About this session

Your clients are putting generative AI and automated decision tools in front of customers, patients, and applicants, and states are writing rules for that use almost as fast as the technology develops. This session walks through Utah's AI Policy Act, the Texas Responsible AI Governance Act, Colorado's ADMTA, California SB 243, and Hawaii HB 2137. For each one it covers who the law reaches, what triggers a violation, and whether a state attorney general or a private plaintiff enforces it.

It then turns to the insurance program. The session explains why a regulator's investigation tends to fall between general liability, E&O, D&O, and cyber, and how Testudo's AI Regulatory Violation insuring agreement is built to respond to the cost of investigation and defense, with fines or penalties only where insurable by law. It also says plainly what stays outside Testudo's appetite, and closes with a sequence brokers can use to map a client's AI deployments against these statutes.

Key takeaways

  • With no single federal AI statute, a company's regulatory exposure gets wider, because it has to track rules state by state and sector by sector.
  • Utah's AIPA, Texas's TRAIGA, and Colorado's ADMTA are enforced by state attorneys general, while California SB 243 and Hawaii HB 2137 run mainly through a private right of action, which can accelerate the volume of potential third-party claims.
  • A regulator's inquiry costs money from the day it opens, and a well-governed company can pay for investigation, defense, appeal, and resolution even when it is ultimately cleared.
  • Healthcare, companion and wellness chatbots, financial and professional services, and any business running a customer-facing generative AI chatbot recur across these statutes and are worth checking first in a book.
  • Start by mapping which generative AI systems a client uses, in which jurisdictions, and for which regulated activities, then ask whether AI regulatory defense is affirmatively granted anywhere in the tower.

Transcript

0:00Introduction and Testudo AI Liability Sessions Overview

  • 0:05

    All right, welcome everyone to Testudo's second webinar, where this time around we'll be covering our newest insurance offering, an additional coverage area to our third party generative AI liability product. Our new AI regulatory proceedings coverage steps in when a regulator formally investigates your company's commercial use of generative AI, paying both the resulting fines or penalties where insurable and the legal costs of defending the proceeding.

  • 0:30

    We'll take this time today to give a broad overview of how AI regulation is emerging in the United States. For some background, around 38 states adopted or enacted close to 100 AI measures in 2025. Wiley Rein's recent publication on emerging 2026 state AI bills lists 12 state legislatures' distinct liability-expanding trends, which may introduce attorney general enforcement, private right of action, and other relief such as punitive damages, related to the non-consensual intimate deepfakes, AI companions, data privacy, chatbot disclosures, dynamic and individualized pricing, policing, elections, and healthcare. As their article puts it, lawmakers often provide individuals with private rights of action, expanding the avenues for liability and redress. Collectively, these trends will reshape the liability

0:36Origins of AI Regulation and State Legislative Trends

  • 1:18

    landscape for all companies incorporating AI solutions into their business operations. Some states have modeled their laws on the comprehensive EU AI Act, and some have narrowly amended existing laws to account for the rise in businesses using AI operationally. This ongoing evolution in regulation brings about a few issues that can be partially fixed with affirmative insurance. For one, AI regulation evolves and appears almost as quickly as the technology is developed, and companies are often left unsure as to whether there's any relevant legislation they should be monitoring.

  • 1:51

    Further, these regulations can often target different industries, leaving an uneven exposure across commercial sectors deploying generative AI tools. As those familiar with Testudo know, our ability to underwrite generative AI liability for deployers of AI tools is a distinct exposure from the liability which AI vendors may incur from selling technology products and services. There's also the international element of US domicile companies with a global presence and the applicable AI regulations they face in different markets in which they operate.

  • 2:20

    With all of these overlapping exposures considered, as well as the rapidly evolving technology and slightly lagging regulatory backdrop, securing affirmative cover for insurable costs relating to AI regulatory proceedings has emerged as a necessary safety net for many sectors. We'll now dive into those industries so that our viewers today, whether brokers or risk managers, can assess their portfolio or company for regulatory violation exposure. Our underwriting of the liabilities arising from commercial use of generative AI tools has taught us that no two companies use generative AI the same way. Even within sectors, the adoption, maturity of systems, education of users, and downstream third parties all differ with each risk.

