Editor's note.
This article describes the general architecture of defence costs, conduct of claims and settlement provisions in liability contracts written in the London and European markets, and applies it to AI claims. No individual carrier wording is quoted and no clause identifier is asserted. One named product is cited, Armilla's Affirmative AI Liability Insurance, using only wording Armilla publishes on its own site. The worked figures in section three are illustrative and are not attributed to any insurer, product or claim.
- Two structures exist. Costs inclusive pays defence out of the limit, so the limit is a budget for the whole event. Costs in addition pays defence outside it, so the limit is a budget for the outcome only.
- AI claims are unusually defence heavy because causation is the substance of the dispute, not a preliminary to it. Expert evidence, forensic reconstruction and disclosure against a non-party model provider are all in the ordinary case.
- On a costs inclusive policy the insurer and the insured can rationally want different things. Defending hard protects your reputation and consumes the money that would otherwise settle the claim.
- Defending a civil claim, being represented at a regulatory investigation, and paying a fine are three separately insurable things. Most programmes cover the first, cover the second only by extension, and treat the third as a question of national law.
- Armilla publishes that its cover extends to AI Regulatory Violations including defence costs and insurable fines under the EU AI Act and the Colorado AI Act. The qualifier insurable is not decoration.
- A serious incident report under Article 73 is not a claim, but it is very likely a notifiable circumstance. Decide the notification rule before the two day clock starts, not during it.
Section 1. The two structures
Every liability policy has to answer a question that has no natural answer: when the insurer spends money on lawyers, experts and court fees, whose money is it.
Costs in addition. Defence spend is paid on top of the limit of indemnity. A policy with a limit of EUR 2,000,000 will pay up to EUR 2,000,000 in damages and settlements and will separately fund the defence. The insured's protection against the outcome is unaffected by how expensive the argument was.
Costs inclusive. Defence spend erodes the limit. The same EUR 2,000,000 policy now provides a total of EUR 2,000,000 for everything, and whatever is spent arguing is no longer available to pay. In some markets this is described as an eroding or wasting limit, which is a more honest name for it.
Neither structure is a defect and both are widely written. Professional indemnity in several European markets is commonly costs inclusive; certain cyber and technology structures are written costs in addition; and mixed programmes are ordinary, where one policy in the tower behaves one way and another behaves the other. The problem is not the structure. It is that a comparison built on the headline limit treats two economically different products as the same product, and a buyer who has never had a large claim has no reason to know that the difference is where the money is.
Section 2. Why AI claims consume defence budget
The reason to care about this now, rather than as a general matter of insurance literacy, is that AI claims sit at the expensive end of the distribution for reasons that are structural rather than incidental.
Causation is the dispute, not the preamble. In a conventional professional negligence claim the parties usually agree what happened and argue about whether it fell below a reasonable standard. In an AI claim they frequently do not agree what happened. Whether the system produced the output alleged, whether it can be made to produce it again, whether anything changed between the event and the investigation, and whether a human decision intervened, are all live and all require evidence to answer.
The evidence is technical and largely yours to produce. Establishing the state of a system on a given date means logs, version history, configuration records, retrieval corpus state and change records. Where those exist the defence is efficient. Where they do not, the defence becomes a reconstruction exercise conducted by experts at expert rates, and the absence of records tends to be resolved against the party who should have kept them. This is the point at which governance work stops being a compliance cost and becomes a defence cost saving, and it is why an assessment scores the corpus and the change history as system components rather than as documentation. That analysis sits at agentcertified.eu, on certifying the knowledge base an agent reads from.
There are usually several candidate defendants. A model provider, a platform or orchestration layer, an integrator, tool and data providers, and you. Every additional party is another set of pleadings, another disclosure exercise and another allocation argument, and the party most likely to hold the decisive evidence is often the one with the least incentive to produce it. The recovery consequence of that structure is treated at subrogation and the AI vendor contract.
The law is unsettled and unsettled law is expensive. The proposed AI Liability Directive, which would have introduced presumptions of causation and disclosure obligations for AI claims, was withdrawn, with the formal notice published in the Official Journal on 6 October 2025. Fault-based AI claims therefore proceed under national law, which differs materially between Member States. Points that would be resolved by a paragraph of settled authority in a mature area of law get argued from first principles, and interlocutory arguments are where defence budgets go.
A single event can produce parallel proceedings. A civil claim, a regulatory process and in some cases a data protection complaint can run at once on the same facts, each with its own timetable and its own costs, and they are not necessarily funded by the same policy.
Section 3. The arithmetic, and the incentive it creates
Take two illustrative programmes with identical headline limits of EUR 2,000,000 and an identical claim. The figures below are illustrative and are not drawn from any insurer, product or reported claim.
Programme B, costs inclusive. Same defence spend of EUR 700,000. The limit has EUR 1,300,000 left. The claimant wants EUR 1,500,000. The insured funds the last EUR 200,000 from its own balance sheet, having bought what it believed was a EUR 2,000,000 policy.
