What Can Go Wrong When a Business Deploys Generative AI? Five Liability Scenarios to Watch
- W. Tom Polowy, MS

- 9 hours ago
- 13 min read
Generative AI can draft customer responses, summarize documents, write marketing copy, analyze records, generate code, and support operational decisions. It can also create a liability problem faster than a business can identify what happened.
The important distinction is this: your business can face exposure even when another company developed the underlying AI model. If your company deploys the chatbot, publishes the output, relies on the recommendation, or connects the system to customer data, plaintiffs may focus on your conduct rather than the model developer’s conduct.
That risk applies to Connecticut businesses of every size. A Hartford professional-services firm, a Stamford technology company, a New Haven manufacturer, a Bridgeport distributor, and a regional business operating across New York, Massachusetts, Rhode Island, or New Jersey can all face similar questions after an AI-related incident:
Who approved the deployment?
What information did the system receive?
Who reviewed the output?
What warnings did customers receive?
What did the business know about the system’s limitations?
What evidence still exists?
Which insurance policy, if any, may respond?
Insurance does not replace responsible deployment. It also does not guarantee payment for every AI-related claim. Coverage depends on the policy language, the insured’s operations, the allegations, the timing of the claim, exclusions, endorsements, retentions, and the facts established during the investigation.
This guide examines five liability scenarios for businesses that deploy generative AI, not companies that develop the underlying models.
What does “deploying generative AI” mean?
A business deploys generative AI when it places an AI-enabled tool into use for internal operations, customer interactions, marketing, professional services, software development, manufacturing, or another business function.
Examples include:
A website chatbot that answers customer questions.
An internal tool that summarizes contracts or medical records.
An AI assistant that drafts customer service emails.
A marketing system that creates text, photographs, or video.
A coding assistant used to develop software.
An AI-connected system that recommends maintenance or production steps.
An automated workflow that uses AI output to approve, deny, route, or prioritize decisions.
A hallucination is an AI-generated response that presents false or misleading information as if it were accurate. The term is widely used in discussions of large language models, although some researchers prefer terms such as “fabrication” or “confabulation.” Wikipedia’s explanation of AI hallucinations provides useful background.
The legal issue is not simply whether the system made a mistake. The issue is whether the business used the output in a way that caused another person or organization to suffer harm.

Scenario 1: A chatbot gives false information and a customer relies on it
How the problem develops
A business launches a customer-facing chatbot to answer questions about pricing, refunds, delivery times, product specifications, service limitations, or contract terms.
The chatbot produces a confident but incorrect answer. A customer relies on that answer and suffers a financial loss.
Consider a Connecticut equipment supplier whose chatbot tells a customer that a specialized replacement component is compatible with an older machine. The customer orders the part, schedules an installation, and shuts down production while waiting. The component does not work. The customer claims lost revenue, installation costs, and the cost of repairing the equipment.
A similar problem can occur in professional services. An accounting firm may use AI to draft a response about a filing deadline. A consulting firm may use AI to summarize a regulatory requirement. A property manager may use AI to answer a tenant’s question about fees or maintenance obligations.
A disclaimer saying “AI can make mistakes” may help explain the system’s limitations, but it does not automatically eliminate responsibility for a misleading business communication.
Potential legal theories
A claimant may allege:
Negligent misrepresentation.
Negligence in the design or supervision of the customer-service process.
Breach of contract.
Consumer-protection violations.
Professional negligence if the response involved regulated or specialized advice.
Failure to correct a known error after the business received notice.
The business may argue that the customer should not have relied on the chatbot. The outcome will depend on the facts, including how the chatbot was presented and whether the company encouraged customers to treat it as an authoritative source.
How insurance may respond
Possible coverage discussions may involve:
Professional liability or E&O insurance for financial loss allegedly caused by professional services, advice, or a service error. Insure Connecticut explains the distinction between general liability and professional liability on its Errors & Omissions Insurance page.
Technology E&O if the business provides technology-enabled services.
A specialized AI liability policy for certain scheduled AI systems and third-party claims.
