predict and potentially large, so insurers are pricing something they do not yet have decades of loss data on. That is a reason to open the conversation early and in writing, not a reason to skip it. The source material identifies three product categories relevant to government agencies, and each has a specific limit worth knowing before you rely on it.
Technology errors and omissions insurance. These policies cover liability arising from a technology product or service failing to perform as intended. Many AI vendors carry the cover, but it typically applies to the vendor's liability to the agency under the contract, not to the agency's liability to the third parties, meaning constituents, harmed by the system's outputs. Verify whether your vendor's policy includes any pass-through coverage for third-party claims, whether the agency can be named as an additional insured, and whether the limits are adequate against the agency's own exposure rather than against the contract value.
Cyber liability policies. Cyber liability policies historically covered data breaches and network security incidents. Some insurers are now extending them to AI-related incidents, including system failures, harmful AI-generated outputs and algorithmic bias claims. Treat that as a possibility to confirm rather than a coverage position. Read your own policy's definitions and exclusions, ask the insurer directly whether an AI-caused wrongful decision that harms a person is covered, get the answer in writing, and request a specific AI endorsement where the answer is no. A cyber policy written for breach response was not drafted with an algorithmic bias claim in mind.
Public entity AI liability programs. Several insurance programs designed for public entities have begun offering or developing AI-specific coverage for claims arising from algorithmic bias, system failures and AI-assisted decisions that harm constituents. These programs typically require extensive underwriting information about the agency's AI governance practices, which creates a useful alignment: the questions the underwriter asks are close to the questions a good governance program answers anyway. Availability is uneven and the terms are still moving, so what is quotable this year may not have been quotable last year.
| Product | What it is written to cover | The gap an agency should expect |
|---|---|---|
| Technology errors and omissions | Failure of a technology product or service to perform as intended | Usually runs to the vendor's liability to the agency, not the agency's liability to constituents |
| Cyber liability | Data breaches and network security incidents, sometimes extended to AI incidents | Definitions and exclusions were drafted before AI harms; coverage of a bias claim has to be confirmed, not assumed |
| Public entity AI liability programs | Algorithmic bias, system failure and AI-assisted decisions harming constituents | Emerging and unevenly available; underwriting demands governance documentation the agency may not have |
| Existing general liability, self-insured or purchased | Standard municipal exposures | May carry an automated systems exclusion written long before government AI existed |
The Exclusion Review You Run This Quarter
Marco's city discovered the automated systems exclusion after the claim arrived. That exclusion appears in many standard municipal liability policies because those policies were written before government AI was widespread. It is not hidden and it is not exotic. It simply sits in a document nobody reads until a claim forces them to. Every agency with AI systems in operation should run a deliberate policy review searching for automated systems and algorithmic decision-making exclusions, and request amendments, endorsements or separate coverage before an incident rather than after.
Run the review as a documented exercise with a named owner and a due date, not as a favor from the broker. List every policy the agency holds or participates in, including any risk pool arrangement. For each one, put the same blunt question in writing: if an AI system this agency operates produces a wrongful decision or a wrongful prioritization that harms a person, does this policy respond? Record the answer, the date and the person who gave it. A verbal reassurance is not a coverage position, and the file you build during this review is the file you will want if the answer later turns out to be contested.
Then map the answers against your AI inventory. An agency typically discovers three states: systems clearly inside coverage, systems clearly outside it, and systems whose status depends on how the policy defines an automated decision. The third category is the dangerous one, because it feels covered. Decide deliberately what to do with each: buy an endorsement, shift the exposure to the vendor's insurance, price out reserves, or accept the risk explicitly at a level of the organization high enough to own that decision. The cost of a policy review and amendment is trivial against the cost of self-insuring a $340,000 claim.
Underwriting Reads Your Governance File
AI liability underwriters ask for documentation of governance practices as a condition of considering coverage and as an input to pricing. The source material lists four categories of documentation that are typically required: an inventory of deployed AI systems with descriptions of their decision scope, evidence of equity impact assessments before deployment, incident reporting and response protocols, and evidence of human oversight for high-impact decisions. That is the source's own list of four, not a count of ours. Agencies that already hold these as part of an AI governance program can produce them for underwriting at minimal additional cost. Agencies that do not have them face two problems at once: inadequate governance and inadequate insurance.
