Key Takeaways
- ·Malpractice policies that cover employed providers will generally cover AI-related claims framed as negligence by the hospital — but policies are not yet updated to clearly address AI-related incidents, creating ambiguous coverage.
- ·Coverage may be circumstance-dependent: if a clinician exercised independent judgment, coverage is more likely. If a clinician blindly trusted a flawed AI recommendation, an insurer may argue the standard of care wasn't met.
- ·By 2026, some insurers are introducing AI policy riders to malpractice coverage and requiring organizations to demonstrate governance aligned with the NIST AI Framework as a condition of coverage.
- ·Some insurers are offering premium incentives for organizations following CHAI or AMA governance guidelines — and raising premiums for heavy AI use without oversight.
- ·Insurance product development is explicitly described as lagging AI deployment. Actual coverage gaps may be wider than currently documented.
- ·Multi-layered exposure is common: cyber insurance may apply if AI failure stems from hacking or data issues, and professional liability coverage must be verified against actual AI-influenced workflows.
The short answer
You should not assume your existing malpractice policies adequately cover AI-related incidents. The coverage is probably there for well-structured claims, but the terms are ambiguous, coverage can be circumstance-dependent based on whether clinicians exercised independent judgment, and insurers are actively updating their products in ways that may create new conditions or gaps. The right step is a direct conversation with your insurer and broker specifically about AI. Ask about exclusions, ask whether AI use is a material misrepresentation risk if you didn't disclose it, and ask how governance documentation affects coverage determinations.
What the Coverage Landscape Actually Looks Like
Malpractice insurance policies that cover acts by employed providers will generally cover AI-related claims if framed as malpractice or negligence by the hospital. This is the baseline — and it's a meaningful baseline. But the word "generally" is doing significant work in that sentence, and the conditions under which coverage might not apply are exactly the conditions most likely to arise with AI-assisted clinical decisions.
The Doctors Company, one of the larger physician-focused malpractice insurers, has published guidance indicating they would likely cover clinicians who exercised appropriate due care — but notes that if a clinician blindly trusted a flawed AI recommendation without applying independent clinical judgment, the insurer might argue the clinician failed to meet the standard of care. That's not a theoretical scenario. Alert fatigue, over-reliance on automated decision support, and insufficient clinician training on AI tool limitations are well-documented patterns in healthcare settings where AI is in use.
The broader problem is that most existing malpractice policies were written before AI-assisted clinical decision support became standard in hospital workflows. The language in those policies doesn't address AI specifically, which means coverage determinations will depend on how claims are framed and how individual insurers interpret existing policy terms in a new context. That ambiguity resolves differently across insurers and across claim circumstances — which is the definition of coverage uncertainty.
The Asymmetric Risk Problem
The literature describes AI coverage uncertainty as "asymmetric risk": your organization bears the liability exposure while coverage terms remain ambiguous. An adverse event involving AI in your clinical workflow creates liability that is yours regardless of how the insurance coverage question resolves. The coverage uncertainty doesn't reduce the liability — it just adds another layer of uncertainty about how that liability will be financed.
How Insurers Are Changing Their Approach in 2026
The insurance industry is moving, if slowly. Several developments are underway that health system executives need to be tracking, because they affect not just renewal terms but active coverage conditions.
The most significant development is that some insurers are now introducing what are being called "AI policy riders" to malpractice insurance products. These are specific provisions addressing AI-assisted clinical decisions, and in some cases they come with conditions: organizations may be required to demonstrate "reasonable security" aligned with the NIST AI Framework as a condition of that coverage applying. This is a meaningful shift from a world where governance was entirely aspirational to one where it can become a contractual requirement for coverage.
AI use questions on applications
Some insurers have begun asking on malpractice insurance applications whether organizations use AI or algorithmic clinical decision support, and requesting descriptions of their governance processes. If your organization is using AI tools and didn't disclose that on your most recent application, this is worth reviewing with your broker. Non-disclosure of material risk factors is a potential grounds for coverage denial.
AI policy riders with governance conditions
By 2026, some insurers are introducing standalone AI coverage riders that require the organization to demonstrate governance practices aligned with recognized frameworks such as NIST AI RMF as a condition of that coverage applying. If you purchase a rider but your governance practices don't meet the specified threshold, the rider may not respond to a claim.
Premium incentives and penalties
Insurers are beginning to offer premium incentives for organizations that can document mature AI governance following CHAI or AMA guidelines. The other side of that dynamic is that organizations with heavy AI use and no documented governance posture are seeing premium increases at renewal. Governance is becoming financially visible in a way it wasn't 18 months ago.
Cyber insurance overlap
If an AI-related adverse event stems from a security incident — a compromised AI model, a data integrity issue affecting AI inputs, or a hacking incident that manipulates AI outputs — the claim may also trigger your cyber insurance. Organizations should verify with both their malpractice and cyber insurers how these policies coordinate in AI-related incident scenarios, because coverage gaps at the boundary between the two policies are a documented risk.
