About this session

Your clients are putting generative AI into customer chatbots, marketing content, healthcare documentation, and automated operations. In Testudo's first webinar, Arden Hovermale explains how those deployments turn into third-party claims, why the business deploying a tool is the likely defendant, and how AI vendors cap their own liability in standard contract terms.

The session then walks through Testudo's litigation data, using the example of the Rodney Smith Ltd. v. Masco Corporation copyright suit. It closes with broker questions on the ISO exclusion CG 40 47 and where CGL, Tech E&O, and Cyber policies leave gaps.

Key takeaways

  • A business that deploys a generative AI tool is the likely defendant when its outputs harm a third party, as Moffatt v. Air Canada showed for a chatbot's wrong fare information.
  • AI developers and vendors routinely cap their own liability in standard contract terms, which pushes the financial risk of a failure onto the deployer.
  • Carriers are increasingly adding generative AI exclusions to general liability and professional liability programs, including the ISO forms effective January 1, 2026.
  • IP infringement is the most frequent harm in Testudo's litigation data, while bodily injury is relatively rare and carries the highest average severity.
  • The three leading causes of incidents are oversight gaps, hallucinations, and misuse, so the questions to ask a client are who uses the AI, for what purpose, and under what controls.

Transcript

0:00Introduction and AI liability overview

  • 0:03

    All right, thank you everyone for joining Testudo's first webinar. We're hosting this to inform brokers, risk managers, and business owners on everything there is to know about generative AI liability. My name is Arden Hovermale. I'm an underwriter at Testudo. And as a bit of background, Testudo was born out of the Lloyd's Lab with the capacity of four Lloyd's syndicates. They've backed our mission to underwrite third-party liability coverage for US companies using generative AI in their business operations. We launched in February this year. Some of the main messages I'll be covering today include the basic fact that generative AI creates novel risks. Deployers of generative AI tools are likely liable for their outputs. Traditional insurance does not affirmatively cover generative AI risk exposure. And our insurance product does cover such risks. So, thank you for attending our webinar where we'll walk you through three key topics.

  • 0:50

    What generative AI is, how generative AI is being used across different industries, and AI-related litigation insights. Our goal is to show you how our product is useful to you and your clients and to assist in identifying where generative AI risk exposure exists in your portfolio. Most companies do not realize that they've assumed this risk. All right.

1:16What is generative AI and primary risk factors

  • 1:18

    Generative AI refers to AI models that are trained on large data sets and generate new data and content, otherwise known as outputs, such as text, images, video, audio, or code, based on patterns it's learned. Traditional AI, or predictive AI, has been around since the 1940s, but since November 2022, generative AI has been widely adopted by both consumers and businesses. It's used by companies for the same reason that brings about its own risk, its capacity for creating new content. There's a lot to be said for the value of systems that can generate text, images, and video and communicate with customers via natural language, easing the burden on human staff. Now, there are a few issues worth talking through. Generative AI is basically a predictive text. Some people call it a stochastic parrot. It's very good at stringing words together, but it

  • 2:06

    doesn't always understand what it's saying, and it can produce incorrect outputs. It sometimes produces what we call hallucinations, which are answers that sound believable, but are actually falsified. No matter how many guardrails have been put in place, individuals prompting models can always find ways around them. Safeguards can always be broken. These systems are trained on enormous amounts of data, and some of that includes copyrighted material. There's also a chance that personal or private data has made its way into the mix. You can think of generative AI a bit like a tool deployed that is going to cause problems sooner or later. This webinar will go through these potential issues arising from generative AI and explore how they can give rise to claims.

  • 2:46

    In the advertising and marketing industry, we see generative AI used extensively to assist in creating new content. This quickens the pace of content creation and its applicability cross-sector has led marketing teams in virtually any industry to outsource work to generative AI tools. This method has extended to industries such as manufacturing and food and beverage where entire concepts for products have been designed with AI assistance and later marketed using AI tools. A more ubiquitous form of generative AI are chatbots, which are used across industry by companies with interactive digital front doors who want to harness more consumer attention when they visit their website by allowing those consumers to prompt chatbots for recommendations.

  • 3:25

    Many of those attending today are likely familiar with ChatGPT and Claude, two products offered by base model developers OpenAI and Anthropic. These consumer-grade chatbots are sold directly from developers to customers. But companies in nearly any industry can purchase these tools from developers and outfit them to suit their own business purposes. This is the exposure where Testudo comes into play. Imagine a manufacturer using a website chatbot to advise consumers on which product to purchase.