The gap in that example is not the EUR 200,000. It is the EUR 700,000, which is the amount by which the two policies differ in economic value while presenting identically in a comparison table.
The second and less obvious consequence is behavioural. On a costs inclusive policy, the insurer funding the defence is spending its own indemnity. Every month of contested litigation reduces what remains to settle with, which gives the insurer a rational preference for settling early. The insured, facing a claim that alleges its AI system harmed somebody, may have a strong reputational and commercial interest in a public vindication. Those two positions are both reasonable and they point in opposite directions, and the wording that decides who wins is the conduct of claims condition. It is worth reading before the disagreement, not during it.
Section 4. Conduct of the defence and consent to settle
Three provisions work together and are best read as a single mechanism.
Conduct of claims. Most liability wordings written in the London and European markets give the insurer the right to take over and conduct the defence and settlement of any claim in the insured's name, and require the insured's cooperation. That is not unusual and it is the price of somebody else funding the defence.
Consent to settle. Some wordings require the insured's consent before a claim is settled. Where that provision exists it is very commonly qualified: if the insured refuses to consent to a settlement the insurer is prepared to make, the insurer's liability is limited to the amount for which the claim could have been settled together with costs incurred to that date. The insured is free to fight on and does so at its own expense from that moment.
Allocation. Where a claim contains both covered and uncovered elements, which is common when an AI event produces a mixture of contractual, regulatory and tortious allegations, the wording will say how defence costs are apportioned between them. An allocation provision that looks technical is the difference between the insurer funding the whole defence and funding a percentage of it.
A buyer comparing a policy written on a United States style duty to defend basis, where the insurer must defend and typically pays costs in addition, with a European or London market policy giving the insurer conduct on a costs inclusive basis, is not comparing two prices for the same thing. That is worth holding in mind when reading any coverage comparison written for a different market, and the specific European relevance of United States carrier positions is set out at United States carrier AI exclusions and what they mean for a European buyer.
Section 5. Civil defence, regulatory representation and fines
These three are routinely discussed as one thing and they behave differently.
Defending a civil claim is the core grant of a liability policy and the subject of everything above.
Being represented at a regulatory investigation is not a claim by anyone. Nobody is seeking damages. An authority is exercising a supervisory power, and responding to it costs legal and technical time whether or not it ends in any finding. Many general liability wordings do not respond to that at all without a specific extension, and where an extension exists it is frequently sublimited well below the policy limit. This is the most commonly assumed and least commonly held cover on the whole subject.
Paying a fine is a question of national law and public policy before it is a question of insurance. Whether an administrative penalty can lawfully be insured differs between jurisdictions and is not a matter any policy wording can settle by itself. We do not state which Member States permit it, because that is a jurisdiction by jurisdiction legal question this desk has not read at source for each of them. What is publicly stated by one carrier is useful as a shape: Armilla publishes that its Affirmative AI Liability Insurance covers AI Regulatory Violations including defence costs and insurable fines under the EU AI Act and the Colorado AI Act. The word insurable is a load-bearing qualifier and it is there because the answer varies. Our fuller treatment is at does AI insurance cover EU AI Act regulatory fines.
The exposure being insured against here is not small. Article 99 of the AI Act provides for administrative fines of up to EUR 35,000,000 or 7 per cent of total worldwide annual turnover for the prohibited practices in Article 5, up to EUR 15,000,000 or 3 per cent for other operator obligations, and up to EUR 7,500,000 or 1 per cent for supplying incorrect, incomplete or misleading information, whichever figure is higher in each case, with the lower of the two applying to small and medium-sized enterprises and start-ups. The penalty architecture is set out at agentliability.eu, on Article 99.
Section 6. The incident report and the notification clause
One interaction deserves its own section because the timing is tight enough to catch a well-run organisation.
Article 73 of the AI Act requires reporting of serious incidents to the market surveillance authorities of the Member States where the incident occurred. The Article 73 page as displayed on the Commission's AI Act Service Desk on 28 August 2026 gives the deadlines: not later than 15 days after the provider or deployer becomes aware of the incident in the general case, not later than 2 days in the case of a widespread infringement or a serious and irreversible disruption of critical infrastructure, and not later than 10 days in the event of death. The status of the Commission's guidance and template for that regime, which remains a draft, is set out at agentliability.eu, on which AI Act instruments are final and which are not.
A report to a regulator is not a claim. Nobody has demanded anything from you. But almost every liability wording requires the insured to notify not only claims but circumstances that may give rise to a claim, as soon as the insured becomes aware of them, and a formal report to a supervisory authority stating that a serious incident occurred is close to the paradigm case of such a circumstance. Two consequences follow.
First, a notification made in the correct period preserves cover for the resulting claim even if that claim arrives years later and after the policy has expired. That is the whole function of the circumstance notification mechanism, and it is treated in detail at retroactive dates and prior acts.
