Ask a small business owner who is liable when an AI tool gets something wrong and you tend to get one of two answers: “the software company, surely” or a slightly nervous shrug. Neither is much comfort when a client rings about a figure in your report that turns out to have been invented, or when a CV-screening tool quietly filters out half of your applicants.
In nearly every scenario that matters to an SMB, the liability lands on you — the business that used the output, not the vendor that generated it. This guide sets out where the risk sits, what your vendor's terms promise, where standard insurance stops, and the controls that meaningfully reduce your exposure. It is general information rather than legal or insurance advice: the specifics depend on your jurisdiction, your contracts and your policy wording, so treat it as a checklist for your broker and your solicitor.
Where AI liability actually lands
Three parties could in theory carry the can: the vendor who built the model, the employee who used it, and the business that sent the output to a client. In practice the third absorbs almost all of it.
Your client contracted with you, and is owed the standard of care a competent professional in your field would exercise. That duty does not thin out because you used a tool: “the AI did it” reads, legally, much like “the spreadsheet did it”. Your employee is covered by the same principle in reverse — employers are generally vicariously liable for staff acting in the course of their work, so the junior who pasted the client list into a chatbot does not become the defendant.
There are four kinds of AI-related harm a small business realistically causes, and they map onto different parts of your risk cover:
- Wrong or fabricated information in advice, reports, proposals or client communications — a professional negligence problem.
- Data protection breaches, usually from pasting personal or confidential data into a consumer-tier tool — a regulatory and contractual problem.
- Discriminatory outcomes in hiring, pricing, lending or scheduling — an employment and consumer-law problem, and in the EU often a regulated high-risk use.
- Intellectual property infringement in generated images, copy or code — an IP problem that lands wherever the output was published.
Notice what these have in common: the harm is caused when the output leaves your business, not when the model produced it. That is the most useful thing to understand about AI liability, because it tells you where to put your controls.
What your AI vendor's terms really say
Pull up the terms of service for the three AI tools you use most. You will find some version of the following each time.
The service is provided “as is”, with no warranty of accuracy. Vendors are explicit that outputs may be wrong and that reviewing them is your job. Several go further and prohibit relying on outputs for professional advice without human review.
Liability is capped at the fees you have paid — typically the preceding 12 months, sometimes the preceding one to three. Do the sum: a ten-person team on a €25 per-user plan pays €3,000 a year, so the cap is €3,000, or €750 on a three-month cap. Against a professional negligence claim, a lost tender or a regulator's attention, those are rounding errors.
The indemnity usually runs towards the vendor, not away from it. You typically agree to indemnify them against claims arising from your use of the service. Some business tiers now add a copyright indemnity for claims that an output infringed someone's IP — a genuine benefit, but conditional: paid plans only, safety filters left on, and no knowingly infringing prompts. It does not cover a client suing you because a number was wrong.
Data handling depends on your tier. Consumer tiers may use your inputs to improve the service unless you opt out; business tiers generally do not train on your data and will sign a data processing agreement. If you handle client-confidential material, that is the difference between a defensible position and an indefensible one.
None of this is unreasonable — it is how software has always been sold. The point is that you cannot transfer the risk upstream by buying a bigger plan.
Where your insurance quietly stops covering you
Most SMBs delivering advice or professional services carry professional indemnity (PI) cover, often alongside public liability and a cyber policy. Three gaps open up once AI is part of how the work gets done.
Silent AI. Most policies written before 2025 say nothing about artificial intelligence, and silence is not the same as cover — it means the question gets argued at claim time, the worst possible moment to find out. Insurers have spent two renewal cycles deciding what they think, and the results are landing in wordings now: sometimes an explicit extension, sometimes an exclusion for “automated decision-making” or “generative artificial intelligence”.
The cyber/PI boundary. Cyber policies are built around attacks: ransomware, intrusion, business email compromise. An employee pasting a client's personal data into a free chatbot is none of those — it is authorised use of a sanctioned device by a trusted person, which many cyber policies treat as out of scope while PI treats it as a data issue rather than a professional error. Ask which policy picks it up, in writing.
