Why Plum's AI suite is five policies, and why that is the honest answer
In August 2026, insurtech Plum launched a full-stack AI risk management suite for Indian businesses. The detail that matters is what the suite is made of: cyber insurance, professional indemnity (errors and omissions), directors and officers liability, commercial general liability, and asset protection. Five towers, not one AI policy.
That structure is an admission, and a correct one. An AI failure has no fixed legal shape. The same underlying model error gets litigated as a professional-services mistake, a governance failure, a data breach, or a product defect depending entirely on how it surfaces and who was harmed. A liability system built on decades-old policy categories does not reorganise itself because the causal chain now runs through a model, so the loss lands wherever its consequences look most familiar to a court or an adjuster.
The demand side has moved faster than the understanding side. Plum reported a 45% spike in AI risk coverage queries over the six months before launch, and says roughly 40% of Indian organisations are now running AI at significant or full scale. The firm says it works with more than 1,000 businesses in India, so the query trend reflects what its corporate clients are actually asking for. Plum co-founder and CEO Abhishek Poddar put the gap plainly at launch: "Companies are adopting AI at speed, but the way they think about protection hasn't evolved."
The practical consequence for a risk manager or broker is that the question "do we have AI cover" is malformed. The real question is: for each way our AI deployment can fail, which of our existing towers responds first, which definitions decide that, and where do the wordings cut against each other. That is the map this post builds, across four concrete failure modes.
Failure mode 1: hallucinated advice delivered to a client
A consulting firm, a wealth manager, a healthtech platform, or a GCC delivering analysis to its parent ships an AI-assisted deliverable containing a confident, fabricated claim. The client acts on it and loses money. ET Now's 11 August 2026 headline captured the scale bluntly: "AI Hallucinations Could Cost Businesses Crores."
First responder: professional indemnity. The client's claim is for negligent professional services, and it does not matter to the claimant that a model drafted the error. The PI policy's operative definition is the wrongful act: typically a negligent act, error or omission in the performance of professional services. The first fight is whether output generated by a model, reviewed lightly or not at all by a human, still counts as "performance of professional services" by the insured. Most Indian PI wordings were drafted before this question existed, so the answer turns on silence, and silence is where adjusters find room to decline. The corpus post on silent AI exclusions in commercial policies covers how insurers are now closing that silence from both directions.
Second in line: D&O. If the losses are large enough, shareholders or regulators ask why management deployed an unvalidated model in a client-facing workflow. That is a governance claim against directors and officers personally, and it is not duplicative of the PI claim: PI responds to the client's loss, D&O responds to the allegation that the board's oversight of AI adoption was itself the wrongful act.
What does not respond: cyber (no security failure occurred), CGL (pure financial loss, no bodily injury or property damage), and property (nothing was damaged).
Failure mode 2: an agentic system executes a wrong transaction
An autonomous agent with tool access pays the wrong vendor, places a duplicate order, reprices a product catalogue overnight, or executes a trade outside mandate. No attacker, no breach. The system did what it was designed to do, against the wrong target. As Plum co-founder and CTO Saurabh Arora put it at the suite's launch: "Failures don't always show up as incidents. They show up in outputs and decisions."
This is the failure mode that fits existing towers worst, because every candidate policy defines its trigger around something that did not happen.
- Cyber typically triggers on a security failure or network compromise: unauthorised access, malware, denial of service. An agent acting within its granted permissions is, by definition, authorised. Unless the wording extends to system failure or operational error (some do, many do not), cyber declines.
- Crime and fidelity covers dishonest or fraudulent acts of employees or third parties. An agent has no dishonest intent, and most crime wordings require one.
- PI responds only if the wrong transaction occurred in the course of professional services to a client. An internal treasury or procurement error usually is not that.
- CGL needs third-party bodily injury or property damage. A mis-payment is neither.
The residual home is often first-party: the company simply eats the loss, which is why agentic deployments need pre-agreed spending limits, reversibility windows and human checkpoints far more than they need a premium. The corpus treatment of agentic AI risk governance and insurance strategy works through those controls. At placement, the two questions that matter are whether the cyber wording includes system failure without a security event, and whether any tower affirmatively addresses autonomous system error. If the answer to both is no, the exposure is uninsured today, and it is better to know that in a renewal meeting than in a claim dispute.
Failure mode 3: model-driven discrimination in hiring or credit
A resume-screening model systematically filters out candidates by proxy variables correlated with gender or caste, or a credit model prices loans in a pattern a regulator reads as discriminatory. The harm surfaces slowly, across many decisions, exactly the pattern Arora's "outputs and decisions" framing describes.
First responder, in theory: employment practices liability. Discrimination in hiring is the textbook EPLI peril. In India, standalone EPLI is thin; it is more often an extension or sublimit inside the D&O programme than a tower of its own. That makes the D&O wording's EPL extension, its sublimit, and its definition of employment wrongful act the operative text for an AI hiring claim.
Second: D&O proper. If the discriminatory pattern becomes a regulatory investigation or a public controversy, the claim against directors is that they failed to test the model for bias before deployment. The wrongful act definition in D&O is usually broad enough to reach an oversight allegation, but two carve-outs bite: conduct exclusions (if the bias was known and tolerated) and, increasingly, explicit AI or algorithm exclusions appearing in renewal wordings.
For credit and financial products: PI. A lender or fintech whose model harms customers faces claims closer to professional negligence in the provision of financial services, plus regulatory exposure that most wordings exclude as uninsurable fines.
Cyber, CGL and property have essentially no role here. This failure mode lives entirely in the liability towers, and mostly in their least-negotiated clauses.
Failure mode 4: a vendor's model leaks your training data
You fine-tuned a vendor's model on customer records, or your teams pasted client data into a third-party tool, and that data now surfaces in the vendor's outputs to other users, or in a breach of the vendor's infrastructure. This is the one failure mode that lands cleanly in cyber, and even here the edges are sharp.
First responder: cyber. Data breach response, notification, third-party privacy liability: this is what the tower is for. Under the Digital Personal Data Protection Act, 2023, the company remains the data fiduciary even when a processor caused the leak, so the regulatory and notification burden lands on the insured regardless of fault. The corpus post on DPDP data fiduciary liability and cyber cover maps that exposure in detail.
Three cuts to check in the wording. First, the definition of computer system: older wordings cover "the insured's network," and data sitting in a vendor's model weights or training pipeline is not obviously on your network. Look for explicit cover for data held by service providers or cloud providers, and check whether an AI vendor fits that definition. Second, voluntary disclosure: if an employee pasted the data into the tool, an insurer may argue the disclosure was voluntary rather than a security failure. Third, fines: the DPDP Act's schedule sets penalties of up to INR 250 crore for failure to take reasonable security safeguards, and whether civil regulatory penalties are insurable in India remains contested; most wordings cover them only "where insurable by law."
Second in line: D&O, if the vendor was onboarded without diligence and the breach is large enough to become a governance question. PI, if the leaked data belonged to a client and the engagement promised confidentiality. The same event can open three towers at once, which makes the other-insurance and priority clauses across them a live issue, not boilerplate.
Where the definitions cut across each other
Lay the four failure modes side by side and the pattern is visible: the gaps are not missing policies, they are definitions that fail to meet.
- Wrongful act (PI, D&O) was drafted for human negligence. Whether an unreviewed model output is the insured's act, the vendor's act, or nobody's act is unsettled in Indian wordings, and each insurer's silence resolves differently at claim time.
- Security failure (cyber) requires something unauthorised. Authorised agents doing wrong things, and employees voluntarily feeding data to tools, both sit outside it.
- Occurrence, bodily injury, property damage (CGL) keep pure financial and algorithmic harms out of the general liability tower almost entirely; CGL becomes relevant mainly when AI controls something physical, a warehouse robot, a vehicle, a medical device, at which point product liability questions arrive with it.
- Silent AI is being closed from both ends: some insurers are adding AI exclusions at renewal, while a separate market sells the risk back through affirmative standalone cover, mapped in the corpus post on affirmative AI liability insurance for Indian corporates and GCCs. A buyer can be squeezed between the two: excluded in the old towers before qualifying for the new one.
The direction of travel in the market makes the gap map urgent rather than academic. A storyboard18 report on 4 August 2026 found deepfake fraud already outpacing available insurance, with experts arguing India needs AI-specific cover. Fortune India's framing of the Plum launch a week later on 11 August, "AI is changing insurance, Plum wants to insure the risks it creates," and CIOL's the next day, "AI Adoption Is Creating New Enterprise Risks," both describe the same fact: buying interest is arriving before coverage literacy. A 45% jump in queries means thousands of Indian buyers asking for "AI insurance" without a shared definition of what they are asking for. The buyers who get paid at claim time will be the ones who asked tower-level questions at renewal.
The renewal questionnaire: what to ask each insurer
Turn the map into renewal work. One set of questions per tower, asked in writing, with answers reflected in endorsements rather than emails.
- Cyber: Does the trigger extend to system failure and operational error without a security event? Is data held by AI vendors and cloud providers inside the definition of computer system? Are DPDP-related regulatory costs covered where insurable by law? Is there an AI exclusion in the renewal draft that was not in the expiring wording?
- Professional indemnity: Does the definition of professional services capture AI-assisted and AI-generated deliverables? How does the related-claims clause aggregate many outputs of one model? Does the contractual liability exclusion cut across accuracy warranties your engagement letters now give?
- D&O: Is there an EPL extension, and does its employment wrongful act definition reach algorithmic hiring decisions? Any new AI or algorithm exclusion? How do the D&O and PI towers allocate a claim that alleges both negligent service and negligent oversight?
- CGL and product liability: If AI controls anything physical, is software-driven harm within the product definition? Where does CGL hand off to PI for financial-loss claims?
- Property and asset protection: Are models, training data and weights recognised as insured property or data assets, and at what valuation basis?
Answering these questions across five wordings from multiple insurers is exactly the clause-by-clause comparison work that consumes broking teams at renewal. Sarvada gives commercial-insurance brokers structured, searchable access to insurer policy wordings, so trigger definitions, AI exclusions and cross-tower gaps can be mapped side by side instead of reconstructed by hand from PDFs. Broking firms building AI risk programmes for corporate and GCC clients can Request Access to evaluate the platform for their liability practice.