Est.

Who Pays When a Robot Hurts Someone on a Customer Site

Liability for robot injuries splits among maker, integrator, and operator.

Technology Risk Analyst · · 9 min read
Cover illustration for “Who Pays When a Robot Hurts Someone on a Customer Site”
Robot Maker Coverage · October 7, 2026 · 9 min read · 2,072 words

When a robot injures someone on a customer site, no single party automatically absorbs the loss. Liability spreads across manufacturer, integrator, and operator according to who controlled what at the moment the machine failed, and the structure of that split is the entire subject of this piece. Physical AI systems use sensors, software, and AI models to decide how to act as conditions change, and that flexibility is the property PYMNTS identified in June 2026 as the thing that breaks the liability framework traditional insurance policies were built to handle. A forklift behaves the same way on the day it's decommissioned as it did on the day it rolled off the line. A robot that learns in the field behaves differently: its behavior at the moment of injury can differ from its behavior at the moment it was shipped, trained, or commissioned, because continuous learning turns "design" into a moving target that changes faster than a court can pin down. One injury can set off simultaneous disputes among the hardware maker, the AI model developer, the system integrator, and the company running the floor, often with no contract clause that cleanly says which failure caused the loss.

The liability chain is structured across manufacturer, integrator, and operator

Three parties sit in the chain for any robot deployed on a customer site, and each answers for a different slice of what happened. The party whose decisions are the least documented is the one courts and insurers will end up leaning on.

The manufacturer answers for the machine as it was supplied. Product liability law gives three traditional theories to work with: design defect, manufacturing defect, and failure to warn. None of the three fits cleanly once the product keeps rewriting its own decision-making after it leaves the factory. Wilson Elser raised this exact problem in July 2026: when a robot is powered by a model that updates itself through interaction, what is "the design" supposed to mean at the moment of injury? The Figure robot adapts in real time off a pre-trained model, uploading fleet data for centralized retraining. At this stage, Optimus units from Tesla focus on learning and data collection, not fixed autonomous operation. In either case, once learning after the sale is what caused the injury, a plaintiff has to decide what exactly they're challenging as unreasonably dangerous, the model as shipped or the model as it has since become. Manufacturing defect claims hold up better when the failure is mechanical, a sensor that dies or an actuator that seizes. Even there, a robot typically draws its foundation AI model, its computer vision chips, and its actuators from different suppliers, so tracing the failure to one responsible party takes forensic engineering before a claim can even be filed.

The integrator, the company that assembled, programmed, and commissioned the system for the customer's floor, sits in the most exposed spot in the chain whenever the buyer has no safety team of its own. An under-resourced buyer that purchases an autonomous system doesn't make its own safety gap disappear by purchasing it. That gap moves upstream to whoever installed and commissioned the machine. When a collaborative robot injures a worker, the list of parties who can be pulled into the dispute includes everyone involved in making, operating, programming, owning, and overseeing it, and workers' compensation covering the injured employee does not take a product liability claim against the integrator off the table. An integrator holding a complete risk assessment and validation record is in a materially stronger position in that dispute than one whose file has gaps, because that record is the primary defense, not paperwork filed away for compliance.

The operator, the business running the robot day to day, answers for how the machine was deployed, maintained, and supervised, including whether emergency override protocols existed and were actually enforced on the floor. Liability can diffuse even further out to third-party component suppliers, data providers, and cloud platforms, but courts and insurers tend to land the burden on the integrator or the operator even when the failure started upstream of both. If an operator gave an ambiguous verbal command, changed operating parameters after commissioning without telling the integrator, or never retrained staff on an updated software build, it carries exposure regardless of where the original fault sits. The warehouse manager who bought a cobot without running a hazard analysis on the new floor layout is making exactly this bet, usually without realizing it.

Where the standard insurance stack breaks

Every party in that chain is likely carrying a policy it believes covers an autonomous-robot incident. In most cases that policy was never written with a machine that acts without continuous human direction in mind, and the mismatch is built into the policy's structure rather than being an oversight by any one carrier.

Commercial general liability is built on an assumption of human-caused bodily injury and property damage. Promise Legal noted that an autonomous agent causing a loss without direct human intervention can fall outside the insuring agreement of a CGL policy. If the loss doesn't fit the policy's own definition of an "accident," a standard business policy may not respond at all, and adaptive AI behavior makes that accident framing harder to satisfy than it looks on paper. Even where CGL does respond, it typically pays for physical damage only. It does not cover the production losses that follow when a robot failure shuts down a line for days.

Technology errors and omissions coverage was built for financial loss that comes from professional mistakes, not for bodily injury or property damage. When an autonomous system controls a physical process and someone gets hurt, tech E&O is the wrong instrument by design. Honigman flagged the sharper version of this trap for deployers in May 2026: an enterprise's own tech E&O policy, if it carries one, likely does not respond to a claim arising from deploying a vendor's AI tool, because tech E&O is built for companies that provide technology services, not for companies using someone else's technology to run their own warehouse or plant.

