Chief executives face potential lawsuits as insurers restrict coverage and regulators assess responsibility for software-related harms.
In light of the agentic AI breaches of numerous web properties, insurers and lawyers are preparing for potentially multimillion-dollar claims arising from software agents that act beyond their developers’ intended controls.
The debate could extend liability beyond AI firms to their senior executives, including OpenAI CEO Sam Altman and Anthropic CEO Dario Amodei, although no court has yet ruled that an AI developer’s leaders are personally responsible for an agent’s actions, according to an analysis by The Decoder.
Tim Rayner, Verisk’s UK head of claims, has told the Financial Times that responsibility for the Hugging Face breach incident ultimately rests with OpenAI’s CEO because of an alleged lack of control within the business. Rayner’s argument is that chief executives remain responsible for ensuring proper corporate oversight, even when an AI system acts autonomously.
The potential insurance implications are broad:
- Aon has examined more than 300 AI-related disputes and identified possible exposure under crime, intellectual-property, cybersecurity and technology errors-and-omissions policies. Claims involving management failures could also fall under directors-and-officers insurance, which may cover executives facing lawsuits over corporate decisions or governance, according to one news source.
- At insurer Stewarts, Aaron LeMarquer, head of insurance disputes, has said shareholders could sue directors if they could show that inadequate risk management caused losses. He expects AI litigation to develop along lines seen in earlier disputes involving pollution, tobacco and pharmaceuticals. However, there is currently no case law establishing that executives are liable for an AI system’s conduct.
- On 29 September 2026, the non-profit Legal Advocates for Safe Science and Technology had filed a lawsuit in San Francisco Superior Court against OpenAI. The complaint cites a state AI law that says it is not a defense that a system caused harm independently. OpenAI spokesperson Drew Pusateri has called the case “completely without merit”, according to Cyber magazine.
Cyber insurers start restricting coverage
- The Insurance Services Office (now under Verisk) has begun issuing AI-specific exclusions, while carriers are also using sub-limits and application questions to restrict coverage.
- Attorneys at Pryor Cashman have warned that policyholders may discover only after a loss that protection they assumed they had was reduced or removed.
The market is therefore confronting two unresolved questions: who is legally responsible when an autonomous agent causes harm, and which policy — if any — must respond. Claims could involve multiple forms of insurance, while insurers are increasingly addressing uncertainty through exclusions rather than broader coverage.
