---
title: "Professional indemnity insurance and AI: zero hits"
author: Marc Diks
date: 2026-07-22
modified: 2026-07-22
category: AI & Insurance
reading_time: 12 min
url: https://www.marcdiks.nl/en/blog/professional-indemnity-insurance-ai
canonical: https://www.marcdiks.nl/en/blog/professional-indemnity-insurance-ai
language: en
---

# Professional indemnity insurance and AI: zero hits
> **TL;DR**
>
> - **None of the nine professional indemnity policies I checked mention AI.** Not as a covered risk, not as an exclusion — the fault definition is technology-neutral, so an AI error falls under ordinary cover in principle.
> - **Three old exclusions can still break your AI claim.** Promised results, IP infringement in AI-generated content, and the cost of redoing AI-produced work are excluded in almost every policy.
> - **Silent cyber shows how this ends.** Insurers stayed silent on cyber risk for years, until Lloyd's forced the market in 2019 to explicitly confirm or exclude cover — silent AI is following the same pattern.
> - **The EU AI Act's oversight requirements have been delayed to December 2, 2027.** An omnibus deal by the Council and the European Parliament pushed back the high-risk obligations; only the transparency duty still takes effect on August 2, 2026.
> - **Call your broker this month.** Ask for written confirmation of cover for your AI use, while the silence still works in your favour.

Article 14 of the EU AI Act requires human oversight of high-risk AI systems. That obligation was set to take effect on August 2, 2026, until the Council and the European Parliament finalised an omnibus deal this summer that delays the high-risk obligations to December 2, 2027, and to August 2, 2028 for AI embedded in regulated products. What does still take effect on August 2, 2026: the transparency duty — people must know when they're dealing with an AI system.

I went looking for that requirement in nine professional indemnity policies. Zero insurers mention it. Zero even mention the word AI.

## Nine policies, zero mentions of AI

This week I searched the current policy terms of nine insurers offering professional indemnity insurance in the Netherlands. The names: Nationale-Nederlanden, Centraal Beheer, a.s.r., Allianz, HDI Global, AIG, Hiscox, Chubb and Turien & Co. I searched for eight terms: artificial intelligence, AI, algorithm, chatbot, generative AI, automated decision, and machine learning.

The result: not a single policy mentions AI. Not as a covered risk, not as an exclusion, not as a condition. The only near-hit across hundreds of pages of terms is in [AIG's](https://www.aiginsurance.nl/content/dam/aig/emea/netherlands/documents/documenten-toolkit/nl-finba-10100523-algemenevoorwaarden.pdf) policy, where the word "automated" appears. But that refers to data subjects' rights around automated decision-making under GDPR, not to coverage.

What you do find everywhere is a fault definition that's decades old. [Allianz](https://www.allianz.nl/content/dam/onemarketing/benelu/allianz-nl/local/s/S1680.pdf) describes a professional error as "any negligence, mistake, omission, wrongful act, carelessness and the like." Not a word about the tool used to make that error. A calculation mistake in Excel, a bad piece of advice from memory, or a wrong answer from a chatbot: to the policy, it's all the same thing.

That silence isn't policy. It's a backlog.

## Why your AI error is probably covered anyway

Back to basics for a moment. Professional indemnity insurance covers pure financial loss: financial damage a client suffers because of an error in your professional work, without anything being broken or anyone being hurt. The wrong tax advice, the missed deadline, the miscalculation.

For the law and for your client, it doesn't matter whether that error came from your own pen or from an AI tool. You delivered the advice, you're liable. Legally, AI is just a tool, no different from your spreadsheet. And because the fault definition in every policy I checked is technology-neutral, an AI error falls under cover in principle. Did you use ChatGPT for client advice and copy a wrong answer without checking it? That's negligence or carelessness — precisely what you're insured for.

That's strikingly good news, because the conventional narrative is gloomier. Search this topic and you mostly find lawyers and advisors warning about an "AI insurance gap." The policy terms themselves say the opposite: there's no AI gap, there's AI silence. And that silence works in your favour, because insurers haven't committed to any exclusion anywhere.