The Standard of Care Question
Malpractice liability turns on whether the standard of care was met. AI introduces two related complications to that analysis. First, the standard of care for AI-assisted clinical decisions is not yet well-defined in case law — there isn't a large body of settled litigation establishing what "reasonable care" looks like when a clinician uses AI output. Second, the standard of care may be evolving in ways that create exposure for organizations that haven't kept up.
The "reasonable physician" standard in malpractice law is typically measured against what a similarly situated physician in similar circumstances would do. As AI tools become standard in clinical workflows, the standard of care may eventually reflect expectations around how AI should be used — including when to override it, how to document AI-informed decisions, and what monitoring responsibilities clinicians have for AI recommendations they act on.
Organizations that can demonstrate they thought through these questions — through governance policies, clinical training, and documentation practices — are in a substantially better position in a malpractice claim than organizations that deployed AI without addressing them. That's true both for litigation outcomes and for coverage determinations.
Insurance Product Development Is Lagging AI Deployment
The insurance industry's own assessments describe their product development as explicitly lagging AI deployment in healthcare. That means the coverage gaps that exist today are not yet fully visible — they will become apparent as claims accumulate. Organizations that discover their policies don't cover an AI-related incident after the incident has occurred are in the worst possible position: facing a claim with no clear coverage, no documented governance, and no contemporaneous evidence that they assessed the risk. The time to address this is before an incident, not after.
Vendor Indemnification and Contract Provisions
Malpractice coverage addresses your organization's liability exposure. It doesn't address the relationship between your organization and your AI vendor when the vendor's product is implicated in an adverse event. These are separate legal and financial questions that require separate attention.
Vendor contracts for AI clinical tools frequently include broad limitations of liability that cap the vendor's exposure to the contract value, exclude consequential damages, and disclaim responsibility for clinical outcomes. In practice, this means that even when a vendor's AI product performs as marketed but that performance is insufficient to prevent an adverse outcome, your organization may bear the full liability while the vendor faces limited or no exposure. The Pieces Technologies enforcement action illustrates one path — regulatory action by a state AG — but that path doesn't deliver compensation to the affected health system for adverse outcomes.
Indemnification provisions
Vendor AI contracts should include indemnification provisions requiring the vendor to defend and indemnify your organization for claims arising from the vendor's AI performing in ways inconsistent with the vendor's representations. Most standard vendor contracts don't include this language. It requires negotiation.
Limitation of liability review
Review the limitation of liability clauses in every active AI vendor contract. Understand what the vendor's maximum exposure is under the contract and whether that exposure is proportionate to the clinical risk the tool creates. If a vendor's contract limits their liability to the annual contract value while the tool is making recommendations in high-acuity clinical settings, that's a mismatch worth addressing.
Performance warranty terms
Some AI vendor contracts include performance warranties that create a basis for recovery if the tool performs materially below its stated specifications. Review whether your current contracts include these terms and whether the specifications in the contract reflect what was actually marketed to you during the procurement process.
What to Actually Do
The practical steps here are straightforward, even if implementing them takes time. They reduce both actual liability exposure and coverage uncertainty.
Review current policies with your insurer and broker
Schedule a conversation specifically about AI. Ask whether AI use in clinical workflows is a material fact that should be disclosed on your policy. Ask about any AI exclusions or limitations in your current policy language. Ask what their claims-handling approach would be for an AI-related adverse event under your current coverage.
Ask about AI riders and governance-linked coverage
Ask your insurer whether they offer AI policy riders, what the conditions are for those riders to respond to a claim, and whether demonstrating governance aligned with NIST AI RMF or CHAI guidelines affects premium or coverage. You may find that the conversation reveals options you weren't aware of.
Review vendor contracts for indemnification and liability terms
Engage your legal counsel to review the limitation of liability, indemnification, and performance warranty terms in every AI vendor contract. Identify gaps and determine whether renegotiation is appropriate. At minimum, document the review and the organization's risk acceptance for contracts where the liability terms are unfavorable.
Build the governance documentation that coverage determinations will rely on
When an AI-related claim reaches your insurer, the coverage determination will turn partly on whether your organization demonstrated reasonable care in deploying and overseeing the AI tool. Governance policies, validation documentation, training records, and monitoring logs are the evidence of reasonable care. Building this infrastructure is both the right governance practice and the right insurance posture.
Verify coordination between malpractice and cyber insurance
Confirm with both insurers how the policies coordinate in an AI-related incident scenario where the AI failure has a data integrity or security dimension. Identify any coverage gaps at the boundary and address them before a claim makes the gap visible.
Frequently Asked Questions
Common questions healthcare executives ask about malpractice coverage and AI liability.
If our clinician follows an AI recommendation and a patient is harmed, who is liable?
