Policyholders increasingly turn to artificial intelligence (“AI”) platforms to answer insurance coverage questions. This is risky because: (1) AI models hallucinate legal content at alarming rates; and (2) AI cannot apply nuanced, fact-specific and jurisdiction-specific legal analysis. As OpenAI Foundation recently acknowledged, “ChatGPT . . . neither has nor uses any degree of legal knowledge or skill.” See
https://fingfx.thomsonreuters.com/gfx/legaldocs/xmvjydomqpr/Nippon%20Life%20v%20OpenAI%20motion%20to%20dismiss.pdf. Any policyholder who receives a “no coverage” answer from AI should consult experienced coverage counsel before accepting that conclusion.
Cyber/Data Privacy
Non-Deal Exposure: Practical Tips for Enhancing Insurance Coverage For Private Equity Funds and Portfolio Companies
When private equity fund managers think about insurance, they usually think of Representations & Warranties Insurance (“RWI”). That makes sense—RWI covers representations baked into the deal itself that are front of mind when buying and selling portfolio companies (“PortCos”). But once a deal closes and a PortCo continues operations under new PE ownership, a whole new set of operational issues unrelated to pre-closing representations can surface, giving rise to potential claims under a host of different lines of insurance, including directors and officers (“D&O”), errors and omissions (“E&O”), cyber, crime/fiduciary, general/limited partner (“GP/LP”), commercial general liability (“CGL”), and property policies, among others. To make matters worse, coverage gaps between policies issued at the fund level and the PortCo level, finger-pointing between insurers, lapsed policies, and inadequate coverage can result in substantial financial losses for the PE Fund and PortCo alike.
Continue Reading Non-Deal Exposure: Practical Tips for Enhancing Insurance Coverage For Private Equity Funds and Portfolio CompaniesInsurance Industry’s Use of AI: A Fair or Unfair Claim Settlement Practice?
The insurance industry has been swift to adopt artificial intelligence (“AI”). According to consulting firm McKinsey & Company, 76% of insurers surveyed have already begun using generative AI in their day-to-day operations. [1] This adoption spans the different facets of insurers’ work cycles, including claims, underwriting, legal, and risk management. Policyholders and their attorneys must remain aware of the potential pitfalls of AI implementation, particularly as it pertains to claims management.
Continue Reading Insurance Industry’s Use of AI: A Fair or Unfair Claim Settlement Practice?When Geopolitic Events Disrupt the Cloud: Insurance Coverage for Data Center Supply Chain Losses in a New Era of Conflict
A New Risk Landscape for AI Infrastructure
Escalating tensions involving Iran—including maritime incidents affecting oil transport and alleged cyber and physical targeting of digital infrastructure in the Middle East—highlight a growing and underappreciated risk for AI-driven data centers: disruption that originates far beyond the insured’s own operations. These developments are not occurring in a vacuum. They come at a time when hyperscale data center expansion has become a central driver of economic growth in the United States, as well as a national security priority, underpinning everything from cloud computing to artificial intelligence development.
Continue Reading When Geopolitic Events Disrupt the Cloud: Insurance Coverage for Data Center Supply Chain Losses in a New Era of ConflictThe New Frontier: Data Centers, AI & Insurance Implications
Amazon’s recent announcement to invest at least $20 billion in cloud computing and AI data center campuses across Pennsylvania—a record‑breaking private investment in the Commonwealth—marks a turning point in digital infrastructure build-out. Spanning sites in Luzerne and Bucks counties, the project promises 1,250 full‑time roles and thousands more in construction, while pairing with high‑demand energy sources like a nearby nuclear plant. The rapid expansion of AI data centers poses a unique set of risks—ranging from construction hazards to power and environmental challenges— and highlights the need those involved in these large infrastructure projects to close potential insurance coverage gaps and to explore alternative risk transfer solutions.
