- Customer contact is not what creates liability. Loss is. Internal tools produce losses that land outside the business through five ordinary routes, and in each of them the injured party is external.
- The exclusion in your policy does not ask whether the tool was internal. A specimen of market form CG 40 48 01 26 defines generative artificial intelligence as a machine-based learning system or model trained on data with the ability to create content or responses, and stops there.
- Internal work product is the largest of the five routes and the least visible, because the output stops being AI output the moment a person pastes it into a document with your logo on it.
- An internal tool that infers employee emotions is not merely regulated, it is prohibited. Article 5(1)(f) of the EU AI Act has applied since 2 February 2025 and sits at the top penalty tier.
- No single policy owns internal AI. Each route lands somewhere different, which is why the inventory has to come before the coverage conversation rather than after it.
The wrong boundary
Operators draw the risk line where the brand is visible. It is a reasonable instinct and it is the same instinct that makes a shop owner insure the shopfront rather than the stockroom. The problem is that insurance does not follow visibility. It follows the loss, and it asks three questions in order: who was harmed, what were they harmed by, and does a policy in this programme respond to that kind of harm.
Notice that none of those questions is "was the system customer-facing". That fact is invisible to every stage of a claim. It is a description of your internal architecture, and the person who has been harmed neither knows it nor cares. What they know is that they received bad advice, were turned down for a job, were invoiced twice, or had their data exposed.
So the useful reframing is not "is our AI internal" but "does anything this tool produces or decides ever leave the building". Almost always something does. Below are the five routes it takes, in rough order of how often they catch a business by surprise.
Route one: internal work product that becomes external work product
This is the big one and it is almost never on anyone's risk register. A member of staff uses an assistant to draft a summary, build a model, research a question or write a first version of something. That output is internal for about forty minutes. Then it is edited lightly, pasted into a document carrying your letterhead, and sent to a client, a lender, a regulator or a counterparty.
At that moment the output stops being AI output in any sense your business records. It is now your professional advice. If it contains an invented figure, a misread clause, a citation to a case that does not exist, or a confident statement about a rule that changed last year, the claim that follows is an ordinary professional negligence claim about your work. Nobody will describe it as an AI incident. It will be described as a mistake in a report.
This is why the professional indemnity conversation matters even for businesses with no customer-facing AI at all. The exposure did not arrive because a machine talks to your clients. It arrived because the volume and speed of drafted material rose while the review step stayed the same size. Two specific patterns are worth naming, because they are the ones that produce claims rather than near misses. The first is unreviewed numerical output, where a person checks that a paragraph reads well and does not re-derive the figure inside it. The second is research output, where the tool supplies a source that looks exactly like a real source. Both are covered in more depth in our note on documenting AI decisions for insurance purposes.
Route two: decisions about people
Internal by definition, external in consequence. A screening tool that ranks applicants, a scheduling system that allocates shifts, a performance tool that flags outliers, a wellbeing tool that reads sentiment in messages. None of these has a customer anywhere near it. All of them make decisions about human beings who have rights and, in some cases, regulators.
The reference case here is not an AI case in the way people expect. In EEOC v. iTutorGroup the tutor application software automatically rejected female applicants aged 55 or older and male applicants aged 60 or older. The United States Equal Employment Opportunity Commission alleged that more than 200 qualified applicants based in the US were rejected on that basis. The matter settled by consent decree with USD 365,000 paid to affected applicants, alongside training, a new anti-discrimination policy and injunctive relief. The line worth keeping is the one the EEOC's then-chair Charlotte A. Burrows used: "Even when technology automates the discrimination, the employer is still responsible."
In Europe the regulatory framing is more explicit. Employment is point 4 of Annex III to the EU AI Act, the standalone high-risk list, with those obligations applying from 2 December 2027 after the AI Omnibus entered into force on 27 July 2026. Sector detail sits on agentliability.eu, on the Annex III high-risk categories.
One category deserves separate mention because it is not a future obligation. Article 5(1)(f) prohibits the placing on the market, the putting into service for that purpose, or the use of AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the system is intended for medical or safety reasons. That prohibition has applied since 2 February 2025. Prohibited practices sit at the top of the Article 99 penalty structure, up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover, whichever is higher, with the lower of the two figures applying to SMEs and start-ups. A morale dashboard that scores the tone of internal messages is the purest example of an entirely internal system that is nonetheless the single most heavily sanctioned thing on this list.
On the coverage side, this route lands in employment practices liability, which is a separate policy that a large number of smaller programmes simply do not include. Recruitment and HR specifics are set out in AI liability for recruitment and HR agencies.
Route three: internal agents that move money
Reconciliation, invoice matching, payment approval, expense checking, supplier onboarding. These are the tasks businesses automate first because they are repetitive and rule-shaped, and they are also the tasks where an error is immediately a cash loss rather than a reputational one.