The clinician and the hospital retain the primary liability exposure. AI does not transfer responsibility for clinical decisions to the vendor — the clinical professional who acts on AI output is still the licensed practitioner responsible for patient care. The key variable for coverage is whether the clinician exercised appropriate independent judgment before following the recommendation. If the clinician reviewed the AI output, applied clinical reasoning, and made a judgment call that turned out to be wrong, that's a standard malpractice analysis. If the clinician simply accepted the AI recommendation without independent review, an insurer may argue the standard of care wasn't met, which creates coverage risk. This is why training clinicians on the appropriate use of AI tools — including when and how to apply independent judgment — is a governance priority, not just a training priority.
Does our vendor's FDA clearance shift liability to the vendor if their AI performs incorrectly?
Generally, no. FDA clearance establishes that a medical device met a regulatory threshold for market approval. It doesn't create a direct liability relationship between the vendor and your patients, and it doesn't shift the standard of care analysis for your clinicians. Vendors typically rely on limitation of liability clauses in their contracts, not regulatory clearance, as their primary liability protection. The Texas AG Pieces Technologies settlement illustrates that vendors can face regulatory consequences for misleading marketing, but that enforcement action didn't deliver compensation to affected health systems or their patients. Your organization's malpractice exposure from AI-related adverse events is primarily governed by your contract with the vendor and the standard of care analysis applied to your clinicians' decisions.
Are there AI-specific exclusions in standard malpractice policies?
Most existing malpractice policies were written before AI-assisted clinical decision support became widespread, so they typically don't include AI-specific exclusions. They also don't include AI-specific coverage confirmations. The gap is the ambiguity: policy language designed for traditional clinical decision-making scenarios is being applied to situations involving AI recommendations, and how that language applies depends on how claims are framed and how individual insurers interpret their policies. Some insurers are beginning to add AI-specific language through riders or endorsements. Whether that language adds coverage or creates new conditions and exclusions depends on the specific product. This is why a direct conversation with your insurer about AI specifically is warranted.
What does 'governance as a coverage condition' actually mean in practice?
By 2026, some insurers are introducing AI policy riders that include specific conditions for coverage to apply, one of which may be that the organization has demonstrated governance practices aligned with recognized frameworks like NIST AI RMF. In practice, this means that if your organization purchases a rider but doesn't have the governance practices the rider requires, the rider may not respond to an AI-related claim. This is analogous to a cyber insurance policy that requires specific security controls: if you claim coverage under a policy that required MFA and you didn't have MFA enabled, the insurer may deny the claim. Organizations purchasing AI-specific insurance products need to read the conditions carefully and verify their governance practices actually satisfy them.
Should we require AI vendors to carry their own insurance?
Yes, and you should verify they have it. Vendor contracts for AI clinical tools should specify minimum insurance requirements, including errors and omissions coverage and general liability, and should require the vendor to provide certificates of insurance naming your organization as an additional insured. This doesn't eliminate your organization's liability exposure, but it creates a source of recovery from the vendor if the vendor's product is implicated in an adverse event. The practical challenge is that many AI vendors are smaller companies, and their coverage limits may not be proportionate to the clinical risk their tools create. Understanding the vendor's insurance posture should be part of your vendor evaluation process.
What's the relationship between AI governance and our insurance premiums?
The relationship is becoming more direct. As of 2026, some insurers are offering premium incentives for organizations that can document governance practices following CHAI or AMA guidelines, and raising premiums at renewal for organizations with significant AI use and no documented governance. The direction of travel is clear: insurers are building AI governance posture into their risk assessment of healthcare organizations, and organizations that haven't invested in governance will pay more for the same or weaker coverage over time. Beyond the premium question, documented governance is increasingly relevant to coverage determination in the event of a claim. The organization that can demonstrate it had a structured governance program, trained its clinicians, monitored AI performance, and documented its decisions is in a substantially better position than one that cannot.
Sources
- The Doctors Company. AI and Physician Liability: Guidance for Clinicians Using AI Clinical Decision Support. 2024.
- 2026 Landscape of Artificial Intelligence Governance in Healthcare. Internal knowledge synthesis from regulatory and governance landscape analysis. 2026.
- AI Governance in Healthcare: Current State, Frameworks, Implementation Evidence, and Gaps. Internal knowledge synthesis. 2025.
- Legal Pitfalls, Tips, and Strategies for AI in Healthcare Organizations. Reference analysis of AI liability exposure and contract provisions. 2025.
- NIST AI Risk Management Framework (AI RMF 1.0). National Institute of Standards and Technology. January 2023.
- Coalition for Health AI (CHAI). "Blueprint for Trustworthy AI Implementation Guidance and Assurance for Healthcare." 2023, updated 2025.
- State of Texas v. Pieces Technologies, Inc. Office of the Texas Attorney General. 2024.
Related Questions
- ›Who is liable when an AI clinical decision support tool contributes to harm?
- ›How do we evaluate an AI vendor's claims before signing a contract?
- ›Does our vendor's BAA actually prevent them from using our patient data?
- ›What to require from AI vendors before deployment?
- ›How should we document AI-assisted decisions in the medical record?
- ›What should our board be asking about AI risk?