  • 2:59

    That variety means that third party harm is not yet a narrow, well-defined risk. In fact, it's a rapidly widening one. With each additional day that companies deploy generative AI, they incur a growing exposure to third party harms that is either being self-insured or at best silently covered, which means that insurance coverage may not respond as expected. In terms of strategic implications for businesses, we know that broad regulatory landscapes can be overwhelming for companies. The fact that there isn't a single federal statute does not mean that a company's regulatory exposure is lessened. It actually broadens the scope of their exposure with a fragmented regulatory environment. Our AI regulatory proceedings coverage is designed so that when a generative AI regulatory proceeding is brought against an insured, the coverage responds to the legal costs and expenses of the

3:19Strategic Implications for Commercial AI Deployers

  • 3:45

    investigation, defense, appeal, and resolution a company incurs in cooperating with and working through the proceeding itself, as well as the resulting fines or penalties where insurable. The moment a regulator opens an inquiry, the insured is spending money to respond, whether or not it has done anything wrong. An attorney general action can be triggered by, for example, a missed disclosure at the start of a high-risk interaction or an allegation of bias in a consequential decision. In a landscape shifting across dozens of state regimes, a well-governed company can find itself paying the cost of the investigation, defense, appeal, and resolution, even where the insured is ultimately cleared.

  • 4:22

    Companies must familiarize themselves with applicable AI regulations in their operating markets and align internal policies with those rules and supervisory standards. Businesses can establish strong governance frameworks, risk management protocols, and accountability mechanisms to better manage AI technologies. But for commercial entities which are deploying generative AI to absorb the bulk of third party communications, there is a non-zero error rate which basically ensures that consumers will interact with an erroneous output or hallucination at some point.

  • 4:52

    Some of the earliest demand we've seen for affirmative AI liability risk transfer comes from industries which, perhaps unsurprisingly, owe a higher standard of care to their third party clients, patients, or students. Just to name a few, healthcare, financial institutions and services, education, law firms, and retail commerce comprise some of the highest demand and interest we've seen. While these sectors may take additional precautions internally to establish risk management frameworks around AI usage with internal policies, safeguards, and reporting procedures, they also understand that AI liability is a traditional liability risk emerging through the use of new technology.

  • 5:25

    As such, there's more nuance to the risk profile than first meets the eye, as one must consider how third party claimant attitudes will shape around a commercial entity using AI tools for consequential decisions in high-risk environments. These concerns are already manifesting as claims across different lines of insurance. Within D&O, we've seen the early stages of AI washing claims, where the reliance of regulators on consumer protection and anti-fraud laws has led to arguments that companies have misled consumers with deceptive AI marketing practices.

  • 5:56

    The FTC and SEC in particular have been operating as the primary enforcement bodies for deceptive AI practices and misrepresentations about the use of AI. We've also seen lawsuits against model developers over safety concerns regarding their products. Defective product liability claims have been brought against entities such as OpenAI and Character AI, arguing that defective AI design or failure to warn have led to physical, financial, and emotional damages.

  • 6:21

    Liability for similar harms, though under different legal theories, transfers to the commercial deployers of these tools, who, as we covered in our last webinar, are liable for when outputs of their AI tools cause third party harm. Lawsuits against them, rather than accusing these companies of defective product design, allege negligence in deployment. And it is in alignment with this objective to advocate for the prevention of AI-driven consumer harm on the operational deployer level that regulatory trends are emerging.

  • 6:48

    There is also a divergence in compliance practices. Global companies now use technology that naturally does not follow traditional territorial limitations, as AI outputs can be used worldwide. They therefore face a choice. They can try and follow the strictest US state-specific or EU rules. Or they can risk federal and state regulatory investigation and litigation and even EU regulatory crossfire. If we are to drill down and consider companies operating solely in the US, companies would need a 50-state radar for AI regulatory changes as well as an updated understanding of sector-specific regulator expectations.