Second, an organisation operating to a two day regulatory clock is not going to convene a discussion about insurance notification policy. The decision has to have been made already and written into the incident response plan: a serious incident report to an authority triggers a parallel notification to brokers and insurers on the same day, with the same facts, in writing. That is one line in a runbook and it is the difference between a preserved claim and an argument about late notification. The operator-level version of that runbook is at insureyouragent.com, on the AI agent incident response plan.
Section 7. Six questions for the renewal
All six are answerable from the schedule and the wording, by a broker, in a single email.
- On each policy in the programme, are defence costs payable in addition to the limit of indemnity or inclusive of it?
- Who has conduct of the defence, and is our consent required before a claim is settled?
- If we decline a settlement the insurer recommends, is the insurer's liability capped at that figure plus costs to date?
- Does any policy respond to the cost of being represented at a regulatory investigation or inspection, and if so, what is that limb sublimited to?
- Does the excess or deductible erode with defence costs, meaning we fund the first phase of the defence ourselves before the policy engages?
- Where an AI event triggers more than one policy in the tower, do the defence cost structures differ between them, and which policy leads?
Question six is the one most often skipped and most often decisive. An AI event that produces a data breach, a service failure and a client claim can engage a cyber policy, a technology policy and a professional indemnity policy at once, written by different carriers with different defence cost structures and different lawyers. The time to establish which one leads is not the week it happens. A fuller version of the submission-stage exercise is at preparing an AI agent underwriting submission, and the questions running the other way, from the underwriter to you, are at what underwriters ask before writing a policy.
Section 8. The point in one sentence
A limit is a promise about the outcome, and on a costs inclusive policy it is also the budget for the argument, so on the class of claim where the argument is longest and most technical it buys the least. Read the line. It is one line, it is on the schedule you already have, and it is the most valuable ten seconds of reading available to anyone buying AI liability cover this year.
Questions
What does costs inclusive mean on an AI liability policy?
Defence costs are paid out of the limit of indemnity rather than on top of it, so every euro spent defending the claim is a euro no longer available to settle it. The alternative, costs in addition, pays defence spend outside the limit and leaves the full limit for damages and settlement. Both structures are ordinary. The difference is that costs inclusive makes the limit a total budget for the whole event, and costs in addition makes it a budget for the outcome only. Two schedules with the same headline figure can differ in economic value by the entire cost of a defence.
Why are AI liability claims more expensive to defend?
Because causation is the whole fight rather than a preliminary. In an ordinary negligence claim the facts are usually agreed and the argument is about standard of care. In an AI claim the parties often disagree about what the system did, why, whether it can be reproduced, whether a model or configuration change intervened, and which party in the chain caused it. Answering that takes expert evidence, forensic reconstruction from logs, and often a disclosure fight against a model provider who is not a party. Add several potential defendants and unsettled law, and the interlocutory phase alone can cost more than a conventional claim of the same value.
Who decides whether to settle an AI claim, the insurer or us?
Read the conduct of claims condition and the consent to settle clause together. Most liability wordings in the London and European markets give the insurer the right to take over and conduct the defence and settlement in the insured's name. Where a consent to settle provision exists it is commonly qualified, so that if the insured refuses a settlement the insurer recommends, the insurer's liability is capped at that figure plus costs to date. Behind the wording is a real divergence: on a costs inclusive policy, prolonged defence protects reputation and erodes the limit at the same time.
Does AI liability cover pay for a regulatory investigation?
Three things get conflated and they are separately insurable. The cost of defending a civil claim. The cost of being represented at a regulatory investigation, which is not a claim by anyone and which many wordings do not respond to without a specific extension. And the fine itself, whose insurability is a matter of national law and public policy and differs between Member States. Armilla publishes that its Affirmative AI Liability Insurance covers AI Regulatory Violations including defence costs and insurable fines under the EU AI Act and the Colorado AI Act. The word insurable is doing real work. Ask for the limb by name and read its sublimit.
Does a serious incident report to a regulator have to be notified to insurers?
It is not a claim, but under most liability wordings it is very likely a circumstance that may give rise to one, and those wordings require notification of circumstances as soon as the insured becomes aware. Article 73 sets short deadlines for reporting serious incidents, as short as two days in specified cases, and an organisation working to that clock will not be deciding its insurance notification policy from first principles. Decide in advance that a serious incident report triggers a parallel notification to brokers and insurers, and put it in the incident response plan.
What should we ask about defence costs at renewal?
Whether costs are inside or in addition to the limit, on each policy. Who has conduct of the defence and whether our consent is needed to settle. Whether there is a cap on the insurer's liability if we refuse a recommended settlement. Whether representation at a regulatory investigation is covered and what it is sublimited to. Whether the excess erodes with defence costs, which decides who funds the first phase. And how the answers differ across cyber, professional indemnity and general liability, because an AI event commonly triggers more than one and the structures rarely match.