Continue Reading The New Frontier: Data Centers, AI & Insurance ImplicationsThe SEC’s Cybersecurity Incident, Governance, and Management Reporting Requirements: What you Need to Know to Avoid Cyber and D&O Coverage Gaps
The SEC public company cyber disclosure rule raises issues that companies should consider in reviewing existing insurance coverage and in assessing overall risk.
The SEC recently adopted a new cybersecurity disclosure related rule (the “SEC Cyber Disclosure Rule”)[1] in response to increasing risks associated with cyber incidents and a perceived need for investors to receive more fulsome corporate disclosures about cybersecurity risks, governance, and material incidents. In prior efforts to improve consistency and accuracy of public company cybersecurity risk disclosures, the SEC issued interpretive guidance explaining how cybersecurity risk and incidents should be communicated based on long-standing requirements to periodically—and as needed—disclose material information to shareholders.[2] But in spite of this guidance, in the SEC’s view corporate disclosure practices remained inconsistent, under-disclosure persisted, and investors lacked consistent information by which they could evaluate public companies’ cybersecurity risk. In July 2023, the SEC adopted the SEC Cyber Disclosure Rule, which mandated new disclosures among other things, and which became effective in December 2023.
Continue Reading The SEC’s Cybersecurity Incident, Governance, and Management Reporting Requirements: What you Need to Know to Avoid Cyber and D&O Coverage GapsNavigating Cybersecurity and Data Privacy Regulations in the Insurance Industry
Following record-shattering data breaches, there has been a major push for increased transparency and regulation in the insurance industry regarding consumer data privacy. With an increase in consumer data collection, the threat of ransomware attacks can expose companies to potential litigation or regulatory action if not handled properly.
Read on to learn about the National…
Merck-Settlement of $1.4 Billion Coverage Dispute Over NotPetya Cyberattack Places Renewed Spotlight on War Exclusions in 2024
Last week, Merck & Co. filed documents with the Supreme Court of New Jersey indicating that it reached a settlement with its “all risk” property insurers in a long-running coverage dispute involving over $1.4 billion in losses stemming from a 2017 NotPetya cyberattack that impacted tens of thousands of Merck computers. The coverage litigation, Merck & Co. v. ACE American Insurance Co., focused on the key question of whether the policies’ “hostile/warlike” exclusion applied to the NotPetya attack, which some intelligence agencies have attributed to Russian government attempts to destabilize Ukraine. The settlement was announced just a few days before the New Jersey Supreme Court was set to hear oral arguments during an appeal of the New Jersey state appeals court’s affirmance of a 2021 trial court ruling in Merck’s favor. Merck’s insurers had argued that Merck’s losses were barred by a war exclusion, but the New Jersey trial court found that the exclusion did not apply to malware and cyberattacks and instead was intended to apply only to physical acts of warfare between the armed forces of two or more countries. The terms and the amount of the settlement have not yet been disclosed.
Continue Reading Merck-Settlement of $1.4 Billion Coverage Dispute Over NotPetya Cyberattack Places Renewed Spotlight on War Exclusions in 2024Policyholders Beware – Lloyd’s is Adding New Exclusions to Limit Insurance Coverage for State-Sponsored Cyber Attacks Next Month – Are You Prepared?
Cyberattacks on corporate networks are on the rise, and the ramifications from such an attack can be financially devastating. Recent benchmarking data shows that the number of material cyber breaches at large businesses increased by 20.5% from 2020 to 2021, with cybersecurity budgets across various industries aimed at preventing breaches jumping 51%.[1] Although companies…
Ohio Supreme Court Holds that Insurance Policy Does Not Cover Ransomware Attack on Software
In a unanimous decision, the Ohio Supreme Court found that appellee EMOI Services, LLC’s (“EMOI”) businessowners insurance policy does not cover losses resulting from a ransomware attack on EMOI’s computer software systems.
Continue Reading Ohio Supreme Court Holds that Insurance Policy Does Not Cover Ransomware Attack on Software