California’s new restrictions on automated employment decisions are putting fresh pressure on brokers and insurers to determine where liability sits when employers use third-party AI tools.
Governor Gavin Newsom signed SB 947, dubbed the “No Robo Bosses Act,” on September 30. Beginning July 1, 2027, employers will be prohibited from relying solely on an automated decision system when making disciplinary or termination decisions. Where an employer primarily relies on an automated output, a human must corroborate the decision, while affected employees gain additional notice and information rights.
The legislation does not regulate hiring in precisely the same way. But it arrives as employers, insurers and brokers are already watching litigation over AI-assisted recruitment, including Mobley v. Workday, where plaintiffs allege Workday’s automated hiring tools resulted in discriminatory outcomes. Plaintiffs are seeking class certification, with a hearing scheduled for March 2027. Workday has denied wrongdoing.
Jonathan Mitchell (pictured), financial practice lead at Founder Shield, the innovation practice of The Baldwin Group, believes the uncertainty over liability risk means employers using outside technology should proactively take on the assumption of responsibility. Even where contractual indemnification eventually shifts responsibility to the technology provider, the employer may still face the immediate cost of defending itself.
“You should operate like it’s your liability,” Mitchell told Insurance Business. “Ultimately, it’ll come down to what the contract says with the vendor they’re using.
“Potentially, down the road, you can get yourself removed from the lawsuit or transfer all the liability over to the AI vendor that you use, but it’s going to cost a lot of money to get there.”
The issue puts greater weight on a risk brokers may historically have viewed as peripheral to an EPLI placement: the contracts clients have signed with technology vendors. While brokers cannot provide legal advice, they should be reviewing how clients describe their outsourcing arrangements and if those expose gaps between perceived and actual risk.
The issue may be particularly significant for smaller and middle-market companies that adopt AI tools to streamline HR without the legal resources of larger employers. Mitchell said some organizations may assume that outsourcing a function also outsources the underlying employment liability. A company might use one platform to screen applicants and another for payroll, for example, without fully understanding the contractual allocation of responsibility.
EPLI underwriters are beginning to ask about AI use, although Mitchell noted that detailed scrutiny remains inconsistent in the SME segment of the market. Questions currently tend to center on whether AI is being used, which vendor is supplying it and who inside the insured organization is responsible for overseeing the technology.
“I’m personally not seeing a ton of, ‘I need to see that (AI vendor) contract,’ but maybe that’s where it goes,” Mitchell said. “Right now, it’s probably more of a nice-to-have for us brokers, but I could see it becoming a need-to-have at some point.”
The larger insurance concern may ultimately extend beyond individual EPLI claims; Mitchell drew a comparison with cyber insurance, where insurers learned that widespread dependence on the same technology providers could create hidden aggregation risk.
If dozens or hundreds of insured employers use the same AI employment platform, a problem with that vendor could generate separate claims across an insurer’s portfolio.
“Instead of one class action claim, your book has claims across 40% of your insureds for EPL claims because they were all using this vendor,” said Mitchell.
There are signs that AI exclusions are beginning to reach management liability policies. Berkley Insurance Company, for one, has developed an “Artificial Intelligence Exclusion (Absolute)” endorsement that expressly amends its directors and officers, employment practices liability and fiduciary liability coverage parts. The wording excludes losses arising from the actual or alleged use, deployment or development of AI, including claims involving inadequate AI policies or training and alleged breaches of legal obligations relating to the technology.
The wording remains an emerging rather than market-wide approach. Aon estimated in its 2026 AI risk report that more than 90% of potentially covered AI exposure still sits within “silent AI” insurance, where policies neither expressly cover nor exclude the technology.
But restrictions are developing elsewhere: ISO introduced optional generative AI exclusions for commercial general liability policies, while cyber insurers including QBE have begun using AI-related sublimits for particular exposures. Aon also identified employment-related discrimination as one of the AI risks that could fall within EPLI, making the evolution of policy wording particularly relevant as automated employment decisions generate more claims.
Mitchell said he would “be shocked” if there weren’t more AI exclusions in the near future.
“It’ll likely come down to the answers underwriters are getting to those questions,” he told Insurance Business. “If you’re using a vendor they don’t have a high opinion of, no one is closely overseeing it, or AI is handling 100% of your hiring until the final stage, you could absolutely see exclusions around that.
“I think that’s why we’re starting to see more AI-specific insurance products. Some people are anticipating a need for broader AI coverage because EPL or E&O carriers may simply say, ‘We’re not going to cover this.’ I could see that becoming more prevalent, but it’s certainly not an issue on our book yet.”