In this episode, Ellie Ruiz and Emily McMahan explain why AI is now a board-level governance issue. Directors and officers liability depends on how boards authorize, oversee, and document AI use – not on AI’s mistakes alone. They discuss the risks of moving too fast or too slow with AI adoption, the threat of AI-related securities claims, and how regulatory fragmentation complicates compliance for multinational companies. They also examine how AI-related scenarios are testing traditional D&O insurance policies, and why boards should stress-test their coverage now.

Transcript:

Ellie: Hello and welcome back to Insured Success, the Reed Smith Insurance Recovery Group podcast. I'm Ellie Ruiz, and with me today is Emily McMahon. We're both part of the Reed Smith Insurance Recovery Group in London. Emily, it's really great to have you here. We've got a highly topical episode today. We're talking about AI through the lens of directors and officers liability and D&O cover with an eye on potential future claims.

Emily: Thanks, Ellie.

Ellie: It goes without saying these days, AI is not just an IT risk, it's becoming a boardroom governance, it's a disclosure and regulatory issue, and all of that adds up to make it a D&O issue.

Emily: Yeah, exactly, Ellie. The real question isn't whether an AI system produces a bad output. It's how that output becomes a D&O exposure. So today's episode, we will cover why AI risk is a D&O risk, how D&O policies may respond to that AI risk, and we'll give you some takeaways for our listeners on what they should be doing now to ensure AI risk is sufficiently covered.

Ellie: Kicking off first, I think it's fair to say we can't just be looking at AI risk from any perspective as just a subset of cyber risk, which is how it might have come into most people's sphere first time around. It absolutely sits alongside those cyber exposures, but it's a distinct risk. And it brings into play potential governance failures, strategic missteps, questions about model performance and regulatory non compliance.

Emily: And those categories map naturally onto D&O exposure, including claims alleging negligent oversight, defective AI disclosure, inadequate supervision of automated decisions, or a failure to meet regulatory obligations.

Ellie: I think you can really see how those competing concerns can then amount to quite a significant dilemma for a board. You've got boards that are facing real pressure to adopt AI quickly, but are conscious that they are risking claims exposure if they're deploying AI without proper controls. If you move too fast, there's a risk of errors, there's a risk of bias, misleading statements. But if you move too slowly, then the business loses competitive ground. So damned if you do, damned if you don't.

Emily: Yeah, exactly. It's the classic hindsight problem. Directors don't need to always be right here, but they do need to demonstrate a process where they considered alternatives, they escalated risks, and they recorded their reasons for doing so.

Ellie: As a result, I think it will come as no surprise if you're listening to two lawyers on a podcast that we're always recommending meeting minutes, governance records, all of that becomes central to board processes in respect of any AI-related discussions. For us, it's documenting those AI decisions that helps to protect policyholders, protect our clients against hindsight driven allegations really that can be made either by claimants or can be brought up by insurers in an insurance claim context.

Emily: Exactly. And as Ellie said, for lawyers, that means AI governance can't be an abstract policy document. It needs to hold up as evidence in litigation or regulatory investigation, which shows which systems mattered, who owned them, what testing occurred, and how those risks were escalated. And here, the duty of care point is important, too. Directors who cannot demonstrate a good understanding of their AI tools that they deploy in their organizations may struggle to satisfy that duty of care. And that's not a theoretical risk. Regulatory trends and early US securities class actions already show real consequences for directors who don't engage meaningfully with AI oversight.

Ellie: Yeah, you're absolutely right. One example we often go to is a say a company is making public statements about its AI tools reliability or its commercial value, only for that technology to then underperform, you've got investors who then might want to allege that the board itself has been overstating the reliability or has failed to disclose what might have been known limitations.

Emily: Yeah, and there's also a regulatory dimension. The US currently has a somewhat fragmented sector-specific AI landscape shaped by executive orders, FTC enforcement, and state legislation. And that fragmentation matters for multinationals. A single global AI policy may not suffice across jurisdictions, and the EU's more prescriptive approach so far can create further gaps between those frameworks. So for D&O purposes, it's not just the risk of sanction. Regulatory scrutiny can trigger follow on litigation, reputational damage, and shareholder claims.

Ellie: I'm sure it comes as no surprise to anyone, and the fact that we're talking about this today, AI is a dominant theme across the insurance industry right now. And so it's already shaping risk management, it's shaping market analysis. Interestingly, I think both Emily and I have experienced the commentary that we're seeing suggesting there's a real concern that in the UK we're risking potentially falling behind in a rapid response to AI-driven change. And that came through clearly at an EMIC seminar that we attended recently, featuring Dr. Keith Dear, who's a CEO of AI Startup Cassie and a former advisor to the Prime Minister on Defense and Technology. He gave what felt like a fairly stark warning that society still hasn't grasped the scale of the change. He put across that AI can be both simultaneously underhyped and underestimated. It's one of those major geopolitical forces where you have to be looking at risks that are as significant as the opportunities.

