AI & machine learning
Professional indemnity — written for technology businesses as technology errors and omissions, or tech E&O — protects your company when the work you deliver or the product you sell causes a client a financial loss. For an artificial-intelligence or machine-learning business, that exposure takes a new and still-evolving shape: a model can produce an output a client relies on, and get it wrong. This page explains, in plain terms, how the cover responds and where the genuine uncertainty still lies.
Part of: Technology professional indemnity
In short
Professional indemnity and technology errors and omissions (tech E&O) cover the financial consequences when your AI or machine-learning product, model or service fails to perform as it should and a client suffers a loss as a result — funding your legal defence and any damages or settlement, whether the allegation is negligent advice, a defective algorithm or an output the client relied on. For an AI company the defining exposure is the output itself: a model can generate an incorrect, biased, discriminatory or “hallucinated” result that a client acts on and loses money over, and the law on who is responsible for that is still developing. Cover is almost always written on a claims-made basis, so the policy in force when a claim is notified — not when the work was done — is the one that responds. Because insurers are still shaping how they treat AI risk, the wording, definitions and any AI-related exclusions need checking carefully.
Professional indemnity has always answered one question: did the professional fail to exercise reasonable skill and care, and did that failure cost the client? For a technology business, technology errors and omissions (tech E&O) extends the idea to the product itself — responding when the software or service you supply fails to do what it should and a client suffers a financial loss.
An AI or machine-learning business breaks that mould. A traditional professional, or conventional software, is expected to behave predictably; an AI model is probabilistic by design: it can return a confident, plausible answer that is simply wrong — not through carelessness, but because that is how the system works. Applying a “reasonable skill and care” standard to something built to generate rather than follow fixed rules is genuinely difficult, and the courts and regulators have not settled how negligence, causation and responsibility attach when a client relies on a model’s output.
So this is an area to approach with honesty, not false certainty: the liability landscape is developing, data-protection law already applies, and insurers are reshaping their wordings in response. The table sets out the exposures distinctive to an AI business and where cover for each typically sits — always subject to the policy wording.
| AI-specific exposure | Where cover typically sits (subject to wording) |
|---|---|
| A model returns an inaccurate output that a client relies on and loses money over | PI / tech E&O, as a failure of the professional service or product |
| A biased or discriminatory output that exposes a client to complaints or claims | PI / tech E&O may respond; some wordings treat discrimination specifically, others limit or exclude it |
| A “hallucinated” or fabricated output that a client publishes or acts upon | PI / tech E&O, potentially with intellectual-property or media extensions where content infringes or defames |
| Intellectual-property infringement in training data or in model outputs | Often an IP-infringement extension within PI / tech E&O, but frequently capped or excluded — a key term to verify |
| Disclosure of a client’s confidential or commercially sensitive information | PI / tech E&O breach-of-confidence cover, depending on the wording |
| A UK GDPR or Data Protection Act 2018 liability or regulatory matter | May span PI / tech E&O and cyber; regulatory defence and breach response usually sit in cyber |
| A breach of your own network, or data stolen from your systems | Cyber insurance, not PI / tech E&O — this is own-systems territory |
The first six rows are third-party liabilities — losses suffered by someone who relied on your product, and the territory of PI and tech E&O; the last belongs to cyber, not PI.
The exposure that most sets an AI business apart is the output your model produces and a client relies on. Three versions of the problem recur.
The hard question — and the one the law has not fully answered — is who is responsible when a client acts on a machine’s output. Well-drafted contracts, clear limitations, acceptable-use terms and a “human in the loop” can share or shift that responsibility, and they matter. But a contractual disclaimer does not stop a client bringing a claim, and an allegation still has to be defended. That is the central value of PI and tech E&O: it funds the cost of defending the claim — often the largest early expense — as well as any damages or settlement, whether or not the allegation ultimately succeeds. Given how unsettled the law still is, that defence cost is no remote concern.
Alongside the output, an AI business carries exposures rooted in the data it uses and the rights attached to it. These overlap, and each is the subject of active legal debate rather than settled rule.
Intellectual property. Models are trained on large volumes of material, and that material may be protected by copyright or other rights. A claim can arise from the inputs — how training data was gathered and used — or from the outputs, where a model reproduces or closely imitates protected work. How copyright law applies to AI training and generation is being tested, and views differ. Many PI and tech E&O policies offer an intellectual-property-infringement extension, but it is frequently capped, conditioned or excluded, so it is one of the more important parts of the wording to check.
