AI failures are starting to acquire price tags.
Some are still small: a customer refund, a contractual credit, a court sanction, the cost of redoing a piece of work. Others are becoming materially larger. In July 2026, a federal court gave final approval to Anthropic's $1.5 billion copyright settlement, resolving claims relating to books obtained from pirate libraries for AI development. In Australia, Deloitte agreed to partially refund the government for a A$440,000 report after fabricated references and an invented court quotation were found in work prepared using generative AI. And litigation involving automated hiring, healthcare decision-making, facial recognition, AI-generated content, and conversational systems continues to test who should ultimately bear losses created by AI.
These cases are different in almost every legal respect. What connects them is economic: AI behavior increasingly creates an obligation for somebody to pay.
The frequency of reported incidents is rising alongside the financial stakes. Stanford's 2026 AI Index recorded 362 documented AI incidents in 2025, up from 233 in 2024. Gallagher Re's March 2026 study, drawing on Testudo litigation data, found more than 700 GenAI-related US lawsuits between 2020 and 2025, with filings increasing 978% from 2021 to 2025. Reported incidents and lawsuits are not the same as insured losses, and neither dataset should be treated as a claims triangle. But they show the direction clearly: AI is interacting with enough people, decisions and economic activity for failures to increasingly reach lawyers, regulators and corporate balance sheets.
Stanford AI Index 2026: Responsible AI
Gallagher Re: Smart Systems, Blind Spots
The harder question is what happens next. When an AI system causes a loss, is it the responsibility of the company that built the model, the vendor that turned it into a product, the enterprise that deployed it, or the insurer standing behind one of them?
There is not yet one answer. Increasingly, that ambiguity is becoming part of the financial risk itself.
How quickly is AI liability becoming financially material?
It is important to distinguish between an AI incident and an AI loss.
Most incidents never become litigation. Most litigation never results in a billion-dollar payment. Public incident databases also disproportionately capture unusual or visible failures rather than the everyday errors resolved quietly between companies and customers.
But the emerging record shows the range of ways AI can translate into money.
The Anthropic settlement is at the extreme end. The court had previously distinguished between using books to train models, which it found could constitute fair use in the circumstances before it, and Anthropic's acquisition and retention of books downloaded from pirate libraries. The eventual $1.5 billion settlement, which received final approval in July 2026, resolves the latter claims for a class covering hundreds of thousands of works. It does not establish that every use of copyrighted material for AI training is unlawful. It does establish something commercially important: an unresolved AI-related legal theory can mature into a ten-figure financial exposure.
Official Anthropic Copyright Settlement
Other losses look much more ordinary. Deloitte's Australian government engagement did not produce a billion-dollar lawsuit. It produced a defective professional deliverable. The A$440,000 report contained nonexistent sources and a fabricated quotation attributed to a Federal Court judgment. Deloitte corrected the report and agreed to refund the final instalment of the contract. The recommendations remained unchanged, but the economic consequence was already real: work had been delivered, the client had paid for it, and the vendor had to give some of that money back.
Associated Press: Deloitte to partially refund Australian government after AI-linked errors
Employment automation shows another route. The US Equal Employment Opportunity Commission alleged that iTutorGroup's software automatically rejected female applicants aged 55 or older and male applicants aged 60 or older, affecting more than 200 applicants. The companies ultimately agreed to a $365,000 settlement and other relief. The relevant point for AI liability is not the size of that particular settlement. It is that automating a decision did not automate away the employer's legal duties.
EEOC: iTutorGroup $365,000 discrimination settlement
Even professional use of general-purpose AI can create direct financial consequences. In June 2026, the Ninth Circuit sanctioned two attorneys $2,500 each, suspended them from practice before the court for six months, and imposed additional disclosure requirements after briefs contained nonexistent cases, misattributed quotations and other AI-generated inaccuracies. The court's reasoning is useful well beyond law: the problem was not simply that AI had produced bad information. Responsibility attached when professionals relied on it and put that information into the world under their authority.
The financial consequences of AI therefore do not begin only when a catastrophic model failure occurs. They can begin with a refund, remediation cost, professional sanction, lost contract, regulatory settlement, defence bill or indemnity demand.
Why can an apparently small AI error become a balance-sheet event?
AI systems increasingly operate at the point where another person can rely on what they say or do.
That changes the economic significance of an error.
A hallucination inside an internal brainstorming document may be irritating. The same hallucination inside a legal filing can trigger sanctions. An incorrect number in a private test environment has little third-party consequence. Put it into a customer communication about price, entitlement or payment and it can become a representation made by the business.
