Pennsylvania CPA Journal
AI, Coverage Gaps, and the Risk of Uninsured Claims
AI is already present in many of the accounting platforms used every day. This ubiquity creates a subtle but significant liability problem.
Insightful lessons can be learned by reviewing professional liability issues. With this in mind, Gallagher Affinity provides this column for your review. For more information about liability issues, contact Irene Walton at irene_walton@ajg.com.
Artificial intelligence (AI) has moved from a fringe capability to an embedded feature across the tools that define a modern accounting practice. For CPAs, that shift is also reshaping professional liability in ways that are easy to underestimate and sometimes difficult to manage. At its core, though, this is an issue of coverage uncertainty and the potential gaps that emerge as AI can influence professional judgment, client deliverables, and third-party systems.
The challenge is not necessarily the deliberate adoption of cutting-edge AI tools. The reality is that AI is already present in platforms used every day. Tax preparation software increasingly suggests classifications and identifies potential deductions. Audit analytics tools use pattern recognition to flag anomalies across massive datasets. Bookkeeping systems auto-categorize transactions and generate financial summaries. Even client portals and document management systems rely on natural language processing to organize and retrieve information. In most cases, these capabilities operate in the background, often without the CPA fully understanding how outputs are generated.
This ubiquity creates a subtle but significant liability problem. Consider a firm preparing a complex corporate return using a widely adopted tax platform. The system flags a deduction it classifies as consistent with prior filings and industry norms. The CPA, under time pressure during a busy filing season, accepts the recommendation. Months later, the IRS disallows the deduction and imposes penalties. The client then alleges negligence. If the recommendation originated from an AI-driven classification engine, the involvement of AI becomes part of the factual narrative of the claim. Whether or not the CPA intended to use AI becomes irrelevant; it was embedded in the workflow.
A similar dynamic plays out in audit engagements. Imagine an audit team relying on a data analytics tool to identify unusual transactions in a client’s general ledger. The tool uses machine learning to prioritize which entries deserve closer scrutiny. If the model fails to flag a fraudulent transaction due to bias in its training data, and the fraud later surfaces, plaintiffs may argue that the auditors placed undue reliance on a system they did not fully understand. The issue is not whether the auditors followed professional standards, but rather whether their reliance on AI-tainted output contributed to the failure.
Vendor dependency amplifies the exposure. Most CPA firms do not build their own software; they rely on ecosystems of vendors providing tax, audit, payroll, and advisory tools. Those vendors are in a race to integrate AI capabilities to remain competitive. As a result, CPAs may find themselves using AI-enabled systems without any explicit decision to do so. When something goes wrong, however, the CPA is the accountable professional in the eyes of the client. A bookkeeping platform that automatically categorizes expenses, for example, may misclassify personal expenditures as business deductions. If the error makes its way into financial statements or tax filings, the client’s claim will be directed at the CPA and not the software provider with whom the client has no relationship.
These scenarios highlight how coverage issues easily emerge. Professional liability policies were historically designed to respond to errors in judgment, misstatements, or failures to meet professional standards. They were not built for a world in which algorithmic outputs shape judgments. When a claim involves AI in any capacity – whether through a recommendation, a missed anomaly, or an automated classification – insurers may scrutinize whether the loss falls within the scope of coverage. The more ambiguous the policy language around AI, the greater the risk of disputes over whether a claim is covered at all.
Another complicating factor resides within definitions. “Artificial intelligence” is not a term with a universally accepted legal meaning. In practice, it can encompass everything from simple rule-based automation to sophisticated generative models. A CPA may think of AI as chatbots or advanced predictive tools, while an insurer may interpret the term to include basic machine learning algorithms embedded in standard software. This disconnect introduces uncertainty at the exact moment when clarity matters most, particularly when a claim is underway and coverage determinations are being made.
Consider a firm using an automated reconciliation tool that learns from historical transaction patterns. From a technical standpoint, that tool likely qualifies as AI. From a practitioner’s perspective, it may feel like routine automation. If an error occurs and leads to a material misstatement, the characterization of that tool could influence whether coverage applies. Disputes over definitions can delay claims resolution, increase legal costs, and expose firms to uninsured losses during the process.
The practical consequence of all of this is that CPA firms are operating in an environment where liability tied to AI can arise organically, while insurance responses may be uncertain. This does not mean firms are unprotected, but it does mean that assumptions about coverage reliability may no longer hold. The gap between how CPAs use technology and how policies respond to technology-driven claims is widening.
But firms are not without options. Several best practices are emerging as essential steps to maximize the likelihood of coverage and reduce exposure. The first is developing a clear inventory of AI touchpoints within the firm. This does not require deep technical expertise, but it does require asking vendors direct questions about how their systems generate outputs, what role machine learning plays, and where human oversight is expected. Understanding where AI exists in the workflow is the foundation for managing risk.
Second, firms should strengthen vendor management practices. Contracts with software providers should be revisited with a focus on representations about system accuracy, transparency around AI functionality, and indemnification provisions where appropriate. While vendors may resist broad indemnities, even incremental improvements in contractual protections can help shift some risk away from the CPA.
Third, internal policies and training are critical. Staff should understand when they are relying on automated outputs and when heightened skepticism is warranted. For example, firms can implement review protocols requiring a second level of human verification for AI-generated recommendations in high-risk areas such as tax positions or audit adjustments. Documenting these procedures not only improves quality but also provides evidence of diligence in the event of a claim.
Fourth, firms should engage proactively with their insurance brokers and carriers. Rather than waiting for a claim to test the policy, CPAs can seek clarity during renewals about how their coverage responds to AI-related scenarios. This includes reviewing definitions, asking for illustrative examples, and exploring endorsements or supplemental policies that address AI exposures more directly.
Finally, firms should consider the broader evolution of the insurance market. Just as cyberrisk gave rise to dedicated policies over the past decade, AI-specific coverage is beginning to emerge. While still developing, these products signal a recognition that traditional professional liability frameworks may not fully address the realities of AI-driven practice.
The intersection of AI and professional liability is still taking shape, but one point is already clear: the risk is no longer hypothetical. For CPAs, the path forward lies in acknowledging that AI is embedded in everyday tools, recognizing how that changes liability exposure, and taking deliberate steps to align practices, contracts, and insurance coverage with that new reality.
Marc S. Voses, Esq., and Jonathan S. Ziss, Esq., are partners with Goldberg Segalla LLP, Voses in New York and Ziss in Philadelphia. Voses can be reached at mvoses@goldbergsegalla.com and Ziss can be reached at jziss@goldbergsegalla.com.