Key Takeaways
- Generative AI-related lawsuits in the U.S. grew 978% between 2021 and 2025, and filing growth accelerated to 137% in the most recent year alone.
- Standard cyber, errors and omissions, and general liability policies weren’t built with AI in mind, which leaves many companies with gaps they don’t know about until they file a claim.
- Most AI lawsuits are not about hallucinations. The largest categories involve patent infringement, copyright infringement, and personal injury tied to privacy or data misuse.
- A handful of foundation models power a huge share of enterprise AI tools, which creates the kind of concentrated risk that could trigger claims across many unrelated companies at once.
- Documented AI governance, human oversight, and fast incident response are becoming the practical difference between a covered claim and an uncovered one.
The Lawsuits Are Already Here
If you’ve been telling yourself that AI liability is a future problem, the numbers say otherwise. Generative AI-related lawsuits in the United States grew 978 percent between 2021 and 2025, according to a report from Gallagher Re, produced in conjunction with the Massachusetts Institute of Technology (MIT) and Testudo Global.
The pace is accelerating. Year-over-year filing growth jumped from 59 percent in 2023 to 2024 to 137 percent in 2024 to 2025, and cumulative filings passed 700 by the end of that period, as reported by Risk & Insurance.
Here’s the part that should get a mid-market IT leader’s attention: most of that exposure lands on the companies deploying AI, not just the vendors who built it. If your business uses a chatbot, a GenAI writing tool, an AI-powered hiring platform, or an AI agent that touches customer data, you’re a potential defendant, even if you didn’t write a line of the underlying code.
AI Tool Liability Isn’t Mostly About Hallucinations
The instinct is to assume AI legal risk means an embarrassing chatbot mistake. That’s a real risk, but it’s a small slice of the actual exposure.
According to Testudo’s own litigation data, model hallucinations account for only about 4.9 percent of generative AI lawsuits. The bigger categories are far more mundane and far more common in day-to-day business use:
- Patent infringement, roughly 12 percent of cases
- Copyright infringement, roughly 11 percent of cases
- Personal injury claims tied to privacy violations and misuse of personal data, roughly 10 percent of cases
In other words, the risk isn’t primarily about your AI saying something wrong. It’s about your AI touching data, content, or decisions in a way someone can sue over. That’s a much broader net, and it covers far more of what a typical mid-market company already does with AI tools today.
Where Your Existing Coverage Falls Short
The uncomfortable finding in the Gallagher Re report is not that AI risk exists; it’s that the insurance most companies already carry was never built to catch it.
Traditional cyber, technology errors and omissions (E&O), and commercial general liability policies each cover pieces of the picture, but the seams between them are exactly where AI losses tend to fall. A cyber policy might respond to a data breach but stay silent on a copyright claim. A general liability policy might cover bodily injury but exclude the software failure that caused it. None of these policies were priced or worded with AI failure modes in mind, so insurers are increasingly treating this as unpriced, unacknowledged exposure sitting quietly on their books, sometimes called “silent AI” risk.
The market is starting to respond with solutions. That’s good news for buyers willing to go looking for it. It’s not good news for anyone who assumes their existing policy already has this covered.
A Second, Quieter Risk: Everyone Using the Same Few Models
There’s a structural risk hiding underneath the lawsuit numbers. A small number of foundation models now power a huge share of enterprise AI tools, from customer service chatbots to internal copilots. That concentration means a single flaw discovered in one widely used model wouldn’t create a problem for one company but for, perhaps, thousands.
Insurers are watching this closely because it behaves less like an ordinary liability claim and more like a catastrophic event, the kind that can hit an entire portfolio of policyholders in the same news cycle. For a mid-market company, the practical takeaway is this: your AI risk is not independent of every other company using the same vendor. If that vendor has a bad month, you may be caught in that wave.
What This Actually Means for a Mid-Market Business
None of this means walking away from AI. It means treating AI deployment the way you would treat any other consequential business decision, with documentation, oversight, and a plan for when something goes wrong.
A few practical steps worth taking now:
- Talk to your insurance broker specifically about AI. Ask what your current cyber, E&O, and general liability policies actually say about AI-related claims, not what you assume they say.
- Inventory where AI touches customer or employee data. You can’t assess your exposure to privacy and personal injury claims, the largest category after IP, without knowing where AI systems actually sit in your data flow.
- Keep a human in the loop on consequential decisions. Hiring, lending, healthcare, and legal use cases carry the highest scrutiny. Documented human review is one of the clearest ways to demonstrate reasonable care if a claim does arise.
- Review vendor contracts for liability limits. Many AI vendors cap their own liability tightly, which means the deploying company, not the vendor, often ends up holding the bag.
- Treat AI incidents like security incidents. Fast detection, a documented response, and clear records of what happened and when all strengthen both your legal position and your insurance claim.
Where Emerge Fits In
That last point connects directly to something we have written about before: insurers are increasingly underwriting based on how fast a company can detect and respond to a problem, not just whether they can prevent one (read our take on that shift). The same logic applies to AI-related incidents. A company with real-time monitoring, a documented response process, and a clear paper trail is in a fundamentally different position, both with regulators and with its insurer, than a company that finds out about a problem when the lawsuit arrives.
Emerge helps mid-market companies build exactly that kind of readiness, from managed detection and response to the governance and documentation practices that hold up under scrutiny. If your business is using AI tools and you’re not sure what your current policies would cover, that’s a conversation worth having before you need it, not after.
