Do I need separate insurance for my AI chatbot?
Founders ask this question the week they turn a chatbot on, which is later than it should be asked. The honest answer is that "chatbot" is not a useful category for an insurer, a court, or you. What matters is what the thing is authorised to do. A scripted widget that answers three fixed questions is a very different risk from an agentic chatbot that can quote a price, promise a refund, or change a booking without a human checking it first. This article gives you the test to tell the two apart, walks through what your existing general liability, professional indemnity, and cyber policies actually do and do not cover, and explains where the EU AI Act's disclosure duty fits into the picture.
Key takeaways
- Whether you need separate cover depends on what the chatbot is authorised to do, not on the fact that it is AI. A scripted FAQ widget and an agentic chatbot that can commit your business to a price, a refund, or a promise are different risk categories to any underwriter.
- Many commercial general liability and professional indemnity policies now carry AI exclusion endorsements, including the ISO CG 40 47 and CG 40 48 endorsements available to CGL carriers since 2024, which remove cover for AI-related loss unless the policy affirmatively adds it back.
- The operator, not the model provider, carries the primary liability for what a customer-facing chatbot says. The British Columbia Civil Resolution Tribunal made this explicit in Moffatt v. Air Canada (2024), rejecting the argument that a chatbot's statements were not the company's responsibility.
- Article 50 of the EU AI Act requires that customers be told they are talking to an AI system unless that is obvious from context. This is a compliance duty, not an insurance requirement, but underwriters are starting to ask for evidence of it as part of a chatbot-specific submission.
- Dedicated AI liability products now exist at SME scale, including HSB's AI liability product for small businesses launched in March 2026 and Counterpart's affirmative AI endorsements, so "there is nothing to buy" is no longer an accurate reason to skip the review.
The direct answer: it depends on what the chatbot can do
There is no single answer to "does my chatbot need its own insurance" because "chatbot" describes a UI pattern, not a risk profile. Two businesses can both describe their product as an "AI customer service chatbot" and be running fundamentally different systems from an underwriting perspective. The first system answers from a fixed script or a narrow retrieval layer over your help centre content: it cannot promise a refund, quote a non-standard price, or commit to anything you have not pre-approved in writing. The second system generates novel responses, can access order and account data, and in some deployments can complete a transaction, cancel a booking, or issue store credit without a person reviewing the output first.
The first system is a documentation and content risk, similar in kind to a poorly maintained FAQ page: real but bounded, and usually already inside the scope of general commercial policies that were never written with AI specifically excluded. The second system is closer to giving a new, unsupervised employee the authority to speak for your business to every customer, at any hour, with no manager reviewing what they said before the customer acted on it. That is the system this article is really about, because it is the one where "does my existing policy cover this" stops being a safe assumption.
The test: scripted widget or agentic chatbot
Ask three questions about your specific deployment. Can it say something you have not pre-approved, meaning does it generate free-form language rather than selecting from a fixed set of approved responses? Can it take an action, such as issuing a refund, changing an order, or booking a service, without a person confirming it first? Does it have access to systems or data beyond what is needed to answer a general question, such as a customer's order history, account balance, or eligibility status? A yes to any of these puts you in agentic territory for insurance purposes, regardless of how the vendor markets the product to you or how simple the chat interface looks to a customer.
This distinction is not academic. In Moffatt v. Air Canada, decided by the British Columbia Civil Resolution Tribunal in February 2024, the airline's chatbot gave a customer incorrect information about a bereavement fare policy.[1] Air Canada argued the chatbot was "a separate legal entity" responsible for its own statements. The tribunal rejected that argument outright and held the airline liable, on the basis that a business is responsible for what its customer-facing systems tell customers, whether a person or software said it. The lesson for any operator is direct: an agentic chatbot's output is your business's statement in the eyes of a court, in the same way a salesperson's promise is. For the fuller breakdown of the case and what it means for smaller operators specifically, see our guide to the Air Canada chatbot case.
What your existing policies actually cover, and where they stop
Three policy types are relevant to a customer-facing chatbot, and each has a different, and increasingly narrower, relationship to AI-generated harm.