But note the phrase "in principle." The cover is implicit, not explicit. No insurer has confirmed this in writing, and in a dispute the burden of proof sits with you: you have to demonstrate that your AI error is an ordinary professional error. Which brings me to the part that will actually decide a real claim.

## Three old clauses that can break your AI claim

If your AI makes a mistake and your client claims, the discussion with the insurer won't be about AI. It'll be about three generic exclusions found in nearly every policy I checked, written long before language models existed. That's exactly where the fights will happen.

### 1. The results your AI tool promised

Almost every professional indemnity policy excludes liability for promised results or guaranteed returns. At Nationale-Nederlanden that's article 5.11, at Allianz article 4.17, at HDI article 4.12.

Now the AI scenario. You run an advisory firm and deploy an AI analytics tool. Your website or your proposal states that your approach "predictably delivers 30% higher returns," because that's what your dashboard says. The client doesn't hit that number and claims the difference. The insurer points to the exclusion: this isn't a professional error, it's a broken guarantee, and guarantees are excluded.

The discussion will turn on whether your promise was a best-efforts obligation or a results obligation. That's a classic legal distinction, but AI makes it more toxic. AI tools present their output with numerical confidence: percentages, forecasts, scores. Anyone who copies that confidence straight into a proposal unknowingly turns advice into a guarantee. And a guarantee falls outside your cover.

### 2. Content that turns out not to be yours

Almost every policy also excludes infringement of intellectual property. Nationale-Nederlanden article 5.8, Allianz article 4.9, HDI article 4.5. At Turien the exclusion is limited to intentional infringement, which just shows how differently these old clauses can play out on the same AI scenario. At a.s.r. it goes even further: according to the official [insurance fact sheet](https://verzekeringskaarten.nl/asr/aansprakelijkheidverzekering-voor-bedrijven.pdf), the professional indemnity cover isn't even suitable for businesses advising on intellectual property law.

The AI scenario is obvious. You produce a campaign for a client using images and text from a generative AI tool. A photographer or publisher recognises their work in the output and holds the client liable, who passes the damage on to you. Is that a professional error (covered) or an IP infringement (excluded)?

This is where the discussion gets genuinely nasty, because both readings are defensible. You'll argue you were careless in your review — a classic professional error. The insurer will argue the core of the claim is copyright infringement, categorically excluded. As long as courts are still wrestling with the question of who actually owns AI output, the outcome of that discussion is unpredictable. What we do know: the bill for that uncertainty lands on you, not the insurer.

### 3. The work that has to be redone

The third clause is the least well-known, and perhaps the most dangerous for AI users: the exclusion of costs for redoing work. At Nationale-Nederlanden article 5.13, at Turien article 4.9. The logic behind it is reasonable: your insurer pays for the damage your client suffers because of your error, not for redoing your own substandard work. That's simply your own business risk.

The AI scenario: you deliver a report, a calculation, or a software integration that was largely generated by AI. The client discovers errors, the work has to be redone completely, and in the meantime the client made decisions based on the flawed version. The damage from those decisions is probably covered. The cost of redoing the work isn't. Turien says it explicitly: the cost of redoing work is excluded, consequential damage to third parties is covered.

The discussion will be about the line between the two. Where does "fixing your own work" end and "consequential damage to the client" begin? That boundary was always tricky, but AI makes the problem bigger, because AI makes producing large volumes of output cheap. The more work you produce with AI, the larger the share of a claim that can fall into the "redo" category. And that share you pay yourself.

### The question hanging over all three

Each of these discussions carries one more layer: how did you check your AI? Not a single policy I checked requires human oversight of AI use. But assessing a claim always comes down to concepts like negligence and diligence, and that question sneaks back in there anyway. The business owner who can show that a human reviewed the AI output before it reached the client stands stronger in every discussion than the one who has to admit the output went out unchecked.

