Blog

AI error in production or output: what to record now providers become liable and insurers exclude cover

GEMA v. Suno places liability with the AI provider, while ISO excludes generative-AI harm from standard policies from 2026. What to record per workflow.

· By

Three document stacks side by side on a wooden desk, a hand setting down the third stack, with daylight from the left.
Providers become liable and insurers exclude generative-AI harm; record model, prompts, source and human check per workflow.Image: IamVera.ai — original editorial illustration

Liability for generative AI is shifting in 2026 because the court holds the AI provider directly liable (GEMA v. Suno) while insurers remove generative-AI harm from standard policies; therefore record per workflow which model, which prompts, which source and which human check determined an outcome.

The trigger is a concrete judgment and a concrete insurance change. According to an analysis by Licentium, the Landgericht München I ruled on 31 July 2026 in the case GEMA against Suno (42 O 763/25) that a generative-AI music service is itself primarily liable for copyright infringements. At the same time, from 1 January 2026 ISO/Verisk is introducing endorsements that remove generative-AI harm from general liability policies, according to Insurance Journal. For organisations deploying AI in trust-sensitive processes, this means that liability is no longer only a supplier question, but a design and documentation question per task.

What did the Munich court decide in GEMA v. Suno about the AI provider's liability?

According to the Licentium analysis of the GEMA v. Suno judgment, the Landgericht München I qualified several acts as infringement: training on protected works, retaining those works in the model (memorisation), making the trained model available and generating infringing output tracks. The core is that the court identifies the AI provider as the primary infringer, not the user who types in a prompt.

An overview by Herzog Fox & Neeman places the ruling in a broader IP context and emphasises that liability runs through the whole chain: both the training in the United States and the use of the model and the output in Germany fall under it. In our assessment, that is the most transferable part of the case: the pattern that a provider cannot present itself as neutral infrastructure is not limited to music.

Why are insurers removing generative-AI harm from standard liability policies?

In parallel with the case law, the insurance side is changing. Insurance Journal describes how insurers are beginning to exclude generative-AI harm through new ISO endorsements from standard Commercial General Liability cover. An evidence ledger by Vorp Labs documents that generative-AI exclusions with a January 2026 edition exist and that they exclude bodily injury, property damage and personal/advertising injury "arising out of generative artificial intelligence".

The practical consequence: whereas harm from an AI error might previously have fallen under a general policy, a coverage gap now arises. Organisations bear that risk themselves, unless they arrange separate AI cover. Such specialised cover is, according to Insurance Journal, tied to demonstrable risk management, which places the burden of proof on the insured.

How is liability divided in 2026 between provider, user and insurer?

On the basis of the sources named, a chain of three roles is emerging. This is our editorial ordering, not a quotation from a single source:

  • The provider of the generative model bears direct liability for certain errors and infringements, as GEMA v. Suno shows, and must manage this demonstrably with documentation and possibly its own specialty cover.
  • The user — a healthcare institution, media party, bank or law firm — remains responsible within its own legal framework for how AI output is deployed, and must be able to reconstruct per process which output led to which decision and harm.
  • The insurer pulls generative-AI harm out of standard policies and may offer cover through separate clauses, often on condition of auditable AI use.

An analysis by Holon Law on European AI liability sketches how this fits alongside existing civil frameworks and the EU AI Act. In our discussion of how the law divides liability for AI errors in 2026 we go deeper into those legal frameworks; this article focuses on what the double shift means for your evidence.

What evidence must I be able to show per AI workflow when a claim or incident arises?

If liability differs per role and cover is tied to risk management, the practical question is what evidence you keep reconstructable. A workable checklist per incident or claim:

  1. Which model and which model version produced the output, and at what moment.
  2. Which prompts and which input or source documents were used.
  3. Which sources or substantiation the output drew on, and whether they were verifiable.
  4. Which human check took place and who made the final decision.
  5. Which contractual arrangements with the provider apply, including audit rights.
  6. Which insurance clauses apply and whether generative-AI harm is excluded.

Recording audit rights belongs to this; see how you record audit rights and evidence obligations in AI contracts. Anyone who can show these six points per workflow stands stronger towards both the court and the insurer. More background on this responsibility question can be found in our topic hub on AI governance and responsibility.

How does a verification layer help make that chain of evidence visible?

The six points above revolve around traceability: can you reconstruct afterwards what happened? A verification layer such as Vera can route a task through selected independent AI models and make the verification steps, corrections, disagreements and sources visible for inspection. That supports review and making evidence per AI task reconstructable, but it does not replace the professional's own judgement and it makes control possible rather than removing the risk of errors.

Vera is not a chatbot and not its own language model, and it does not set the legal standard. The legal development comes from the Munich court, the insurance change from ISO and the insurers. What a verification console adds is a visibility layer over that chain: professionals can trace high-trust workflows and reconstruct incidents in line with the new legal and insurance practice. The professional final judgement — and the final responsibility — remains with the user.

Sources and references

  1. Munich Regional Court Rules AI Music Training Infringes Copyright in GEMA v. Suno (42 O 763/25)Licentium · 2026-08-12
  2. Recent Developments in IP Case Law on Generative AI – 8th UpdateHerzog Fox & Neeman · 2026-08-11
  3. How Europe Builds AI Liability (Part II): AI in CopyrightHolon Law · 2026-09-03
  4. Insurer Interest in AI Exclusions Growing as Risk Becomes ClearerInsurance Journal · 2026-07-20
  5. AI Insurance Exclusions Evidence Ledger – ISO Generative AI EndorsementsVorp Labs · 2026-08-15

Sources: The article relies on the analysis by Licentium and Herzog Fox & Neeman of GEMA v. Suno, on Insurance Journal and Vorp Labs on the ISO exclusions, and on Holon Law on European AI liability.

← All articles in this topic ← All articles