  • 7:22

    So you can see here why trying to comply with so many state AI regulations is likely to lead to inadvertent violations. We'll now look at some of the emerging regulatory statutes and acts shaping the space to investigate what standards they're setting and which industries may be targeted. This analysis will highlight the emerging laws in a few different states to isolate which trends around AI deployment regulatory bodies are targeting.

7:48Utah AI Policy Act (AIPA): Disclosure and Transparency Rules

  • 7:49

    To begin, we'll take a look at Utah's Artificial Intelligence Policy Act, which became effective 1st of May 2024. This act was the first US law aimed specifically at generative AI transparency and is enforced by the Utah Attorney General and Division of Consumer Protection. The act creates disclosure requirements for any business that uses, prompts, or otherwise causes generative AI systems to interact with customers. It removes the ability of a company to defend themselves with the argument that the machine did it by naming the deployer of generative AI tools as liable for the outputs it puts into commercial use.

  • 8:23

    Penalties for Utah's AIPA are up to $2,500 per violation. The trigger for a violation here is regarding how a supplier uses generative AI in a consumer transaction. They must disclose their use of generative AI at the outset of a high-risk interaction, which means one involving sensitive personal data or financial, legal, medical, or mental health advice, if this advice is being relied upon for a significant decision.

  • 8:47

    Thus the industries which would be of concern here involve licensed professionals and their firms if they deploy generative AI in client-facing work. This would include, for example, medical and clinical practices, telehealth, law firms, financial advisers and planners, accountants, and mental health or therapy providers. It would also include any consumer-facing businesses which run a generative AI chatbot for customer support. If a consumer directly asks for a disclosure, a business must disclose generative AI use. For regulated occupations and high-risk interactions, the proactive disclosure duty comes into effect. This is squarely within our appetite as a civil action against a deployer under an AI-specific statute.

9:27Texas Responsible AI Governance Act (TRAIGA) Enforcement

  • 9:29

    The next act that we'll look at is Texas's TRAIGA, or the Texas Responsible AI Governance Act. TRAIGA became enforceable 1st of January this year and is exclusively enforceable by the Texas Attorney General with no private right of action. It involves a mandatory 60-day cure period, but it distinguishes between curable civil penalties, which fall between $10,000 to $12,000, uncurable penalties, which can be as high as $200,000, and continuing fines able to be accrued, which can be between $2,000 to $40,000 per day.

  • 10:00

    This enforcement can be brought against any business servicing Texas residents which is operating as a deployer of AI. It prohibits intentional uses of AI tools which are designed to incite harm, self-harm, or criminal activity, as well as intentional unlawful discrimination against a protected class, production or distribution of unlawful sexual deepfakes and CSAM, and infringement of constitutional rights.

  • 10:22

    Substantial compliance with the NIST AI Risk Management Framework or an equivalent standard is an affirmative defense or safe harbor. The AI uses outlined above are designed to target particular industries with the capacity for third party harm. The healthcare industry is one, specifically healthcare providers and telehealth companies deploying AI, who have a disclosure duty. Operators of companion chatbots, wellness chatbots, and character chatbots also fall under this act, as behavioral manipulation and deepfake prohibitions aimed to protect vulnerable third parties from emotional interference with AI systems.

  • 10:55

    Any business whose generative AI tools could produce unlawful explicit content would also be included, as well as employers using AI screening tools for hiring practices. Our aim at Testudo is to protect companies that inadvertently cause this kind of harm. So, our deceptive business practices, antitrust, and consumer protection exclusion is carved back for our regulatory proceedings coverage, meaning we can potentially cover a civil regulatory proceeding alleging behavioral manipulation as an unfair, deceptive, or prohibited AI practice.

  • 11:23

    Now, our underwriting team treats behavioral manipulation by AI tools as high risk, and we still maintain an AI misuse exclusion and a fraudulent or intentional misconduct exclusion. But, as mentioned, our aim is to insure businesses whose deployment of generative AI inadvertently causes third party harm, and we reserve the right to select risk based on our understanding of their exposure. Regarding discrimination claims, our discrimination exclusion is carved back in the same way for regulatory proceedings coverage, as long as the affected party is a non-employee third party.

