Insure Your Agent

The exposure is real. It has been tested, and it is growing.

If an AI agent acts on behalf of your business, the legal consequences fall on your business. That sounds obvious until you work through what it means when your agent invents a policy, sends the wrong email, or approves a transaction it should have refused.

What an agent can do on your behalf.

An agent can make decisions, call tools, move money, update records and talk to customers without a person checking every step. If yours can do any of the following, you carry operational exposure.

  • Issue refunds, credits, discounts or goodwill gestures
  • Send email, WhatsApp or SMS from your domain or number
  • Commit to delivery dates, prices or terms
  • Execute transactions, bookings or purchases
  • Give advice a customer will rely on
  • Handle personal data under GDPR or a similar regime
  • Work with insurance, medical, legal or financial information
  • Act at a speed no manager can follow in real time

The legal rule is old. The technology is new.

In most jurisdictions a business answers for the statements and promises of those acting on its behalf, the same way it would for a junior employee. The difference is that the junior employee has judgement and a manager. Courts have already applied the rule to AI without much difficulty. Whether you are liable is rarely the hard part. What your insurance says about it is.

Two cases, and a pattern.

The law has already made up its mind on the central question. These are the decisions every operator should know, and the quieter losses practitioners see more often.

Moffatt v. Air Canada, 2024

A chatbot invented a bereavement refund policy. The airline was ordered to honour it.

A customer asked Air Canada's website chatbot whether he could claim a bereavement fare after travelling. The chatbot said yes. The real policy said no. When the airline refused and argued the chatbot was responsible for its own words, the British Columbia Civil Resolution Tribunal held Air Canada responsible for information on its own website, whether it came from a person or an automated system, and ordered it to pay. The decision is short and readable, and it ends the idea that "the chatbot said it" is a defence.

What SME operators should take from it

Mata v. Avianca, 2023

A brief cited six cases that did not exist. The court sanctioned the lawyers, and the tool was no defence.

Counsel in New York filed a brief whose citations had been generated by ChatGPT and never checked. The court sanctioned two attorneys and their firm, jointly USD 5,000, by opinion and order dated 22 June 2023. Professional responsibility does not bend around the tool. If your agent produces invented content and someone in your business passes it to a client, the liability sits with that person and the business behind them.

What the case teaches every operator

Autonomous transaction errors

Most are never reported. They compound.

Practitioners describe a recurring pattern: agents that approve refunds outside their authority, send quotes with arithmetic mistakes, or misclassify customer accounts. Each is a small loss. Across a customer base they add up, and in a regulated industry any one of them can open a supervisory inquiry.

What your policies probably exclude.

Four policies sound relevant. None was written with AI agents in mind, and the market is now clarifying, renewal by renewal, what each one does and does not cover. The window in which "we never excluded it" served as a defence is closing.

PolicyWritten forWhere an agent falls outside
Errors and omissions, professional indemnityFinancial loss to a client from a professional service, classically a negligent act by a person.Insurers are adding exclusions for loss arising out of artificial intelligence, algorithmic decision making or autonomous systems. Without one, the claim still turns on whether a person was in the loop and reasonable care was taken. When the agent decided, both are harder to show.
CyberUnauthorised access, data breaches and related events.Losses from a system working exactly as intended, even when what it intended was wrong. A hallucinated response is not a breach. A bad decision is not an exploit.
General liabilityBodily injury and property damage.Most software driven AI losses are economic, and the exclusions for professional services and data handling usually apply. ISO generative AI exclusion endorsements now exist for this line.
Directors and officersClaims against directors and officers personally for mismanagement.The one people forget. If an agent causes serious harm and shareholders or regulators argue the board failed to supervise the deployment, the claim lands here. Some carriers have filed AI exclusions of their own for management liability.

The exclusions to read before your next renewal

The rules that apply, and when.

The EU AI Act, the AI Omnibus that amended its timetable, and the revised Product Liability Directive. What has already applied is marked; today sits on the line.

  1. AI Act in forceRegulation (EU) 2024/1689.
  2. Prohibitions applyArticle 5.
  3. AI Omnibus in forceHigh risk dates move. Transparency stays.
  4. Transparency duties applyArticle 50, unchanged by the Omnibus.
  5. Marking, for systems already on the marketArticle 50(2), for systems placed on the market before 2 August 2026.
  6. Product Liability DirectiveTransposition deadline for Directive (EU) 2024/2853. Software counts as a product.
  7. High risk, Annex IIICredit scoring, employment, critical infrastructure and the other listed uses.
  8. High risk, Annex IAI embedded in regulated products.

The revised Product Liability Directive

A defective AI system is treated as a defective product.

Directive (EU) 2024/2853 replaces a regime nearly forty years old and brings software, AI included, inside strict liability. In plain terms, the business that placed a defective system on the market can be held liable without the claimant proving negligence. For anyone putting an agent in front of end users, that is a real widening of exposure. Does it apply to a small business that uses AI?

The United States

No federal equivalent, and the same direction of travel.

Colorado passed the first comprehensive state AI law in 2024, SB24-205. The Federal Trade Commission has brought enforcement actions against companies that misrepresent what their AI can do. The picture is fragmented, and it moves the same way as the EU.

What this adds up to

You are already inside a new regime.

The laws have changed, the cases have been decided, and the insurance market is catching up. None of it asks you to become a lawyer. It does ask you to know what your agent does, read your policies closely, and have a plan for the day something goes wrong.

Further reading.

Every guide in one place

References

  1. Moffatt v. Air Canada, 2024 BCCRT 149. British Columbia Civil Resolution Tribunal, 14 February 2024.
  2. Mata v. Avianca, Inc., 22-cv-1461 (S.D.N.Y.). Opinion and order on sanctions, 22 June 2023.
  3. Regulation (EU) 2024/1689 (the EU AI Act). Entry into force 1 August 2024.
  4. Directive (EU) 2024/2853 on liability for defective products. Official Journal, 18 November 2024.
  5. Colorado SB24-205, Concerning Consumer Protections in Interactions with Artificial Intelligence Systems. Signed 17 May 2024.
  6. Federal Trade Commission, Operation AI Comply, September 2024.
  7. AIUC-1, published by the Artificial Intelligence Underwriting Company (AIUC). aiuc.com
Next

Where does your business stand? Three questions will tell you.

What your agents do, what your policies say, and what you would do tomorrow if something went wrong. About ten minutes to read, and each one ends with a next step.