When AI becomes the product, not the tool - the E&O gap opening
Current E&O policies were built around a human professional at the centre of every transaction. The line between AI assisting that professional and AI replacing them is moving faster than the policy language is following
When AI becomes the product, not the tool - the E&O gap opening
PROFESSIONAL RISKS
By Paul Lucas
24 Sep 2026

A single question is starting to define the professional liability coverage conversation in ways the market has not yet resolved: at what point does an AI system stop being a tool that a professional uses, and start being the professional service itself?

Alex Ilkos, client executive, professional services at Purves Redmond Limited, put the distinction plainly at a recent Insurance Business Canada professional risks roundtable. "An AI tool helping you perform your professional service - I'm comfortable on that front," he said. "But as AI becomes the service further and further down the line, as it develops, that's where I see a little bit of that grey area."

That grey area is where the next wave of professional liability claims is heading. And the policy wordings that currently cover professional services were not written with it in mind.

What traditional E&O was built to do

Standard E&O policies rest on a single architectural assumption: a licensed professional is at the centre of the transaction. The policy contemplates that individual counselling, advising, and delivering a service. When something goes wrong, the question is whether that professional exercised reasonable care.

Under that architecture, an AI tool sits comfortably within existing coverage. It is an instrument - like a legal database or a financial model - and the professional who used it and reviewed the output remains the accountable party. The claim, if one arises, is against the professional's judgment, and the E&O policy responds to that.

The architecture starts to break when the AI is the service itself.

Agentic AI systems - tools that do not generate an output for a human to review but that take sequential autonomous actions across systems on a client's behalf - are already operating in legal research, accounting reconciliation, and financial advisory workflows. A January 2026 investigation found companies discovering between one and 17 AI agents per employee in security scans, the majority without documented access scopes. These are not tools a professional uses. They are systems that act. When they act incorrectly, the question of who is liable - and which policy responds - is genuinely unresolved.

'The AI said it' is not a defence

The clearest illustration of what happens when AI becomes the service came from Canada itself.

In early 2024, Air Canada's automated chatbot told a bereaved passenger he was eligible for a retroactive bereavement discount - a policy that did not exist. When Air Canada refused to honour the representation, the company argued before the Civil Resolution Tribunal that the chatbot was a separate legal entity responsible for its own actions. The tribunal rejected that position entirely, ruling that Air Canada was responsible for all information on its website regardless of how it was delivered.

"The AI said it" was not a defence.

That principle is now being applied in professional contexts. In Mobley v. Workday, the company faced a US class action in 2025 alleging its AI-based screening tools discriminated against applicants on grounds of race, age, and disability. Workday's argument that it was a software vendor rather than a decision-maker failed to limit its liability. When AI makes decisions that affect clients or third parties, the organization that deployed it carries the accountability - and that accountability arrives at the E&O policy, or tries to.

The coverage question is whether the policy language is there to receive it. In most cases currently, it is not designed for it.

The structural break that has already happened

Canada has no dedicated federal AI statute. The proposed Artificial Intelligence and Data Act died with Bill C-27 when Parliament was prorogued in January 2025 and has not been revived. But the absence of a dedicated AI law does not mean professional services firms are operating without accountability - they are operating under existing professional conduct codes, privacy legislation, and an accelerating body of regulatory guidance that is already establishing duty of care standards for AI use.

The Federation of Law Societies of Canada's position, confirmed in 2025, is that existing competence, confidentiality, and supervision duties apply to AI use without modification. That means a lawyer who relies on an AI output without adequate verification has potentially breached their professional obligations under existing rules - before any new AI-specific regulation arrives.

WTW's Insurance Marketplace Realities 2026 described the January 2025 to January 2026 period as a "structural break" in the professional liability market. Firms that entered 2025 treating AI as a productivity issue, per market analysis published in February 2026, discovered by renewal that it had become an underwriting issue.

That transition is accelerating. The 2026 Legal Industry Report found that 69% of legal professionals now use generative AI for work-related purposes, up from 31% the year before. Thomson Reuters' 2025 Generative AI in Professional Services Report found the same uptake pattern in accounting. Adoption is moving much faster than either policy language or underwriting sophistication.

The cyber trajectory

Natalie Chan, senior risk advisor, specialty, commercial insurance at Navacord, offered the most useful lens for where this ends: "AI risk will evolve to be a separate cover, just like cyber were a decade or more ago."

That parallel has strong support in market analysis. Cyber risk began as silent coverage scattered across general liability, professional liability, and crime policies. As the exposure grew and became harder to price implicitly, the market moved through a now-familiar sequence: exclusions to remove the risk from existing policies, affirmative endorsements to sell it back in structured form, and eventually standalone products with dedicated underwriting, pricing, and claims infrastructure.

Fenwick's June 2026 market analysis found AI following the same path on "a more compressed timeline and with a more fragmented market response." The Artificial Intelligence Underwriting Company's report Underwriting the Agent Economy found that more than 90% of insurers' AI agent exposure currently sits inside conventional policies never built for the technology.

That 90% figure is the number brokers should keep in mind at every professional lines renewal.

The governance window

The underwriting market is gathering AI governance information it does not yet know how to use. That will change, and the gap between now and when it changes is a window that closes at an unpredictable moment.

Ilkos described the broker's role in that window: "We share our expertise with all the different clients because we get to see - we have a strong view into what other clients have done in the space. We can definitely walk through those conversations with clients and kind of assist and sort of guide them to the right resources as they require. And I think that's the interesting point because we sort of benchmark where they're at compared to other peers in similar industries and similar work."

Chan's framing for clients navigating the current environment was precise. "Whether underwriters are asking questions on risk with our clients that have that agentic AI or AI exposure, we are really recommending to our clients: either adopt a formal policy, or perhaps don't use AI. Because at that point, there are certain underwriters that want evidence that the organization is following, have rules, internal governance and guidance around the AI usage, the framework. What kind of tools are they using? Who can access these tools? What does the company allow the usage for? Is there an AI-related incident response plan in place? Everything is about being preparation."

The coverage gap that is opening in the professional liability market is not, in most cases, an absence of coverage for AI-assisted professional work. It is an absence of coverage for the next iteration of AI deployment - autonomous, agentic, consequential - that is already in use at professional services firms whose E&O programmes were not designed to contemplate it.

Ilkos put the priority for the next six to twelve months plainly: "I think we keep moving further and further away with AI from the nature of what the current wordings are designed to cover. Maybe in my example where the AI is the service, it's no longer a lawyer's E&O policy. Maybe we have to move more to the tech E&O front. Maybe there's a new policy as a whole. But kind of defining those lines is what I think we need to see."

Those lines are not yet defined. But the claims that will force the market to define them are already in the pipeline.

Related Stories
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB CA.