Cyber coverage pays for data breaches and network security failures. Most cyber policies explicitly carve out bodily injury, and an AI performance failure with no security breach or media component behind it sits outside what core cyber coverage was built to pay. That coverage requires a cyberattack as the trigger, so it does nothing for the far more common scenario where an AI system simply errs with no breach involved. Product liability policies cover bodily injury claims, but they're generally not written with a device that keeps learning and changing its own behavior after the sale in mind. Inland marine and equipment coverage rounds out the gap list: prototypes, mobile robots deployed at customer sites, and sensor-heavy hardware in transit are frequently underinsured under a standard commercial property policy, and an inland marine or specialized equipment schedule is the correct instrument, especially where deployment limits and replacement values run high.

AI exclusions closing the gray zone in 2026

The gaps described above existed quietly during the early wave of AI deployment, largely because carriers had not yet decided how to treat the exposure. That period is ending. Carriers are now securing regulatory approval to write AI exposure out of standard policy forms, turning what used to be an ambiguous coverage question into an explicit, named exclusion.

Verisk's ISO division, effective January 1, 2026, released three new generative AI exclusion endorsements for commercial general liability and products/completed operations liability policies. CG 40 48 is narrower: it excludes only personal and advertising injury claims tied to generative AI, leaving bodily injury and property damage coverage intact. CG 35 08 is the third endorsement in the ISO suite.

The downstream effect of these exclusions lands hardest on enterprise deployers. Honigman noted that deployers now face a coverage gap that makes a vendor's contractual indemnity often the only path to recovery left. Most vendor indemnities cap total liability at the fees paid, typically twelve months' worth, which sets a hard ceiling on recovery that has no relationship to the size of a bodily injury claim. The word doing the most damage in these endorsements is "arising out of." It's a broad causal standard, so a robotics operator whose general liability policy covers an AI-related injury because the injury itself is physical is reading the endorsement language the way it used to work, when the current language reaches further.

The specialist coverage market's response to these gaps

Carriers that specialize in robotics have started building programs aimed directly at these gaps, and real products now exist that didn't a few years ago. None of them covers the entire chain of liability on its own, and the scope of what each one pays for varies a great deal by program.

Axis Insurance built a program for companies that make and deploy autonomous robots. It covers bodily injury and property damage arising from AI navigation or perception failures, physical damage caused by a cyberattack that takes over a robot's controls, production losses triggered by a software update or sensor failure that takes a robot offline, and cases where a defect in a third-party sensor or component causes the failure but the claim lands on the integrator. Even a purpose-built program like this one doesn't close the whole chain. A single robot incident can still generate simultaneous claims against the hardware maker, the software developer, and the operating company, and each needs its own coverage to respond. AI liability insurance is a coordinated stack of coverage lines, tech E&O, cyber, product liability, D&O, employment practices liability, media and IP liability, and in some structures, parametric coverage layered on top.

Mosaic, working with aiSure and backed by Munich Re, built a parametric-style product around defined performance thresholds. A payout triggers automatically when an operational AI model breaches a contracted accuracy level through underperformance, drift, calibration error, or prediction error, which suits models running under a performance contract more than it suits a one-off bodily injury claim. AIG's CyberEdge Plus addresses cyberattack-related bodily injury, property damage, business interruption, and product liability directly, but it responds only when a cyberattack sits behind the loss, the same limit that applies to the Axis cyberattack coverage.

All of these products share a pricing problem that has nothing to do with how well any one of them is designed. Insurers price commercial risk using claims history and known operating controls, but physical AI gives them very little of either and adds more variables than a conventional machine ever did. The same robot model carries different risk at two different warehouses depending on floor layout, how workers move around it, and which version of its software is running that week. Specialist coverage exists and is improving, but it is solving a pricing problem that the industry is still only a few years into working out.

Underwriting submissions and specialist coverage claims

Finding a carrier that writes specialist robotics coverage is the first step, not the last one. The quality of the underwriting submission behind the policy determines the premium and the payout, because carriers are now treating the degree of autonomy in a system as a primary rating variable.

Carriers are now asking a different underwriting question. It no longer centers on whether an organization uses AI. It centers on what authority has been handed to the AI system, what controls govern how it operates, what approvals have to happen before it can act, and which external systems or physical assets it's permitted to touch or modify. That's a question about architecture, not about a company's AI strategy slide.

Underwriters are now asking for technical documentation alongside the financials that used to carry a submission on their own: continuous telemetry tracking the system's behavior over time, automated mechanisms that can intervene when something goes wrong, and proof of deterministic safeguards that stop a runaway execution cycle before it causes harm. A team that hasn't built these architectural proofs into the system itself, rather than bolting them on as a compliance exercise after the fact, faces two outcomes at renewal: an outright decline, or a premium set high enough to price in the uncertainty the carrier can't otherwise measure. Whether the policy responds when the claim finally comes in depends on whether the integrator has a complete validation record and the operator has enforced override protocols, the conditions a specialist carrier can underwrite with confidence.

Sources

  1. The AI Insurance Gap and What It Means for Technology Contracts: Law Firm, Attorneys, Lawyers - Honigman