As businesses integrate artificial intelligence into daily operations, the disparity between swift adoption and strategic governance is becoming glaringly evident. A recent survey by Gallagher anticipates that fewer than half of organizations currently possess a formal AI risk management framework, leading to a surge in directors and officers (D&O) claims along with disputes over insurance coverage. This emerging landscape signals the urgent need for organizations to establish clear policies surrounding AI use before their next insurance renewal.
Tim Davis, COO of POWERS Insurance & Risk Management, underscores the fundamental necessity of drafting a written policy that delineates acceptable and unacceptable AI usage within an organization. “Identifying AI exposure is nearly impossible without established policies and barriers,” Davis asserts. Such a policy should outline not just which tools may be employed, but also impose strict restrictions to prevent misuse within AI systems.
Beyond policy creation, governance should include a robust feedback mechanism where employees can report AI misuse. “Encouraging staff to notify IT about potential errors enables swift investigation and remediation,” Davis notes. This aspect of governance often gets overlooked, yet mismanagement of AI technologies can expose firms to significant risks.
Equally critical is the choice of AI platforms. Consumer-focused AI tools often lack the data protections that enterprise environments guarantee. Davis recommends establishing a private, enterprise-level AI instance which would limit public visibility of business information inputted into these systems. “We advise businesses to set up a closed enterprise-level instance of AI to create proper guidelines and guardrails,” he explains.
With a solid framework in place, firms can start evaluating their AI-related exposures. It’s imperative that all current employees acknowledge the policy and that onboarding of new hires incorporates this framework to instill best practices from the outset.
Board-level understanding of AI’s liability implications remains insufficient. While many leaders recognize that AI can generate erroneous outputs, the legal ramifications tied to these inaccuracies often fly under the radar. “Business owners frequently overlook how deploying AI can heighten the risk of D&O claims arising from negligence or inadequate disclosures,” Davis warns. Misuse of AI can lead to claims for product liability, material misrepresentation, and failure to disclose AI usage in work products.
The phenomenon of AI “hallucination,” where the system generates misleading or false information, is a primary concern. “In its current state, AI merely reports on everything it reads,” Davis states, suggesting that human oversight is essential before any material is shared or relied upon.
The evidence supporting this caution is apparent in litigation trends. A February 2026 white paper from Techné AI notes a remarkable increase in AI-related securities class actions—a doubling in filings from 2023 to 2024, with 12 new cases recorded in just the first half of 2025. A notable finding: plaintiffs only need to prove that corporate leadership failed to properly govern AI, rather than demonstrating a fault in the AI technology itself.
Davis adopts what he terms the “80 percent rule.” He advocates for treating AI as a tool that gets 80% of the work done while emphasizing that human review is critical for accuracy. This applies universally, including routine tasks like drafting emails.
Assumptions about existing insurance coverage extending to generative AI liabilities are increasingly inaccurate. According to Davis, the primary policy at risk here is the cyber policy. “Coverage will depend on the specifics of a claim; it typically won’t respond to standard generative AI liabilities,” he clarifies.
The commercial general liability market has reacted swiftly; effective January 1, the Insurance Services Office (ISO) unveiled three new endorsement forms that allow carriers to expressly exclude generative AI losses from standard CGL policies. By April 2026, insurers such as W.R. Berkley, Chubb, Travelers, Berkshire Hathaway, and AIG had all initiated filings for these endorsements or proprietary exclusions concerning AI.
Davis emphasizes proactive risk management discussions with clients during renewal periods. “Our focus is on engaging with clients to understand their intended AI applications, which helps us tailor a suitable risk management strategy and evaluate the need for a standalone generative AI policy,” he notes.
A key vulnerability arises during the transition from AI deployment to the establishment of governance structures to mitigate liability. Minimum risk management responses now must include a written policy, an enterprise-level platform, and a thorough coverage assessment during renewals.
“Implement a formal policy that specifies which AI tools can be used, what tasks are permitted with AI assistance, and ensure thorough reviews of all AI-generated information before dissemination,” Davis advises. As the insurance market adjusts and narrow exclusions are becoming common, organizations that delay addressing AI risk management inevitably make a decisive choice, whether they realize it or not.