  • 3:51

    You've probably also heard of growing cases where a chatbot has gone wrong. So, it's easy to visualize the scenario where a manufacturer's chatbot provides incorrect installation instructions to a consumer. Another common scenario recently have been instances where AI-generated images have infringed on another's IP. Imagine the use of generative AI tools for marketing content across nearly every industry and how large this exposure base has become.

4:15Who is liable when AI fails? (Deployer vs. vendor)

  • 4:17

    A key point I'd like to emphasize here is that when a company chooses to use a generative AI tool in the course of their business operations, they are the ones liable when its outputs cause harm. In Moffatt versus Air Canada 2024, the BC Civil Resolution Tribunal held Air Canada liable for negligent misrepresentation after its chatbot gave a passenger incorrect fare information. The tribunal rejected the idea that the chatbot was a separate entity responsible for its own statements. So, Air Canada was responsible for what its AI chatbot told customers. Moffatt was ultimately awarded $650, the difference between the fare he paid and the bereavement fare the chatbot had promised. And there were additional legal expenses for Air Canada.

  • 4:57

    GenAI deployers such as Air Canada may attempt to shift liability onto the vendor of that chatbot, but this is unlikely to succeed. The position of deployers is made harder by the fact that AI developers and vendors routinely cap their own liability in their standard contract terms, pushing the financial risk of AI failures onto the deployer. This leads to the next problem. If carriers cannot properly understand or price the risk that an insured has taken on by using third-party GenAI tools in their operations, carriers cannot with confidence affirmatively cover third-party liability arising from the insured's reliance on these tools. This is why carriers are increasingly adding AI exclusions on commercial general liability and professional liability programs. Verisk ISO issued GenAI exclusions with effect from 1st January 2026 and similar exclusions are now

  • 5:46

    being applied by carriers in admitted and non-admitted markets. So what does Testudo cover to address this emerging space of third-party harm? We have six areas of coverage. Generative AI output errors refers to incidents where a chatbot or other deployment of generative AI by a company causes financial damages to a third party. This is the classic Air Canada type liability that we outlined above. Air Canada allegedly owed a duty of care to the people using its chatbot and did not take reasonable steps to ensure the chatbot's outputs were accurate. Though a chatbot can be informed about a company's policies, a chatbot's outputs are probabilistic. At some point, it will get something wrong, meaning that a company cannot reduce its error risk by 100%. If these errors cause financial loss to third parties, they could bring

5:50Testudo's generative AI insurance coverage breakdown

  • 6:33

    legal action for third-party indemnification. IP infringement is an emerging exposure arising from a commercial entity's use of generative AI tools. Essentially, when training large language models, companies like OpenAI have been found to have scraped vast amounts off the internet, including news stories by media companies like the New York Times, which are copyrighted. Now the owners of such copyrighted materials like book authors, video creators or news agencies are suing not only the AI developers but also the AI deployers using that content in material they generate. Liability could arise if a company uses a GenAI tool to generate a marketing campaign or an outward-facing advertisement which uses copyrighted material and hence bears resemblance to that copyrighted material.

  • 7:17

    Unauthorized data disclosure covers instances where a GenAI chatbot output inadvertently includes sensitive personal information. This is not a cyber event as this does not qualify as a system failure. Rather, the somewhat random outputs of generative AI systems if they contain sensitive data can lead to third-party claims that disclosure of their sensitive personally identifiable information or personal health information wasn't authorized. Our regulatory coverage is our newest coverage area to be released soon. AI regulatory proceedings covers US enterprises from loss and claims expenses arising from the insured's violation of statutes, regulations, and directives governing the deployment of generative AI systems. There are currently 153 total bills enacted in 34 states pertaining to AI policy. Notable examples of this regulation include the

  • 8:04

    Colorado AI Act, the Texas Responsible AI Governance Act, and California's AB 325. Finally, we cover bodily injury and property damage caused directly or indirectly by reliance on generative AI tools. A recent and well-known lawsuit is Joshi versus OpenAI Foundation filed on 10 May 2026. It is alleged that OpenAI's ChatGPT assisted a college student in planning a mass school shooting by providing detailed weapon instructions, identifying optimal attack times, amplifying his homicidal ideations. The wrongful death lawsuit alleges OpenAI defectively designed the system to prioritize user engagement over safety, omitting guardrails that should have escalated the shooter's red flag prompts to human reviewers or law enforcement. The estate of a murdered bystander is suing the AI developer for gross negligence, strict products