A recent incident at Australian retailer Who Gives A Crap illustrates the boundary. A customer received incorrect information suggesting their toilet-paper subscription would effectively more than double in price. When the customer challenged the figure, an AI-generated support email confirmed the wrong information instead of correcting it. The company subsequently suspended the email agent and sent a correction. No material financial loss has been publicly disclosed, so it would be wrong to describe this as a major claim. But it shows how little technical drama is required for financial exposure to emerge: the system simply communicated the wrong commercial terms to a customer and then reinforced them.
SmartCompany: Who Gives A Crap suspends AI agent after pricing error
The same mechanism becomes more consequential as agents receive greater authority. A support agent may move from explaining a refund policy to issuing the refund. A healthcare agent can move from scheduling an appointment to deciding whether a patient's statement should trigger escalation. A financial-services agent can progress from answering account questions to modifying an account or influencing an eligibility decision.
The model has not necessarily become more dangerous. The consequences attached to its output have changed.
This is why one of the most important variables in AI liability is not model size or benchmark performance. It is authority: what the system is permitted to represent, decide, access or execute on behalf of the organization.
Ollive's underwriting work reflects this directly. A support agent that can only answer questions is a different risk from one that can issue refunds, alter entitlements or change customer accounts. The same model can therefore create radically different financial exposure depending on its role and permissions.
Who is actually liable when AI gets something wrong?
The intuitive answer is often “the AI company.” Legally and commercially, the answer is considerably messier.
AI systems usually involve several parties. A foundation-model company provides the underlying model. An application vendor builds a product or agent on top of it. An enterprise purchases that product, configures it and puts it in front of customers. Third-party observability, data, infrastructure and integration providers may sit elsewhere in the stack.
When something goes wrong, technical causation and legal liability do not necessarily follow the same route.
The Air Canada chatbot case remains useful because the tribunal dealt directly with an argument that still appears in AI conversations. Air Canada contended that it should not be responsible for incorrect information supplied by its chatbot. The tribunal rejected the distinction: the chatbot was part of Air Canada's website, and the company was responsible for the information presented there.
That suggests a simple rule: the deployer owns the consequences. But even that is incomplete.
In Mobley v. Workday, applicants have alleged that Workday's automated screening tools discriminated against job candidates. In 2024, a federal district court allowed claims against Workday to proceed on an agency theory, finding that a third-party provider could potentially face liability where employers delegated traditional hiring functions to it. The litigation remains ongoing, and the allegations have not been finally adjudicated. But the case demonstrates why the liability chain can run upstream as well as downstream.
Mobley v. Workday: 2024 agency ruling
Gallagher Re describes this as the vendor-deployer divide. Claimants often pursue the organization that actually interacts with the end user, but contracts and the degree of control exercised by vendors can change where economic responsibility ultimately lands.
The important distinction is between who can be sued and who ultimately pays. They are not always the same party.
Why are contracts becoming the real battleground for AI liability?
Long before a court decides responsibility, companies are negotiating it privately.
Traditional SaaS contracts were designed for relatively passive software. The provider supplied a product; the customer decided how to use it. Warranties, indemnities and liability caps reflected that division.
Agentic AI makes the boundary harder to maintain because the product increasingly performs the work itself.
Mayer Brown argued in February 2026 that agentic-AI agreements are beginning to look less like conventional SaaS contracts and more like hybrids between software and outsourced services, with greater emphasis on outcomes, governance, audit rights, warranties and indemnification. In a later analysis of agentic implementation deals, the firm noted that neither side can model the risk particularly well yet and that liability negotiations can end up shaping the deal itself.
Mayer Brown: Contracting for Agentic AI Solutions
The contractual chain also contains a structural problem. An AI application company may promise broad protection to an enterprise customer while receiving much narrower protection from the foundation-model or infrastructure provider underneath it. Mayer Brown specifically highlights the gaps that can arise between upstream AI-provider indemnities and the downstream liabilities a company accepts, including questions around infringement, privacy, legal compliance and the operation of the agent.
In practice, this can turn AI risk into a balance-sheet negotiation before any incident occurs.
Ollive is already seeing this in customer discovery. One AI vendor told us that four enterprise customers had raised AI-specific liability issues in commercial negotiations, with requested exposure ranging from roughly $500,000 to $5 million to unlimited liability. The vendor negotiated three of those demands back toward conventional contract-value caps. One customer refused, and the deal was lost. The signal is important precisely because it is not a claim: financial liability can affect revenue before a loss ever occurs.
For an AI vendor, there are therefore at least three ways to pay for liability: accept the exposure on its balance sheet, refuse the contractual terms and potentially lose the customer, or transfer defined portions of the risk through insurance.
