In short
  • Outbound risk is your AI doing something wrong. Somebody else suffers, and they come to you. It usually lives in professional indemnity, professional liability or technology errors and omissions.
  • Inbound risk is somebody else's AI coming at you, or a shared supplier failing. You suffer. It lives in cyber.
  • You can have the inbound risk with no AI of your own. European financial supervisors have drawn exactly this line, distinguishing an organisation's internal use of these models from its indirect exposure to them.
  • The overlap is real and it is where arguments happen: an agent you deployed being manipulated into causing harm looks outbound and inbound at once.
  • The single most useful thing you can do costs nothing: ask your broker, in writing, which of your policies responds to an incident that is both, and keep the reply.

Risk one, outbound: your AI does something wrong

This is the risk this site was built around and the one most operators picture. You put an AI tool in front of customers, or you use one to produce work that customers rely on. It gets something wrong. Somebody acts on it and is worse off, and they want you to make it right.

The shape of the loss is old even though the cause is new. A customer relied on something you told them, it was wrong, and they suffered. Insurance has answered that shape for a very long time, which is why the starting point for outbound AI risk is not a specialist AI product but the policy that already covers mistakes in your line of work. For most small businesses that is professional indemnity or professional liability. For a software business it is technology errors and omissions. Our walkthrough of what actually happens after a wrong answer is at if your AI agent gives wrong advice, does insurance cover it, and the question of who pays as between you and the tool vendor is at who pays for an AI agent's mistake.

Two things are worth checking rather than assuming, and both are wording questions rather than matters of principle. The first is whether an AI exclusion has appeared at a recent renewal, because the market has been adding them and they do not announce themselves. The second is whether your definition of professional services still fits work that an AI produced and a human barely reviewed. Neither is a reason to panic and both are a reason to read. Our guide to the exclusions currently circulating is at the AI policy exclusions guide.

Risk two, inbound: somebody else's AI comes at you

This is the risk that has had far more official attention in 2026 and far less attention from small operators, and the asymmetry is worth correcting.

Here you have not deployed anything. Somebody is using AI against you, or against a supplier that you and thousands of other businesses depend on. The end result is familiar: an account compromised, a system down, a convincing fake instruction that moved money, data out of the building, a week of trading lost. Those are cyber losses and a cyber policy is the instrument built for them.

What changes is the tempo, and the change has been described in unusually direct language by Europe's three financial supervisory authorities. In a joint statement on the risks of frontier AI models they say these tools could generate systemic risks through the ability to rapidly discover and exploit vulnerabilities, to target vulnerabilities in shared infrastructure, and through single points of failure across entities. Their annex is blunter still, observing that traditional patching processes relying on a periodic and reactive approach may not be sufficient, and that periodic security checks such as annual penetration tests may leave gaps that are highly exploitable.

That statement is addressed to regulated financial firms and not to you. It is quoted here because it is the clearest public description available of what the inbound risk actually is, and because it makes an important point about which risk the authorities are worried about. It is not about chatbots being rude to customers. The full regulatory reading is at agentliability.eu, and the coverage reading at agentinsured.eu.

Why this matters more than it sounds

Because the two risks ask you completely different questions, and answering one well tells an insurer nothing about the other.

For the outbound half, a proposal form wants to know what your AI touches, whether it speaks to customers, what it can do without a person approving it, and who reviews its output. Those questions are set out at what an underwriter will ask about your AI agent.

For the inbound half, a proposal form wants to know how quickly you patch, whether multi-factor authentication is on everywhere rather than mostly, whether your backups are separate enough from your live systems to survive the same incident, and which suppliers you could not operate without. None of those questions mention AI at all, which is exactly why a business that has thought hard about its chatbot can still answer them badly.

A business with an excellent handle on its AI agent and stale patching has covered the risk that makes headlines and left open the one its own insurers are being warned about. A business with a hardened network and an unreviewed customer-facing agent has done the reverse. Most small businesses are one or the other, and almost nobody is neither.

The trap in we do not use AI

This sentence is said in good faith many times a day, and it answers one question while appearing to answer both.

You can decide not to adopt AI. You cannot decide not to be targeted by it, and you cannot decide that your suppliers will not depend on it. The supervisors quoted above make precisely this distinction: they ask regulated firms to account for the risk arising both from their own internal use of these models and from indirect exposure to them. Indirect exposure is the part that does not care what you decided.

The practical consequence sits on your proposal form. If the AI question is phrased around use, and you use none, your honest answer leaves the inbound half undescribed. That is not a misrepresentation and nobody is going to accuse you of one. It is simply an incomplete picture, and the moment it matters is a claim, which is the worst possible moment to discover an incompleteness. The general disclosure question is at do I need to disclose AI agents to my insurer, and the answer here is to volunteer the dependency picture even where the form does not ask.

Where the two overlap, and why that is the expensive bit

There is a middle case, it is not rare, and it is where two insurers can each reasonably point at the other.

An AI agent you deployed is manipulated into doing something harmful. A hostile instruction is hidden in a document it was asked to summarise, or a customer talks it into a commitment it should never have made, or a supplier's compromised content changes what it tells people. Your agent did it, so it looks outbound. An attacker caused it, so it looks inbound.

Which policy responds depends entirely on how each wording defines its trigger, and that is a question with an answer, but only if somebody asks it before the incident rather than after. We treat the specific case at is a prompt injection attack covered by business insurance, and the more general boundary between cyber and liability cover at do I need AI agent insurance if I have cyber insurance.

The protection is cheap and almost nobody uses it: put the scenario to your broker in writing, in two sentences, and keep the reply. A written answer at placement is worth a great deal more than an argument at claim.

