Insure Your Agent Operator Edition

Does D&O insurance cover AI agent mistakes?

Short answer

Not directly. D&O insurance covers wrongful acts committed by directors and officers acting in their decision-making capacity. An AI agent making a bad financial call, a discriminatory hiring recommendation, or a decision that breaches a regulation is not itself a director or officer, so the agent's mistake is not obviously a wrongful act the policy was written to cover. D&O can still be triggered, but only for a narrower and separate claim: that the board was negligent in approving, delegating to, or monitoring the AI system. The operational error itself usually needs a different policy.

A board approves an AI agent to screen loan applications, shortlist job candidates, or execute a pricing decision. The agent gets it wrong, and the loss is real: a discriminatory outcome, a bad financial call, a regulatory breach. The first instinct of most founders and directors is to check the D&O policy, because that is the policy meant to protect them personally when something goes wrong under their watch. The honest answer is that D&O was not built for this, and understanding exactly where the gap sits is the difference between a claim that gets paid and one that does not.

Key takeaways

  • D&O insurance covers wrongful acts by directors and officers in their decision-making capacity. It does not automatically cover an AI agent's own operational mistake, because the agent is not a director or officer.
  • If an AI agent causes a loss through a bad financial decision, a discriminatory recommendation, or a regulatory breach, the AI's error itself is generally not what triggers a D&O claim.
  • D&O can still respond, but only to a separate and narrower claim: that the board or officers failed to properly approve, delegate to, or monitor the AI deployment.
  • Insurers are adding AI exclusion endorsements to D&O and management liability renewals through 2026, which is narrowing this fallback further.
  • The operational error itself is more likely to be covered, if at all, by errors and omissions, professional indemnity, or product liability insurance, not D&O.

What D&O insurance actually covers

Directors and officers insurance protects the personal assets of a company's directors and senior officers when they are sued or investigated for decisions made in their governance role. The policy trigger is almost always built around the term wrongful act, defined broadly as an actual or alleged error, misstatement, misleading statement, act, omission, neglect, or breach of duty committed by a director or officer while acting in that capacity. Claims typically come from shareholders alleging mismanagement, regulators alleging a breach of duty, employees alleging discrimination in a decision the board signed off on, or creditors alleging negligence around a company's financial position.

Notice what that definition requires: a person, holding a director or officer role, taking an action or making a decision. That structure maps cleanly onto a boardroom vote, a signed resolution, or an executive's sign-off on a strategy. It does not map cleanly onto an autonomous system that generates a recommendation or takes an action without a named human decision-maker in the loop at the moment of the mistake.

This is the core problem. When a company deploys an AI agent to make or heavily influence a real business decision, whether that is scoring loan applicants, ranking job candidates, or executing a trade, the agent's output is not obviously a wrongful act by a director or officer. It is the output of a system the board approved at some earlier point, running autonomously, months or years after that approval. The causal chain between the boardroom and the harmful outcome has stretched, and D&O wordings were not written with that stretch in mind.

The coverage gap when a board delegates a decision to an AI agent

Consider a concrete scenario. A mid-sized lender's board approves the use of an AI agent to pre-screen mortgage applications, with a stated goal of reducing processing time. Eighteen months later, an investigation finds the agent's screening pattern produced discriminatory outcomes against a protected group. Affected applicants bring claims. Regulators open an inquiry. Shareholders, seeing the resulting fines and reputational damage, allege the board was negligent in permitting the deployment.

There are two very different claims buried in that single scenario, and they land on different policies. The first is the discrimination claim itself, against the company, arising from the agent's actual screening decisions. That is an operational liability claim, closer to errors and omissions, professional indemnity, or in the EU, product liability exposure under the revised Product Liability Directive. The second is the governance claim, against the individual directors, alleging that they failed to exercise reasonable oversight before letting an automated system make decisions with legal consequences for real people. That second claim is the one D&O responds to, and only that one.

The gap is this: a board that delegates a consequential decision to an AI agent and then does not maintain active oversight of it has created a governance exposure that only becomes visible after a loss has already occurred. D&O does not protect the board from the underlying loss. It only protects the individual directors from personal liability for having allowed the loss to happen, and only if the underwriter agrees that what happened constitutes a wrongful act under the policy's specific wording, which is not guaranteed.

AI exclusion endorsements arriving on D&O renewals

Through 2024 to 2026, insurers writing management liability lines, including D&O, have been reviewing their AI exposure the same way E&O and cyber carriers have. The pattern is consistent across professional lines: rather than leave AI-related conduct inside a silently broad wording, carriers are adding AI exclusion endorsements at renewal that carve out losses connected to the use or deployment of artificial intelligence systems, or that impose new conditions around disclosure of AI use at the point of underwriting.

