Hallucination Losses and Professional Liability Triggers

When professionals verify and deliver AI outputs, liability shifts from the vendor to them.

Technology & Courts Reporter · · 11 min read
Cover illustration for “Hallucination Losses and Professional Liability Triggers”
AI Model Liability · October 8, 2026 · 11 min read · 2,517 words

A hallucination turns from a technical flaw into a liability event at one specific moment: when a professional takes an AI output, fails to verify it adequately, and hands it to a third party who then relies on it. That moment, not the underlying model error, is what a court or a carrier actually looks at. A fabricated case citation, a poisoned data source feeding a retrieval system, and a synthetic executive email asking for a wire transfer are three different technical failures, but each one routes to a different insurance line: professional negligence, cyber intrusion, or crime. A mapping of AI insurance risk published in May 2026 and revised that June describes this as the defining "silent-AI exposure" problem: an AI-mediated loss lands under a policy that was never priced to absorb it.

The law has produced the clearest paper trail so far, because citation errors are public and easy to check. Sullivan & Cromwell came under scrutiny after one of its lawyers submitted a court filing with numerous errors and false citations, a mix of AI hallucinations and manual mistakes. A federal magistrate judge warned Gordon Rees formally against filing documents with AI-hallucinated citations, and in 2026 opposing counsel alleged that a separate Gordon Rees brief had inaccurate or unsupported descriptions of legal authorities. Neither firm is an outlier. AI researcher Damien Charlotin has tracked more than 370 court decisions since June 2023 in which lawyers were accused of presenting hallucinated AI content, and the AI liability MGA Testudo has logged 720 U.S. incidents of an attorney sanctioned or disciplined for filing AI-hallucinated material, with the highest recorded fine reaching $110,000.

The vendors building the AI tools used in these filings are rarely named as defendants because of contractual liability transfer. Legal AI vendor agreements transfer liability downstream to the firm that deployed the tool, on the logic that the firm reviewed the output before it reached a court or a client. The law firm, not the software maker, is the party that certified the work as sound, so the law firm absorbs the consequence when it was not.

None of this is confined to law practice. Brokers have reported seeing the same broad AI exclusion language spreading into E&O policies held by architects and medical facilities, with one broker calling the spread "concerning." Any profession that certifies a document, a design, a diagnosis, or a disclosure before it reaches a client is exposed to the same mechanism that caught Sullivan & Cromwell and Gordon Rees: reliance on an unverified output, followed by delivery to someone outside the firm.

What replaced the "silent AI" era

For several years, most professional liability policies said nothing at all about AI, neither covering it by name nor excluding it. That silence actually worked in deployers' favor: legal ambiguity meant a claim arising from an AI-related loss could plausibly fall under coverage the policy already provided. That protection has been removed systematically since 2025, and it was removed quietly.

ISO writes the standardized policy forms that underpin most U.S. commercial liability insurance, so the clearest marker of the shift came from there. ISO's endorsements CG 40 47, CG 40 48, and CG 35 08 (edition 01 26) exclude generative-AI-related liability from commercial general liability coverage, and they became available for carriers to attach starting January 1, 2026. Because ISO forms are the template most of the property and casualty market builds from, this was not a niche change. So it reached the base layer of commercial liability coverage across the country.

The scope of what counts as "generative AI" under these exclusions is written broadly on purpose. The definition covers nearly any machine-based system capable of producing text, images, audio, video, or code, sweeping in tools professionals use every day without thinking of them as AI products. A drafting assistant, an image generator embedded in a marketing tool, a transcription service: all of it can fall inside the exclusion's reach.

Carriers moved fast once the ISO language existed. W.R. Berkley introduced what it called an "absolute" AI exclusion across its Directors & Officers, Errors & Omissions, and Fiduciary policies, built around language excluding anything "based upon, arising out of, or attributable to" the actual or alleged use, deployment, or development of artificial intelligence. Berkshire Hathaway, Chubb, and Travelers each sought state regulatory approval to exclude AI-related damages, and regulators approved most of these requests. Hamilton had already pushed broad AI exclusions into professional liability forms since 2024, so it moved ahead of the rest of the market.

The part of this shift that matters most for a deployer is procedural. These exclusions did not require any policyholder to opt in. They arrived at renewal, folded into standard endorsement paperwork, the same way a rate adjustment or a minor definitions change would arrive. An organization whose broker did not flag the new AI exclusion language has no reason to know its coverage changed until a claim gets filed and declined. Most E&O policies across industry segments remain silent on AI rather than actively excluding it, and a small number of insurers have started offering sub-limits as a narrow form of affirmative coverage. But the industry's own read on that silence is that it will not last: it will take one large case where the policy stayed silent and the insurer declined the claim anyway, and the silent approach will end across the board.

