Short answer
An AI provider’s terms may push responsibility downstream, while the customer’s contract is usually with the company that deployed the system. That makes the deployer an important first point of responsibility, not an automatic winner or loser. The result depends on the cause of loss, representations, contracts, control failures, applicable law, and the policy wording across Tech E&O, cyber, general liability, D&O, crime, or other lines.
Evidence frame
- Established
- Responsibility after a loss is shaped by the act, the relationship between the parties, the contract, applicable law, and the evidence—not by the fact that a model was involved.
- Clara inference
- The deployer is often the first commercial party in view because it integrated the system and made the customer promise, while provider terms and customer conduct can change the allocation.
- Hypothesis
- A loss-path map that records provider, deployer, customer, contract, control, and policy pathways could reduce the habit of treating AI liability as one undifferentiated question.
- Unknown
- Which party ultimately pays, and which policy responds, cannot be known without the loss facts, governing law, contract language, policy wording, and available evidence.
Three parties are usually in the frame
| Party | Why it may be involved | What remains uncertain |
|---|---|---|
| Model or platform provider | It supplied the model, service, documentation, or safety representations. | Provider terms, product design, warnings, statutory duties, and the cause of the loss. |
| Deployer or product company | It selected the system, integrated it, made the customer promise, and controlled the use case. | Supervision, testing, configuration, authority, contract allocation, and jurisdiction. |
| Customer or affected person | It relied on the output or was affected by an action taken through the system. | Reliance, notice, comparative fault, consumer law, and contractual remedies. |
Provider terms are evidence of how a company has attempted to allocate responsibility. They are not the final word on legal responsibility. OpenAI and Anthropic publish commercial terms that place meaningful obligations and limits around use; a company should read those terms alongside its customer commitments rather than assuming the lab will absorb every downstream claim.
Liability follows the loss mechanism
“The AI caused it” does not identify a claim. A useful review asks what happened in the world and which obligation, asset, person, or system was affected.
- Financial loss a customer relied on a wrong recommendation, approval, price, or workflow result.
- Security or privacy loss an agent was manipulated, exposed data, used credentials, or changed a protected system.
- Contract or representation loss the company promised an outcome, control, service level, or limitation it could not support.
- Physical loss an AI-enabled machine, vehicle, or industrial process injured someone or damaged property.
- Governance or disclosure loss leadership is accused of misrepresenting capability, failing to supervise, or ignoring a known risk.
These categories can overlap. A prompt-injection event may begin as a cyber incident and end as a customer E&O claim. The company’s evidence should preserve the sequence rather than forcing it into a single label too early.
An agent’s goal does not define its authority
An instruction such as “resolve the customer’s problem” or “reduce the queue” is a goal. Authority is the set of actions the system can take while pursuing it. A system may be asked to draft a refund but be able to issue it, change the ledger, contact a third party, or delegate the work to another agent.
Clara’s Efficient Path note examines incidents in which capable systems treated a boundary as an obstacle to an assigned objective. The risk question is not whether the system felt malicious. It is whether the company gave the system a path to an unauthorized action and whether a human could detect, stop, and reverse it.
That distinction matters for attribution, contract drafting, controls, and insurance evidence. A human-approved objective is not the same thing as human approval of every method used to reach it.
Which insurance lines may respond
Coverage depends on the policy, but the first map is usually practical rather than exotic:
- Technology E&O for a customer’s financial loss arising from the technology or professional service, subject to covered services and exclusions.
- Cyber when the loss runs through network security, privacy, data, system compromise, or response costs.
- General or product liability when bodily injury, property damage, or a covered product exposure is involved.
- D&O when the allegation concerns leadership, disclosure, governance, or management decisions.
- Crime or other specialized lines when funds, deception, employees, vehicles, equipment, or regulated activity create a distinct mechanism.
The presence of a line in this list is not a coverage conclusion. An AI exclusion, a professional-services definition, a contractual liability exclusion, or a condition can change the answer.
Preserve the facts before the claim changes the story
The most useful evidence is contemporaneous and specific. Keep the agent version, model and tools, prompts or policies where appropriate, authority and credential scope, approvals, logs, alerts, customer communications, contract terms, and the exact point at which the company learned of the event.
Also preserve what the system did not do: blocked actions, failed attempts, rollback, shutdown, human intervention, and the limitations known at deployment. A reliable account of a loss includes the boundary, the attempted crossing, and the response.
This is why RISK.md treats evidence, provenance, uncertainty, and change as the spine of a company-owned context packet. The packet does not decide liability. It makes the facts easier for legal, security, insurance, and executive reviewers to examine.
The question Clara is carrying forward
The market does not need a theory that shifts every AI loss to one party. It needs better allocation: who had authority, who made the promise, who could control the system, which safeguards were in place, and which policy or contract was intended to respond.
Clara is testing whether a structured record of deployed authority can make those questions answerable before a loss and more legible after one. That is the bridge between the public incidents in Efficient Path, the form analysis in AI Exclusions, and the future insurance systems described in the manifesto.
Common questions
Who is liable when an AI agent causes a loss?
There is no universal answer. The deployer is often the first commercial party in view because it integrated the system and contracted with the customer, but provider terms, product design, supervision, customer conduct, law, and the facts of the loss all matter.
Can a model provider be liable for an AI agent’s actions?
Potentially, depending on the facts and applicable law, but provider contracts commonly contain allocation, disclaimer, indemnity, and use restrictions that affect the analysis. Those terms should be read rather than assumed away.
Does insurance cover AI liability?
Some AI-related losses may fall within existing E&O, cyber, general liability, D&O, crime, or other policies, while exclusions and definitions may narrow or remove coverage. Only the actual policy and claim facts answer the coverage question.
Is a hallucination automatically an insurance claim?
No. A model error becomes an insurance question when it connects to a covered loss, obligation, and policy trigger. The customer’s reliance, the company’s promise, the professional service, the loss amount, and the wording all matter.
What should a company do after an AI incident?
Preserve the system and authority record, contain the event, identify affected people and data, notify the appropriate internal and external parties, review contract and policy obligations, and avoid changing or deleting evidence before legal and insurance guidance is obtained.