A west suburban HVAC contractor started using an AI scheduling and dispatch agent eighteen months ago. It handles incoming service requests, assigns technicians, quotes jobs, and coordinates parts orders with three different suppliers. Runs around the clock. Cut administrative overhead by roughly 30 percent. The owners thought they'd figured it out.
Then a supplier dispute landed in their lap. The AI had been generating purchase orders using a pricing formula that didn't account for a contract amendment from six months earlier. By the time anyone caught it, the company had $112,000 in materials commitments at the wrong price. Legal fees to unwind the contracts cost another $22,000.
Their commercial broker reviewed the program. The GL doesn't cover economic harm without a physical component. The E&O policy has AI ambiguity in the insuring agreement. The crime policy doesn't reach it because no employee was defrauded. The cyber policy has an FTF provision that requires a human to have received a fraudulent instruction.
Four policies. None of them clearly responded to the loss.
This isn't an edge case anymore. Illinois manufacturers, contractors, schools, and property managers are deploying AI agents in operational roles. The same commercial program that worked fine before doesn't automatically cover what those agents do. Five coverage lines are worth checking now rather than at claim time.
Gap 1: Your crime policy doesn't recognize your AI agent as an employee
Commercial crime policies cover theft, fraud, and fidelity losses. Most include a funds transfer fraud provision and a computer fraud provision. Both sound like they should cover losses that occur when an AI agent gets manipulated or makes a bad payment decision.
The problem is the definition of "employee."
ISO's standard commercial crime form defines employee as a natural person. That's a legal term meaning a human being. It doesn't include software. It doesn't include automation. It doesn't include an AI agent authorized to act on your company's behalf.
When your AI purchasing agent commits the company to an overpriced contract because a vendor fed it manipulated pricing data, that transaction wasn't made by an employee. The crime policy's coverage structure doesn't reach it cleanly. The funds transfer fraud provision, the computer fraud provision, the employee theft provision - all of them key off definitions written when "someone acting on behalf of your company" meant a human being.
Some crime forms have first-party loss language broad enough to reach AI-initiated fraud losses. But that's not standard, and it varies by carrier and form. Knowing whether yours has it requires reading the actual definitions, not the insuring agreement headings.
Gap 2: General liability covers physical harm, not what AI agents usually cause
Your commercial general liability policy covers bodily injury and property damage. A customer slips on your floor, GL responds. A contractor breaks a client's window, GL responds. Physical harm to a physical thing.
AI agents mostly cause a different kind of harm. They give wrong information. They make bad scheduling decisions. They commit your company to contracts you didn't intend to sign. They generate content that turns out to be inaccurate. That's economic harm, not physical harm.
Most GL forms have explicit exclusions for economic losses that don't stem from bodily injury or property damage. When your AI customer service agent tells a client their order ships in three days and it takes three weeks, the resulting losses almost certainly don't have a physical component. GL doesn't get there.
And since January 2026, there's a second GL problem. ISO filed endorsements CG 40 47 and CG 40 48, which specifically exclude coverage for AI-generated content and AI-enabled systems. AIG filed AI exclusion language with the Illinois Department of Insurance specifically. If your GL policy renewed in 2026 and your carrier adopted these endorsements, AI-related harm may now be explicitly excluded even where the old policy language might have reached it.
Most business owners don't know their GL endorsement schedule changed at renewal. It usually doesn't affect the premium, and nobody calls to explain it. Pull your current endorsement schedule and look for form numbers in the CG 40 4x range or any endorsement with "artificial intelligence" in the title.
Gap 3: E&O covers professional judgment, and AI output isn't clearly that
Professional liability, called E&O, is the natural coverage for a mistake that causes a client financial harm. An accountant makes a calculation error, a consultant gives bad advice, a contractor misspecifies a design. E&O exists for exactly those situations.
AI-generated errors look similar but don't land in the same place legally.
E&O is built around human professional judgment. The policy covers a person who made an error in a professional service. When an AI tool generates the output and the output is wrong, there's a real question about whether that constitutes a "professional service" under the insuring agreement. Some underwriters have decided it does. Others haven't. When they're undecided, you find out at claim time.
E&O also typically covers claims from clients you had a direct professional relationship with. If your AI agent's output harms a third party who wasn't your direct client, your E&O may not respond at all.
Then there are the exclusions. ISO's January 2026 filings touched professional liability forms the same way they touched GL. Some carriers have added explicit AI exclusions to their E&O policies. If you're an Illinois contractor, manufacturer, or school using AI tools that touch professional decisions, your E&O renewal this year may look different from last year's. Ask your broker to pull the endorsement schedule and look for any AI-related language before you assume the coverage stayed the same.