11:53Colorado ADMTA: Automated Decision-Making Regulations

  • 11:54

    Colorado's original AI Act was enacted in 2024 but never actually came into force. It was replaced before its effective date by a narrower law which will take effect 1st of January 2027 under the name the Automated Decision-Making Technology Act and will be solely enforceable by the Colorado Attorney General with no private right of action. The act in its renewed state will focus on increased transparency about consequential decisions and disclosures about adverse outcomes by deployers of ADMT.

  • 12:22

    The ADMTA applies only when automated decision-making technology is used to materially influence a consequential decision, referring to employment, housing, education admissions, lending and financial services, insurance, healthcare, legal, and government services. Penalties can be up to $20,000 per violation as deceptive trade practices under the Colorado Consumer Protection Act.

  • 12:47

    The ADMTA eliminates the former discrimination-related obligations in the Colorado AI Act and now focuses more on reducing the risk to consumers of their access to, eligibility for, or selection for those outlined industries. Deployers under the act can satisfy the disclosure responsibility with a prominent public notice regarding the ADMT used for a consequential decision. We've addressed the relevant industries involved here, but it's important to reiterate the cross-sector entities which are exposed. Employers in their capacity as deployers of HR tech for hiring and promotion, which can involve a wide range of sectors, landlords and property managers, lenders and fintech companies, insurers, healthcare providers, and technology-enabled educational institutions deploying AI in eligibility or access decisions.

  • 13:32

    Once the act takes effect, Testudo's regulatory proceedings coverage is built to respond to a civil action against a deployer over consumer-facing discrimination or disclosure or notice failure, particularly in healthcare, housing, education, and lending, the sectors which the act specifically targets. As mentioned earlier, employee-side discrimination stays out of scope for our cover. California's SB 243 became effective 1st of January 2026 and regulates deployers of companion chatbots, which are AI systems with a natural language interface that give adaptive humanlike responses to meet the user's social needs. Importantly, this does not include chatbots used solely for customer service.

13:55California SB 243: Companion Chatbots and Private Right of Action

  • 14:15

    SB 243 is worth pausing on because it enforces differently from the statutes we've covered so far. Utah's AIPA, TRAIGA, and Colorado's ADMTA are each enforced by a state attorney general. SB 243 is enforced through private right of action. So, while it's part of the emerging AI regulation we're witnessing, we're highlighting it today because it's less of a regulatory proceeding exposure and more of a driver of third party claims.

  • 14:38

    The substantive duties took effect on 1st of January 2026. Those include a clear and conspicuous disclosure wherever a reasonable person could be misled into thinking that they're speaking with a human. For known minors, a disclosure that responses are AI generated, together with a reminder to take a break at least every 3 hours of continued use, and a documented self-harm and crisis referral protocol. A separate annual reporting requirement of crisis referral data to the state's Office of Suicide Prevention begins 1st of July 2027.

  • 15:08

    On enforcement, any person who suffers injury from a violation may bring a civil action for injunctive relief, statutory damages of at least $1,000 per violation, or actual damages, whichever is greater, and reasonable attorney's fees. The per-violation measure means exposure can stack quickly across a large user base. The case behind this law is that of Megan Garcia, who sued Character AI after her 14-year-old son died by suicide following months of use of a companion chatbot. The court allowed the claim to proceed on product liability grounds and rejected a First Amendment defense, and Character AI, its founders, and Google settled that case and four related ones in January 2026 before any judgment.