Why the Coverage Structure Most Deployers Rely On Was Never Designed to Respond to This Loss

Diagram: Three Coverage Lines, Three Structural Gaps. Visualizes: Show three parallel coverage lines — Commercial General Liability, Cyber Insurance, and Technology E&O — each with a single labeled gap explaining why it does not respond to an AI…

Most companies deploying AI tools assume their existing insurance stack, commercial general liability, cyber, and technology errors and omissions, provides some baseline of protection against an AI-related claim. Each of the three has a structural reason it does not, and the three gaps do not overlap so much as stack on top of each other.

Start with CGL. ISO has issued endorsements stripping out coverage for bodily injury, property damage, and personal and advertising injury that arise out of generative AI, along with a narrower version that removes only the personal and advertising injury piece. For any company whose AI tools interact with customers directly, or feed into decisions that cause physical or financial harm, this removes the base layer of liability protection that CGL was supposed to provide. That gap leaves the policy with no floor under it.

Cyber insurance was never built to fill that hole. Cyber policies respond to ransomware and data breaches, the incidents they were designed around from the start. They typically do not cover bodily injury, intellectual property infringement, defamation, hallucination-driven financial loss, or harm from data disclosed through an AI system's own outputs. A hallucinated financial projection delivered to an investor, or a defamatory statement an AI chatbot generates about a competitor, sits outside what a standard cyber program was ever written to touch.

Technology E&O is where the confusion runs deepest, because it sounds like exactly the right policy for an AI-related claim and usually is not. Tech E&O exists to cover vendors and suppliers of technology products and services. A company that deploys a vendor's AI tool to serve its own customers, or to improve its own internal operations, is not itself providing a technology service in that transaction. It is a user of one. Its own Tech E&O policy, if it carries one at all, likely does not respond to a claim arising from that deployment, because the policy was underwritten around the company acting as a technology provider, not a technology buyer.

That gap pushes companies to rely on vendor indemnification instead, but that reliance usually fails too. Most AI vendor agreements cap total liability, including any indemnification obligation, at twelve months of fees paid. Vendor Tech E&O policies themselves often exclude the very risks AI systems generate: hallucination-related losses, IP infringement, and data disclosure through model outputs. An indemnity clause backed by a policy that excludes the risk it is supposed to cover is a promise with no funding behind it. Being named an additional insured on the vendor's policy does not fix this either, because that status only extends as far as the underlying policy's own coverage goes. If the vendor's policy excludes AI-specific risks, you get no protection from standing as an additional insured on that same policy.

Early industry reporting puts a number on how often this gap has already produced a loss: one in five commercial insurers reported an AI-related loss in 2025, and only about half of those losses were fully covered. Boards carry a related exposure of their own. Some D&O forms now carry optional exclusions broad enough to capture governance failures, regulatory inquiries, and disclosure-based claims tied to AI use, which leaves directors of AI-deploying companies personally exposed for governance decisions unless they go out and secure affirmative cover for that exposure specifically.

How hallucination losses flow across a multi-party deployment and who absorbs them

Diagram: Where an AI Hallucination Loss Actually Lands. Visualizes: Visualize a liability chain showing how an AI hallucination loss travels from origin to ultimate bearer across four parties: model vendor → deploying organization → enterprise…

An AI hallucination loss does not originate and settle in one place. It travels through a chain, model vendor to deploying organization to enterprise customer to the third party actually harmed, and the commercial agreements along that chain are built to make sure the deploying organization is the one left holding the loss the vendor has disclaimed.

Where a loss actually originates shapes which coverage line might respond to it, and that origin is often genuinely ambiguous. A flawed model output, an adversarial prompt designed to manipulate the system, a compromised third-party tool feeding the model bad data, a human choosing to trust an AI output without checking it, a vendor's own failure, or physical harm caused by an automated action: each of these points toward a different line of coverage, and courts end up deciding which framing controls a given case.

The vendor liability transfer mechanism described earlier in the legal context holds across every industry running AI deployments. Vendors are not named in the resulting negligence claims because their contracts shift liability to whoever deployed the technology, on the premise that the deploying organization reviewed the output before it went anywhere. The deployer becomes the responsible party because it was the last checkpoint before the output reached someone outside the organization.