Gap 4: EPLI wasn't written for strict liability AI hiring violations
Illinois HB 3773 took effect January 1, 2026. If your company uses any AI tool to screen, score, rank, or evaluate job applicants, the statute applies. No minimum employer size. A five-person DuPage County shop using an AI resume filter is in scope.
The statute is strict liability. Intent isn't a defense. If the AI produces a biased outcome, your company can be liable whether or not you knew, whether or not you reviewed any individual score, and whether or not the AI was built and maintained by a third-party vendor.
Standard EPLI was designed for human conduct. A manager made a biased decision. A supervisor created a hostile environment. HR failed to properly document a termination. These are human acts that flow through EPLI's insuring agreement in a way courts and carriers recognize.
A strict liability regulatory violation produced by an algorithm your company licensed doesn't fit that structure the same way. Whether your EPLI insuring agreement reaches it depends on how "wrongful employment practice" is defined in your specific form and whether your carrier takes the position that AI output constitutes a discriminatory act by a covered person.
The regulatory defense gap compounds this. IDHR investigations under HB 3773 start long before any lawsuit. If your EPLI only triggers on civil litigation, the $30,000 to $75,000 in legal fees you'll spend in the regulatory phase isn't covered at all. That's where most HB 3773 exposure actually lands first, in the investigation phase, before a complaint becomes a lawsuit.
Illinois manufacturers and schools who've automated any part of their hiring process need to know whether their EPLI covers this before a complaint arrives.
Gap 5: Cyber FTF provisions assume a human got manipulated
Cyber insurance is often the last hope when other policies don't clearly respond to a technology-related loss. Cyber policies do have provisions that look relevant: funds transfer fraud, computer fraud, social engineering coverage.
But cyber FTF provisions were designed for a specific attack pattern. A fraudster sends a spoofed email to your CFO. A human reads it. The human initiates a wire. Your business loses money. That's the pattern FTF covers in most standard cyber forms.
When an AI agent receives a manipulated input and initiates a transfer on its own authority, there's no human receiving the fraudulent instruction. The fraudster communicated with the AI. The AI acted. Whether your FTF provision reaches that scenario depends on whether your specific form requires the fraudulent instruction to land on a person, or whether the language is broad enough to cover instructions received by an automated system.
Most forms aren't broad enough. They were written before businesses were authorizing AI agents to move money. The language reflects the world that existed when the forms were developed.
Some cyber carriers offer broader first-party loss coverage that might reach AI-directed financial losses. But this is the least standardized part of the cyber market, varying more across forms than almost anything else in commercial coverage. You need the actual language in front of someone who knows what to look for.
What an actual AI coverage audit looks like
Five questions, one per coverage line.
Crime: How does your form define "employee" and what mechanism does the funds transfer fraud provision require? Does that definition reach an AI-initiated transaction?
GL: Does your current endorsement schedule include CG 40 47, CG 40 48, or any carrier-specific AI exclusion filed with the Illinois DOI? If so, what does it exclude?
E&O: Does your insuring agreement define "professional services" in a way that reaches AI-generated output? Are there AI exclusions in the endorsement schedule?
EPLI: Does the policy cover administrative and regulatory proceedings, not just civil lawsuits? Does the insuring agreement's definition of a wrongful act reach a strict liability AI hiring violation?
Cyber: What triggers the funds transfer fraud insuring agreement? Does it require a human to receive the fraudulent instruction, or is the language broad enough to reach an AI-directed transfer?
None of these questions take long to answer with the right broker. They all require reading the actual policy forms, not the summary pages. The answers will tell you whether your commercial program covers what your AI agents are actually doing.
Illinois businesses running AI can't assume their coverage moved with them
A Naperville property management company. A Will County school district that automated part of its hiring process. A DuPage County manufacturer with an AI procurement agent. A west suburban contractor whose AI handles scheduling and dispatch.
None of these businesses thought of themselves as AI companies when they deployed these tools. They thought of themselves as operations that found a more efficient way to handle a function.
The insurance market doesn't see it that way. From an underwriting standpoint, a company whose AI agent commits it to contracts, screens job applicants, or routes financial transactions carries AI liability exposure whether or not the company thinks of itself as being in the AI business.
The five coverage lines above weren't designed to cover that exposure automatically. Some have been updated to exclude it explicitly. Others have language ambiguous enough that you'd be betting on favorable interpretation at claim time.
That's not a comfortable position, and it's not one worth carrying quietly when the alternative is knowing exactly where you stand.
If you're an Illinois business using AI agents in manufacturing, contracting, property management, education, or any other commercial context, reach out to Jack Ray directly. He handles commercial accounts across DuPage County, the Chicago suburbs, and the broader Illinois market and can walk through your current program against each of these five gaps.
Email: jray@lakeshoreriskadvisors.com