World Model Readiness
Engraved governance instrument

For your company

Governance & Compliance

Module · Who pays when the AI is wrong

The AI Liability & Insurance Check

When an AI output causes real damage, the question is not whose fault it feels like, but which contract, which policy, and which clause actually carries the cost. Most companies discover the answer during the claim, which is the worst possible time. This module checks the five places liability hides: your own contracts, your insurance, your vendors' indemnities, what you tell customers, and whether anyone has modelled what a bad day would cost.

Question 1 of 5 · Liability is mapped

If an AI output caused a customer loss, do you know which of your contracts carries it?

AI outputs flow into deliverables governed by contracts written before AI was in the picture. Those contracts still allocate liability, usually to you, whether or not anyone has read them with AI in mind. Mapping that exposure per contract type is cheaper than discovering it in a dispute.

Question 2 of 5 · Insurance actually covers it

Does your insurance cover a loss caused by an AI system, and have you confirmed that?

Standard professional and cyber policies were not written with AI errors in mind, and some now exclude them explicitly. Assuming you are covered is not the same as your insurer agreeing. The time to have that conversation is before the claim, not during it.

Question 3 of 5 · Vendors carry their share

When you use a vendor's AI, do their contracts actually indemnify you if it fails?

AI vendors work hard to push liability downstream: caps at the subscription fee, disclaimers on accuracy, no indemnity for outputs. If their contract leaves the risk with you, their model failing becomes your problem to pay for. What the indemnity says matters more than what the salesperson promised.

Question 4 of 5 · Customers were told

Do your customers know when AI is involved, in a way that holds up legally?

A disclaimer that AI assisted an output can limit your liability, but only if it is clear, visible and honest, not buried in a footer. Silence about AI involvement can look like a misrepresentation once something goes wrong. This is a drafting decision, made deliberately or made for you.

Question 5 of 5 · The bad day is modelled

Has anyone worked out what your worst realistic AI failure would actually cost?

You cannot size insurance, indemnities or reserves against a number nobody has estimated. A rough model of the plausible worst case, direct loss, remediation, legal, reputational, tells you whether your controls are proportionate or theatre. The first serious incident is an expensive way to learn the figure.

For the statistics · one click each

Three questions for the public picture

These do not affect your score. They feed the anonymised, aggregated statistics; groups under 8 respondents are never shown.

Do you know whether your insurance covers AI-caused losses?

No idea
We assume so
Reviewing it now
Confirmed in writing
Confirmed excluded

Have you mapped where AI output creates contractual liability?

Not at all
For some contracts
For most contracts
Fully mapped
Not sure

Has anyone estimated the cost of your worst realistic AI failure?

Never
A rough guess
One scenario modelled
Several scenarios modelled
Prefer not to say

Your context

Used to calibrate the report. Company size and sector remain in the anonymized dataset; your email does not.

What the five levels look like

Every dimension in this assessment is scored 1 to 5. This is what the levels mean, dimension by dimension. The graded report diagnoses where your own answers land and what to do about it.

Liability is mapped

  1. 1Never considered
  2. 2Vague assumption
  3. 3Partially mapped
  4. 4Mapped for key contracts
  5. 5Mapped and priced

At the low end: If you cannot say which contract carries an AI-caused loss, you are exposed everywhere by default. Map your top few contract types against the AI outputs that feed them, starting with the highest-value customers. What good looks like: Mapped and priced liability turns AI risk into a number you can manage rather than a surprise. Revisit it when contract terms or AI use change; a map of last year's contracts protects last year's business.

Insurance actually covers it

  1. 1Never asked
  2. 2Assume covered
  3. 3Reviewing with broker
  4. 4Confirmed partial cover
  5. 5Confirmed, AI-specific cover

At the low end: An AI loss against an untested policy is a claim you may discover is uninsured at the worst moment. Ask your broker directly whether AI-caused errors are covered, and get the answer in writing. What good looks like: Confirmed, AI-specific cover means one whole category of risk is genuinely transferred. Re-check it at each renewal; AI exclusions are being added to policies faster than most buyers notice.

Vendors carry their share

  1. 1Never checked
  2. 2Vendor terms as-is
  3. 3Read, not negotiated
  4. 4Some indemnities secured
  5. 5Indemnities negotiated in

At the low end: Accepting vendor AI terms unread usually means accepting all the risk for a fraction of the value. Read the liability and indemnity clauses on your main AI vendors before the next renewal. What good looks like: Negotiated indemnities mean the party who built the model shares the cost when it fails. Keep checking new AI purchases; vendors reset liability to their favour in every fresh contract.

Customers were told

  1. 1No disclosure
  2. 2Buried in terms
  3. 3Generic disclaimer
  4. 4Clear on key outputs
  5. 5Clear and legally reviewed

At the low end: No disclosure leaves you defending both the error and the silence about how it was made. Add a clear statement where AI materially shapes a customer-facing output, and have legal confirm the wording. What good looks like: Clear, reviewed disclosure on the outputs that matter is both a legal shield and a trust signal. Keep it accurate as your AI use changes; a disclaimer that no longer describes reality can hurt more than none.

The bad day is modelled

  1. 1Never estimated
  2. 2Gut feel only
  3. 3Rough single scenario
  4. 4Modelled key scenarios
  5. 5Modelled and stress-tested

At the low end: Without a cost estimate, every decision about AI risk is being made blind. Sketch your most plausible bad-day scenario and put a number on it; even a rough figure changes how seriously the risk is treated. What good looks like: Modelled and stress-tested scenarios let you size coverage and controls against reality. Refresh the model as AI reaches higher-stakes decisions; the worst realistic case grows with the scope.