  • 15:48

    The industries in scope are operators of any sector of companion and character chatbots, wellness and emotional support chatbots, and social or entertainment products offering humanlike AI interaction. Our appetite here is deliberately limited. Companion chatbots are a high-risk class and our interest in mental health tools and in AI that can be manipulative or deceptive is minimal. So we maintain exclusions for harassment and abuse, indecent conduct content, and suicide or self-inflicted injury. So anything in this space underwritten case by case to avoid encouraging any moral hazard

  • 16:19

    before we do write the risk. SB 243 is a good example of how our product responds beyond our regulatory cover. Because enforcement is a private right of action rather than a regulator, an SB 243 claim over a disclosure failure or harmful output would be a third party claim rather than a regulatory proceeding. The attorney general enforced statutes that we're covering today are answered by our regulatory cover, but a statute like SB 243 increases the ability for third parties to bring civil action, which would fall instead under a third party liability agreement.

16:50Hawaii HB 2137: Synthetic Media and Digital Imitations

  • 16:51

    Now, the last statute we'll add to our radar is Hawaii's HB 2137, which we actually only last week when it took effect. It takes a different shape from the acts we've covered so far. So, where the other acts regulate disclosure, consequential decisions, or companion chatbots, HB 2137 targets synthetic media, meaning the use of AI generated digital imitations of a real identifiable person without their consent.

  • 17:16

    The act prohibits the knowing publication of a realistic AI generated imitation of an identifiable individual's voice, face, or likeness without consent where that imitation is used in an advertisement, causes reputational or financial loss, or is used to commit fraud, defamation, or other criminal acts. It carves out parody, satire, commentary, criticism, scholarship, political or educational expression, news reporting, and documentary or biographical use. Its enforcement is driven primarily by a private right of action allowing an affected individual to recover up to $25,000 per advertisement or their actual damages, plus punitive damages where malice is proven, as well as attorney's fees. The attorney general's role is limited to injunctive or equitable relief where the distribution involves broad public interest or widespread harm.

  • 18:03

    The industry affected here is naturally advertising and marketing, ad agencies, brands and advertisers, marketing technology vendors, and media, entertainment, and talent platforms that deploy synthetic performers or AI generated likenesses in campaigns. However, as we touched on in our last webinar, nearly every industry is using generative AI for their respective marketing purposes, meaning that the industries impacted by this act actually extend further than just the advertising industry.

  • 18:29

    The per-advertisement measure is structured similarly to the per-violation and per-day structures which we saw in SB 243 and TRAIGA. Testudo's response here follows the same logic we applied to SB 243. So because HB 2137 is enforced mainly through private litigation, the bulk of its exposure is a third party claim rather than a regulatory proceeding. A private suit for an unauthorized digital imitation could route through our GenAI IP infringement and personal injury or GenAI output error coverage. However, the attorney general enforced track could engage our AI regulatory proceedings coverage. And there our value is primarily the cost of the investigation and defense spend.

  • 19:06

    As with other high-risk exposures, the risk we're able to underwrite is the inadvertent case where, for instance, an advertiser deploys a synthetic likeness it reasonably believed was cleared and finds itself the subject of an action. Now, consumer-facing algorithmic discrimination is an exposure we are frequently asked about. Algorithmic discrimination is broader than generative AI. It can result from conventional machine learning models, scoring systems, recommendation engines, rules-based decision tools, or predictive analytics, which are systems that reach a decision without generating content.

19:19Algorithmic Discrimination and Consumer Protection Litigation

  • 19:39

    Our data locates where the exposure is concentrating, and the clearest signal is consumer AI and recommendation. Consumer AI and recommendation is the single most common business application across our incident and litigation data. And every one of these 733 applications is actually a lawsuit, not an incident. So adjacent consumer-facing categories, being surveillance and mass monitoring and social media recommendation algorithms, sit just behind. Consumer-facing systems are already where AI litigation is landing. The harms chart points to the same way, but it should be read carefully. Regulatory is the second most frequent harm tagged, but that bar is largely composed of court sanctions against attorneys who filed AI hallucinated citations.

  • 20:18

    That tells us that evidenced regulatory enforcement, meaning the kind that reaches discrimination in deployed systems, is just beginning. The two charts measure different things, types of harm versus categories of deployed application. So they aren't correlated, but when read together, they point in the same direction, which is that regulation tends to follow the sectors with the highest capability for harm. And for AI systems, both regulated litigation and deployment volume center around consumer-facing applications of AI.

