Headlines this year have been awash with tales of rogue AI agents breaking free of their restraints and launching unprecedented attacks on people and companies.
From a personal perspective, it’s concerning. From an insurer’s perspective, it raises difficult questions around liability, accountability, and how existing legal principles apply when AI behaves in unexpected ways.
AI is disrupting the legal sphere, challenging traditional tort law head-on through two important factors - foreseeability and causation. Because of the ‘black box’ nature of AI and the unpredictable ways models can fail, it’s becoming difficult to establish foreseeable harm or a clear causal link between human action and the resulting damage.
But what does this mean for the future of AI in law? And how can the insurance world really build the right infrastructure around AI’s impact on liability frameworks if we’re still grappling with the basics?
Anat Lior, Professor of Law at Drexel University’s Thomas R. Kline School of Law, consultant to Relm Insurance, and an expert in AI’s impact on the legal sector, told Insurance Business that AI agents, relatively new as they are, are already challenging traditional concepts of legal liability.
“We’ve had emerging technologies in the past and we’ve managed to push through with a legal system that works well alongside them. But with AI, there’s a general consensus that ‘this time it’s different’. We're seeing a transformation of technology across the board here.”
For Lior, those two areas of tort law - foreseeability and causation - are muddied when AI comes into play.
“In tort law, we want to assign liability to a wrongdoing that’s foreseeable, something that the person should have seen coming and, because they didn't or they acted in a negligent way, we want to hold them liable. But if we can't foresee or understand what's expected to go wrong with AI or the type of harms that can be associated with it, then the basic notion of using tort liability is disrupted as a result. We just don't know where to cross the line.”
Because with AI nothing is foreseeable, and at the same time everything is foreseeable. Lior likens the situation to the ‘Paperclip Problem’ - a famous AI safety thought experiment illustrating how a superintelligent AI with an apparently harmless goal could accidentally destroy humanity due to a lack of human values.
“The second issue is causation,” Lior told IB. “We want to make sure there's a legal link between the wrongdoer, the issue that caused the harm, and the actual harm that happened. And, because of the open-weight model or the proxies that’re unclear, there’s not always evidence of a causal link between the decision, the human interaction, and the end result of harm.”
Solutions to these two tort issues are currently being looked at, with the American Law Institute now trying to create some AI principles that would work with the existing legal system - but it’s easier said than done.
“Some scholars believe that because the tort system was built for humans, we need to rethink if AI would fit into it,” added Lior. “Personally, I don't agree with that - I think tort law is very flexible and adaptable to new technologies. And, currently, it's the only thing we actually have given the lack of regulation.”
A recent study suggests the courts may already be doing exactly that. Published in July 2026, researchers examined 559 US federal court opinions in which AI played a role in the parties’ arguments, finding that courts have primarily relied on existing legal doctrines rather than creating new AI-specific rules.
For insurers, adaptability is the new world order here. One in five insurance professionals say their insureds have already experienced losses linked to AI risk, according to Gallagher’s 2026 AI Adoption and Risk Benchmarking Survey. Because as tech continues to evolve, so too do the related risks - which is where the issue of Silent AI comes in. Silent AI is an unpriced insurance risk where artificial intelligence liabilities are neither explicitly included nor excluded in traditional policies, creating hidden coverage gaps.
And the scale of that hidden exposure here could be enormous. More than 90% of insurers’ exposure to AI-related risks currently sits within ‘silent’ coverage, according to a recent report.
“Traditional policies are already covering this because we're seeing doctors using AI, and then we have malpractice liability, or we're seeing tech companies using AI, and then we have Tech E&O and cyber insurance which already exists - everything can be built onto existing policies.”
Lior argues that AI is unlikely to disappear, despite inevitably causing some harm. Much like automobiles and aviation, society may ultimately accept those risks in exchange for the technology’s benefits. Rather than broadly excluding AI, insurers could adapt existing coverage as understanding of the technology improves.
However, the industry remains divided.
“An AI policy might be absorbed into the traditional policies we all know and use, but there's very slow movement within the insurance industry to try to approach it,” added Lior. “It may be about fixing the silent AI coverage - which normally only happens when a big harm occurs and then everything and everyone needs to reconsider and readjust their policies.
“Unfortunately, I think that will happen soon and then companies will have to reconsider this. There's a lot of people comparing AI coverage to cyber insurance but I’m not sure if the trajectory will be the same given that cyber insurance started from exclusions. I don't see a similar trajectory of exclusions in the AI sphere because of the general purpose technology.”
This uncertainty allows for gaps to creep into the AI liability space, especially in regard to AI agent accountability. As Lior told IB, the biggest legal gap here centres around the lack of certainty over which liability regime should apply.
“We currently have three main camps; one that sees AI as a product to which we can apply products liability and its defects. One that says that traditional notions of negligence should apply to AI activities. And the third approach, the one I advocate for though it's not popular right now, is a strict liability approach. We don't care about fault; the mere fact that you're doing it and that it is casually linked is sufficient for us to assign liability to you.
“The traditional example here is similar to wild animals. If you own a tiger, it doesn't matter what you do, if it gets out and bites someone you will be held strictly liable. The gap is unclear about which liability regime should apply here because AI is not software or a product in the traditional sense, and a negligence analysis might be challenging due to the black box and foreseeability issues.”
It’s a whole new legal minefield to work through - and one for which there’s no clear answer for just yet. This issue of accountability leads to further questions around how AI should be dealt with should an incident occur. Say, for instance, an AI agent negotiates a contract and gives bad financial advice, or a chatbot makes a healthcare recommendation that causes harm - how should that then be treated? Is AI a ‘defective product’? Is it a negligent person? Or is it something entirely new? Well, this is a question that Lior’s been contemplating since she wrote her dissertation in 2017.
“One of my papers talks about legal analogies. Can we analogize AI to a dog, to a tiger, to a small child, to a disabled person? There is a call to analogize AI to products, to just see it as a product when you can, from there you can talk about design defects or failure to warn defects. Or maybe we should focus on the negligence of whoever used or produced the AI: you have the user, the prompter, the data trainer, the programmer, the distributor, and other people and corporations in the AI’s pipeline. This is the ‘many hands’ problem. We're not sure who within the pipeline should be assigned liability. And it’s hard to prove because ofthe black box and the opacity of the technology itself.”
This uncertainty, however, really strengthens the case for tougher rules today, with Lior doubling down on her belief that strict liability makes more sense right now. Longer term. however, the framework may change.
“I do believe that eventually we will shift into negligence, just because there will be an equilibrium of enough safety mechanisms with society understanding that this is an important thing, and we don't want to reject it given its benefits.”
Lior likens our current stage of AI readiness as the first years of the automotive industry - when cars were almost foreign objects that no one really understood the dangers of and that weren’t built with proper safety precautions in mind.
“You see pictures of people driving cars in the 1950s while making coffee from an espresso machine or having child’s car set strapped to the outside of the window - it just blows your mind. I like to think we’re discovering the seat belts and the airbags of AI. We will figure out how to make it safer to a point where negligence will make more sense. But right now, because of the novelty of it and the surge of litigation that we're seeing, it might take some time.”
Read about AI risk management products here: