Liability

The Insurance Handoff: D&O, Cyber, and E&O in an AI Incident

Tamara Gracon April 2026 7 min read

When an AI system causes harm, three different insurance towers all claim the loss belongs to someone else. Understanding the gap is a governance responsibility, and most boards discover it too late.

An AI system produces a harmful output. A biased hiring decision. An incorrect medical recommendation. A fraud detection model that blocks legitimate transactions at scale. A contract review tool that misses a material term. Whatever the scenario, the company sustains a loss, or causes one, and the question of coverage arises.

The expectation, in most boardrooms, is that this is what insurance is for. Three towers of coverage. D&O, cyber, E&O. One of them will respond.

In practice, they often do not. The reason is not obscure policy language or bad faith by insurers. It is a structural gap created by the fact that AI incidents sit at the intersection of all three coverage types, and each type was written with a different incident in mind.

What Each Tower Was Designed to Cover

D&O insurance protects directors and officers against claims alleging wrongful acts in their capacity as corporate decision-makers. It was designed for securities fraud claims, breach of fiduciary duty, employment practices matters, and governance failures. It was not designed for technology incidents. D&O carriers facing an AI-related claim will typically argue that the loss arises from a technology failure or a professional service deficiency outside the scope of board governance.

Cyber insurance covers losses arising from data breaches, network intrusions, and cyber events. It was designed for incidents where a malicious actor penetrates systems or data is exfiltrated without authorization. When an AI system causes harm through its own outputs, through bias, error, or unintended consequence, cyber carriers will typically argue that there was no breach, no intrusion, and no qualifying cyber event. The AI operated as designed. The policy does not cover AI outputs.

E&O insurance, also called professional liability, covers claims arising from professional services that fail to meet the expected standard of care. It was designed for law firms, accounting firms, consultancies, and technology vendors. It was not designed for companies whose primary business is not technology services. Boards operating a manufacturing company, a healthcare system, or a financial institution that deployed an AI tool may find that their E&O coverage was structured for a different kind of exposure.

Where the Gap Opens

The gap opens precisely at the scenario that is most likely in an AI incident. An AI system that was working as designed produced an outcome that caused harm. No breach. No governance decision directly in the causal chain. No professional service failure in the traditional sense.

D&O says it is a tech problem. Cyber says there was no cyber event. E&O says the company is not a professional services firm. The loss sits in the gap between all three. The company, and potentially the directors, absorbs it.

The Board's Governance Obligation

Understanding this gap is a board-level responsibility, not just a risk management function question. Directors who approve AI deployments without a documented analysis of how the existing coverage architecture responds to AI-related incidents are approving those deployments with incomplete information about the risk profile.

The questions boards should be asking before significant AI deployments:

  • Has coverage counsel reviewed the D&O, cyber, and E&O policies specifically for AI incident response? Generic policy review does not address AI-specific gaps.
  • Are AI-specific endorsements available from current carriers? Some insurers now offer AI liability endorsements. Whether they are available, and at what cost, is relevant to the deployment decision.
  • What is the claims notification obligation if an AI incident occurs? Trigger clauses differ across policies, and delayed notification can void coverage even when a qualifying event occurred.
  • Has the company's AI-related exposure been disclosed in underwriting? Coverage that was not underwritten for AI exposure may be challenged when AI exposure causes a loss.

Getting Ahead of the Gap

The boards in the best position on AI insurance coverage are the ones that mapped the gap before an incident, not after. Coverage can be restructured. Endorsements can be added. Underwriting can be redone with AI exposure accurately disclosed. Vendor contracts can include AI liability provisions that shift risk appropriately.

None of this is possible after the incident that makes the gap visible. The time to close it is when the AI system is still being evaluated for deployment, before the board approves it, and before the first claim tests whether the insurance architecture actually works.

Ready to assess your board?

The Compass is where every Vela engagement begins. Request access or a briefing to see what it surfaces for your board.

Request a Briefing More Resources