When a customer got DPD's chatbot to swear at him in January 2024, the parcel firm blamed a system update and switched the AI off within hours. Today AI agents handle far more customer conversations than they did then. When one of them causes real damage, someone will have to answer for it, and that person may need their insurance to respond.
According to new research, the person held responsible is usually the chief information officer, whether or not anyone formally gave them the job.
The study, commissioned by the communications software company 8x8 and carried out by Censuswide, surveyed 2,501 CIOs and chief technology officers at organisations with at least 50 staff in the UK, US, France, Australia and Ireland. Across all five markets, 52% said the CIO was held accountable when an AI agent made an error. Only 16% named customer service leadership, and 6% legal or compliance.
In the UK, half of respondents named the CIO, 20% customer service leadership and 5% legal or compliance. The share rose with company size, from 45% of CIOs at firms with 50 to 99 staff to 62% at organisations with 500 or more. Among respondents from UK government and public administration, it was 86%.
The survey records how technology leaders think blame is assigned, not who has been sued or sanctioned, and 8x8 sells the kind of consolidated platform its report recommends. But it raises a practical question for brokers: if accountability is landing on the CIO, is the CIO covered?

Read next: Insurers face hidden AI liability as agent risks multiply
For now, it probably will, provided the CIO is within the policy's definition of an insured person. In mid-sized firms the CIO is often not a board director, so that definition is the first thing to check.
In a briefing for brokers, Zurich and the law firm DAC Beachcroft argued that standard directors' and officers' wordings rarely need to define AI in order to respond to it. In their view, a broadly drafted "wrongful act" should cover management decisions about deploying the technology, and regulatory investigations into those decisions are likely to fall within cover. They found that only a few policies, in particular sectors, exclude AI. They also cautioned that affirmative AI wordings need careful drafting to avoid narrowing protection by accident.
Other lines are changing faster though. Research by Willis found that professional liability carriers moved away from silent AI cover between January 2025 and January 2026, towards either explicit warranties or outright exclusions. Gallagher found this year that one in five insurance professionals said their clients had already suffered losses linked to AI.
Read next: AI agents could leave commercial losses between insurance policies
In UK financial services, accountability for AI is a regulatory matter as well as an insurance one. The Commons Treasury committee reported in January that about three-quarters of UK financial services firms now use AI, with insurers and international banks among the heaviest users. The committee accused regulators of a "wait-and-see" approach and asked the Financial Conduct Authority to publish guidance by the end of this year. The guidance is to cover how consumer protection rules apply to AI, and what level of assurance senior managers will be expected to give for harm the technology causes.
The FCA has said that the consumer duty and the senior managers and certification regime already apply to AI, and it has decided against creating a dedicated senior management role for the technology. Its Mills review of AI in retail financial services, published in July, agreed that the existing accountability regime still works, but called for clearer guidance on what "reasonable steps" look like as more decisions are handed to AI.
For insurers, that means responsibility for an AI agent's mistake already sits with the senior manager who owns the part of the business where the agent operates. That may not be the CIO, and the 8x8 findings suggest many organisations have yet to decide who it is.
Read next: AI adoption is outpacing governance frameworks, Willis warns
The 8x8 report also has implications for claims. When an AI agent deals with a customer, the record of that conversation is kept in the communications platform, not in the CRM system or the AI tool on top of it. Organisations running several communications systems end up with records spread across them, which makes it harder to reconstruct what an agent did and why.
Of the respondents, 82% said the location of AI infrastructure affected which platforms they bought, and 30% called it the deciding factor. In the UK, 91% said data sovereignty had become a higher priority over the past year. Few are consolidating quickly: the most common obstacles cited were the cost and complexity of migration (30%), regulatory and data-residency rules (24%) and fear of being locked in to one supplier (16%).
The first question for clients is who owns AI governance. The 8x8 data suggests that in many organisations the CIO has taken on the role without anyone deciding it. For regulated clients, brokers should also ask whether that responsibility is written into a senior manager's statement of responsibilities.
Brokers should then confirm that the D&O policy's definition of an insured person reaches officers below board level. At renewal, AI wordings should be read across D&O, cyber, technology errors and omissions, and professional indemnity together, because a loss can fall between policies.
Records matter too. A client that can show who approved an agent, what it was allowed to do and where its interaction records are kept will be easier to defend in a claim or an FCA inquiry, and easier to place.