Two distinct failure modes live here and they land in different places. The first is straightforward error: the agent approves something it should have queried, or pays the same invoice twice, or applies the wrong tax treatment across a quarter before anyone notices. The second is manipulation: a supplier email is not from the supplier, and an agent processing it acts on the instruction faster and more obediently than a person would have.
The second pattern is the one the insurance market has moved on first. Coalition's Affirmative Artificial Intelligence Endorsement, added on 26 March 2024 to its US Surplus and Canada Cyber policies, has exactly two limbs, and one of them extends funds transfer fraud cover to fraudulent instruction carried out through deepfakes or other AI. That is a US and Canadian product rather than a European one, and it is cited here for what it shows about where the market drew the line rather than as something you can buy in Rotterdam. The line it drew is instructive: the endorsement responds to an AI-assisted deception, not to an AI-generated mistake. Those are different events and your programme may treat only one of them.
Route four: an agent with credentials is a credential
Any internal agent useful enough to keep has access to something: a mailbox, a document store, a database, a code repository, a cloud account. That access is a security surface, and it is a surface with an unusual property. It can be talked to.
The manipulation route is covered separately in is a prompt injection attack covered by business insurance, and it applies with full force to internal systems, because an internal agent that reads incoming documents or email is reading text written by strangers whether or not you think of it as customer-facing.
The other pattern is cost rather than compromise. QBE North America publishes an LLMjacking coverage that responds to the increased cloud service fees a threat actor runs up on cloud-hosted AI resources reached with stolen credentials, and to the cost of retraining a model damaged in the process. Whether or not that specific cover is available to you, the shape of the loss is worth understanding, because it is one that a business discovers on an invoice rather than through an alert.
Route five: personal data does not become less personal indoors
An internal tool that summarises support tickets is processing customer data. One that drafts a reference is processing employee data. One that searches your document store is processing whatever is in the document store, which in most businesses is more than anyone remembers putting there.
The regulatory position here does not turn on customer contact at any point, and neither does the coverage position. This is the route where the gap between what the business believes it is doing and what it is actually doing tends to be widest, simply because the tool was adopted to save time on an internal task and nobody performed the exercise of listing what it can read.
Why the exclusion will not save the distinction
Operators who accept all of the above sometimes fall back on a last position: our policy would respond anyway, because our AI use is incidental. This is where reading the definition matters more than reading the exclusion.
A specimen of the market form CG 40 48 01 26 defines the operative term as follows: "'Generative artificial intelligence' means a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code." The sibling form CG 35 08 01 26, which addresses products and completed operations, carries the same definition word for word.
Read what that definition does not contain. It does not distinguish a customer-facing system from an internal one. It does not distinguish an autonomous agent from a person using an assistant. It does not carve out incidental, occasional or assistive use. It does not require the system to have made a decision, only to have the ability to create content or responses. A staff member using a mainstream assistant to draft an email is inside that definition on its face.
Two honest caveats belong with that. First, these are specimens of the forms rather than filing records, so the right way to describe them is as forms we have read rather than as filings we have confirmed. Second, and more practically, whether any such endorsement sits on your programme is a question about your schedule, not about the market. The point is only that if one does, the internal or external distinction you have been relying on is not in the wording. Our broader walkthrough is at AI policy exclusions for SME operators, and the European market context is on agentinsured.eu, on AI exclusions in cyber and errors and omissions policies.
Four questions, and the list that answers them
Before any of this becomes a coverage conversation it has to become a list. Ask every team one question: what do you use to produce work that then goes to somebody else, or to decide something about a person. Record five columns for each answer. The tool. The team. Whether output leaves the business. Whether it touches personal data. Whether a named person reads it before it goes.
Expect the list to contain things nobody procured. In most small businesses the highest-exposure internal AI was never bought, never reviewed and appears on no software register, because an individual signed up for it, it does useful work, and there was never a moment at which anyone was supposed to be told.
Then take four questions to whoever placed your insurance, and ask for answers by policy, section and clause rather than as reassurance.
- Does any policy in our programme carry an AI exclusion or endorsement, and does its definition of AI turn on customer contact, autonomy or decision-making in any way?
- If a client alleges that a deliverable we produced with assistance contains an error, does our professional indemnity respond, and does anything in the wording distinguish AI-assisted work from work drafted by hand?
- Do we carry employment practices liability at all, and if so does it respond to a claim arising from an automated or semi-automated screening decision?
- If an internal agent acted on a fraudulent instruction and money left the business, which policy responds, and does it respond to an error by the agent as well as to a deception of it?
If the answer to question one is that no exclusion exists today, ask the follow-up that matters more: what is expected at our next renewal. Programmes are changing shape faster than businesses are, and the useful time to discover an exclusion is while you can still negotiate around it. The pre-deployment version of this exercise is at the AI agent pre-deployment insurance checklist, and the script for the conversation itself is in what to tell your insurance broker about AI agents.
The honest summary
Internal-only AI does not mean uninsured exposure. It means unexamined exposure, which is a different and more fixable problem. There is a reasonable version of the original sentence, and it sounds like this: our AI is internal, we have listed every tool, we know which of them produce output that leaves the business, we know which of them decide something about a person, and we have asked our broker in writing how each of those two categories is treated. A business that can say that has done the work. A business that says "it is internal only" and stops has described its architecture and answered nothing.