Confidentiality. Clients routinely entrust an AI provider with sensitive or commercially valuable information. If it is absorbed into a model, surfaced in an output or otherwise disclosed, a breach-of-confidence claim can follow — to which PI and tech E&O cover commonly responds, subject to the terms.
Data protection. Where training data or outputs involve personal data, the UK GDPR and the Data Protection Act 2018 apply in full. Obligations around lawful basis, fairness and transparency are all engaged, and the rules on automated decision-making are especially relevant to models that influence significant decisions about individuals. A data-protection failure can give rise both to third-party claims and to regulatory action, and where that liability falls — between a PI or tech E&O policy and a cyber policy — depends closely on how each is worded, which is why the two should be read together.
AI businesses often ask whether tech E&O and cyber insurance are the same thing. They are not, and the boundary is worth stating plainly.
A simple test: if the question is “did our product give a client a wrong answer?” you are in PI and tech E&O territory; if it is “were our systems broken into or taken down?” you are in cyber territory. The two can overlap — a data-protection incident can touch both — and many AI businesses carry both, which is precisely why the wordings should dovetail so a loss does not fall between them.
The market reality is that insurers are still developing how they treat AI risk. Some policies now carry AI-related definitions, proposal questions or exclusions, and a standard tech E&O wording cannot be assumed to pick up liability for the outputs of an AI model without being read carefully; new regulatory regimes such as the EU AI Act are emerging alongside. Two practical points follow. First, cover is almost always written on a claims-made basis, so the policy that responds is the one in force when a claim is made and notified, not when the work was done — which makes continuity of cover important as the business evolves. Second, under the Insurance Act 2015 you owe a duty of fair presentation: describing your AI and machine-learning activities fully and accurately at proposal is itself material, because an inaccurate presentation can put a later claim at risk. A specialist broker can help test the wording against how your models are actually built and used.
It is worth asking us to re-market your cover when:
We would rather say so than waste your time. We are probably not for you if:
It can. PI and technology errors and omissions cover are designed to respond when your product or service fails and causes a client a financial loss, and an incorrect or defective model output can fall within that. Whether a particular claim is covered depends on how the policy defines your activities and on any AI-related exclusions, so the wording needs checking. The cover is the starting point; the terms decide the detail.
Tech E&O, a form of professional indemnity, answers for your product or service failing and causing a client a loss — a wrong output or a defective model. Cyber answers for your own systems being breached, your data being stolen or your platform being taken offline. Many AI businesses need both, and the wordings should be aligned so a loss does not fall between the two policies.
This is genuinely unsettled, and the answer depends on the facts, your contracts and developing law. Clear limitations, acceptable-use terms and human oversight can share or shift responsibility, but they do not stop a client bringing a claim. PI and tech E&O cover is valuable precisely here: it funds the defence and any settlement whether or not the allegation ultimately succeeds.
It may. A model trained on skewed data can produce outputs that disadvantage a group of people, and resulting claims can reach the provider that supplied the model. Some PI and tech E&O wordings address discrimination specifically, while others limit or exclude it, so this is an important point to confirm in the policy terms rather than assume.
Often, in part. Many PI and tech E&O policies include an intellectual-property-infringement extension that can respond to claims arising from training data or model outputs, but it is frequently capped, conditioned or excluded. Because the law on AI and copyright is still developing, this is one of the more important elements of the wording to review.
Where you process personal data, the UK GDPR and the Data Protection Act 2018 apply, including duties of fairness and transparency and the rules on automated decision-making. A data-protection failure can lead to both third-party claims and regulatory action, and the cover for each may sit across PI / tech E&O and cyber depending on the wording — which is why the policies should be read together.
A claims-made policy responds to claims first made against you and notified during the policy period, regardless of when the work was done. For a fast-moving AI business this makes continuity of cover important: a gap, a late notification or letting cover lapse can leave a past project unprotected. Under the Insurance Act 2015 you also owe a duty of fair presentation, so describe your AI activities fully and accurately at proposal.
The exposures facing AI companies — wrong, biased or “hallucinated” outputs, training-data and intellectual-property questions, and data-protection duties — are new, and insurers are still shaping how their wordings respond. A specialist broker can help you read professional indemnity, tech E&O and cyber cover together, check for AI-related exclusions, and make sure your policy reflects how your models are actually built and used. Tell us what your business does, and we will help you arrange cover that fits. Or call 0117 325 0027.
Get a quote Request a callbackApex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority. Registered in England and Wales, company number 07014570. This page is general information about professional indemnity insurance, not advice on your individual circumstances, and it does not guarantee that cover will be available or on what terms.