Be precise about what governance quality buys you. Insurers weigh it, and better documented programs generally get better terms and a better chance of an offer at all. That is a tendency in how risk is priced, not a promise. A thick file does not guarantee coverage, does not guarantee a lower premium, and does not guarantee an outcome if a claim goes to litigation. Records of validation, monitoring and human review are evidence of diligence. What the records actually say matters more than the fact that they exist, and an agency that documents a badly run test has documented a badly run test.
Of those four categories, the inventory is usually the one that stalls a submission. Agencies discover that they cannot list their AI systems with confidence, because tools arrived through different routes: a procurement, a feature switched on inside an existing platform, a pilot that quietly became production. An underwriter asking what AI you operate is asking a question your agency may not have a defensible answer to, and the honest response is to build the inventory first and apply second. That work is not wasted if the insurance conversation stalls, because every other control in this lesson depends on knowing what is running.
The same caution applies to human oversight. A system whose recommendations are subject to documented human review before action is in a stronger position than one whose recommendations execute automatically, and that is worth building. It is not a shield. A reviewer who approves every recommendation without the time, information or authority to disagree has produced a rubber stamp, and a rubber stamp is a record of the AI deciding with a human signature attached. Design the review so that overriding the system is realistic: give the reviewer the reasons behind the recommendation, the time to weigh them, and explicit authority to say no.
Allocating Liability in the Vendor Contract
When an AI system causes harm, both the agency and the vendor may be liable, and the contract between them determines how that liability is allocated. Many standard vendor contracts cap the vendor's exposure at the value of the contract, which may be far less than the damages from a significant failure. Agencies should negotiate specific provisions covering the vendor's indemnification obligations for claims arising from defects in the system, the vendor's obligation to maintain adequate insurance including AI liability cover, and the allocation of liability for claims arising from agency use of outputs the vendor warned against or that departed from recommended use parameters.
That last item deserves attention because it cuts against the agency. Off-label use, meaning use outside the parameters the vendor documented, is where an indemnity most often fails to respond. Marco's city ran a prioritization tool without human override for seventeen months. If the vendor's documentation had recommended human review of prioritization output, the city's own operating pattern would have weakened its position against its own vendor. Read what the vendor told you the system was for, and either operate inside it or renegotiate so that your actual operating pattern is the one the contract covers. AI Contract Negotiation works these clauses at the level of negotiating positions.
Keeping the Picture Current
The exclusion review is a task with an end. The exposure it measures is not, because the AI inventory changes underneath it. A tool arrives through a procurement, a feature is switched on inside a platform the agency already owns, a pilot becomes production without a second decision, and the coverage map drawn in March is describing a different agency by September. An annual review repeated heroically by one risk manager will drift, and the drift is invisible until a claim lands on a system that was not on the list.
The durable fix is small: make the coverage question a step in the path a system already travels to reach production, owned by a named official with the authority to hold a deployment until it is answered. That places the check where new systems necessarily pass, rather than where someone has to remember to look. It also survives a change of staff, which an annual exercise held in one person's calendar does not.
What the City Did Next
Marco's city settled the pothole claim for $215,000, less than the original demand but a significant uninsured loss for a self-insured city of its size. The settlement included non-monetary commitments: an equity audit of any AI system affecting infrastructure prioritization before redeployment, and a human override review step for any AI recommendation affecting a street segment in a census tract with median household income below the citywide median. Those governance commitments were the right approach regardless of the claim, and they cost a fraction of the settlement they followed.
They are now also the basis of the city's AI liability insurance application. The insurer in discussions with the city since the settlement has indicated that the equity audit protocol and the human override requirement are the two governance factors that most affect its willingness to offer coverage and its premium calculation. That is one insurer's stated view of one applicant, not a general rule, and the city will not know its terms until it has them in writing. The wider point holds regardless: the governance investment and the insurance outcome are not separate decisions. They are the same decision made at different points in time, and Marco made his fourteen months late.