  • 20:44

    Consumer protection is therefore the largest single lane of AI-related legal exposure in our data, and commercial deployers in these sectors are most likely to fall short of emerging standards. The closest analogy is privacy in the early cyber era. As AI disclosure and notice obligations spread and plaintiffs are able to easily map existing private rights of action onto AI-driven decisions, we'd expect the same sequence of regulatory and statutory activity first, then increasing private litigation.

  • 21:13

    Private right of action is already the leading driver of legal action in our database, and this dynamic should push it higher. Because of the use of traditional AI in cases of algorithmic discrimination, it would generally fall outside of our policy's definition of a generative AI system. However, if a policyholder's scheduled generative AI system was used in the decision and if an authority alleges violation of an AI regulation, the allegation could fall under our regulatory proceedings coverage.

  • 21:41

    The discrimination and civil rights exclusions are carved back only for generative AI regulatory proceedings involving non-employees. Employment-related discrimination, including AI-assisted hiring and other employment decisions, remains excluded and is outside of our underwriting appetite. Our retrospective change in law exclusion also applies where a law is enacted or brought into force after policy inception, operates retrospectively, and the relevant loss would have not arisen or would not have been increased but for that retrospective effect.

22:11The AI Regulatory Gap: Why GL, E&O, D&O, and Cyber Fall Short

  • 22:13

    So, we've covered the emerging state regulations and the exposures companies may not realize that they have. Now, as brokers and risk managers, you're probably asking, how do we actually use this information to place cover for specific clients? And where does regulatory proceedings coverage fit into that picture? The short answer is that AI regulatory proceedings coverage sits outside of the typical traditional harms which these companies insure for when they deploy new technology. Typical GL exposures like BI/PD versus typical professional liability covered harms like financial loss describe who the claimant is and what they've lost.

  • 22:46

    This builds the claimant profile that underwriters consider, and our other insuring agreements address third party bodily injury, property damage, financial loss, personal injury, unauthorized data disclosure, and IP infringement in affirmative language to meet client demand for that contract certainty. However, regulatory proceedings are different. The counterparty is a regulator. The loss in the first instance is the cost of responding to that regulator, and the trigger is the proceeding itself rather than any third party's damages.

  • 23:11

    This is why it tends to fall through the gaps of conventional program and why we've designed it to sit alongside the coverages that a company already holds rather than overlap with them. Consider how the traditional lines respond. Casualty and general liability answer to BI and PD suffered by a third party. Without physical harm, the GL tower will not respond to the cost of defending an attorney general's investigation into a disclosure failure or an algorithmic discrimination allegation.

  • 23:37

    Professional liability and E&O respond to a claimant being a client seeking damages for negligent professional services. And most forms either exclude regulatory proceedings or were not drafted considering an AI-specific statute as the source of a wrongful act. Cyber will often pick up privacy and data breach regulatory actions, but an AI regulatory proceeding is not a breach event. Failure to disclose the use of AI, behavioral manipulation, or bias in a consequential decision may not qualify as a privacy incident, and cyber's regulatory grant will usually not be triggered without that qualifying event.

  • 24:08

    These harms typically fall under violation of consumer protection and transparency harms rather than privacy harms. D&O is the one line that addresses regulatory exposure, and it's where we've seen AI washing claims driven by the FTC and SEC. However, this is management and securities exposure, which is distinct from the operational deployment level where these consumer harms can occur, and thus the consumer protection and discrimination proceeding space is where our product responds.

  • 24:35

    A useful way to picture it for a client is the deployment of a single generative AI system going wrong and touching several towers. A generative AI chatbot incident could produce a third party bodily injury claim routing through a GL tower. A separate interaction with that chatbot could produce a financial loss claim routing through professional liability, and a malicious attack could qualify as a data breach and trigger a cyber response. Separately, third party harms caused by the deployment could prompt an attorney general investigation under TRAIGA. The first three harms correspond to the injured claimant, and the deployer's silent GL, E&O, and cyber cover may respond, but regarding the attorney general's proceedings, only our AI regulatory proceedings coverage would respond to that regulator.