Emily: Yeah, exactly, Ellie. And he also noted that the US market in this case is moving faster, arguably, both in AI adoption and in the insurance markets response. So for the UK audience, he identified three takeaways to bridge this gap. First was modernize underwriting and claims processes, review policy wordings urgently for fitness in an AI enabled world, and build that internal AI literacy because not using AI at all is itself a key risk.

Ellie: Yeah, the big question I don't think the big question anymore is whether AI is going to transform risk and insurance. It just already has. The real question that I came away with that we've been discussing for the UK is whether that emerging gap between the UK and other markets can be closed before it becomes a real competitive disadvantage when you're looking at other insurance markets.

Emily: Thanks, Ellie. So let's focus now on these insurance policies themselves. The central question to consider is whether traditional D&O wordings are ready for these AI-related claims. So for example, Ellie, do you think wrongful acts definitions capture negligent oversight right now?

Ellie: Yes. I think that one's probably one we'd be more comfortable with. Yes, we would expect them to, obviously wording specific.

Emily: Great. Good to know. And what about investigations? Do you think they fall within insured proceedings?

Ellie: That is maybe one that more depends on the precise wording of any policy. Broad scope, yes, investigations into the use of AI can fall within insured proceedings. The question, I suppose, is whether investigation captures often how these things originate is early stage sort of self-initiated review amongst organizations that are well aware of the risks. And I think it's worth knowing at what point from an insurance perspective, defense costs advancement becomes available as well. It's often the case that a forensic investigation into an AI incident has the potential to become very costly very quickly. So that available insurance cover is going to matter.

Emily: No, that's a good point. And on another point, do you think insurers will seek to characterize those AI losses as operational failures, which maybe arguably are better suited to technology E&O cover?

Ellie: It's an interesting one. I think AI claims often can have very mixed characteristics. They involve board oversight alongside product performance, they can involve cyber events or discrimination or IP infringement, and it's going to be on a case-by-case basis the balance of those factors that determines which of your suite of policies maybe should respond. So to try and give some examples, a claim around misleading AI disclosures might look more like classic D&O, whereas a customer claim over a defective output potentially is heading more in the direction of technology E&O. And then something like an algorithmic discrimination investigation, that might sit somewhere between the two and be a little bit more difficult to categorize.

Emily: Exactly. And the insurer's characterization of that matters as well. Frame it as board level oversight and D&O cover engages, but frame it as an operational or technology failure, and insurers may argue another line should respond, or that exclusions apply.

Ellie: That's a really great way of putting it. I think in each example, it's the policy wording that's going to matter, including if we go back to your original questions, does the claim actually allege a covered wrongful act? Are investigation costs and the advanced defense costs available? And are there other policies which are potentially competing for cover? If there are multiple policies that do potentially offer cover, is there a priority order in which a policyholder has to approach them? That's why we'd say brokers, coverage counsel, like Reed Smith, risk managers, get them all involved before a claim actually arises. That just helps our policyholder clients to be confident that they've purchased truly comprehensive cover. As a first step, it's why the quality of AI governance matters both before and after a claim. And if that's just known to affect insurer appetite for cover, it affects limits, it affects pricing at placement. And then you're looking at if things like causation exclusions in particular, I think will come up for a lot of discussion around placement and renewal. It's all related to the insured's account of their oversight of the product.

Emily: Exactly. And that also applies when you think about the duty of fair presentation on placement and at renewal. While this technology is novel, the general premise remains the same that any disclosure in respect of what the technology can achieve, how secure it is, or how it might be valued, needs to be accurate and properly understood by insurers. And, you know, if not, a policyholder could face allegations from insurers of misleading or inaccurate disclosure and presentation of the risk. So given how quickly AI use is expanding within organizations, there is a real risk that a proposal form completed even a year ago no longer reflects this reality. If disclosure is not made properly, or if there's found to have been deliberate or reckless non-disclosure, the policyholder could face remedies up to and including avoidance of that policy. So from a policyholder perspective, this disclosure exercise should be revisited specifically for AI at every annual renewal.