General liability. Commercial general liability policies traditionally cover bodily injury and property damage arising from your business operations, and some also extend to certain reputational or advertising injury claims. From 2024, ISO made endorsements CG 40 47 and CG 40 48 available to CGL carriers, allowing them to explicitly exclude bodily injury or property damage arising out of the use of artificial intelligence.[2] Whether your policy carries one of these endorsements depends entirely on your carrier and your renewal date. A policy bound before your business deployed the chatbot may not have it. A policy renewed after 2024 increasingly does. This is not something to infer. Ask your broker for the endorsement schedule and check specifically for AI-related exclusion language.
Professional indemnity. If your chatbot gives advice, recommendations, or anything resembling professional guidance rather than pure order-status information, professional indemnity is the more relevant line, and it has moved even faster than general liability toward AI-specific exclusions. Many PI carriers added AI exclusion wording to their standard forms from 2024 onward in direct response to rising claims frequency tied to generative AI outputs. If your PI policy is silent on AI, that silence often favours you at claim time, but a policy that mentions AI explicitly and excludes it removes cover for exactly the scenario a chatbot creates. Our companion piece on whether professional indemnity covers AI tools in client work goes deeper on how this plays out by sector.
Cyber liability. Standard cyber policies are built around data breach, ransomware, and network security failure. They are not designed to respond to a chatbot that gives a customer wrong information or makes an unauthorised commitment without any data ever being compromised. If your chatbot's failure mode is "it said something wrong" rather than "it leaked something," your cyber policy is very likely the wrong document to be relying on, no matter how comprehensive it looks on the declarations page. A full walk-through of what standard business insurance does and does not pick up is in our guide to whether your business insurance covers AI mistakes.
The disclosure question: Article 50 and why it matters beyond compliance
Article 50 of Regulation (EU) 2024/1689, the EU AI Act, requires providers and deployers to ensure that natural persons are informed they are interacting with an AI system, unless this is obvious to a reasonably well informed person from the circumstances.[3] For a customer service chatbot, the safer practice is an explicit, visible disclosure rather than relying on the obviousness exception, since what counts as obvious is precisely the kind of question that gets litigated after something has already gone wrong. This is fundamentally a compliance obligation rather than an insurance one, and it applies regardless of whether you carry AI-specific cover at all.
It matters for insurance for a more practical reason. Underwriters writing chatbot-specific submissions increasingly ask for evidence that the operator has met basic transparency obligations, treating a dated screenshot or configuration record of your Article 50 disclosure as part of the governance evidence that supports a better rate. An operator who can show the disclosure was live from day one, alongside a written description of what the chatbot is and is not authorised to do, is submitting a materially stronger file than one who cannot. For the EU compliance detail behind this obligation, see agentliability.eu's Article 50 deployer guide.
What "separate coverage" actually looks like at SME scale
Until recently, the honest answer for a small business asking about dedicated AI liability cover was that almost nothing existed below enterprise scale. That has changed through 2026. HSB, a Munich Re subsidiary, launched an AI liability insurance product aimed at small businesses in March 2026, and Testudo, backed by Apollo, Atrium, and QBE capacity, launched in January 2026 with a similar market focus.[4] Counterpart offers affirmative AI coverage endorsements that can be added to management liability programmes, giving a more accessible entry point than a standalone AI liability policy for businesses that do not yet have formal AI governance documentation.[5] At the higher end, Armilla, operating as a Lloyd's of London coverholder, and Munich Re's own aiSure product serve larger programmes with more demanding documentation requirements.
None of these products require you to have solved AI governance perfectly before you can get a quote. What they do require, in every case, is a clear written description of what your chatbot is authorised to do, which is exactly the exercise the test earlier in this article is designed to produce. An operator who cannot answer "what can it say and what can it commit us to" in a single paragraph is not ready for a quote conversation yet, separately from whether they end up buying a policy at all.
A four-step check before you decide either way
First, get your broker to confirm in writing whether your current general liability, professional indemnity, and cyber policies carry an AI exclusion endorsement. Silence is not the same as confirmation. Second, write down in one paragraph what the chatbot is actually authorised to do: what it can say, what it can access, and what it can commit the business to without a human step. Third, check specifically whether it can complete a financial transaction or issue a binding commitment unsupervised, because that single fact is what moves you from a documentation risk to an operator liability risk in the Moffatt v. Air Canada sense. Fourth, keep a dated record of your Article 50 disclosure and your chatbot's scope definition together, since both become part of the evidence file an underwriter, or a court, will want to see if something goes wrong. For the fuller conversation to have with your broker once you have these answers, see our guide on what to tell your broker about AI agents, and for how European enterprises are approaching the same coverage gap at larger scale, see AI exclusions in cyber and E&O policies on agentinsured.eu.