  • 8:52

    liability, and negligent entrustment. Now, this lawsuit is in regards to a developer, but Testudo insures deployers. So in this instance, the lesson which commercial entities deploying generative AI can take away is that if your brand is deploying the generative AI system which causes, which third parties interact with, it is likely that your brand will be held liable for erroneous generative AI outputs causing third-party harm. The only difference here is that the student used a consumer-grade version of ChatGPT but that chatbot could be deployed by a school system, a therapist practice, other companies.

  • 9:25

    Outsourcing your company's third-party interactions to a generative AI tool, no matter how intelligent a mechanism may seem, is a new exposure that companies are either self-insuring or trusting their current silent commercial general liability or E&O cover to address. We offer affirmative cover here for companies' peace of mind that this risk is addressed in their insurance program. Now into an update on the litigation we track at Testudo.

9:47Litigation update, AI lawsuits and median claim demands

  • 9:53

    The point of our data is to monitor which sectors are seeing lawsuits alleging that third-party harm arose from the enterprise's use of generative AI tools and which sectors are adopting generative AI at a faster rate. Across the board, the litigation environment is accelerating in terms of lawsuits raised against deployers of generative AI in traditional industries. Filings have increased each quarter since Q1 2023 and class actions with generative AI named as a core aspect of damages have grown from near zero to consistent double-digit run rates. The median demand amount we see where lawsuits have stated demand is $5 million. The most litigated AI systems at this point in time are ChatGPT, Grok, Claude, and Gemini. Our mission as a liability market is to isolate how an insured could be accused of negligently deploying generative AI in the case of third-party damages. So

  • 10:40

    we track the use of generative AI in business operations to assess where a commercial entity could be overexposing themselves via their deployment. An analysis of our data shows that IP infringement is the leading cause of action by sheer number of lawsuits. Notably, negligence is utilized as a foundational theory of liability across a broad spectrum of harms, including economic loss, physical injury, emotional distress, and privacy violations.

10:49AI incident data, IP infringement, bodily injury and privacy

  • 11:08

    Based on our corpus of generative AI-related incidents, IP infringement is by far the most frequent harm we see. Bodily injury, perhaps unsurprisingly, has the highest average severity of any category. While bodily injury is relatively rare compared to harms like IP, these claims are almost always critical, making this a primary tail risk exposure for deployers in healthcare, autonomous systems, and physical infrastructure specifically.

  • 11:31

    This means that healthcare systems using generative AI assistant tools, entities using generative AI for autonomous supply chain operations, and those in the energy, power, and infrastructure space all sit in higher risk bands for potential damages inflicted by the systems they deploy. Autonomy claims also stem from the use of generative AI in the education sector. Frequent use cases here are systems deployed to track plagiarism or cheating. And because in this case, students are not able to simply opt out of these systems that their school has chosen to deploy, autonomy claims against those educational institutions for defaming students with hallucinated or baseless plagiarism accusations are on the rise.

  • 12:09

    Privacy and incidents related to the use of personally identifiable information in generative AI systems are high frequency and high severity, making data exposure a persistent threat across all industries. This risk is particularly acute in data-heavy sectors like healthcare, financial institutions, real estate, law firms and public entities. To protect against this vulnerability, we offer coverage for unauthorized data disclosure arising from the use of these tools.

  • 12:37

    When tracking AI incidents by foundation model, the vast majority of incidents lists the underlying model as unknown. This obscurity highlights a very critical reality when we look at lawsuits. AI deployers are the primary targets for litigation. Because end users and third parties interact directly with your brand, not your back-end technology vendors, the legal and reputational fallout lands on the deployer. Plaintiffs often don't know or care which base model is involved. They sue the face of the product. We'll see this exact dynamic play out in a lawsuit case study later in this presentation.