Ellie: Yep, it's going to just become the norm before a risk arises to have mapped a business's AI risk across the entire insurance program. And also to conduct what are known in the industry as stress tests. So there's D&O, which we've spent more time on today, and that is one part of it, but also cyber cover, technology E&O and other lines of cover may also respond depending on the facts. Policy language is best interrogated now. Interrogate it as early as you can. It enables policyholders to determine how something like claim or something like wrongful act might be defined, and go through all the relevant exclusions and identify which of those might be invoked in the context of an AI claim. For example, a typical D&O policy might well include a standard cyber related exclusion. That's fairly common across the board, particularly in policies placed a few years ago. And it's really interesting to look at how that might interact with, for example, an AI-enabled cyber attack. That's not an uncommon way in which AI might be deployed against a business. Policyholders generally we're advising to resist really broad exclusions. Anything that's drafted with the potential to capture too much in the way of routine automated procedures that may now be predominantly governed by AI. Always advisable, and I think this is something that doesn't actually stand specifically in the context of AI, but just always advisable to seek clarity and if it's beneficial, agree sublimits rather than accepting silence or ambiguity on something as difficult to wrap your arms around as AI in the business.

Emily: No, exactly. And good point. Picking up on what you were talking about in relation to stress testing, a useful stress test should identify which policy responds to which part of the loss. For example, whether investigation costs and side A protection are adequate and how those exclusions interact. Another specific example, an exclusion aimed at traditional cyber events should not be inadvertently sweeping up an AI governance failure, which as you mentioned earlier, could also have a cyber element. So the board should consider whether it can evidence the board level governance rather than just the pure operational failure here.

Ellie: That kind of analysis, it can include how an AI failure might unfold. They often unfold as a sort of series of related events. And that takes us inevitably in the context of an insurance discussion as to how the policy's aggregation language might operate. Likely to be a point of some significance, I think, in most AI-related claims, determining whether incidents are going to be treated as one claim with one limit and one deductible or multiple. And given the circumstances, typically insurers and policyholders will sit on opposite sides of that line. From a governance side, I think it's also worth giving some consideration as to whether AI risk is currently sitting with the right committee. Its prevalence in everything the business is doing these days means that it needs to be sat somewhere where the people responsible will have sufficient information, they have sufficient technical expertise and above all else, decisions need to be being documented in a way that's going to make sense to the relevant regulators. And if it gets there, to a court.

Emily: Thanks, Ellie. So if we're leaving the audience today with some practical takeaways and questions to address, what might they be? I'm thinking first is the AI governance framework sufficiently robust to withstand regulatory scrutiny and shareholder challenge.

Ellie: Hundred percent agree. My top choice might be, I've mentioned it already a couple of times over the course of this discussion, but is your board documenting its AI decision making in a way that protects against the risk of those hindsight driven claims we've mentioned? It protects against allegations you're moving too quickly, too slowly, or any misunderstanding about how that technology is expected to operate.

Emily: Yeah, no, really good point. And I would say maybe the last would be asking whether the D&O program or just the wider insurance program at your organization has been stress tested against these AI specific scenarios that we've touched on today. As a reminder, that includes regulatory investigations, algorithmic discrimination, intellectual property infringement, and litigation arising from AI related disclosures.

Ellie: None of this, to be clear, is meant to be overly intimidating. We are definitely not suggesting that directors ought to suddenly become AI engineers. But it is important, and I think directors and boards do need to be asking disciplined governance questions about AI. It's important to understand the material systems, their limitations, and the controls. That is going to be a big part of satisfying the requirement of insurers when cover's being placed.

Emily: Yeah, and the reality is that AI risk will not always fit neatly into existing lines of cover. So the work needs to be done now to identify where D&O cover responds, where other policies respond, and where gaps may emerge so they can be addressed.

Ellie: Yeah. If you're thinking about how AI is first going to appear in an insurance context, that first claim, the question just isn't going to be, was AI risky in the abstract? We all know there are risks around how AI is being deployed and how quickly it's developing. The question for a board is going to be what did the board know? What did the board ask? What did the board record? Which all feeds into, then, what did it do next? And ultimately, did you have an insurance program in place that was structured to respond to this?

Emily: Yeah, exactly. So I think that's a good place to leave it today. Thank you again, Ellie, and obviously to our listeners, thank you for joining us. The Reed Smith Insurance Recovery Group is always here to assist, so please don't hesitate to reach out.

Ellie: Thanks very much.

Outro: Insured Success is a Reed Smith production. Our producers are Shannon Ryan, Amanda Saunders, and Mason Kautz. To learn more about Reed Smith's Insurance Recovery Group, please contact [email protected]. You can find our podcast on podcast streaming platforms, reedsmith.com and our social media accounts at Reed Smith LLP.

Disclaimer: This podcast is provided for educational purposes. It does not constitute legal advice and is not intended to establish an attorney-client relationship, nor is it intended to suggest or establish standards of care applicable to particular lawyers in any given situation. Prior results do not guarantee a similar outcome. Any views, opinions, or comments made by any external guest speaker are not to be attributed to Reed Smith LLP or its individual lawyers. 

All rights reserved. 

Transcript is auto-generated.

Related Insights