Major insurers are moving to limit their exposure to artificial intelligence (AI) failures after a series of costly and highly publicized incidents, including defamation lawsuits, financial losses from AI-generated errors, and sophisticated scams leveraging AI technologies. Insurers such as AIG, WR Berkley, and Great American are seeking regulatory approval to exclude AI-related claims from corporate policies, citing the unpredictable nature of large language models and the difficulty in quantifying liability. These moves come as enterprises rapidly adopt generative AI tools, leading to expensive mistakes and raising concerns about systemic, correlated losses that traditional underwriting cannot easily address.
Industry experts warn that the lack of clear causation between AI outputs and real-world consequences, combined with slow-moving legislation, has delayed a maturity leap in enterprise AI governance. However, the growing frequency and impact of AI-driven failures are expected to force a reset in enterprise expectations and risk management practices. As the hype around AI continues to outpace regulatory and oversight mechanisms, companies may soon face an overcorrection in how they balance model performance, safety constraints, and business speed, with insurers and regulators playing a pivotal role in shaping the future of AI risk management.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
Rather than broad exclusions, some insurers including QBE and Chubb began using endorsements and partial-coverage approaches to define narrow AI protections while excluding widespread or systemic events. This signaled a broader market shift toward ring-fencing AI risk instead of fully underwriting it.
AIG, W. R. Berkley, and Great American sought regulatory approval for policy exclusions that would limit or deny claims tied to the use or integration of AI systems such as chatbots and agents. The move reflected growing concern that AI incidents could produce large, correlated losses across many insureds.
Google was hit with a $110 million defamation lawsuit tied to allegedly harmful output from its AI Overview feature. The case highlighted how generative AI errors can create large legal liabilities for technology providers.
Engineering firm Arup lost about £20 million after criminals used deepfake technology to impersonate company executives and trick staff into transferring funds. The loss became a prominent example of AI-enabled fraud with major financial consequences.
Air Canada was required to honor a discount that its customer-service chatbot had incorrectly invented, becoming an early public example of AI-generated business liability. The incident was later cited by insurers as evidence that AI systems can create direct financial exposure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcetomshardware.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.