/ 4 min read / Entertainment & Media Guide to AI: Three years on

Insurance implications of AI

Introduction

AI is now embedded in content development, advertising, rights management, audience analytics, and ordinary professional services. Insurance remains an important risk-transfer tool, but the rapid adoption of generative AI has made policy wording and risk controls more important. Companies should identify where AI is used, who supplies it, what data it processes, and who bears responsibility when the technology fails.

E&O

Errors and omissions (E&O) coverage generally addresses liability arising from mistakes in professional services. Generative AI increases that exposure because it can produce plausible but inaccurate information, reproduce outdated or biased data, or create work product that has not been adequately reviewed. In entertainment and media, examples include an AI-assisted rights-clearance report that omits a conflicting license, a marketing campaign built on fabricated audience data, or a production tool that inserts inaccurate factual material into published content.

Coverage may turn on whether the activity qualifies as a covered professional or media service and whether exclusions for intellectual property (IP), privacy, contractual liability, or intentional conduct apply. Human review, approved-use policies, vendor diligence, and records showing how outputs were verified can reduce loss and help demonstrate that an error was negligent rather than knowing.

CGL, media liability, and IP

Commercial general liability (CGL) “personal and advertising injury” coverage may respond to certain enumerated offenses, including some copyright or right-of-publicity claims connected to an insured’s advertising. But it should not be treated as comprehensive IP coverage. Many CGL forms contain broad IP exclusions, and coverage may depend on a close connection between the alleged infringement and an advertisement. Media liability and standalone IP policies may provide a better fit for companies whose core operations involve publishing, music, film, advertising, or licensing.

The legal landscape has also developed. In 2025, the U.S. Copyright Office concluded that purely AI-generated material is not copyrightable, although human-authored selection, arrangement, or modification may be protected. A federal court also rejected a fair-use defense in Thomson Reuters v. Ross Intelligence where copyrighted legal materials were used to build a competing AI product, illustrating that training-data disputes will be highly fact-specific.

Digital-replica risk is now more concrete. Tennessee’s ELVIS Act protects an individual’s voice as well as name, image, and likeness, while California laws restrict certain uses of digital replicas of living and deceased performers. Claims involving an unauthorized cloned voice, synthetic performer, or altered likeness may implicate media liability, CGL, IP, or specialty coverage, depending on the allegations and exclusions.

Cyber and privacy

AI systems can expose confidential information through prompts, retain personal data, and become targets for model manipulation, data poisoning, and AI-assisted cyberattacks. A cyber policy may respond when the loss involves a covered security failure, privacy event, extortion demand, or business interruption. It generally will not replace E&O or IP coverage for defective output, infringement, or loss of rights. Policyholders should confirm how their policies address data supplied to third-party AI vendors, voluntary disclosure of information, biometric or privacy claims, and incidents originating in an outsourced platform. 

D&O

Directors and Officers (D&O) exposure increasingly extends beyond the underlying technology to how management governs and describes it. In 2024, the Securities and Exchange Commission brought “AI washing” cases against two investment advisers for false and misleading claims about their AI use. Similar allegations against public companies could support securities, derivative, fiduciary-duty, or misrepresentation claims where AI capabilities, risks, or controls were inaccurately described.

Boards should understand material AI uses, assign oversight responsibility, and ensure that public statements are supported. D&O policies may provide important protection, but coverage may depend on such issues as the definition of a claim, conduct exclusions, insured-versus-insured provisions, and notice requirements.

Specialized coverage and practical review

The market now includes specialty products designed to address AI performance risk and certain third-party liabilities, in addition to standalone IP coverage. These products can be useful, but they may be narrow or conditioned on technical diligence and specified performance metrics.

Companies should review their insurance program alongside AI vendor contracts. Key questions include whether a policy covers first-party loss as well as third-party claims; infringement arising from training data and outputs; discrimination and digital-replica claims; regulatory investigations; contractual indemnities; and losses caused by model drift, hallucinations, or vendor failure. The most effective approach is coordinated: sound AI governance, clear contractual allocation of risk, and insurance tailored to the company’s actual uses.

Related Insights