That makes AI liability a GTM issue as much as a legal one.
What changes when AI moves from generating answers to taking actions?
Generative AI made inaccurate content cheap to produce. Agentic AI makes inaccurate action cheap to repeat.
That is a meaningful shift in the economics of failure.
A human employee may make one erroneous refund before someone notices. An agent with access to the same tool can potentially repeat the behavior across a large interaction volume. A customer-support agent can commit the company to an exception repeatedly. An automated collections workflow can communicate with thousands of consumers. A retrieval error can expose the wrong customer's information across more than one interaction.
The risk is therefore not simply:
What is the probability that the agent makes an error?
It is also:
How many times can the same error propagate, and what is the value attached to each action?
This is where conventional AI safety metrics and financial liability begin to diverge. A system can have a high overall task-success rate while still producing an unattractive insurance risk if the remaining failures occur in high-severity interactions. A 99.9% successful agent processing a million interactions still leaves a thousand failures. Whether those failures are harmless formatting mistakes or unauthorized $10,000 transactions is what matters economically.
The same distinction appears in litigation. The latest Stanford AI Index notes substantial gains in agents' ability to complete real computer tasks, while still observing significant failure rates on structured benchmarks. As agents become capable enough to operate real systems before becoming perfectly reliable, enterprises face a period in which capability and liability increase together.
The economic question is therefore becoming unavoidable: how much autonomy can a company safely delegate before the expected value of agent failures becomes material?
Why doesn't the company that built the model simply pay?
Commercial AI stacks are full of limitations of liability, warranty disclaimers and narrowly defined indemnities.
There are legitimate reasons for this. A model provider does not control every downstream prompt, retrieval corpus, integration, permission, workflow or human decision. An application vendor may not control what an enterprise customer asks an agent to do. The enterprise itself may configure a system in ways neither upstream provider anticipated.
Each participant therefore has an incentive to limit responsibility for behavior it cannot fully control.
But the result can create a liability gap in the supply chain.
Imagine an enterprise customer suffers a $5 million loss from an agent sold by an AI application vendor. The enterprise's contract requires the application vendor to indemnify it. The application vendor relies on a foundation-model provider but has an upstream liability cap equal to a small fraction of the enterprise claim. Even if the underlying model contributed materially to the failure, contractual recovery upstream may not match the vendor's downstream obligation.
Who caused the loss and who funds the loss have become two different questions.
This is why current legal commentary increasingly treats warranties, indemnification and liability caps as core components of AI architecture rather than boilerplate procurement language. Morgan Lewis noted in September 2026 that when vendors use AI to create deliverables, familiar contractual questions about warranties and remedies remain, but probabilistic output and distributed responsibility make the allocation significantly more complicated.
Morgan Lewis: AI Deliverables and Liability
Where does insurance enter the AI liability chain?
Insurance matters when the contractual and legal allocation of liability leaves a party holding an exposure it does not want to retain entirely on its own balance sheet.
The problem is that the insurance market is still adapting to what that exposure actually is.
Gallagher Re's 2026 research argues that AI liability can cross cyber, E&O, casualty and product-liability structures, particularly where the loss comes from hallucinations, discrimination, AI outputs or autonomous behavior rather than a conventional cyberattack. Its Q1 2026 InsurTech report describes AI liability insurance as part of a broader shift around “digital delegation”: businesses increasingly delegate activities to software, while insurance has to determine who bears the consequences when delegated systems fail.
The specialist market is starting to respond. In March 2026, HSB, part of Munich Re, introduced AI liability coverage for small and medium-sized businesses, explicitly positioning it around lawsuits and AI-related losses that some general-liability policies may exclude. Other providers are developing standalone or affirmative AI products for different parts of the market.
HSB: AI Liability Insurance launch
This does not mean every AI exposure requires a new policy. Cyber should continue to respond to covered cyber events. Tech E&O should continue to respond where the underlying technology-service trigger is met. General and professional liability still have important roles.
The emerging problem is the residual: AI behavior that creates a real financial obligation but does not map cleanly onto the policy the company expected to respond.
That is where affirmative AI liability becomes relevant.
Where does Ollive fit into the growing financial liability of AI?
Ollive's thesis starts one step before the insurance policy.
If AI financial liability is created by what a system actually says, decides and does in production, underwriting the exposure requires visibility into that behavior.
Ollive connects to an AI company's production logs and traces and looks for behaviors that can become legal, regulatory, contractual or financial liability: an unsupported claim a customer might rely upon, a commitment outside the agent's authority, a failure to escalate, a disclosure of protected information, or an action the system was not authorized to take.
