Robyn Adcock, Cyber/Tech national manager at Gallagher, discusses emerging AI liability risks and how businesses can strengthen governance and incident response planning.
Getting your Trinity Audio player ready...
null

As organisations increasingly integrate AI into day-to-day operations, the range of associated risks continues to grow, from algorithmic bias and data poisoning to other emerging exposures.

Gallagher's third annual AI Adoption & Risk Survey found that while many business leaders believe they have a good understanding of AI-related risks, fewer than half have implemented formal risk management frameworks to help govern AI use. This disconnect highlights an opportunity for organisations to strengthen governance, improve oversight and evaluate whether their existing insurance programs and risk controls are prepared for emerging AI-related liabilities.

Let's understand what these risks mean for Australia and New Zealand, with expert insights from Robyn Adcock, Cyber/Tech national manager, Gallagher.

Q. Insurance industry respondents believe AI liability claims will impact several classes of business. What other AI-related exposures do you anticipate?

As AI adoption continues to accelerate, organisations are likely to see exposures emerge across a wide range of industries. In the professional liability space, businesses in sectors such as healthcare, financial services and professional services that use AI to support decision-making could face claims if AI-generated outputs contribute to errors or unintended consequences.

Another key area is data poisoning, in which a threat actor or disgruntled employee deliberately manipulates datasets or attempts to influence AI training with incorrect or incomplete data, resulting in outputs that may cause harm.

These scenarios raise several insurance considerations. One of the most significant concerns is business interruption losses, which occur when an AI model needs retraining or must be taken offline.

Moreover, businesses relying on third-party AI platforms could face cascading disruption if those services become unavailable. This raises important questions around operational resilience, vendor dependency and contingency planning.

Another important area to consider is regulation. Across Australia and New Zealand, organisations are facing increasing expectations around AI governance, transparency and accountability. When an AI-related incident occurs, the question is how businesses determine when and how the problem originated, what actions they need to take to stop it, what they should do in the meantime and what they are doing to prevent it from happening again.

Liability considerations are equally complex. When an AI-related incident causes harm, responsibility may be shared between the AI developer, the technology provider and the organisation deploying the system. As AI becomes more deeply embedded in business operations, contracts, governance frameworks and human oversight will play an increasingly important role in determining accountability.

Q. Less than half of the business leaders we surveyed said they have an incident response plan for AI-related risks. Is that level of preparedness lower than you would expect?

Yes, although it isn't entirely unexpected. We observed a similar pattern when ransomware first emerged as a major threat. Many companies had no incident response plan at all, but over time, organisations developed playbooks for ransomware, social engineering and other cyber incidents.

However, AI incidents require an additional response. It's not simply about calling your lawyer to understand legal obligations or bringing in cyber specialists to contain an incident.

With issues such as AI bias or data integrity, organisations often need to delve into the AI platform's black box to figure out what went wrong, understand how to stop the problem and assess whether they need to pivot to another platform to keep the business operating. This may require the expertise of data scientists or other technology specialists.

In addition to the legal and operational issues, there are reputational concerns and third-party supply chain risks.

Recently published research on AI and human-related cyber risk in Australia and New Zealand found that 64% of organisations in the region already use AI agents that take autonomous actions within workflows, while 50% reported that their use of AI was unapproved or ungoverned.1

We're going to see more attention paid to best practices for AI and to how businesses can modify or add to existing ransomware incident response plans.

Q. How is the insurance industry responding to AI liability risks?

Some carriers in the market are already adapting to these emerging risks. As AI adoption grows, we're seeing greater attention paid to AI-related exposures, with insurers assessing how existing cyber, technology liability and professional indemnity policies may respond.

The insurance market has faced a similar shift before. A decade ago, many traditional policies didn't initially exclude cyber-related losses. As claims increased and insurers gained a better understanding of the exposure, exclusions emerged and standalone cyber insurance products were developed.

We could potentially see a similar evolution with AI-driven losses. If claims begin to increase in frequency and severity, insurers are likely to revisit policy wordings, and we may see more exclusions added in the short term.

Right now, we're not seeing widespread AI-specific exclusions across the Australian market, but insurers are watching developments closely. As these risks continue to evolve, organisations should regularly assess their coverage and understand how their existing policies respond to potential AI-related liabilities.

We know that AI incidents are already occurring. The question is: what will be the frequency of incidents for the rest of 2026 and beyond, and how severe will any insured losses be?

