Q. Less than half of the business leaders we surveyed said they have an incident response plan for AI-related risks. Is that level of preparedness lower than you would expect?
Yes, although it isn't entirely unexpected. We observed a similar pattern when ransomware first emerged as a major threat. Many companies had no incident response plan at all, but over time, organisations developed playbooks for ransomware, social engineering and other cyber incidents.
However, AI incidents require an additional response. It's not simply about calling your lawyer to understand legal obligations or bringing in cyber specialists to contain an incident.
With issues such as AI bias or data integrity, organisations often need to delve into the AI platform's black box to figure out what went wrong, understand how to stop the problem and assess whether they need to pivot to another platform to keep the business operating. This may require the expertise of data scientists or other technology specialists.
In addition to the legal and operational issues, there are reputational concerns and third-party supply chain risks.
Recently published research on AI and human-related cyber risk in Australia and New Zealand found that 64% of organisations in the region already use AI agents that take autonomous actions within workflows, while 50% reported that their use of AI was unapproved or ungoverned.1
We're going to see more attention paid to best practices for AI and to how businesses can modify or add to existing ransomware incident response plans.
Q. How is the insurance industry responding to AI liability risks?
Some carriers in the market are already adapting to these emerging risks. As AI adoption grows, we're seeing greater attention paid to AI-related exposures, with insurers assessing how existing cyber, technology liability and professional indemnity policies may respond.
The insurance market has faced a similar shift before. A decade ago, many traditional policies didn't initially exclude cyber-related losses. As claims increased and insurers gained a better understanding of the exposure, exclusions emerged and standalone cyber insurance products were developed.
We could potentially see a similar evolution with AI-driven losses. If claims begin to increase in frequency and severity, insurers are likely to revisit policy wordings, and we may see more exclusions added in the short term.
Right now, we're not seeing widespread AI-specific exclusions across the Australian market, but insurers are watching developments closely. As these risks continue to evolve, organisations should regularly assess their coverage and understand how their existing policies respond to potential AI-related liabilities.
We know that AI incidents are already occurring. The question is: what will be the frequency of incidents for the rest of 2026 and beyond, and how severe will any insured losses be?
Q. Who will ultimately be held responsible for incidents involving AI?
That's one of the biggest questions organisations are asking today. If an AI platform causes harm, who is to blame? The reality is that responsibility is unlikely to rest with a single party. Depending on the circumstances, liability could be shared across multiple organisations involved in developing, deploying or using the technology.
This highlights the importance of contracts and governance. Businesses should understand exactly how their AI vendors operate, what responsibilities each party has and where liability lies in the event of an error.
Businesses should carefully review their contractual arrangements with AI vendors, who typically cap liability at 12 months of fees and are generally reluctant to deviate from standard terms of service. This situation can create limited recourse against an AI vendor.
We are also advising clients to review their cyber and technology liability policies with their broker to ensure the policy includes a waiver-of-subrogation clause, so coverage is not restricted when the client enters into a contract that limits the supplier/vendor's liability.
From a risk management perspective, businesses shouldn't automatically assume responsibility rests with the AI provider. They need to ask the legal questions and clarify their own obligations while maintaining human oversight.
There is a clear expectation that, as AI evolves, regulators and courts will provide greater clarity on how liability should be allocated. Until then, organisations should exercise caution when selecting vendors and implement strong governance.
Q. How can businesses be more proactive in managing their AI exposures and what might best practice look like?
We've been advising our clients to monitor their cyber policy and other lines of coverage as insurers continue to assess how policies should respond to AI-driven losses.
Businesses can implement several safeguards around AI as they adopt it:
- Use privileged access mechanisms that govern who can access the platform and input data.
- Having a human-in-the-loop is critical to ensure someone audits and monitors outputs regularly.
- Stay informed about evolving regulations and guidance on appropriate AI use and gain a deep understanding of incident response.
- Keep up with publicly available frameworks such as ISO 42001, the NIST AI Risk Management Framework and Australia's Voluntary AI Safety Standard to stay updated with best practices as you adopt AI.
The insurance market continues to evolve as more organisations adopt AI. We may see exclusions being added to traditional lines of coverage or endorsements that expand coverage in some way, which could have different implications for AI developers and deployers.
Q. How should companies approach the development of an AI incident response plan?
It's similar to the ransomware playbook. You could face legal exposure, so your legal counsel may play a part. You may also need external legal advisers who understand the evolving regulations in play and can help with any regulatory investigation.
But you might want to identify who your AI experts are — whether it's a proprietary or third-party platform, to determine where the tool malfunctioned, what caused the issue and how to prevent it from happening again.
If you rely on a platform to provide essential services and products to your clients, what would happen if it suddenly became unavailable? Can you pivot to another platform? Do you have insurance that would cover this? There are many questions to consider, and numerous areas that a traditional ransomware plan won't cover.
For more insights on managing the risks as your business operationalises AI and for our complete survey findings, view the Gallagher 2026 AI Adoption & Risk Survey: AI in Action.
VIEW THE 2026 AI ADOPTION & RISK SURVEY