That distinction matters because technical failures and financial failures are not the same thing. A service can return a 200 OK while the agent makes a representation that creates a contractual dispute. An agent can execute a valid tool call while exceeding the business authority it was supposed to have. Conventional infrastructure monitoring can tell you that the request succeeded; liability monitoring needs to tell you whether the result crossed an obligation.
Ollive uses that runtime evidence across the insurance lifecycle. Historical production telemetry can help distinguish risks at underwriting. Continuous monitoring can surface deterioration and verify controls during the policy period. If an incident becomes a claim, the same record can help reconstruct what the agent saw, what it said or did, which permissions and controls were active, and how the company responded.
The objective is not to insure every bad AI output. It is to connect behavior → exposure → control → evidence → insurance closely enough that the residual financial risk can be deliberately transferred rather than discovered after a demand letter arrives.
That becomes increasingly important as AI vendors accept larger contractual obligations to win enterprise customers. The vendor should be able to answer two different questions with the same production evidence:
What are we doing to prevent the agent from creating the liability?
And:
If it still does, what stands behind the financial obligation?
The first is a risk-management problem. The second is an insurance problem. AI companies increasingly need both.
Is AI liability ultimately a technology problem or a financial one?
It starts as a technology problem and ends as a financial one.
Models will become more reliable. Guardrails will improve. Agents will receive better permission systems, evaluations, escalation logic and monitoring. Those improvements matter because they reduce the frequency and severity of failure.
They will not eliminate residual risk.
As AI performs more economically consequential work, the cost of the remaining errors rises. A system that recommends, represents, approves, denies, purchases, refunds, routes or advises is participating in an activity to which the law and commercial contracts already attach duties.
The legal system does not need to make an AI agent a separate legal person for that liability to exist. It can apply existing concepts including negligence, misrepresentation, discrimination, agency, professional responsibility, consumer protection and contract law.
What is new is the distribution of responsibility.
The model provider may have contributed to the behavior. The AI vendor may have designed the agent. The enterprise may have deployed it. A customer may have relied upon it. Contracts may reallocate the resulting loss. Insurance may transfer part of it again.
That is why “who caused the AI failure?” is increasingly the wrong financial question.
The better question is:
When this system creates a loss, who has actually agreed to pay?
For many companies deploying AI today, the answer is still being written.
Frequently asked questions about AI financial liability
Who is liable when an AI system makes a mistake?
There is no universal answer. Liability depends on the underlying duty, the role of each party, the degree of control over the AI system, applicable law and the contracts between the model provider, AI vendor and enterprise deployer. Courts have already found deployers responsible for chatbot statements, while other litigation is testing whether AI vendors themselves can face direct liability where customers delegate consequential functions to their systems.
Are AI lawsuits actually increasing?
Yes, although datasets use different definitions. Stanford's AI Incident Database recorded 362 documented incidents in 2025 compared with 233 in 2024. Separately, Gallagher Re, using Testudo litigation data, reported more than 700 US GenAI-related lawsuits between 2020 and 2025 and a 978% increase in filings from 2021 to 2025. Neither figure should be interpreted as an insured-claims count.
What are the main financial losses caused by AI?
AI-related financial exposure can include customer refunds, lost revenue, contractual damages and indemnities, defence costs, regulatory settlements, professional sanctions, discrimination claims, intellectual-property claims, bodily injury or property damage, and incident-response costs. The applicable exposure depends heavily on what the AI system was doing and who relied on its output.
Can an enterprise pass AI liability back to its vendor?
Sometimes. Commercial contracts can require vendors to indemnify customers or accept elevated liability caps for defined AI failures. But the scope of the indemnity, exclusions and liability cap determine how much risk actually moves. The vendor may also have substantially narrower recovery rights against its own model or infrastructure providers.
Does existing business insurance cover AI liability?
Some AI-related losses may already trigger cyber, Tech E&O, CGL, professional liability or other policies. Others may not fit the relevant triggers or may be subject to AI-specific exclusions. Coverage depends on the particular event and policy wording. The emerging specialist market is developing affirmative AI liability products to address parts of the residual exposure.
What does Ollive do?
Ollive monitors the production behavior of AI agents for legal, regulatory, contractual and financial exposure and uses the same runtime evidence to support purpose-built AI liability insurance. The goal is to reduce preventable loss, preserve evidence when incidents occur, and provide financial protection for defined residual liability that remains after technical controls.
This article is for informational purposes only and does not constitute legal or insurance advice. Litigation discussed as ongoing contains allegations that have not necessarily been proven. Insurance coverage depends on the applicable policy wording, endorsements, facts, law and underwriting terms.