AI error in production or output: what to record now providers become liable and insurers exclude cover
GEMA v. Suno places liability with the AI provider, while ISO excludes generative-AI harm from standard policies from 2026. What to record per workflow.
You must now document per workflow which model you used, what prompts or inputs drove it, where the training data came from, and what human review occurred before the output reached a user or decision-maker. Liability for AI errors has shifted from supplier alone to your organisation's own design and record-keeping.
The prompt is an analysis of 7 September 2026 of liability for generative AI errors now that providers are liable and insurers exclude cover, which argues that a court judgment and a parallel insurance change have moved the burden of proof onto the organisations deploying AI. The case in question is GEMA v. Suno, in which a German court held the AI provider primarily liable for copyright infringement through training, retention and output. In our assessment, the pattern that a provider cannot present itself as neutral infrastructure applies beyond music: any organisation deploying generative AI in a trust-sensitive process now carries documentation as a core control, because insurers have begun excluding generative-AI harm from standard policies, and specialised cover is tied to demonstrable risk management.
What has changed in liability and insurance?
Two developments converge in 2026. First, the Landgericht München I ruled that a generative-AI music service is itself primarily liable for copyright infringement across the entire chain: training on protected works, retaining those works in the model, making the model available and generating infringing output. The court did not treat the user's prompt as the point of liability; it identified the provider as the primary infringer. Second, insurers are introducing exclusions for generative-AI harm in standard Commercial General Liability policies, effective from January 2026. These exclusions remove coverage for bodily injury, property damage and personal or advertising injury arising from generative artificial intelligence. The result is a coverage gap: harm from an AI error that might previously have fallen under a general policy now does not, unless you hold separate AI-specific cover.
Which failure modes and risks now require your documentation?
- Training on protected or sensitive material — models built on data the provider had no right to use, creating liability upstream of your deployment.
- Memorisation and reproduction — personal data or copyrighted material reproduced or closely inferred from model outputs, traceable to training data.
- Output harm without human review — decisions or content generated by the model and delivered to users or decision-makers without documented human verification.
- Unverifiable model provenance — inability to reconstruct which model, version or training run produced a given output.
- Absent audit trail — no record of prompts, inputs, corrections, disagreements or the basis on which a human approved or rejected the output.
- No contractual evidence of risk management — no documented controls or audit rights in your agreement with the model provider.
What concrete controls must you be able to demonstrate?
- Record the model and its purpose — document which model each workflow uses, the version, the provider, and the lawful basis for the data the model touches.
- Log all inputs and prompts — maintain a timestamped record of what was fed into the model for each task, including any context or system instructions.
- Document the source and training provenance — record what you know about where the model's training data came from and any known limitations or exclusions.
- Capture human review and decision — log who reviewed the output, what they checked, whether they approved, modified or rejected it, and on what grounds.
- Maintain verification steps and disagreements — if multiple models or reviewers were consulted, record where they agreed and where they diverged, and how the disagreement was resolved.
- Preserve the audit chain — keep records reconstructable and accessible for at least the period your insurer or a court might require, with clear custody and integrity controls.
How does this fit with your existing liability and insurance obligations?
The Munich judgment sits within a broader European framework. Liability for AI errors now runs through the entire chain: both the training in the jurisdiction where the model was built and the deployment and output in the jurisdiction where harm occurred. Your organisation is not insulated by the fact that you did not build the model. At the same time, the insurance exclusion means that standard policies no longer cover you. Specialised AI cover exists, but it is tied to demonstrable risk management. That means the insurer will ask to see your controls, your audit trails and your evidence per incident. The professional responsibility — and the final liability — remains with you.
What tooling can support this, and what remains your own judgement?
A verification layer can route a task through selected independent models, make the verification steps, corrections, disagreements and sources visible for inspection, and support the reconstruction of incidents in line with the new legal and insurance practice. Such a tool adds visibility and traceability to high-trust workflows. It does not, however, replace your own professional judgement, set the legal standard, or remove the risk of errors. The legal development comes from the courts and the insurers. What a verification console does is make control possible and evidence reconstructable. The final decision — and the final responsibility — remains yours.
Sources: This article draws on reporting and guidance from Licentium, Herzog Fox & Neeman, Holon Law, Insurance Journal and Vorp Labs.
Written by
Marit Halversen
Covers AI governance and regulatory design, with a focus on how compliance obligations land on architecture rather than on paperwork.