What makes this arrangement dangerous rather than merely inconvenient is how much complexity it conceals. Large language models present themselves through simple interfaces, a prompt box, a chat window, and they seem to deliver broad general capability and high accuracy without friction. That apparent simplicity hides a real shift: the complexity those interfaces seem to eliminate does not disappear, it moves into the infrastructure, compliance processes, and specialized staff the deploying organization now has to build and maintain. A company that adopts an AI tool expecting a straightforward cost reduction has, in practice, taken on risk in proportion to the complexity it cannot see from the user-facing side of the product.

This is not a side effect companies can route around by picking a cheaper or simpler tool. Mastering that shifted complexity, through abstraction layers that manage model behavior, workflows aligned to catch errors before they reach a third party, and in-house expertise that understands where the model is likely to fail, is itself becoming the source of competitive advantage. Organizations that treat AI adoption as a pure cost play, without building the compliance and oversight capacity the shift demands, are the ones most likely to discover the uninsured gap at the worst possible moment: after a hallucination has already reached a client, a regulator, or a court.

The party with the least control over how the underlying model was built and trained, the enterprise deployer, ends up as the primary bearer of liability when something goes wrong, holding a vendor indemnity capped at a year of fees and backed by an insurance policy that may exclude the very loss at issue, underneath a CGL, cyber, and Tech E&O stack that, as shown above, was never built to respond to this category of claim.

Coverage structures designed to respond to hallucination-triggered claims

A handful of insurance products have been built specifically to respond to AI hallucination losses, and understanding where each one sits matters as much as knowing that they exist. The insurability frontier mapping referenced earlier sorts AI perils into four tiers: affirmatively insured, silent-AI exposure, actively excluded, and outside the reach of conventional private insurance. Hallucination losses are at the boundary between the first two tiers, and which side of that boundary a given company lands on depends heavily on the exact wording it negotiates into its policy.

For AI vendors themselves, the most complete affirmative product on the market is a coordinated program combining Tech E&O, Cyber Liability, and D&O coverage in one structure, built around model errors, hallucinations, training data IP exposure, biased outputs, and the actions of autonomous agents. Enterprise buyers increasingly require their AI vendors to carry this kind of program before they will sign a contract at all, which turns it from a defensive purchase into something closer to a sales requirement for the vendor.

Carriers in this space have settled into distinct areas of focus. Public materials show Munich Re oriented around model performance and drift, with parts of the Lloyd's market concentrated on hallucination and broader AI liability questions. Tokio Marine Kiln and CFC have built out coverage around intellectual property and technology E&O concerns specifically. Apollo ibott has positioned around emerging liability tied to autonomous systems, and Coalition has built its AI-related response around deepfakes and AI-enabled cyber incidents. No single carrier covers the full span of hallucination-related loss, so a company's coverage program typically has to draw on more than one of these positions to close the gap described in the sections above.

Cyber coverage has started to move too, though narrowly. AXA XL added a GenAI endorsement to its CyberRiskConnect policy in October 2024, and it covers data poisoning, usage-rights infringement, and regulatory violations tied to the EU's AI Act. That endorsement is a real step forward for the specific risks it names, but it remains built on top of the structure and exclusions of the underlying cyber program, and it is not a substitute for broader AI liability coverage.

Companies running physical AI systems, robots operating on a factory floor or in a warehouse, face a different version of this problem, and a different product has emerged to address it. Axis Insurance built a program that covers bodily injury and property damage from AI navigation or perception failures, physical damage from a cyberattack that takes over a robot's controls, and production losses from a software update or sensor failure even when no physical damage occurs. If you deploy physical AI systems in the field, that kind of purpose-built program closes a gap none of the standard CGL, cyber, or Tech E&O lines were ever positioned to fill.

Across all of these products, the underlying lesson is the same one that runs through the whole insurance landscape described here: coverage built for AI risk has to be bought affirmatively and worded with the specific loss scenario in mind. No combination of silence, assumption, or vendor promise is standing in for it anymore.

Sources

  1. The Insurability Frontier of AI Risk: Mapping Threats to Affirmative Coverage, Silent Exposures, and Exclusions
  2. From Model Design to Organizational Design: Complexity Redistribution and Trade-Offs in Generative AI
  3. The AI Insurance Gap and What It Means for Technology Contracts: Law Firm, Attorneys, Lawyers - Honigman

More in AI Model Liability