
For your company
Governance & Compliance
Module · Who pays when the AI is wrong
The AI Liability & Insurance Check
When an AI output causes real damage, the question is not whose fault it feels like, but which contract, which policy, and which clause actually carries the cost. Most companies discover the answer during the claim, which is the worst possible time. This module checks the five places liability hides: your own contracts, your insurance, your vendors' indemnities, what you tell customers, and whether anyone has modelled what a bad day would cost.
What the five levels look like
Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.
Liability is mapped
- 1Never considered
- 2Vague assumption
- 3Partially mapped
- 4Mapped for key contracts
- 5Mapped and priced
At the low end: If you cannot say which contract carries an AI-caused loss, you are exposed everywhere by default. Map your top few contract types against the AI outputs that feed them, starting with the highest-value customers. What good looks like: Mapped and priced liability turns AI risk into a number you can manage rather than a surprise. Revisit it when contract terms or AI use change; a map of last year's contracts protects last year's business.
Insurance actually covers it
- 1Never asked
- 2Assume covered
- 3Reviewing with broker
- 4Confirmed partial cover
- 5Confirmed, AI-specific cover
At the low end: An AI loss against an untested policy is a claim you may discover is uninsured at the worst moment. Ask your broker directly whether AI-caused errors are covered, and get the answer in writing. What good looks like: Confirmed, AI-specific cover means one whole category of risk is genuinely transferred. Re-check it at each renewal; AI exclusions are being added to policies faster than most buyers notice.
Vendors carry their share
- 1Never checked
- 2Vendor terms as-is
- 3Read, not negotiated
- 4Some indemnities secured
- 5Indemnities negotiated in
At the low end: Accepting vendor AI terms unread usually means accepting all the risk for a fraction of the value. Read the liability and indemnity clauses on your main AI vendors before the next renewal. What good looks like: Negotiated indemnities mean the party who built the model shares the cost when it fails. Keep checking new AI purchases; vendors reset liability to their favour in every fresh contract.
Customers were told
- 1No disclosure
- 2Buried in terms
- 3Generic disclaimer
- 4Clear on key outputs
- 5Clear and legally reviewed
At the low end: No disclosure leaves you defending both the error and the silence about how it was made. Add a clear statement where AI materially shapes a customer-facing output, and have legal confirm the wording. What good looks like: Clear, reviewed disclosure on the outputs that matter is both a legal shield and a trust signal. Keep it accurate as your AI use changes; a disclaimer that no longer describes reality can hurt more than none.
The bad day is modelled
- 1Never estimated
- 2Gut feel only
- 3Rough single scenario
- 4Modelled key scenarios
- 5Modelled and stress-tested
At the low end: Without a cost estimate, every decision about AI risk is being made blind. Sketch your most plausible bad-day scenario and put a number on it; even a rough figure changes how seriously the risk is treated. What good looks like: Modelled and stress-tested scenarios let you size coverage and controls against reality. Refresh the model as AI reaches higher-stakes decisions; the worst realistic case grows with the scope.