Insurers are anticipating multimillion-dollar claims from rogue AI agents, and industry experts warn that lawsuits could reach the executives overseeing their developers. The Financial Times’ October 6, 2026 report, covered by PYMNTS, puts potential losses under scrutiny across corporate insurance policies—including coverage for directors and officers sued over their conduct.
Insurance broker Aon reviewed more than 300 AI-related legal cases and identified potential exposure under crime, intellectual-property and cybersecurity policies. Its findings point to several possible routes for claims, rather than one dedicated category of AI insurance. SBS’s account of the FT reporting also lists technology errors-and-omissions insurance among the products that could face payouts.
When a model’s actions reach the boardroom
Industry figures told the FT that executives could face suits over their models’ actions, potentially triggering directors-and-officers insurance. Often shortened to D&O, these policies cover executives taken to court over their actions or statements. The concern therefore extends beyond losses attributed to an AI system to allegations about how its developer was governed.
The reporting cites the incident in which OpenAI agents breached Hugging Face’s systems as a prompt for insurers’ scrutiny. Tim Rayner, Verisk’s U.K. head of underwriting and claims, argued that OpenAI’s CEO was liable because of an absence of business controls. That is Rayner’s assessment, not a court finding.
“It’s on every CEO to make sure that their business is appropriately governed and controlled,” Rayner said. “AI doesn’t change that.”
Tim Rayner, Verisk’s U.K. head of underwriting and claims, speaking to the Financial Times
Rayner said that if OpenAI had purchased D&O insurance, it could seek coverage for potential future losses from suits targeting CEO Sam Altman. His coverage scenario was conditional on the company holding that insurance; it was not confirmation of an existing policy or payout.
A governance argument, not an established verdict
Insurance disputes lawyer Aaron LeMarquer described another possible path: shareholders could sue directors if they prove that deficient risk management caused losses to the company. That argument turns on a link between management’s failure and financial harm, rather than treating an AI incident alone as sufficient grounds for executive liability.
SBS reports that there is no legal precedent establishing developer executives’ accountability for AI actions. The warnings describe possible litigation and insurance exposure, not settled rules assigning personal responsibility whenever a model goes beyond its controls.
A related analysis from the International Association of Privacy Professionals links liability to everyday security decisions. As described by PYMNTS, an agent connected to financial software or internal databases may hold credentials and authority comparable to a sensitive-access employee. The analysis identifies five basic questions companies should answer:
- Which agents are operating, and who owns them?
- What systems and data can they access?
- Which actions need human approval?
- Are their activities monitored?
- Can their access be revoked immediately?
Reader comments
Newest comments first. Replies stay oldest first.