← BlogAI Consultancy

Who Pays When Your AI Agent Makes a Costly Mistake? Liability, Insurance, and Vendor Contracts Explained

By Aditya JhaSeptember 12, 20267 min read

Who Pays When Your AI Agent Makes a Costly Mistake? Liability, Insurance, and Vendor Contracts Explained

A mid-market fintech's AI agent auto-approves a refund request it should have escalated, twelve thousand dollars, gone in one autonomous decision made at 2am with no human in the loop. The COO calls the vendor expecting this to be exactly the kind of thing the vendor's insurance exists for. It isn't. The vendor's standard tech errors-and-omissions policy explicitly doesn't cover losses from an autonomous agent's multi-step decision, only from a discrete, identifiable software defect, and the fintech's own general liability policy quietly picked up a blanket AI exclusion at its last renewal without anyone on the finance team noticing. Nobody is denying the mistake happened. The argument is entirely about whose policy, if any, was ever supposed to pay for it.

Why doesn't your existing insurance already cover an AI agent's mistake?

Because the standard commercial general liability (CGL) policy most businesses already carry is being actively rewritten to exclude it. Effective 1 January 2026, ISO introduced three new endorsements, CG 40 47, CG 40 48, and CG 35 08, that let insurers exclude bodily injury, property damage, and advertising-injury claims arising from generative AI from standard CGL policies, and the exclusion applies whether the AI tool was built in-house or bought from a vendor.

This matters at a scale most finance teams haven't clocked yet: ISO forms underpin roughly 82% of US property and casualty policies, so this isn't a niche carrier decision, it's quietly propagating through renewal cycles across the market. A business that assumed its general liability policy was a backstop for an AI agent's mistake may find out otherwise only when it files the claim.

If the vendor's contract says they'll 'indemnify' you, does that actually protect you?

Partially, and often less than the word implies. A vendor's indemnification clause is a promise to cover certain losses, typically third-party IP claims, but these promises are structurally limited: most vendor agreements cap total liability, including the indemnification obligation itself, at roughly twelve months of fees paid, which can be a small fraction of the actual downstream loss from an autonomous agent's error.

There's a second, quieter problem: an indemnification promise is only worth as much as the insurance or balance sheet actually standing behind it. A vendor can agree in writing to indemnify you and still have no policy that covers that specific type of loss, which means the promise is uncollectable exactly when you need it. Ask what insurance backs the indemnity, not just whether the clause exists.

Who actually bears the risk in practice, the vendor or the business that deployed the agent?

Increasingly, the deploying business. The reasoning courts and regulators are converging on is that the business chose to deploy the agent, chose how to configure it, and chose what decisions to let it make autonomously, so the party with the least technical visibility into the model, the enterprise customer, ends up absorbing the downstream liability by default unless its contract explicitly shifts that back.

That's the opposite of how most companies assume risk is allocated when they sign a vendor agreement, and it's exactly why the contract terms below matter more for an AI agent than they ever did for ordinary SaaS.

What should actually be in an AI agent vendor contract before you sign?

Contract termWhat to actually require
Vendor insuranceTech E&O and cyber liability coverage with limits matched to the realistic blast radius of an agent error, not a generic minimum
Additional insured statusYour company named as an additional insured, with annual certificates of insurance provided proactively, not on request
Liability cap carve-outsGross negligence, security incidents, and autonomous-decision failures excluded from the standard 12-month-fees liability cap
Defined failure categoriesExplicit definitions for 'AI agent error' and 'autonomous decision failure' in the contract, not generic force-majeure language that wasn't written with agents in mind
Human-in-the-loop requirementsContractually required approval checkpoints for any decision above a defined dollar or risk threshold, shifting exposure back to a designed control rather than an unbounded autonomous action

Standard SaaS contract templates weren't written for a system that can make an autonomous, financially consequential decision at 2am. Treat the agent's contract like the risk it actually carries.

How AIBOOTSTRAPPER helps

There isn't a single AIBOOTSTRAPPER case study specifically about an insurance claim or contract dispute, so we won't manufacture one, this is a governance and contracting problem more than a build problem. What we do build into every agent, as a matter of architecture rather than paperwork, is the risk-tiered human-in-the-loop approval layer that keeps the highest-stakes decisions, refunds, disbursements, contractual commitments, off fully autonomous rails in the first place. That's the cheapest form of risk transfer available: an agent that can't autonomously make the $12,000 mistake doesn't need a $12,000 insurance claim.

If you're about to sign a vendor contract for an AI agent that touches money, contracts, or regulated decisions, run it past the checklist above before you sign, not after something breaks. Book a call, or take the AI Readiness Score to see where your own governance gaps sit before you commit to a vendor.

Want this done for you?

Book a free strategy call and we'll show you how to build and market your business with AI.

FAQ

Questions, answered

Everything you might want to know before we hop on a call.

Increasingly, no. Since 1 January 2026, ISO's new endorsements let insurers exclude losses arising from generative AI from standard commercial general liability policies, and because ISO forms underpin most US P&C policies, this exclusion is spreading quickly through renewals whether or not a business notices it happening.

Not necessarily. Vendor indemnification is typically capped at around twelve months of fees paid, far below the potential cost of a serious autonomous-agent error, and the promise is only as good as the insurance or balance sheet actually backing it. Ask what specific policy covers the indemnity before relying on it.

In practice, responsibility is trending toward the business that deployed and configured the agent, not the vendor, on the reasoning that the deploying company chose how much autonomy to grant it. This makes contract terms and internal approval controls more important than assuming the vendor's coverage will absorb the loss.

Require human approval for any decision above a defined dollar or risk threshold, contractually and architecturally. An agent that structurally cannot make a large autonomous mistake removes the liability question for that category of decision entirely, rather than relying on insurance or indemnification to clean it up after the fact.

Keep reading

Let's talk

Ready to build and sell with AI?

Book a free 30 minute strategy call. We'll map the highest ROI AI move for your business, no pitch, just value.