Anti-Patterns
- Assuming an existing policy covers AI. General liability, errors and omissions and cyber policies were largely written before government AI, and some carry explicit automated systems exclusions while others simply never contemplated an algorithmic harm. The failure is learning this from a coverage denial rather than from a review. Ask the blunt question in writing before deployment, keep the answer, and treat a broker's verbal reassurance as no answer at all.
- Treating the governance file as a guarantee. Documentation of inventory, assessments, incident protocols and oversight improves your position with underwriters and in litigation. It does not decide either one. An agency that presents a thick binder as proof of diligence invites the other side to read what is inside it, and a badly run test documented carefully is still a badly run test.
- Letting human override become a rubber stamp. A documented review step is protective only if the reviewer can realistically disagree. Approval records showing almost no overrides, reviewers with no access to the reasoning behind a recommendation, and review windows too short to think in all produce automatic decisions with a signature attached. Measure override rates and investigate when they sit at zero.
- Relying on the vendor's errors and omissions policy for constituent claims. Vendor technology cover typically runs to the vendor's liability to the agency under contract. The claim a government most fears comes from a resident, which is exactly the category most likely to sit outside that policy. Confirm pass-through coverage and additional insured status explicitly rather than inferring them from the fact that the vendor is insured.
Practice Prompts
- Search the policy documents your agency holds or participates in for automated systems, algorithmic decision-making and artificial intelligence language, in both the coverage grants and the exclusions. Record what you find per policy with the page reference, and flag language that is ambiguous rather than clearly for or against.
- Draft the written question you will send your insurer or risk pool about AI-caused harm, and the list of policies you will send it about. Then draft what you will do with each of the three possible answers: covered, not covered, and depends.
- Take one deployed system and assemble the four documents an underwriter asks for: its inventory entry with decision scope, the pre-deployment equity impact assessment, the incident reporting and response protocol, and the evidence of human oversight. Note which you could produce this week and which would have to be created.
- Pull a live AI vendor contract and locate the limitation of liability clause, the indemnification clause with its exclusions, and the insurance requirements. Write one sentence stating what the agency would actually recover if that system seriously harmed a resident tomorrow.
Reflection
Sit with the AI system in your agency that touches the most people, and ask three questions in order. Does any policy the agency holds respond if that system produces a wrongful decision that harms someone, and can you point to the language rather than the assumption? If the answer is no or unclear, who currently owns that gap? And if a claim arrived tomorrow, would the governance record show diligence that actually happened, or a file assembled after the letter arrived? The distance between the answer you would like to give and the answer you can evidence is your real exposure.
Glossary
- Automated systems exclusion. Policy language removing coverage for losses arising from automated or algorithmic decision-making, common in liability policies written before government AI.
- Technology errors and omissions insurance. Cover for liability when a technology product or service fails to perform as intended, commonly scoped to the vendor's liability to its customer.
- Cyber liability policy. Cover originally written for data breaches and network security incidents, which some insurers are extending toward AI incidents by endorsement.
- Additional insured. A party named on another organization's policy so it can claim under that policy directly, commonly required of AI vendors by the purchasing agency.
- Self-insured. Bearing losses from reserves rather than transferring them to an insurer, viable only where the entity can absorb a significant loss.
- Sovereign immunity. The doctrine that a government cannot be sued without its permission. It varies by jurisdiction and is not a complete defense to an AI claim.
- Equity-based liability. Exposure under the Equal Protection Clause and statutes such as Title VI of the Civil Rights Act when a program's outcomes disadvantage protected groups.
- Off-label use. Operating a system outside the parameters its vendor documented, a common reason an indemnification clause does not respond.
Related Lessons
- Insurance and Liability for Government AI is the companion lesson covering the three shields and the legal theories beneath them in depth. Read it alongside this one.
- Enterprise Risk Frameworks for AI is the wider risk structure an agency liability program reports into.
- AI Contract Negotiation works indemnification, caps and insurance requirements at the level of actual negotiating positions.
- Algorithmic Impact Assessments produces the pre-deployment analysis that underwriters and plaintiffs both ask to see.