13:12Causes and legal theories (oversight gaps, hallucinations, misuse)

  • 13:14

    When we look at third-party damages arising from a commercial entity's use of GenAI, the top three causes of incidents are oversight gaps, hallucinations, and misuse. Oversight gaps most often arise from a commercial entity's failure to properly monitor outputs and verify them before they reach third parties. In sectors like law, this is a growing area of concern with high-profile firms being outed for their negligent reliance on AI tools when hallucinated citations are discovered in court. But oversight gaps also apply in instances where outputs cannot always be verified. Think of the hospitality sector where chatbots handle thousands of guest queries a day. Those chatbots were designed to accommodate that activity and there would be no purpose in having a human verify every single output. Another example of this is in healthcare where the point of using GenAI is to accommodate administrative work and free up

  • 14:01

    physician and nurse time for face-to-face appointments. If GenAI is being used so that patients can check in or discharge themselves, there's likely no human oversight for every output of that system based on the volume of interactions which take place. In this case, there's a natural degree of error which could cause third-party harm for the reason that outputs cannot always be verified. Now, we've just mentioned law, hallucinations in the case of law firms, but those hallucinations are also a concern in applications where generative AI takes autonomous action for entities in supply chain operations. Generative AI has been an incredible investment for its capacity to manage inventory and communicate with other commercial partners' AI systems to predict deliveries. But a hallucination could pass between multiple third-party systems before its error is discovered and lead to a cascade of downstream financial harms. This introduces a

  • 14:48

    dilemma for traditional insurance. Commercial general liability policies often hinge on the definition of an accidental occurrence. If a deployer knew that a generative AI system is probabilistic by design, meaning it is statistically certain to make a mistake eventually, does a resulting hallucination legally qualify as an accident? That ambiguity is exactly why we offer affirmative coverage to replace any market uncertainty with contractual clarity.

  • 15:14

    The third leading cause of AI incidents is misuse, driven heavily by the rise of shadow AI in the workplace. Even when an enterprise invests millions in a secure firm-wide AI stack, the risk remains that employees will quietly use unauthorized external AI tools to speed up their daily work. This is why we as a market underwrite AI liability by focusing on the context in which AI is used. We already know that at some point there will be errors. But our underwriting approach is based on understanding who uses the AI systems for what purpose and under what controls. Our approach is therefore not based on a technical performance assessment of the model. It is based on understanding the liability context, the harms that are caused. AI liability is fundamentally a liability problem, not a technology problem.

  • 15:59

    Thus, we have a few questions here that brokers and risk managers alike will find useful for assessing the exposure engendered by an insured's deployment of GenAI. Is there human verification of outputs or a human in the loop? And if there cannot be human verification for every output, what risk controls or risk transfer can you rely on for that natural degree of error? Are there specific corporate governance structures addressing AI deployment oversight? Does your organization have a chief AI officer? Who sets the example for responsible AI use? And finally, is the system being used for its intended purpose?

  • 16:32

    The most useful takeaway I can offer with these questions is that yes, there are steps one can take internally to manage AI risk and reduce oversight gaps and misuse. But again, hallucinations are certainty when using GenAI tools. Safeguards can always be broken. Training data includes copyrighted material and there may be unauthorized disclosure of personally identifiable information.

  • 16:54

    The other side of our underwriting approach involves legal theories used against companies when their use of GenAI causes third-party damages. Arguments largely gravitate around copyright, negligence, and defamation claims. Many copyright claims are levied against AI developers because they've trained their systems on copyrighted content and outputs often include that content. But deployers using these systems are liable for outputs and therefore capable of being named in copyright suits if the outputs of their GenAI systems include protected IP.

  • 17:25

    When we look at high-risk sectors based on the types of third parties interacting with an insured's GenAI outputs, healthcare and education naturally rise to the top based on the vulnerability of patients and students. We anticipate these areas to be ripe for negligence accusations if GenAI outputs cause harm to these third parties. Two industries of note here regarding litigation trends would be financial services and healthcare. Financial services is currently categorized in our data as the highest risk traditional industry when we look at total lawsuits, many of which are class actions. And healthcare has fewer total lawsuits but a heightened severity risk as previously mentioned with bodily injury and sensitive health data exposure.

18:05Case study, Rodney Smith Ltd. v. Masco Corporation

  • 18:06

    To apply what we've seen in litigation trends to a real scenario, we'd like to highlight a recent lawsuit concerning a deployer's use of generative AI leading to IP infringement. Rodney Smith versus Masco Corporation is a lawsuit that demonstrates the commercial necessity of generative AI IP infringement coverage. Rodney Smith sued Masco Corporation, which is a manufacturer of kitchen products using generative AI for marketing, in the Southern District of New York on 12 June 2026, alleging copyright infringement. Rodney Smith's iconic photographs were allegedly imitated using a generative AI tool in an advertisement video on the defendant's website with stills from that video then appearing in print advertising.

