The Safety Net With a Hole Cut In IT: AI Mistakes
Your insurer has quietly stopped covering AI mistakes. Your AI vendor never started. Welcome to the gap where your money lives.
There is a particular species of comfort that comes from believing you are insured. You sign the contract, you file the policy in the drawer marked "things I shall never read again," and you sleep the sleep of the covered. Somewhere out there, you assume, is a safety net. Should you fall, it will catch you, possibly with a stern letter and an excess, but it will catch you.
I am here, with some reluctance, to tell you about the hole.
Because somewhere between 2025 and 2026, while everyone was busy asking their new AI tools to write their emails and summarise their board packs, the people who sell insurance did something rather quiet and rather clever. They looked at this exciting new world of machines that confidently invent things, and they reached for a pair of scissors. Across commercial general liability, professional indemnity, cyber, the lot, insurers began stitching in AI-specific exclusions. The net is still there. It still looks like a net. It simply now has a hole in the exact spot where you are most likely to land.
The net is still there. It still looks like a net. It simply now has a hole in the precise spot where you are most likely to land.
And here is the part that turns a mild inconvenience into a genuine problem. When your own insurance backs away, there is, in theory, a second net. The indemnity from the AI vendor. The clause where the supplier promises that if their clever machine causes you grief, they will make it good. Surely, you think, that will catch me.
Reader, I invite you to read that clause.
What the vendor actually promised (and what it very much did not)
Here is what most AI vendor contracts do promise, and it is worth giving them credit for it. They will typically indemnify you against third-party intellectual property claims arising from the model's output. If the machine coughs up something that infringes somebody's copyright and that somebody comes after you, the better vendors will step in. Good. That is a real protection and it exists because the vendors were, quite reasonably, terrified of exactly that lawsuit.
Now here is what those same contracts do not promise, expressed with the kind of surgical precision that should make you sit up. The vendor's terms almost always exclude liability for the accuracy, completeness or reliability of the output itself. Which is a long and lawyerly way of saying: if the machine is simply, confidently, catastrophically wrong, that is not their problem. That is yours.
Pause on the elegance of this for a moment, because it deserves appreciation in the way a beautifully executed pickpocketing deserves appreciation. The one thing generative AI is famous for, the one behaviour that has launched a thousand cautionary LinkedIn posts, is that it hallucinates. It makes things up. It cites cases that never existed and quotes statistics it dreamed over lunch. And that behaviour, the signature failure mode of the entire technology, is the precise thing the indemnity is drafted to step around.
So let us line the two nets up next to each other. Your insurer: "We don't cover AI errors." Your vendor: "We don't cover AI errors either." You, in the middle, holding a tool whose entire personality is errors, having signed both documents believing each one had your back.
Your insurer will not catch the hallucination. Your vendor drafted their indemnity specifically so they need not either. You are the net.
A short, true story about a chatbot and an airline
If this all sounds theoretical, allow me to introduce the case that lawyers now cite the way parents cite cautionary tales about hot stoves. An airline deployed a customer-service chatbot. The chatbot, doing its confident best, told a grieving customer about a bereavement fare policy. The policy it described did not, strictly speaking, exist. The customer relied on it. When the airline tried the now-legendary defence that the chatbot was, and I paraphrase only slightly, a separate legal entity responsible for its own statements, the tribunal was unmoved. The company was liable for what its machine said. All of it. Static page or chatbot, it was all the airline's website, and therefore all the airline's problem.
The lesson landed across boardrooms with a thud: you own what your AI says. Not the vendor who built it. Not the model that spoke it. You. The entity whose logo sits above the chat window is the entity holding the bill.
Which brings us neatly, and slightly ominously, back to your contracts.
The four clauses standing between you and the floor
The good news, and there is some, is that a hole in a net is a fixable thing. You cannot make your insurer un-cut their exclusions, and you cannot make the vendor rewrite their standard terms out of the goodness of their heart. But you can negotiate. That is what contracts are. And there are four places where a business signing an AI deal in 2026 should be planting its flag.
Clause One
The standard indemnity covers third-party IP claims and stops there. Push for it to extend to losses arising from the output being wrong, not merely from it being someone else's. This is the single clause that addresses the hole directly, and it is the one vendors resist hardest, which tells you exactly how much it is worth.
Clause Two
Where did the model learn its trade, and what is the vendor doing with the prompts and data you feed it? If the model was trained on material it had no licence to use, your use of its output can pull you into a secondary infringement claim. And if the vendor reserves the right to train on your confidential inputs, you may be handing over the crown jewels in the small print.
Clause Three
The model you diligenced in January is not the model running in June. Vendors update, retrain and quietly retire versions. A contract written for stable software does not account for a supplier changing the product underneath you without a word. Build in notice rights, so the thing you bought does not silently become a different thing.
Clause Four
The rules here move like weather. The EU AI Act's high-risk obligations were pencilled in for August 2026, then the Digital Omnibus agreement moved the goalposts toward December 2027, and the ground may well shift again before you finish this sentence. A termination-for-convenience or renegotiation right, triggered when a new rule materially changes your cost or risk, is how you avoid being married to a use case that regulation has since made untenable.
None of these four is exotic. Every one of them is the kind of provision a boilerplate commercial contract drafted before 2025 simply does not contain, because in 2024 nobody was buying a product whose defining feature was the confident invention of facts. The templates have not caught up. The risk has.
The uncomfortable sentence to end on
Here is the thing I would want a fellow CEO or head of legal to take away, stripped of all the wit, because underneath the jokes this is a genuinely serious point. You are very probably operating right now on the assumption that you are covered, when the two documents you are relying on have each been carefully drafted to ensure you are not.
That is not a reason to panic, and it is certainly not a reason to unplug the AI, which has by now made itself far too useful to sack. It is a reason to read the contract before you sign the next one, and to have someone read the ones you have already signed. Because the cheapest possible moment to discover a hole in your safety net is now, on a Tuesday, with a coffee, and not eighteen months from now, mid-fall, wondering why nobody is catching you.
The net can be repaired. But somebody has to notice the hole first.
Have your AI vendor contract read by someone who reads the exclusions
RMOK Legal reviews commercial and AI contracts for a fixed fee from £400 plus VAT, confirmed before any work begins, handled personally by a senior solicitor. We read the clause the vendor hoped you would skip. Not sure where to start? Run your agreement through our free contract risk checker first.
Book a free discovery call →This article is general commentary on commercial and AI contracting in 2026 and is not legal advice. It does not create a solicitor-client relationship, and every contract turns on its specific wording and context. Regulatory timelines referred to, including the EU AI Act phasing and the Digital Omnibus agreement, were accurate at the time of writing and continue to change. For advice on your situation, speak to a qualified solicitor. RMOK Legal solicitors are authorised and regulated by the Solicitors Regulation Authority. For related reading, see our EU AI Act compliance guide and our commercial contract review service.