Commercial general liability only if the allegations fit the policy’s covered personal and advertising injury or another applicable insuring agreement. CGL is not a universal solution for inaccurate advice or pure economic loss. Review the fundamentals in What Does Commercial General Liability Insurance Cover?.
Coverage may be limited by professional-services exclusions, contractual liability provisions, knowledge exclusions, cyber exclusions, or policy definitions that do not contemplate the company’s actual AI use.
Evidence to preserve
Preserve the complete record, including:
The customer’s original question.
The exact chatbot response.
Date, time, and time zone.
Model name and version.
System prompts and guardrails.
Source documents or databases accessed by the chatbot.
Customer-facing disclaimers and escalation instructions.
Human review records.
Website and chatbot version history.
Customer communications before and after the incident.
Documentation showing when the business learned that the answer was wrong.
Do not overwrite the original chatbot transcript while attempting to correct it. Create a forensic copy first.
Scenario 2: AI-generated marketing content infringes copyright or trademarks
How the problem develops
A business asks generative AI to create an advertisement, blog post, product image, slogan, software code segment, sales presentation, or social media campaign. The business publishes the output without checking whether it resembles protected third-party material.
A Connecticut manufacturer may use an AI-generated image in a product catalog that closely resembles a competitor’s protected photograph. A New York retailer may publish an AI-written slogan that is confusingly similar to a registered trademark. A software company may incorporate AI-generated code containing licensing or attribution requirements that its development team did not identify.
The problem can also involve a generated statement about a competitor or individual. If the statement falsely claims that a competitor committed fraud, sold unsafe products, or violated the law, the business may face defamation or business-disparagement allegations.
Potential legal theories
Potential claims include:
Copyright infringement.
Trademark infringement.
Trade dress infringement.
False advertising.
Unfair competition.
Defamation or libel.
Misappropriation of name, image, or likeness.
Breach of a licensing agreement.
Businesses should not assume that an AI tool’s terms of service transfer all rights or provide a complete defense. The business remains responsible for deciding what to publish, sell, distribute, or incorporate into its products.
The U.S. Copyright Office’s Artificial Intelligence initiative provides current information about copyright and AI-related issues. The Federal Trade Commission’s guidance on AI claims also reinforces a basic principle: companies must support the claims they make about AI products and services.
How insurance may respond
Possible insurance considerations include:
Media liability or advertising injury coverage.
Technology E&O.
Intellectual property liability coverage.
A specialized AI liability policy that expressly addresses certain AI-generated content claims.
Defense coverage under a policy that responds to advertising injury, subject to its language and exclusions.
CGL policies vary significantly. Some may address certain advertising injury allegations, while others contain exclusions or restrictions for intellectual property disputes. A policy may also distinguish between accidental use of protected material and intentional infringement.
Do not assume that a vendor’s indemnification clause solves the problem. Review the vendor’s indemnity, limitations of liability, defense obligations, choice-of-law provisions, insurance requirements, and procedures for handling infringement notices.
Evidence to preserve
Preserve:
The original prompt.
Every generated version.
The final published version.
Metadata and timestamps.
Human edits and approval notes.
Copyright or trademark searches.
License agreements.
Vendor terms of service in effect when the content was created.
Internal marketing policies.
Records of who approved publication.
Takedown requests, demand letters, or platform notices.
If the content is disputed, do not casually delete the file or replace it without preserving the original. Deletion can complicate the defense and may create separate evidence-preservation concerns.
Scenario 3: The AI system discloses protected or confidential information

How the problem develops
An employee pastes confidential information into a public AI tool. Alternatively, a chatbot connected to an internal knowledge base retrieves information that the user should not see.
Examples include:
A customer-service chatbot exposes another customer’s account details.
An employee enters a patient record into an external AI platform.
A law firm uploads privileged material to a system without confirming data-use terms.
A manufacturer exposes trade-secret designs through an AI coding or drafting tool.
An AI assistant retrieves employee payroll information for an unauthorized user.