  • 18:44

    The interesting part of this lawsuit is that it details how the upstream AI model provider or vendor may also be implicated as an entity who aided in generating the infringing content. For this case, the upstream model developer is currently unknown. But according to this lawsuit, the claimant plans to add the developer as a defendant once discovered. So when you look at the entity accused of infringement, it is the deployer, Masco Corporation, who is named first because their brand name is on the copyrighted images.

  • 19:11

    For commercial entities using similar tools, the deployer is the obvious defendant because the deployer is putting the allegedly infringing output into the world. So how would Testudo respond? For traditional industry entities who are using generative AI tools to produce advertising content for their brand, Testudo's policy would respond to third-party demands alleging IP infringement because of the insured's use of AI-generated images. Beyond IP exposure, we produce resources upon request for each industry detailing how companies use generative AI, popular AI vendor tools, and what hypothetical loss scenarios that use could lead to. Our appetite is detailed here to show the various use cases of generative AI which companies may engage in as well as the industries doing so.

19:21Who can Testudo help? (High-risk industries and use cases)

  • 19:55

    More information on our industry appetite is available on our website. As an additional example here, I've included a scenario for healthcare. Further hypothetical loss scenarios like this can be provided upon request. Now, thank you very much for attending. We'll now address a few questions which have been sent in. So, first, which resources are available for brokers and risk managers to understand their company's AI risk? Our most popular resource is our intelligence reports. By using the name of an insured, we find public sources online confirming their use of generative AI systems and we create reports that frame the use case which could give rise to third-party exposure.

20:08Q and A, resources for brokers and intelligence reports

  • 20:36

    By isolating these, we help brokers and risk managers proactively identify whether operational use of GenAI can lead to third-party damages and help secure affirmative coverage for those systems. Does your product fill the coverage gap for CG 40 47, the generative AI exclusion? Yes, it does. If an insured selects from a module offering the three coverage areas of note here, which would be bodily injury, property damage, and personal injury, our coverage fills the gap created by AI exclusions used on CGL placements. Similarly, our third-party financial loss and personal injury coverage areas fill the gap created by AI exclusions used on E&O placements.

21:17Q and A, geographic hotspots for AI litigation

  • 21:17

    Which states see the most litigation? Currently, the most litigious states for GenAI lawsuits based on our database are California, Texas, New York, Illinois, Pennsylvania, and Florida. How does this product differ from tech E&O and cyber? Our understanding is that tech E&O would not cover all liabilities arising from the insured's use of AI since it is designed to cover damages arising from the technology services and technology products which a company sells. If a company sells no services or products containing AI, tech E&O does not apply.

21:32Q and A, how GenAI liability differs from tech E&O and cyber

  • 21:53

    Our clients are often companies that don't buy tech E&O because they're traditional industry manufacturers, retailers, professional services firms, etc. For example, a hotel chain using GenAI chatbots to handle guest questions and recommend tourist activities would not buy tech E&O because this chatbot is not a product they sell. It's an operational aspect of their business. These entities require AI liability coverage.

  • 22:16

    Cyber coverage responds to malicious attacks or system failures. But as we said before, hallucinations are part of how AI technology works. They don't count as cyber events. Similarly to commercial general liability on the question of an accidental occurrence, hallucinations have a nonzero probability of happening even without malicious attack or system failure. So third-party damages arising from the use of generative AI require affirmative coverage by carriers. Our policy is designed with these specific harms in mind.

22:44Next steps and conclusion

  • 22:46

    Thank you again for attending today. If you have any questions or have left any in the chat, I can get back to you individually over email with a response. As mentioned previously, our website's broker hub has extensive resources detailing our capabilities, our appetite, and our coverage areas. It also details the resources we offer to brokers, including intelligence reports and portfolio underwriting to assist in identifying clients with distinct exposures. Our mission as a market is to provide our affirmative coverage so that clients are able to unlock GenAI deployment. Traditional industry players are using generative AI to compete within their respective sectors and young startups are building enterprises around AI tools. In both cases, companies may lack the resources to stay on top of emerging AI regulation and unknowingly fall foul of certain requirements. Our liability product delivers the peace of mind that AI-driven

  • 23:33

    operational risk and now regulatory infringement risk are affirmatively covered, unlocking generative AI deployment even in the technology's nascent stage. Thank you.