LawQi

Module 7.2 · Topic 2

Coverage Gaps and Emerging Exclusions

Bottom Line Up Front: Carriers are adding explicit AI exclusions to new policies and endorsements to existing ones. The gaps are specific: undisclosed AI use, unverified outputs, hallucination errors, and…

2.1 AI-Specific Exclusions in Modern Policies

Modern professional liability policies are adding explicit AI exclusions. The specific language varies, but the categories are consistent. Here are the exclusions appearing most frequently in 2026 renewals:

  • Undisclosed AI Use Exclusion: "Coverage does not apply to claims arising from the use of artificial intelligence or automated systems that were not disclosed to the client and documented in engagement materials." This exclusion directly penalizes nondisclosure and is increasingly mandatory.
  • Unverified Output Exclusion: "Coverage does not apply to errors arising from reliance on AI-generated outputs that were not subjected to independent verification or quality control prior to delivery to the client." This exclusion incentivizes verification workflows but may be interpreted strictly.
  • Hallucination Carve-Out: "Coverage does not apply to errors arising from fabrications, hallucinations, or false factual statements generated by AI systems." Some policies define hallucination narrowly (only complete fabrications) while others define it broadly (any output the AI cannot explain or ground).
  • Confidentiality Misuse Exclusion: "Coverage does not apply to claims arising from the unauthorized disclosure of confidential client information through the use of AI systems, cloud-based AI tools, or failure to maintain adequate data protections." This exclusion focuses on how client data enters the AI system, not just the output.
  • Training & Compliance Condition: "Coverage is conditioned upon the insured's completion of annual AI competence training and documented compliance with the insured's AI use policy." This is not strictly an exclusion; it is a coverage condition. Failure to meet the condition can void coverage.

2.2 AI Security Riders and New Carrier Requirements

To offset exclusions, carriers are offering AI security riders—optional coverage that covers specific AI risks if the firm implements specified protective measures. Understanding rider requirements is essential because accepting a rider means committing to its conditions. Here is the process for evaluating and implementing a rider:

  1. Audit Your Current State: Before your renewal conversation with your insurer, inventory your current AI practices: what tools do you use, what client data enters those tools, what verification do you perform, and what do you disclose to clients. Document the answers.
  2. Review the Rider Requirements: When your insurer proposes an AI rider, extract the specific requirements. These typically include: (a) documenting AI tools and their permitted uses, (b) implementing minimum verification standards, (c) training requirements, (d) data protection agreements with vendors, and (e) reporting obligations to the insurer.
  3. Map Requirements to Your Practices: For each rider requirement, assess whether your current practices satisfy it or require modification. Create a simple table: requirement, current practice, gap, remediation needed. Do not assume your current practices meet the standard—carriers define standards differently.
  4. Implement Missing Elements Before Renewal: Identify which elements you can implement immediately (documentation, training) and which require planning (vendor agreements, system changes). Start implementation before your renewal conversation, so you can speak credibly about your compliance path.
  5. Negotiate the Rider Terms: If the rider includes expensive conditions (e.g., monthly audits, third-party verification), negotiate. Some carriers will phase in requirements or offer alternatives that achieve the same risk reduction at lower cost.
  6. Confirm Renewal Coverage in Writing: Once you have agreed on a rider, ensure that your renewal documentation explicitly states that coverage applies provided you comply with the rider's conditions. Get this in writing before you renew.

2.3 Hallucination Risk and Coverage Implications

One of the most confusing coverage questions is whether your insurance covers losses from AI hallucinations—situations where the AI confidently produces false information, like fake case citations, made-up dates, or fabricated facts. The answer is: sometimes, but increasingly not.

In the first generation of AI liability claims (2022–2024), courts and carriers treated hallucinations as covered errors: the attorney made an error by relying on unverified AI output, and the error caused loss, so insurance covered the loss. The insurer's position was that the attorney's failure to verify was negligence, and negligence is a covered peril. But as hallucinations became better understood as a systematic failure mode of large language models, carriers shifted their position. Now, most carriers argue that hallucinations are not covered because they result not from the attorney's negligence but from the AI system's incurable defect. This is a meaningful distinction: it means that once you know an AI system is prone to hallucination, relying on it constitutes a deliberate risk, not an honest mistake.

Coverage for hallucination losses now depends on: (1) whether your policy explicitly excludes hallucinations, (2) whether you disclosed to your client the possibility of hallucinations, and (3) whether you followed a documented verification procedure. If you implemented industry-standard verification (e.g., checking all citations, confirming all facts), then a hallucination that slips through your verification is more likely to be covered than a hallucination you did not attempt to verify. The lesson is not that hallucinations are uninsurable; it is that hallucination coverage now requires documented prevention and verification practices.

2.4 Confidentiality Breaches and UPL Exposure

Confidentiality breaches are the fastest-growing class of AI-related insurance claims. They arise when client data fed into an AI system is inadvertently disclosed, when an AI system retains data after use, or when an AI system is hacked. These breaches trigger two insurance issues: cyber liability coverage (for the breach itself) and professional liability coverage (for your breach of client confidentiality under ABA Model Rules).

Confidentiality Breach Coverage Questions

  • Cloud-Based AI Systems: Many AI tools operate on cloud infrastructure. When you send client data to a cloud AI system, does your engagement letter disclose this? Does your cyber liability coverage extend to third-party cloud providers? Does your professional liability policy exclude coverage for breaches arising from cloud system use? These are critical questions that interact across your coverage forms.
  • Data Retention: AI systems sometimes retain training data. If a client's confidential information is retained by an AI system and later disclosed (through a data breach, regulatory access, or competitive use), who is liable? Is this a breach you caused (triggering professional liability) or a systems failure you cannot control (excluded from coverage)? The distinction determines whether you have recovery.
  • Unauthorized Access Control: If you share AI outputs with staff who should not see them, or if you store AI outputs on systems that are accessible to unauthorized users, are you liable for the resulting client confidentiality breach? Most insurers view this as a security failure on your part, potentially excluded from coverage if your policy contains a requirement to maintain adequate access controls.

UPL Exposure From Confidentiality Failure

Unauthorized Practice Risk: If your AI workflow inadvertently discloses a client's confidential information, and that disclosure results in harm to the client (e.g., opposing counsel learns a negotiating position, a third party discovers a confidential vulnerability), the client may claim that you engaged in "unauthorized practice" by failing to keep information confidential. Some states view this as a violation of ABA Model Rule 1.6 (Confidentiality) that creates liability separate from malpractice. Confirm that your professional liability coverage extends to UPL claims, and implement data governance practices that prevent confidential information from leaving your secure environment without explicit authorization.