For D&O specifically, this shows up less as a blanket AI exclusion and more as underwriters asking harder questions at renewal: does the board have visibility into where AI is used in the business, was the deployment risk-assessed and documented, and is there a named owner for AI governance. A board that cannot answer those questions in writing is increasingly being treated as a higher-risk placement, and some renewals are now explicitly narrowing cover for claims connected to AI-related decisions where no board-level oversight process can be evidenced. If your D&O policy has renewed in the last year and nobody reviewed the AI-related language in the endorsements, that is worth correcting before the next renewal, not after a claim.

What actually responds instead of D&O

Splitting the operational error from the governance failure is the most useful mental model here. The operational error, the AI agent's actual bad decision, is what a company's errors and omissions or professional indemnity policy is built to address, and even those policies carry real gaps for AI-caused losses. Our companion article, Does your business insurance cover AI mistakes?, walks through why E&O, cyber, and general liability were mostly written before autonomous agents existed and why insurers are now adding exclusions of their own. For losses with a financial dimension specifically, our guide to AI agent financial error liability covers pricing errors, bad advice, and unauthorised actions in detail, including which policy type is most likely to respond to each.

D&O sits behind all of that, protecting the individuals who governed the decision to deploy the AI system in the first place, not the system's output. In practice this means a company facing an AI-caused loss is usually running two separate coverage conversations at once: one with the E&O or product liability carrier about the loss itself, and a second, narrower one with the D&O carrier about whether the board's oversight of the deployment was adequate. For operators building or deploying AI agents across European markets, the broader liability architecture, including how professional indemnity frameworks are evolving specifically for AI agents, is covered in the European AI liability coverage frameworks published on agentinsured.eu.

What to ask your broker and what to document

Two things determine whether a D&O claim survives if a regulator or shareholder later alleges the board was negligent in permitting an AI-driven decision: what was asked of the insurer in advance, and what the board can prove it actually did.

On the broker side, ask in writing for a clause-by-clause position: does the current D&O policy respond to a claim alleging the board failed to oversee an AI deployment, has any AI-related exclusion or condition been added at the last renewal, and what specific evidence would the underwriter expect to see to support a defence. Do not accept a verbal reassurance. Get the answer in writing, with clause references, before the next renewal.

On the documentation side, three things matter most. First, board minutes that show the AI deployment was actually discussed, not just noted, including what risk was identified and how it was weighed against the benefit. Second, a documented risk management process covering how the AI system is monitored, what escalation thresholds exist, and where a human reviews or can override its output. Third, a record of incident logging and any reporting tied to deployer obligations, which in the EU includes Article 26 of the AI Act, requiring deployers of certain AI systems to maintain human oversight, monitor operation, and keep logs. None of this guarantees a D&O claim will be paid. It is, however, the exact evidence an underwriter and a court will look for when deciding whether a board exercised reasonable oversight, as opposed to simply approving a system and walking away from it.

The three-question diagnostic on The Questions page is a useful starting point for mapping where your current policies stand before you have this conversation with your broker, and the coverage pathway page walks through what a documented AI oversight file looks like in practice.

Frequently asked questions

Does D&O insurance cover AI agent mistakes?

Not directly. D&O insurance covers wrongful acts by directors and officers acting in their decision-making capacity, and an autonomous AI agent's own output is not a decision made by a named director or officer. D&O can still respond, but only to a separate claim: that the board or officers were negligent in approving, delegating to, or failing to oversee the AI system. The operational mistake itself is more likely to sit with errors and omissions, professional indemnity, or product liability cover, not D&O.

Will D&O insurance pay out if our AI agent causes a regulatory breach?

It depends on what is actually being alleged. If a regulator or shareholder claims the AI agent itself broke a rule, that is not automatically a wrongful act by a director or officer, and D&O may not respond. If the claim is that the board failed to exercise reasonable oversight before allowing the AI to make regulated decisions, for example failing to meet deployer obligations under Article 26 of the EU AI Act, that framing looks much more like a traditional D&O claim and defence costs are more likely to be covered, subject to the policy's specific wording and any AI exclusion endorsement.

What insurance actually covers an AI agent's mistake if D&O does not?

For the operational error itself, the more relevant policies are errors and omissions or professional indemnity insurance, which respond to negligent acts causing financial loss, and in the EU, the revised Product Liability Directive (Directive (EU) 2024/2853, applicable from 9 December 2026) which treats defective AI software as a product for strict liability purposes. D&O sits behind those policies and responds only to claims against the individuals who governed the deployment, not to the AI's decision itself.

What should we document to protect our D&O coverage if the board approved an AI deployment?

Keep board minutes that show the AI deployment was discussed and approved with an understanding of its risk, a documented risk management process covering monitoring, escalation thresholds and human review, and a record of any incident reporting tied to deployer obligations under the EU AI Act. This evidence is what allows a director to argue that reasonable oversight was exercised if a regulator or shareholder later alleges the board was negligent in permitting AI-driven decisions, and it is also what a D&O underwriter will ask for at renewal.

References