Five questions that sort your own position out

  1. Does anything we run produce output that a customer or the public relies on? If yes, you have outbound risk, whether or not you think of the tool as AI.
  2. Can any of it take an action without a person approving it? Send, book, cancel, refund, commit, publish. This is the line between an assistant and an agent, and it is the line insurers care about.
  3. Which suppliers could we not operate without for a week? That list is your inbound exposure, and it is almost always shorter and more concentrated than people expect.
  4. How long does it take us to apply an urgent security update, honestly? Not the policy. The last time it actually happened.
  5. If we lost our main systems tomorrow, could we restore from something the same incident could not have reached? If the answer is unclear, that is the finding.

Questions one and two size the outbound half. Questions three to five size the inbound half. If you can answer all five in a paragraph each, you can have a better conversation with a broker than most businesses ten times your size. The full pre-deployment version of this is at the pre-deployment insurance checklist.

What to actually do

Three things, none of which requires buying anything.

Work out which halves you carry using the five questions. Most businesses find they carry both and had only been thinking about one.

Find out which policy each half sits in today, by name and by policy number, and whether either has an AI exclusion added since you last read it. If nobody in the business can say which policy answers a wrong AI output, that is the gap, and it exists before any insurer has done anything.

Ask the overlap question in writing. One email. If an incident involves both an attacker and our own AI tool, which of our policies responds, and which does not. File the answer with the policies.

None of that makes you safer on its own. All of it means that if something happens you will spend the first week dealing with the incident instead of dealing with an argument about which insurer owns it, and for a small business the difference between those two weeks is very large.

Questions

What are the two different AI risks a small business can have?

Outbound and inbound. Outbound is your AI doing something wrong: a chatbot giving a customer wrong information, a tool producing advice somebody relies on, an agent taking an action it should not have taken. Somebody outside your business suffers, and they come to you. Inbound is somebody else's AI coming at you: an attacker using AI to find and exploit a weakness faster than you can patch it, or a supplier that many businesses depend on going down. You suffer, and you are looking for cover for your own losses and your own response. They are close to opposites, they sit in different policies, and having one does not give you the other.

Which policy covers my AI making a mistake?

Usually the policy that already covers professional mistakes in your line of work, which for most small businesses is professional indemnity or professional liability, or technology errors and omissions if you build software. That is the policy that responds when somebody claims your work or your advice caused them loss, and an AI tool being involved in producing that work does not automatically move it elsewhere. Two things to check rather than assume: whether an AI exclusion has been added at your last renewal, and whether the definition of your professional services covers work an AI produced with limited human review. Both are wording questions, not principles.

Which policy covers an AI-assisted cyber attack on my business?

Cyber, in almost every case. The attacker using AI does not create a new class of loss: you still end up with a breach, an outage, extortion, funds diverted by a convincing fake, or a business interruption. Those are the losses a cyber policy is built for. What AI changes is the speed and the likelihood, and therefore the questions a cyber insurer asks you about patching, authentication and backups. It is worth reading your policy conditions on those points specifically, because a condition you cannot meet is worth more attention than an exclusion you can read.

We do not use AI. Do we still have AI risk?

Yes, and this is the most useful sentence in this article. You can decline to adopt AI. You cannot decline to be a target of it, and you cannot decline to depend on suppliers who use it. European financial supervisors have made exactly this distinction in a published statement, asking regulated firms to account for the risk from their own internal use of these models and, separately, from indirect exposure to them. The same logic applies to a business of any size. If you answer a proposal form question about AI by saying you do not use it, you have answered honestly and you have said nothing at all about the inbound half.

What is a risk that falls between the two?

The clearest example is an AI agent you deployed being manipulated into doing something harmful, whether by a hostile instruction hidden in a document it reads or by a customer talking it into a commitment. It looks outbound, because your agent did it and your customer suffered. It looks inbound, because an attacker caused it. Which policy responds turns on how the wordings define the event, and this is precisely where two insurers can each point at the other. The practical protection is to raise the scenario in writing before you buy, and to keep the answer.

What should I tell my broker?

Describe both halves in one conversation rather than one at a time. For the outbound half: what your AI touches, what it can do without a human approving it, and who checks its output. For the inbound half: which suppliers you could not operate without for a week, and what your patching, authentication and backup arrangements actually are rather than what the policy assumes. Then ask one question in writing: if an incident involved both, which of my policies responds and which one does not. A broker who answers that clearly has earned the renewal.

Sources

  1. Joint Committee of the European Supervisory Authorities, ESA Statement titled Toward a consistent and risk-based approach for ICT risks from frontier AI models, carrying the date 31 July 2026 on its own cover. The three capability claims quoted in this article, the annex observations on periodic patching and on annual penetration tests, and the distinction between internal use and indirect exposure, were all read in the published document retrieved from esma.europa.eu on 2 September 2026. The publication entry was also read at eiopa.europa.eu on the same date. That statement is addressed to regulated financial entities and their supervisors. It is not addressed to small businesses, it creates no obligation for one, and nothing in this article suggests otherwise.
  2. The outbound and inbound framing, the five diagnostic questions and the three actions are this desk's own analysis, offered as a way of organising a conversation with a broker. They are not attributed to any regulator, insurer or standards body.
  3. Descriptions of what professional indemnity, technology errors and omissions and cyber policies typically respond to are general market descriptions. No individual policy wording is quoted, no form or clause number is cited, and no insurer's terms are described. Your own policy is the only document that decides your own position.
  4. This article does not state the law of any country. Whether a particular loss is recoverable depends on the wording of your policy and on the law that governs it, and both should be checked locally.
  5. No relationship exists between Future Proof Intelligence and any authority, insurer or broker. No product is recommended here and none is offered for sale on this site.