Your HR team is using an AI tool to screen resumes. Your marketing director runs customer emails through a language model before they go out. Your customer service chatbot handles the first few rounds of every support conversation.
None of that is unusual in 2026. Most businesses are running AI tools somewhere.
What is unusual: most of those same businesses have no idea which of their existing policies respond when something goes wrong. And they don't find out until the letter arrives.
This isn't theoretical
A Chicago-area law firm used an AI research tool to prepare a brief. The tool cited three cases that didn't exist. The brief filed. Opposing counsel caught it. The state bar opened an inquiry.
A Naperville manufacturer's procurement system ran AI-assisted contract review. The model flagged terms as standard that had a one-sided arbitration clause buried in them. The business signed. It's now in a seven-figure dispute with limited options.
A DuPage County retailer ran product descriptions through a generative AI writing tool. One output closely echoed a competitor's registered trademark. The competitor's attorneys sent a letter. Defense costs started at $25,000 before anyone went to court.
None of those companies thought they had an insurance problem when they started using the tools. They thought they were saving time.
The two groups asking about this
Businesses asking about AI insurance usually fall into one of two groups: companies that build AI products, and companies that use AI tools in their operations.
Both have exposure. But the coverage solutions look different, and mixing up the answers creates gaps.
Companies building AI products are dealing with product liability questions. If your software, chatbot, or agent causes a client harm, Tech E&O is the first line of response. The question is whether your Tech E&O form was written before 2024 and whether it says anything meaningful about AI-generated outputs. Most don't.
Companies using AI tools are dealing with third-party vendor questions mixed with employment law, IP, and privacy questions. Your GL and cyber policies are in the picture, but so are forms most operations teams have never reviewed. And in Illinois, the state statutes create additional exposure that doesn't depend on anyone suing you in federal court.
What coverage actually exists
Tech E&O / Professional Liability. If your business provides services and AI is part of how you deliver them, professional liability coverage matters. A consultant using AI to generate analysis, a marketing firm producing AI-written deliverables, a legal tech company whose product summarizes contracts. When the AI output is wrong and the client loses money, the Tech E&O policy is supposed to respond.
Whether it actually does depends on the form language. Some carriers have issued AI endorsements that extend coverage to AI-generated outputs. Others have added exclusions that carve them out. If you don't know which category your policy falls into, that's the first question to answer. The form from 2022 is a different product than what's being written in 2026.
Cyber insurance. Cyber is primarily first-party coverage. It responds to what happens to your company when your data or systems are compromised. But there's a second-order AI question: if your employees are pasting customer data into a commercial AI tool and that tool has a breach or a data leak, does your company's privacy liability trigger? Some cyber forms include regulatory defense for privacy violations. Others don't. AI tools that ingest sensitive data are a new surface for an old question, and the answer isn't consistent across carriers.
General liability. Standard CGL wasn't built for AI. ISO published two AI exclusions in January 2026, designated CG 40 47 and CG 40 48, and several carriers have been filing these with state regulators, including in Illinois. If your GL policy carries those endorsements, bodily injury and property damage arising from AI-related incidents may be excluded entirely. If you're not sure, look at your declarations page for those form numbers. It's worth a few minutes to find out before a claim.
Media liability and IP coverage. This one's growing fast and most businesses haven't thought about it yet. Generative AI produces content, and that content sometimes reproduces material from training data in ways that trigger copyright or trademark claims. The litigation is active now. Some Tech E&O forms include media liability as a sub-coverage. Standalone media liability policies exist. If your business publishes AI-generated content at any real volume, whether blog posts, product copy, images, or customer communications, this question deserves a specific answer rather than an assumption that your existing policies cover it.
Employment practices liability. Illinois employers using AI in hiring decisions have lived under HB 3773 since January 1, 2026. The statute creates strict liability for using AI tools that create a disparate impact in hiring or promotion by race, color, sex, national origin, disability, or age. Intent isn't a defense. There's no minimum employer size. A 10-person company with a basic AI resume screening tool carries the same statutory exposure as a 5,000-person company.
EPLI forms haven't universally caught up to this. Some EPLI carriers are adding explicit AI hiring exclusions. If your business uses AI anywhere in talent decisions, your EPLI form should be on the list of things to read before renewal.
The vendor AI clause problem
This is the gap most businesses are completely missing.
When you sign up for a third-party AI platform and click through the agreement, you've probably accepted indemnification terms that shift liability onto you if the tool's outputs cause harm. Enterprise-grade AI vendor agreements often include clauses that indemnify the vendor for misuse, for outputs relied on without human review, or for use in applications outside the vendor's stated use cases.
Some of those clauses are reasonable. Some are aggressively one-sided. And a lot of Illinois businesses are running their operations on AI tools whose contracts nobody has actually read.
This isn't a coverage problem you can insure your way out of. It's a contracting problem. But the insurance consequence is real. A claim arising from a vendor AI clause that shifts liability onto your business may not fall cleanly within any existing policy if the underlying incident was caused by third-party AI you don't control. You can end up holding a loss that no carrier agreed to cover because nobody mapped the vendor agreement to the policy terms.
What Illinois businesses specifically should know
Illinois is one of the most active states for privacy and AI legislation. That changes the insurance calculus for businesses operating here.
BIPA creates strict per-violation damages for collecting biometric data without written consent. The statute defines voiceprints as a biometric identifier. AI meeting tools that do speaker identification, voice authentication systems, and facial recognition tools in the workplace are all potential BIPA exposure. The Cruz v. Fireflies.AI case (active litigation as of late 2025) raised the specific question of whether AI speaker diarization in meeting transcription constitutes voiceprint collection under BIPA. Cyber policies sometimes cover BIPA regulatory defense. Standard GL policies typically don't.
GIPA (the Illinois Genetic Information Privacy Act) creates $2,500 to $15,000 in damages per violation for collecting genetic information without consent. Pre-employment physicals that include family health history questions are the most common trigger. GIPA damages run three to six times higher than BIPA on a per-violation basis, and almost no coverage literature exists for it. It's an exposure most businesses in Illinois aren't thinking about at all.
HB 3773, effective January 1, 2026, covers AI-assisted hiring discrimination with no floor on employer size. It's not limited to tech companies or companies whose primary product is AI. It covers any Illinois employer using AI tools in talent decisions. Most HR technology platforms have some AI layer in them now, which means the exposure is broader than people realize.
None of those statutes require proof of intent. They care about whether the requirements were violated.
What to actually do
Start with a complete list of every AI tool your business is using, including the tools individual employees adopted on their own without going through IT or procurement. Shadow AI use is common, and the exposure travels with the tool regardless of how it was procured.
Then pull the policy forms for Tech E&O, cyber, GL, and EPLI. If you don't have Tech E&O and you're using AI in client-facing work, that's a significant coverage gap. If you have it, look for AI-specific exclusions or endorsements. Check GL for the ISO CG 40 47 and CG 40 48 endorsements. Review your EPLI for AI hiring language.
Read the vendor agreements for the AI tools your business relies on most heavily. The indemnification clauses, the use limitation language, and the data processing terms are the most relevant sections for insurance purposes.
And work with a broker who actually understands where this market is right now. AI insurance is evolving faster than most brokers' working knowledge. Carriers are filing new exclusions, creating new endorsements, and building standalone AI liability products on a timeline that makes 2023-vintage advice genuinely unreliable. You want someone who's read the current forms, tracks what's being filed in Illinois, and can tell you specifically what your policies will and won't do when a claim shows up.
A licensed commercial producer at an independent brokerage in the RateShield trusted network can help. Call (773) 850-3801.