RatedWithAI

RatedWithAI

Accessibility scanner

AI Risk & InsuranceSeptember 25, 2026

Your D&O Policy Is the One That Pays When AI Oversight Fails

Every AI risk register ends with "we have insurance." Which policy, though? Cyber answers for a breach. Tech E&O answers to a customer. An oversight claim names the people who signed off on the deployment — and that is a different tower, with different exclusions, underwritten from a questionnaire somebody filled in from memory.

Side A
The layer that responds when the company cannot indemnify the individuals
Incorporated
What the application becomes once the policy issues — including its AI answers
Characterisation
The real fight: which policy in the tower the same facts belong to

The claim is about the decision to deploy, not about the software

An AI-governance claim rarely alleges that a model was wrong. It alleges that the people running the company approved something they did not understand, failed to put a monitoring system in place, or described the technology to investors and customers in terms the product did not support. Those are management-liability allegations: breach of the duty of oversight, misrepresentation, failure to supervise.

That matters because insurance follows the allegation rather than the technology. A claim that says "your classifier misfired and cost us money" is a professional-liability claim. A claim that says "you deployed a classifier into a regulated decision with no validation, no owner and no board reporting, and told the market it was audited" is a D&O claim, brought against individuals, for defence costs that start accruing before anyone decides whether the model was actually defective.

Four policies, one set of facts

01
D&O — the oversight and disclosure allegationPRIMARY HERE

Responds to claims against directors and officers for wrongful acts in their corporate capacity, including failure of oversight and misstatements about the business.

Watch the professional-services exclusion, which exists specifically to push service-delivery claims out of this policy, and check whether Side A sits above it with its own limit.

02
Tech E&O / professional liability — the customer's allegationSERVICE FAILURE

Responds when a client says the service you delivered was negligent or did not perform. This is where a hallucinated output that harmed a customer belongs.

Its insured-vs-insured and contractual-liability terms differ from the D&O form, so a claim pushed here can meet a different retention and a different duty to defend.

03
Cyber — the incidentNARROWER THAN ASSUMED

Breach response, notification, extortion, business interruption. A prompt-injection exfiltration is plausibly here; an unlawful automated decision is not.

Many teams name cyber as their AI cover because it is the policy they have read most recently. It is the least likely of the four to answer an oversight claim.

04
EPL — the employment allegationHIRING TOOLS

Employment practices liability is where an AI screening, scheduling or discipline tool generates claims, often bundled into a private-company management-liability package.

Check the definition of wrongful employment act against algorithmic decisions, and check whether class claims are sublimited — that is where the exposure concentrates.

A well-pleaded complaint will allege several of these at once, on purpose. The practical consequence is that your first insurance problem is not a denial — it is two carriers each pointing at the other while defence costs run, which is why the allocation question is worth settling in writing before a claim rather than after.

The renewal application is where cover is won or lost

AI questions have moved from supplemental forms into the main application. They are specific, and they are answered under a declaration that the statements are true.

“Do you use AI in decisions affecting individuals?”

Answerable only from an inventory. Shadow use in recruiting or support is the ordinary reason this answer turns out to be wrong, and it is wrong in the direction that helps the carrier.

“Do you have a written AI governance policy?”

A draft in a shared drive is not a policy. If you say yes, the document should be dated, adopted and produceable on request, with a named owner.

“Do you test for bias or accuracy, and how often?”

An aspirational cadence here is a misrepresentation waiting to be read back. Answer with what you actually did last year.

“Has any regulator or claimant raised an AI issue?”

Known-claim and prior-knowledge wording turns a soft no into a coverage defence. Resolve any doubt with the broker before signing, not afterwards.

Who signs the form

Frequently a finance or ops lead who did not write the governance programme and will not see the policy. Have the AI owner review the AI answers, in writing.

What came back with the quote

Read the renewal for a new AI exclusion, sublimit or condition precedent. Terms are moving faster than most companies re-read their forms.

Governance documentation is the underwriting artefact

The same file does three jobs: it answers the application truthfully, it is the oversight record a derivative claim asks for, and it is the evidence of reasonable steps that several statutory regimes reward. Companies that treat AI governance as a compliance chore build it once and then cannot find it at renewal. Companies that treat it as an insurance asset keep it dated, owned and short — an inventory of AI uses, a policy with a named owner, minutes showing it reached the board, and the last audit with its findings and what changed.

One governance claim nobody documents: can everyone use the product?

Accessibility is the oversight item with the shortest distance between a public page and a demand letter — anyone can test it from outside, today, without discovery. It also has the cheapest possible audit trail: a dated scan of the pages a customer actually touches. Run one free and file it with the governance record.

Run a Dated Scan for Free →

Frequently Asked Questions

We have cyber and tech E&O. Why would we need D&O for an AI problem?

Because those policies are written around different claimants. Cyber responds to a security incident and its costs. Tech E&O responds to a customer alleging your service failed them. An oversight claim is brought by shareholders, members or a regulator against the individuals who approved the deployment or described it to the market, and the loss is defence costs and settlement on behalf of those individuals. That is the D&O grant. A company with excellent cyber cover and a thin D&O tower is insured for the wrong story.

We are private with no shareholders. Is this still relevant?

Yes, in two ways. Private-company D&O forms typically also cover the entity for a broader range of management-liability claims, including employment practices, which is where an AI hiring or discipline tool lands. And investors in a priced round are shareholders with information rights and, eventually, with counsel. The exposure is smaller than a public company's, not absent.

Which exclusion is most likely to decide the claim?

There is no single answer, which is the point — the outcome usually turns on which policy in the tower the claim gets pushed into rather than on whether anything covers it. The professional-services exclusion on the D&O form is written to push service-delivery claims to E&O, and an AI failure can be argued into either. Bodily-injury exclusions matter once the model touches a physical or clinical decision. Conduct exclusions matter where the allegation is a knowing misstatement about what the AI does. Read the three together and the question becomes how the same facts get characterised.

What makes the renewal questionnaire so important?

Applications are incorporated into the policy, and an inaccurate answer supports a rescission or misrepresentation argument at exactly the moment you need cover. Carriers now ask specific AI questions: do you use AI in decisions about individuals, do you have a governance policy, who owns it, do you audit for bias, what did the audit find. Those questions are answered by whoever fills in the form, often without reading the policy they are asserting exists. An aspirational answer is the most expensive sentence in the renewal.

Does saying yes to the AI-governance questions raise our premium?

Generally the opposite. Carriers price uncertainty, and a documented governance programme with a named owner and dated audits is the evidence that supports the better terms — sometimes the difference between an AI exclusion or sublimit and a clean renewal. The expensive answer is the vague one, which invites both a higher price and a broader exclusion.

What should we do before the next renewal?

Three concrete things. Inventory where AI touches decisions about people, so the application is answerable from a document rather than from memory. Ask the broker in writing which policy in the tower responds to an AI-oversight allegation and get the answer in writing. And check whether any form has picked up an AI exclusion or sublimit since the last renewal — they are appearing quietly, and the first time most companies read one is after a claim.

Related Guides