- AI Audit Methodology and AI Assurance Programs generate the independent evidence that a governance file describes work that actually happened.
- Algorithmic Accountability Mechanisms covers the appeal and redress paths that stop grievances becoming claims.
- Crisis Management for AI Failures is what runs after the claim letter arrives.
- Rights-Impacting and Safety-Impacting AI Safeguards defines the category of system where this exposure is highest.
Closing
The uncomfortable thing about Marco's story is that every step in it was ordinary. The exclusion was standard language. The reliance on a system without override was convenient. The correlation between property value and maintenance need was in the historical data, which is exactly where a model looks. Nobody made a dramatic mistake. The city simply deployed an automated decision system into a liability structure designed for a world without one, and then waited twenty-two months for the two facts to meet.
The work this lesson asks for is unglamorous and cheap relative to what it prevents: read the policies, write the questions down, get the answers in writing, name an owner, and keep the inventory current as systems change. Do that before an incident and it is a program; do it after, and it is a deposition exhibit. Then take the exclusions in your actual policies and the terms in your actual contracts to your counsel and your insurer, because they are the only people who can turn the general shape of this lesson into an answer you can rely on.
Key Takeaways
- Review existing policies for automated systems exclusions now. Finding that exclusion before an incident is a policy review task; finding it afterward is a financial crisis with a claimant attached.
- Sovereign immunity does not fully protect government AI liability. Most states have waived immunity for negligence, and systems that disadvantage protected classes raise civil rights exposure. Plan on being liable and let counsel tell you where you are not.
- Negotiate AI-specific liability allocation in vendor contracts. Require indemnification for defects, vendor insurance with the agency as additional insured, and explicit allocation for use outside documented parameters.
- Underwriting weighs governance quality; it does not reward paperwork. Better programs generally get better terms, which is a tendency in pricing rather than a promise of coverage or premium.
- Human override helps only when it is real. A review nobody has the time, information or authority to fail is a rubber stamp. Track override rates and treat zero as a finding.
- Documentation is evidence of diligence, not a defense in itself. Its value in a claim depends on what it shows, and a file assembled after the letter arrives reads exactly like one.
- Governance investment and insurance outcome are the same decision. They are separated only by time, and by whether you make it before the claim or after it.
Frequently Asked Questions
We are self-insured. Does any of this apply to us?
All of it, and the exclusion question becomes more urgent rather than less. Self-insurance means the loss lands on the agency's own funds, so an uncovered AI claim is paid directly out of a budget meant for services, as Marco's city discovered. Self-insured entities still hold or participate in policies and pool arrangements, still face automated systems language in those documents, and still need an inventory showing which systems could generate a claim. Work the reserve question with finance, and ask whether a specialized policy or a joint arrangement is available for the exposures reserves could not absorb.
Our cyber policy mentions technology failures. Are AI incidents covered?
Possibly, and possibly not, and the difference is in the definitions rather than the marketing. Cyber policies were written around breaches and network security incidents, and an algorithmic bias claim or a wrongful automated decision may not fall inside a definition drafted for data compromise. Some insurers are extending cover toward AI incidents by endorsement. Put the specific scenario to the insurer in writing, name the system and the kind of harm, and keep the reply. A favorable reading of the policy by someone inside your own agency is not a coverage position.
If we build a strong governance program, will we get coverage?
It improves your chances and your terms, and it guarantees neither. Underwriters weigh governance quality because it correlates with loss experience, so the inventory, assessments, incident protocols and oversight evidence are genuinely worth putting in front of them. But availability of AI cover is uneven, insurers are still learning to price these risks, and an insurer can decline for reasons unrelated to your program. Build the governance because it reduces the harm, and treat the insurance benefit as a likely side effect rather than the objective.
Does documenting human review protect us from a negligence claim?
It helps and it does not settle the question. Records of validation, monitoring and human review are evidence that the agency exercised care, and they are read rather than counted. A process that produced a signature on every recommendation, from a reviewer with no time and no override authority, documents automation rather than oversight, and the other side will make that argument. Design the review so a person can genuinely say no, measure how often they do, and treat the record as the byproduct of real diligence rather than its substitute.
Skill.re