## Silent AI: how the previous silence ended

We've seen this pattern before, and I experienced it up close in the insurance market. For years, traditional policies stayed silent on cyber risk. No cover, no exclusion, just silence. The market called it "silent cyber": cyber damage that quietly rode along on fire and professional indemnity policies never designed for it.

That silence didn't end voluntarily. In 2019, Lloyd's of London stepped in and [forced the entire market](https://www.reinsurancene.ws/lloyds-details-phased-implementation-of-silent-cyber-mandate/) to take a position. In phases, starting January 1, 2020, every policy had to make explicit whether cyber was covered or not. Confirm or exclude — silence was no longer allowed. Law firm [Allens](https://www.allens.com.au/insights-news/insights/2022/11/when-silence-is-no-longer-golden-the-demise-of-silent-cyber-and-the-need-for-dedicated-cyber-insurance/) describes what followed in dry terms: the global insurance market subsequently excluded cyber from almost all standard policies, often with clauses that weren't negotiable at renewal.

Replace "cyber" with "AI" and you're looking at the next three years. The silence in today's professional indemnity terms is silent AI, and the first move has already happened. Hiscox now runs an [AI clause](https://www.hiscox.nl/beroepsaansprakelijkheid-ai) on its Dutch site confirming that AI activities are assessed within the scope of existing covered activities. Note the wording: confirming, not expanding. This is exactly how it started with cyber, with reassuring clarifications. Then came the underwriting questionnaires, then premium differentiation, and finally the exclusions for anyone who didn't meet the conditions.

My prediction: within three years, every major Dutch professional indemnity policy will carry an AI clause. The only question is whether yours confirms cover or excludes it.

I can hear you thinking: if cover is implicit already, why rush? Because policy terms aren't forever. Insurers can amend terms at renewal, and as soon as the first major AI losses ripple through the market, they will. Business owners who've already gotten it in writing how their AI use falls under cover will negotiate from a very different position than those who left it to the silence.

## The law demands oversight, your policy doesn't ask for it

There's a second reason not to put this off, and it's written into the law. [Article 14 of the EU AI Act](https://artificialintelligenceact.eu/article/14/) requires that high-risk AI systems operate under effective human oversight. That obligation was originally set to take effect on August 2, 2026. After a political agreement on May 7, 2026 and [final approval by the Council on June 29, 2026](https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/), its application has been delayed to December 2, 2027, and to August 2, 2028 for AI embedded in products already covered by existing EU safety rules. On August 2, 2026 itself, it's mainly the transparency duty that takes effect, not the oversight duty. Use AI for, say, recruitment and selection or credit assessment, and under the new timeline you'll still fall under the oversight requirement once it arrives. I wrote earlier about the broader training obligation under the AI Act in [my post on the AI training obligation](/en/blog/ai-training-obligation-2026).

That delay doesn't change the core of this story, it just postpones it. Even the legislator had to push back its own AI-oversight deadline by sixteen months. Don't expect your insurer to move substantially faster with an AI clause of its own.

See the mismatch? The legislator requires human oversight of AI. None of the nine insurers asks about it in their terms. You could read that as freedom: the policy sets no requirements, so I don't have to do anything. I read it as a vacuum that will get filled from two directions at once. The regulator asking how your human oversight is organised, and the claims handler asking, during a claim, who reviewed the AI output. Whoever has no answer to either question stands weak twice over. That oversight, by the way, doesn't start with your tools but with your board — a point I made earlier in [my post on AI oversight in the supervisory board](/en/blog/the-empty-chair-ai-oversight-supervisory-board).

Organised oversight is also not bureaucracy — it's evidence. A fixed second-pair-of-eyes moment for AI output going to clients, and a brief log of who checked what. That's all it needs to be for an SME. But in a claim, that's the difference between being able to show you work carefully with AI, or only being able to claim it.