Q. Who will ultimately be held responsible for incidents involving AI?

That's one of the biggest questions organisations are asking today. If an AI platform causes harm, who is to blame? The reality is that responsibility is unlikely to rest with a single party. Depending on the circumstances, liability could be shared across multiple organisations involved in developing, deploying or using the technology.

This highlights the importance of contracts and governance. Businesses should understand exactly how their AI vendors operate, what responsibilities each party has and where liability lies in the event of an error.

Businesses should carefully review their contractual arrangements with AI vendors, who typically cap liability at 12 months of fees and are generally reluctant to deviate from standard terms of service. This situation can create limited recourse against an AI vendor.

We are also advising clients to review their cyber and technology liability policies with their broker to ensure the policy includes a waiver-of-subrogation clause, so coverage is not restricted when the client enters into a contract that limits the supplier/vendor's liability.

From a risk management perspective, businesses shouldn't automatically assume responsibility rests with the AI provider. They need to ask the legal questions and clarify their own obligations while maintaining human oversight.

There is a clear expectation that, as AI evolves, regulators and courts will provide greater clarity on how liability should be allocated. Until then, organisations should exercise caution when selecting vendors and implement strong governance.

Q. How can businesses be more proactive in managing their AI exposures and what might best practice look like?

We've been advising our clients to monitor their cyber policy and other lines of coverage as insurers continue to assess how policies should respond to AI-driven losses.

Businesses can implement several safeguards around AI as they adopt it:

  • Use privileged access mechanisms that govern who can access the platform and input data.
  • Having a human-in-the-loop is critical to ensure someone audits and monitors outputs regularly.
  • Stay informed about evolving regulations and guidance on appropriate AI use and gain a deep understanding of incident response.
  • Keep up with publicly available frameworks such as ISO 42001, the NIST AI Risk Management Framework and Australia's Voluntary AI Safety Standard to stay updated with best practices as you adopt AI.

The insurance market continues to evolve as more organisations adopt AI. We may see exclusions being added to traditional lines of coverage or endorsements that expand coverage in some way, which could have different implications for AI developers and deployers.

Q. How should companies approach the development of an AI incident response plan?

It's similar to the ransomware playbook. You could face legal exposure, so your legal counsel may play a part. You may also need external legal advisers who understand the evolving regulations in play and can help with any regulatory investigation.

But you might want to identify who your AI experts are — whether it's a proprietary or third-party platform, to determine where the tool malfunctioned, what caused the issue and how to prevent it from happening again.

If you rely on a platform to provide essential services and products to your clients, what would happen if it suddenly became unavailable? Can you pivot to another platform? Do you have insurance that would cover this? There are many questions to consider, and numerous areas that a traditional ransomware plan won't cover.

For more insights on managing the risks as your business operationalises AI and for our complete survey findings, view the Gallagher 2026 AI Adoption & Risk Survey: AI in Action.

VIEW THE 2026 AI ADOPTION & RISK SURVEY


Sources

1Tarre, Mark. "AI Use Outpaces Governance in Australia & New Zealand," Security Brief, 29 Jun 2026.


Disclaimer

Gallagher provides insurance, risk management and benefits consulting services for clients in response to both known and unknown risk exposures. When providing analysis and recommendations regarding potential insurance coverage, potential claims and/or operational strategy in response to national emergencies (including health crises), we do so from an insurance and/or risk management perspective, and offer broad information about risk mitigation, loss control strategy and potential claim exposures. We have prepared this commentary and other news alerts for general information purposes only and the material is not intended to be, nor should it be interpreted as, legal or client-specific risk management advice. General insurance descriptions contained herein do not include complete insurance policy definitions, terms and/or conditions, and should not be relied on for coverage interpretation. The information may not include current governmental or insurance developments, is provided without knowledge of the individual recipient's industry or specific business or coverage circumstances, and in no way reflects or promises to provide insurance coverage outcomes that only insurance carriers' control.

Gallagher publications may contain links to non-Gallagher websites that are created and controlled by other organisations. We claim no responsibility for the content of any linked website, or any link contained therein. The inclusion of any link does not imply endorsement by Gallagher, as we have no responsibility for information referenced in material owned and controlled by other parties. Gallagher strongly encourages you to review any separate terms of use and privacy policies governing use of these third party websites and resources.

Insurance brokerage and related services to be provided by Arthur J. Gallagher & Co (Aus) Limited (ABN 34 005 543 920). Australian Financial Services License (AFSL) No. 238312.