Questions
Our AI never speaks to a customer. Do we still need AI cover?
Probably yes, because customer contact is not what creates the exposure. Liability follows the loss, and internal tools produce losses that land outside the business through five routes: internal drafting whose output travels into a client deliverable, screening that makes an employment decision, finance tools that move money, agents holding credentials that a third party can steal or manipulate, and any tool processing personal data. In each case the injured party is external and the claim is external. That no customer ever typed into the system is an internal detail about how the loss was produced, not a defence.
Does an AI exclusion in my policy apply to internal tools?
Read the definition rather than the exclusion. A specimen of market form CG 40 48 01 26 defines generative artificial intelligence as a machine-based learning system or model that is trained on data with the ability to create content or responses, including but not limited to text, images, audio, video or code. That draws no line between a customer-facing chatbot and a staff member drafting an internal memo that later becomes a client report, and it does not distinguish autonomous agents from assisted work. If your programme carries an exclusion of that shape, the question of who the tool was pointed at never arises.
Is an internal HR screening tool a regulated AI system under the EU AI Act?
Employment is point 4 of Annex III, the standalone high-risk list, with those obligations applying from 2 December 2027 following the AI Omnibus that entered into force on 27 July 2026. Separately and already in force, Article 5(1)(f) prohibits using AI systems to infer emotions of a natural person in the workplace and in education institutions, except for medical or safety reasons. That has applied since 2 February 2025 and sits at the top Article 99 tier, up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover, whichever is higher, with the lower figure applying to SMEs and start-ups.
Which policy responds when an internal AI tool causes a loss?
It depends on how the loss travelled outward, which is why the inventory matters more than the tool. Output that reached a client is professional indemnity territory. An employment decision is employment practices liability, which many smaller programmes do not carry. Money leaving on a false instruction is crime or fidelity cover, and in some markets a funds transfer fraud limb inside a cyber policy. Credential theft against a cloud-hosted model is a cyber question, as is personal data. No single policy owns internal AI, and each route lands somewhere with its own exclusions.
What should we inventory first?
Start with the tools nobody procured. The riskiest internal AI in most small businesses was never bought, never reviewed and appears on no software register, because an individual signed up for it and it does useful work. Ask each team one question: what do you use to produce work you then send to somebody else, or to decide something about a person. Record the tool, the team, whether output leaves the business, whether it touches personal data, and whether anyone reads it before it goes. That list is what your broker and your underwriter will both ask for.
Sources
- Regulation (EU) 2024/1689 (EU AI Act), Article 5(1)(f): prohibition on AI systems used to infer emotions of a natural person in the areas of workplace and education institutions, except where intended for medical or safety reasons. Applicable since 2 February 2025. Text read at the European Commission AI Act Service Desk, ai-act-service-desk.ec.europa.eu, 24 August 2026.
- Regulation (EU) 2024/1689, Article 99: up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover for Article 5 prohibited practices, whichever is higher, with the lower of the two figures applying to SMEs and start-ups. Annex III point 4 covers employment, workers management and access to self-employment.
- Regulation (EU) 2026/1744, the AI Omnibus, in force 27 July 2026. Annex III standalone high-risk obligations apply from 2 December 2027 and Annex I from 2 August 2028. European Commission, AI Omnibus enters into force.
- US Equal Employment Opportunity Commission, EEOC v. iTutorGroup. Consent decree, USD 365,000 to affected applicants, plus training, a new anti-discrimination policy and injunctive relief. eeoc.gov.
- CG 40 48 01 26, headed "EXCLUSION" and "GENERATIVE ARTIFICIAL INTELLIGENCE (COVERAGE B ONLY)", and CG 35 08 01 26, headed "EXCLUSION" and "GENERATIVE ARTIFICIAL INTELLIGENCE", modifying the products and completed operations liability coverage part. Both quoted from specimens of the forms carrying the Insurance Services Office copyright line, read 17 August 2026. These are specimens rather than filing records, and are described as such throughout.
- Coalition, Affirmative Artificial Intelligence Endorsement, added 26 March 2024 to US Surplus and Canada Cyber policies. Two limbs: security failure and data breach extended to an AI security event, and funds transfer fraud extended to fraudulent instruction via deepfakes or other AI. coalitioninc.com.
- QBE North America, LLMjacking coverage within its AI-focused cyber offering, responding to increased cloud service fees run up on cloud-hosted AI resources reached with stolen credentials and to the cost of retraining a damaged model. No sublimit or cap is published and none is stated here. qbe.com.
- Policy structure described in this article reflects the common shape of professional indemnity, employment practices liability, crime and cyber wordings in the United Kingdom and European markets. No individual carrier form is cited beyond those named above. Wordings vary materially between insurers and between renewals, and the only reliable answer is the one read off your own schedule.