Frequently asked questions
Do I need separate insurance for my AI customer service chatbot?
It depends on what the chatbot can actually do, not on the fact that it is a chatbot. A scripted widget that answers FAQs from a fixed script carries low incremental risk and may already sit inside your existing professional indemnity or general liability cover, subject to any AI exclusion endorsement. An agentic chatbot that can quote a price, promise a refund, change a booking, or give advice a customer relies on is making representations that bind your business the way a staff member's would. Most standard commercial policies were not underwritten with that scenario in mind, and many now carry explicit AI exclusions, which is why a coverage review before deployment matters more than the chatbot's technical sophistication.
Does my general liability or professional indemnity policy already cover chatbot mistakes?
Only if the policy is silent on AI or contains affirmative AI language, and increasingly it is neither. ISO introduced endorsements CG 40 47 and CG 40 48 that insurers can attach to commercial general liability policies to exclude bodily injury or property damage arising from AI systems, and many professional indemnity carriers added their own AI exclusion wording from 2024 onward in response to rising claims frequency. A policy issued or renewed before your business deployed the chatbot may predate these endorsements and still respond, but you should not assume that. Ask your broker directly whether an AI exclusion endorsement has been added at your last renewal.
What is the difference between a chat widget and an agentic chatbot for insurance purposes?
A chat widget answers from a fixed script or a narrow retrieval system and cannot take actions or make commitments outside pre-approved text. An agentic chatbot can generate novel responses, access customer or order data, call other systems, and in some deployments complete a transaction or issue a refund without human review. Insurers price these very differently because the agentic version can create a binding representation or an unreviewed financial action, which is the fact pattern behind Moffatt v. Air Canada. If your chatbot can say something your business has not pre-approved, treat it as agentic for coverage purposes regardless of how it is marketed to you.
Does the EU AI Act require me to disclose that customers are talking to a chatbot?
Yes, in most cases. Article 50 of Regulation (EU) 2024/1689 requires providers and deployers to ensure natural persons are informed that they are interacting with an AI system, unless this is obvious from the circumstances to a reasonably well informed person. For a customer service chatbot embedded on a website or messaging channel, the safest reading is to disclose explicitly rather than rely on the obviousness exception. This is a compliance obligation, not an insurance requirement, but underwriters increasingly ask for evidence of Article 50 disclosure as part of the governance documentation that supports a chatbot-specific quote.
What should I check before adding an AI chatbot without buying new coverage?
Four things. First, confirm with your broker in writing whether your current general liability, professional indemnity, and cyber policies contain an AI exclusion endorsement. Second, define in writing what the chatbot is actually authorised to commit your business to, since that scope is what an insurer and a court will both look at. Third, check whether the chatbot can complete financial transactions or issue commitments without a human step, because that materially changes the risk category. Fourth, keep a dated record of the Article 50 disclosure your chatbot displays to users, since this becomes part of your evidence file if a dispute arises.
Related reading
Run the Coverage Audit
Before you talk to a broker, use the Coverage Audit tool to map your chatbot's actual scope against your existing policies. It takes ten minutes and produces the document your broker needs to review your position.
Start the Coverage AuditReferences
- Moffatt v. Air Canada, 2024 BCCRT 149 (BC Civil Resolution Tribunal, February 14, 2024).
- Insurance Services Office (ISO). Commercial general liability endorsements CG 40 47 (Exclusion, Access or Disclosure of Confidential or Personal Information and Data-Related Liability, With Limited Bodily Injury Exception) and CG 40 48, made available to carriers for artificial intelligence related exclusions from 2024.
- Regulation (EU) 2024/1689 of the European Parliament and of the Council on artificial intelligence (EU AI Act). Article 50, transparency obligations for providers and deployers of certain AI systems, including the duty to inform natural persons they are interacting with an AI system.
- HSB (a Munich Re subsidiary). AI liability insurance product for small businesses, launched March 2026. Testudo, backed by Apollo, Atrium, and QBE capacity, launched January 2026.
- Counterpart. Affirmative AI coverage endorsements for management liability and directors-and-officers programmes.