A chatbot combines information from separate customer accounts and displays the wrong person’s data.
The incident may involve personally identifiable information, protected health information, financial data, employee data, trade secrets, privileged communications, or confidential customer records.
Connecticut businesses must consider applicable privacy, contractual, and breach-notification obligations. Connecticut’s breach-notification statute is available through the Connecticut General Statutes. A business should involve qualified legal and forensic professionals before deciding whether an incident requires notice.
Potential legal theories and obligations
Possible exposure includes:
Privacy claims.
Breach-of-contract claims.
Confidentiality claims.
Trade-secret misappropriation allegations.
Regulatory investigations.
Consumer-protection claims.
Data-breach notification and remediation obligations.
Employment-related claims if employee information is exposed.
Professional-discipline issues in regulated industries.
A company can face a serious incident even when no hacker entered the system. An unauthorized disclosure caused by poor access controls, excessive data retention, vendor configuration, or an employee’s unsafe use of a tool can still create liability.
How insurance may respond
Possible coverage discussions may involve:
Cyber liability insurance.
Privacy liability coverage.
Network security coverage.
Breach-response services.
Regulatory defense, where available.
Technology E&O if the failure involved a technology service or system.
Media liability if the disclosure becomes part of a publication or communication claim.
Cyber policies differ widely. Some cover investigation, notification, legal review, public relations, credit monitoring, and third-party liability. Others restrict coverage based on the type of information, the nature of the event, the insured’s security controls, or whether the data was intentionally submitted to the system.
Insure Connecticut outlines cyber coverage considerations on its Cyber Liability Insurance page. Businesses can also review Third-Party Liability in Cyber Insurance for additional context.
Evidence to preserve
Secure and preserve:
AI prompts and outputs.
Access logs.
Identity and permission records.
Data-flow diagrams.
Vendor contracts and data-processing terms.
Model configuration.
API logs.
DLP and security alerts.
Screenshots of the exposed information.
Incident-response timelines.
Forensic images where appropriate.
Communications with affected parties.
Records of containment and remediation.
Do not continue testing the exposed system with live personal information. Move testing to a controlled environment using synthetic or redacted data.
Scenario 4: Reliance on an AI output causes bodily injury
How the problem develops
A business uses generative AI to create health, safety, maintenance, construction, transportation, or operational instructions. An employee or customer follows the output and suffers bodily injury.
Consider a Northeast manufacturer that uses an AI assistant to draft machine-maintenance steps. The instructions omit a lockout/tagout step. A worker is injured while servicing equipment.
A construction company may use AI to summarize site-safety procedures. A healthcare provider may use AI to draft patient communications. A commercial kitchen may use AI to provide food-safety guidance. A logistics company may rely on AI-generated loading instructions.
The business does not need to claim that the AI is “intelligent” for a claimant to argue that the company failed to exercise reasonable care. The focus will be on the company’s deployment decision, supervision, training, testing, warnings, and response to known errors.
Potential legal theories
A claimant may allege:
Negligence.
Failure to warn.
Negligent supervision.
Product liability.
Professional malpractice.
Breach of statutory or regulatory duties.
Premises or operational liability.
Workers’ compensation exposure for an injured employee.
The distinction between workers’ compensation and third-party liability matters. An employee’s injury may trigger workers’ compensation obligations, while a customer, contractor, visitor, or other third party may bring a liability claim.
How insurance may respond
Possible policies include:
Workers’ compensation for covered employee injuries.
CGL for third-party bodily injury caused by business operations.
Products liability coverage when an AI-assisted product or instruction contributes to injury.
Professional liability for covered professional services.
Technology E&O for a technology service failure.
Umbrella or excess liability for covered claims above underlying limits.
No policy should be treated as an automatic answer. CGL may contain exclusions for professional services, expected or intended injury, contractual obligations, or products-completed operations issues. E&O may exclude bodily injury and property damage. Workers’ compensation does not cover every third-party lawsuit.
Evidence to preserve
Preserve:
The exact AI-generated instruction.
The employee or customer’s version of the instruction.