Material change and disclosure. Insurance contracts run on what you told the insurer when you applied, and in several markets adopting a materially new method of delivering your services counts as a change you must disclose. If your renewal questionnaire asked about AI and the answer has since changed, update it — a disclosure argument is far cheaper to settle before a claim than after one.
Four questions to ask your broker this month
This takes one email and costs nothing. Ask for the answers in writing, and keep the reply with your policy documents.
- Will this policy respond to a claim where AI-generated content contributed to the error? Not “is AI covered”, which gets a vague answer. Describe the scenario: a report we produced with AI assistance contained an inaccurate figure, the client relied on it, and they are claiming their loss.
- Does any part of my cover exclude artificial intelligence, machine learning or automated decision-making? Ask them to point to the clause, or to confirm in writing that there is none.
- Which policy responds if an employee discloses client data to a third-party AI service by accident? If the answer is “cyber”, check that the definition of a covered event does not require an attack or unauthorised access.
- Do I need to notify you that AI is now part of how we deliver work, and what evidence would you want after an incident? The second half matters more than it sounds: the answer is almost always a record showing which tools were approved, who reviewed the output and when — which tells you exactly what to start keeping.
Five controls that limit your exposure
You cannot buy this risk away, but you can make it much smaller — and every item below is achievable in an afternoon with no legal team.
1. A named human signs off on anything that leaves the building. Not “someone checks it” — a named role, recorded. This one control converts an indefensible position into a defensible one, because you are judged on whether a competent professional reviewed the work, not on whether a machine helped produce it.
2. Keep confidential and personal data out of consumer tiers. Decide which tools are approved for client data, put them on business plans with a data processing agreement and training switched off, and say plainly which tools are not approved. Unapproved tools get used when the sanctioned path is awkward, so make it the easy one.
3. Write AI into your client contracts. Disclosure of AI assistance, a limitation of liability, and clarity on who owns the output are all straightforward to add at your next contract refresh. Our guide to AI clauses for client contracts covers the specific wording, including how to mirror your vendor's cap rather than absorbing an unlimited one.
4. Verification rules for facts, figures and citations. The rule that prevents most real incidents is boring: any number, quotation or legal reference going to a client carries a link to its primary source, or it comes out of the document. See how to prevent AI hallucinations in client work for the full workflow.
5. Keep a one-page record, and a plan for the bad day. Which tools are approved, for which processes, reviewed by whom, last checked when. Your insurer, your client's procurement team and your solicitor will all ask for it, and it takes fifteen minutes a quarter to maintain. Pair it with a short AI incident response plan so the first hour after a mistake is spent containing it, not deciding who to call.
A worked example: the invented statistic
A nine-person consultancy sends a market-sizing section in a tender response. One statistic is attributed to an industry report that does not exist — the model invented a plausible title, publisher and figure. Procurement cannot find the source, asks, and withdraws the consultancy from a €40,000 tender. They also ask for a credit note on the previous engagement, on the grounds that they can no longer trust its numbers.
Walk the money through. The vendor's cap is three months of subscription at €25 for nine users — €675 — and in practice the vendor owes nothing, because its terms required the consultancy to verify outputs. The PI policy may respond to the credit-note claim, assuming no AI exclusion, less a €2,500 excess. The lost tender is not an insurable loss at all, because nobody sued for it, and neither is the reputational cost of being the firm that submitted a fabricated citation.
Total recoverable: a few hundred euros against a five-figure loss. Cost of the control that would have prevented it: one line in a checklist requiring every external figure to carry a working source link.
The bottom line
AI liability is not a new category of law so much as an old one with a faster failure mode. The duty of care you already owe clients is unchanged; what has changed is how quickly a confident, well-formatted, entirely wrong document can reach them. Your vendor's cap will not cover it and your insurer may not yet have decided whether they will, so the realistic strategy is to shrink the probability rather than hope to transfer the cost.
Do the two cheap things this month: email your broker the four questions above, and introduce a named sign-off plus a source-link rule for anything that leaves the business. If your AI use touches hiring, pricing or anything else a regulator would call high-risk, add your regulatory obligations to that list — a more demanding conversation than professional negligence, and one worth having before you scale the use case rather than after.
Where does your business stand on AI?
Take the free 3-minute AI Readiness Quiz and get a personalised score with your next steps.
Take the Free Quiz →