## What to arrange with your broker this week

The question isn't whether you're insured. The question is whether you can prove it later, at the moment a claims handler looks critically at your AI use. So my advice is simple: call your broker. Not next quarter — this month, while the silence in the terms still works in your favour. Four points for that conversation:

- **Report your AI use and ask for written confirmation.** Describe concretely what you use AI for and ask your broker to get the insurer to confirm that errors from that use fall under the fault definition. An email is enough. Paper beats silence, even favourable silence.
- **Walk the three exclusions against your own practice.** Check whether your proposals contain results promises that actually come from an AI dashboard. Then check whether you deliver AI-generated content to clients, and how large a share of your work would have to be fully redone in case of an error. Those are the three places where your claim can run aground.
- **Document your human oversight.** Agree internally who reviews AI output before it goes to a client, and log it briefly. It helps you with your insurer and with the EU AI Act.
- **Ask your broker to monitor the terms.** AI clauses are coming, first confirming, then restricting. Agree that you'll get a heads-up the moment your insurer changes its terms on this point, so you can switch or adjust before an exclusion quietly slides into your policy.

The oversight requirements for high-risk AI have been delayed to December 2027, but the zero hits from my search will stay in place for a while after that — just not forever. Silent cyber lasted years and was then over within two, and that zero in the policy terms isn't reassurance. It's a countdown, even if the statutory alarm clock has been set a little later than it first was.

## Sources

- Policy terms reviewed: [Nationale-Nederlanden, model M 03.2.29 C](https://www.nn.nl/Download/Voorwaarden-M-03.2.29-C-Beroepsaansprakelijkheidsverzekering-DL273840.1901.htm), [Centraal Beheer 251-RV-35-AVB-C](https://www.centraalbeheer.nl/-/media/files/zakelijk/polisvoorwaarden/251-rv-35-avb-c-cbb-bedrijfsaansprakelijkheidsverzekering-beroepsaansprakelijkheid.pdf), [a.s.r. AVB 2024-01](https://www.chabotassuradeuren.nl/download.asp?guid=E3B04E31-4F90-40A7-A1BB-C27BBE259BBA), [Allianz S1680](https://www.allianz.nl/content/dam/onemarketing/benelu/allianz-nl/local/s/S1680.pdf), [HDI BAV.AV.2.S](https://www.hdi.global/globalassets/_local/europe/nl-nl/downloads/specialty/professional-indemnity/voorwaarden-bav.av.2.s.pdf), [AIG BA 2021](https://www.aiginsurance.nl/content/dam/aig/emea/netherlands/documents/documenten-toolkit/nl-finba-10100523-algemenevoorwaarden.pdf), [Hiscox MPH-2013B](https://media.insify.com/nl/2025/Voorwaarden_Beroepsaansprakelijkheidsverzekering_BAVa-H_LEGAL.pdf), [Chubb Pro Advocaten 2.0](https://www.chubb.com/content/dam/chubb-sites/chubb-com/international/netherlands/ChubbProAdvocaten2.0.pdf), [Turien & Co. / CNA Model 032019](https://mijnturien.nl/media/1911/ba-cna-2016-adv.pdf) and [Klaverblad SME liability](https://www.klaverblad.nl/aansprakelijkheidsverzekering-mkb).
- Hiscox on AI within professional indemnity cover, including the AI clause: [hiscox.nl](https://www.hiscox.nl/beroepsaansprakelijkheid-ai)
- Lloyd's silent cyber mandate and its phased rollout from January 1, 2020: [reinsurancene.ws](https://www.reinsurancene.ws/lloyds-details-phased-implementation-of-silent-cyber-mandate/)
- Text of Article 14 of the EU AI Act on human oversight: [artificialintelligenceact.eu](https://artificialintelligenceact.eu/article/14/)
- Final approval of the delay to high-risk obligations (December 2, 2027 / August 2, 2028): [Council of the EU, press release June 29, 2026](https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/)
- a.s.r. insurance fact sheet for business liability insurance: [verzekeringskaarten.nl](https://verzekeringskaarten.nl/asr/aansprakelijkheidverzekering-voor-bedrijven.pdf)