Training and safety materials.
Testing and validation records.
Applicable industry standards.
Human approval records.
Warning labels.
Maintenance and inspection logs.
Incident photos and video.
Witness statements.
Equipment settings.
System audit trails.
The AI model and configuration used at the time.
A business should issue a legal hold when litigation is reasonably anticipated. It should also preserve physical evidence without altering or discarding equipment involved in the incident.

Scenario 5: An AI-driven decision causes property damage
How the problem develops
Generative AI becomes more consequential when it connects to physical operations. An incorrect recommendation can damage a building, machine, vehicle, inventory, customer property, or infrastructure.
Examples include:
AI-generated loading instructions place heavy equipment on an unsuitable surface.
A system creates an incorrect HVAC or refrigeration setting.
AI-generated code causes a robotic system to move outside its programmed limits.
An AI scheduling tool sends a delivery to the wrong location, resulting in damage to customer property.
An AI maintenance recommendation causes a machine to operate without a required inspection.
A construction workflow uses an incorrect sequencing recommendation that damages completed work.
Property damage claims often involve multiple parties. The property owner, contractor, equipment manufacturer, software vendor, maintenance provider, and business deployer may all dispute responsibility.
Potential legal theories
A claimant may allege:
Negligence.
Breach of contract.
Product liability.
Faulty workmanship.
Failure to supervise.
Failure to inspect.
Professional negligence.
Damage to property in the care, custody, or control of the insured.
That last issue matters. CGL policies often treat damage to property in the insured’s care, custody, or control differently from damage to unrelated third-party property. Businesses should review this distinction before assuming that a general liability policy will cover damage to equipment or materials being handled.
How insurance may respond
Potential insurance discussions may include:
CGL for covered third-party property damage.
Commercial property insurance for covered damage to the business’s own premises or equipment.
Equipment breakdown insurance for certain mechanical or electrical breakdowns.
Inland marine coverage for property in transit or away from the main premises.
Products liability coverage.
Technology E&O or professional liability.
Business interruption coverage following a covered physical loss.
Specialized AI liability coverage, if the policy addresses the scheduled system and the type of claim.
The cause of loss matters. A policy covering equipment breakdown may not cover damage caused solely by an incorrect business decision. A property policy may require direct physical loss. An E&O policy may exclude physical damage. A CGL policy may contain care, custody, or control exclusions.
Evidence to preserve
Preserve:
System logs and decision records.
AI prompts and outputs.
Equipment settings.
Maintenance and inspection records.
Delivery and scheduling data.
Contracts with customers and vendors.
Photographs and videos.
Repair estimates and invoices.
Expert reports.
Software version information.
Human override records.
Security footage.
Communications regarding the incident.
Do not reset, upgrade, or reconfigure the system before collecting relevant evidence unless necessary to prevent additional harm. Document any emergency changes.
How should Connecticut businesses control AI liability?
A practical AI risk-control program should include the following steps.
1. Create an AI inventory
List every AI tool used by the business, including tools employees adopted without formal approval.
Record:
Vendor and product name.
Model or version.
Business purpose.
Users and departments.
Data accessed.
External integrations.
Whether outputs reach customers.
Whether the system influences physical operations.
Contract and renewal dates.
2. Classify uses by risk
Low-risk uses may include brainstorming or formatting internal content.
Higher-risk uses include:
Legal, medical, financial, or insurance advice.
Hiring and employment decisions.
Customer eligibility or pricing.
Safety instructions.
Product design.
Manufacturing or equipment control.
Public statements about people or competitors.
Processing protected or confidential information.
Require stronger review as the potential harm increases.
3. Require human review
Human review should be mandatory before AI output is:
Sent to a customer as authoritative information.
Used in a contract.
Published in advertising.
Submitted to a regulator or court.
Used for professional advice.
Used in a safety-critical process.
Used to make an employment or eligibility decision.
Connected to machinery or automated controls.
Human review must be substantive. Clicking “approve” without reading the output does not create meaningful oversight.