25:17Broker and Risk Manager Application: Mapping Client AI Deployments

  • 25:18

    So for brokers managing a book, we've seen that a handful of sectors recur across these statutes and are worth prioritizing. Healthcare is the clearest. Clinical and telehealth providers and mental health services appear under Utah's AIPA high-risk interaction disclosure duty, TRAIGA's healthcare provisions, and Colorado's consequential decision list, making this the most consistently exposed sector that we see. Operators of companion, character, and wellness chatbots are the next cluster, sitting among TRAIGA's behavioral manipulation and deepfake prohibitions as well as California's SB 243's companion chatbot regime. This is a high-risk exposure we consider, though underwritten case by case and against our misuse, indecent conduct, and self-harm exclusions.

  • 26:01

    Financial and professional services, including lenders, fintechs, insurers, financial advisers, accountants, and law firms, are included under AIPA and Colorado's ADMTA wherever AI touches advice or consequential decisions. So when landlords and property managers use it in housing, and technology-enabled schools and law firms deploy it as an AI assistant, this is one to watch. Additionally, any consumer-facing business running a generative AI support chatbot is worth a look for the disclosure failing that can trigger acts such as AIPA, even where the use itself seems low risk.

  • 26:34

    Any business which produces marketing material with generative AI is at risk of infringing on a third party's likeness. HB 2137 specifically targets ad agencies, brands and advertisers, marketing technology vendors, and media, entertainment, and talent platforms. But companies using out-of-the-box generative AI tools for their own marketing practices similarly face this exposure. The one sector to raise with a caveat is employment. HR tech and AI hiring tools feature prominently in both TRAIGA and Colorado's ADMTA. But again, employee-side discrimination sits outside our appetite, and our coverage responds to only non-employee third parties.

  • 27:10

    So how do you assess a book or client for this? The practical sequence is the one we've walked through today, just in reverse. So you'd start by mapping the client's generative AI deployment, looking at which systems they use, in which jurisdictions, and touching which regulated activities. They could be high-risk interactions under AIPA, consequential decisions under Colorado's ADMTA, companion chatbots under SB 243, screening tools under Texas's TRAIGA, or marketing content generation tools under HB 2137.

  • 27:37

    From there, we would interrogate the existing program for the silent AI gap. Is AI regulatory defense affirmatively granted anywhere in the tower? In most cases, it is neither clearly covered nor clearly excluded, which is the exposure a company is unknowingly self-insuring. We are more than happy to do this coverage gap work with you. Now, a final few, couple final points worth mentioning are that because some civil penalties are uninsurable as a matter of public policy in a number of jurisdictions, the real value of this coverage is the certainty it brings to the cost of responding, meaning the investigation, defense, appeal, and resolution spend, with fines addressed only where they are insurable by law.

  • 28:17

    For a company facing a fragmented regulatory landscape that produces new developments nearly every week, that defense cost certainty is often the difference between a manageable proceeding and an open-ended one. Everything we've discussed today sits against a state-by-state backdrop, and you may reasonably ask whether that backdrop is about to change. There are active efforts at the federal level to pause state AI regulation, and several of the state laws themselves are being challenged in court. Now, it'd be easy to read that as a reason to wait, but we would suggest the opposite. None of these efforts have displaced the statutes which are being enforced right now. And the tension between a shifting federal position and dozens of state regimes adds a layer of uncertainty rather than removing the exposure. So for a deployer, the practical question is what the exposure is today. And that's precisely the uncertainty which affirmative cover is built to absorb. So if anything, an unsettled federal

  • 29:04

    picture makes defense cost certainty more valuable. So thank you very much for attending. As in previous webinars, we'll address any questions raised via our follow-up email to attendees. Our underwriting team is more than happy to walk through specific deployment scenarios or portfolio exposures with you directly. That's what we're here for, and we love a challenge, so we'll make sure to make time to assist you and your clients. If you're a broker interested in exploring where in your book we can be of use, please get in touch. We'd love to sit down with you and go through the details.