4. Minimize data
Do not place confidential information into a tool until the business understands:
Where the data is stored.
Whether the vendor uses it for model training.
Who can access it.
How long it is retained.
Whether it can be deleted.
What security controls apply.
Whether the vendor provides breach notice.
Whether the vendor contract includes indemnification.
Use redacted, synthetic, or anonymized data during testing.
5. Test before launch and after updates
AI behavior can change when the model, system prompt, data source, integration, or vendor configuration changes.
Test for:
False answers.
Disclosure of confidential information.
Prompt injection.
Biased or discriminatory outputs.
Unsafe instructions.
Copyright or trademark concerns.
Incorrect customer-specific information.
Failure to escalate uncertain questions.
The NIST AI Risk Management Framework and its Generative AI Profile provide a useful structure for governing, mapping, measuring, and managing AI risk.
6. Review insurance before deployment
Give your broker a written description of the AI use. Include the system’s purpose, data access, customer interaction, professional-service role, physical-operation connection, and vendor contract.
Ask specifically about:
Cyber liability.
Privacy liability.
Technology E&O.
Professional liability.
Media and advertising liability.
CGL.
Products liability.
Equipment breakdown.
Business interruption.
Umbrella and excess liability.
Specialized AI liability products.
For a specialty-market reference, businesses can review generative AI insurance resources from Icon Insurance Solutions. The coverage described by any specialty provider must be reviewed carefully, including scheduled systems, definitions, exclusions, limits, retentions, territorial terms, and claims-made requirements.
7. Report incidents promptly
Do not wait until a demand letter arrives. Notify the appropriate insurer or broker when an incident may involve:
A privacy breach.
A customer alleging financial harm.
A bodily injury.
Property damage.
A copyright or trademark complaint.
A defamation allegation.
A regulator.
A vendor dispute.
Prompt notice can affect defense rights, incident-response access, and the ability to preserve evidence.
Frequently asked questions
Does general liability insurance cover AI mistakes?
It may respond to some covered third-party bodily injury, property damage, or advertising-injury allegations, depending on the policy. It generally is not designed to cover every financial loss caused by inaccurate professional advice or a chatbot error.
Does cyber insurance cover generative AI?
A cyber policy may address privacy, network security, data breach, incident response, or certain technology-related liability. It may not cover every AI output problem, particularly where no security or privacy event occurred. Review the policy’s definitions and exclusions.
Do I need E&O insurance if my business uses a chatbot?
If the chatbot supports professional services, advice, consulting, software, or other specialized work, E&O or technology E&O may be relevant. The need depends on what your business does and how customers rely on the output.
Is the AI vendor responsible if its model produces a harmful answer?
The vendor may have contractual or legal responsibility, but the deploying business can still face a claim. Vendor liability and insurance do not automatically protect the business from the claimant’s first demand.
What should I do after an AI-related claim?
Preserve prompts, outputs, logs, configuration records, contracts, communications, and physical evidence. Notify your broker and insurers promptly. Involve qualified legal and technical professionals before making admissions or deleting data.
Can a disclaimer eliminate AI liability?
No. A disclaimer may help establish how the system was presented, but it does not automatically defeat negligence, privacy, contract, consumer-protection, intellectual-property, bodily-injury, or property-damage claims.
The practical takeaway
Generative AI does not need to malfunction dramatically to create business liability. A single incorrect chatbot answer, unreviewed image, exposed customer record, unsafe instruction, or faulty operational recommendation can become a legal and insurance problem.
Connecticut and Northeast businesses should treat AI deployment as an operational risk issue, not only an information-technology project. Build an inventory, limit sensitive data, require meaningful human review, preserve evidence, review vendor contracts, and explain the use of AI to your insurance broker before the system goes live.
If your business is deploying generative AI, review your cyber, E&O, CGL, professional liability, property, and umbrella program before a claim tests the gaps. Insure Connecticut LLC can help businesses compare coverage options across multiple insurance markets and identify where policy language may not match the way the business actually operates.
Sources and further reading
.png)

Comments