Security1 distinct publisher3 min readPublished
David Halbreich of Reed Smith says the coverage question AI companies get wrong is when, not what, and that the governance artifacts underwriters now collect can come back as warranties a carrier uses to deny.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Follow any of these and your For You feed starts watching them — no settings page required.
security
Thousands of credentials survived five years of pentests inside Jira ticket comments1 distinct publisher
security
GitLab 19.3 puts agent runtime, inference models and secrets under one permission model1 distinct publisher
security
An agent guard that runs on your laptop, and cannot tell you whether anyone keeps it on1 distinct publisher
security
Verisk files three endorsements that let carriers exclude generative AI from general liability2 distinct publishers
Start with the policy trigger. D&O and E&O policies for AI companies are typically written on a claims-made basis, so they respond to claims asserted during the policy period rather than to loss from an occurrence that took place inside it [5]. Many also carry a retroactive date limiting how far back the conduct behind a claim can have occurred [6]. The two dates that decide who pays are the assertion date and the retroactive date; the day someone noticed the model had drifted plays no part in that calculation [18].
Now run a merger through that structure. On an acquisition it is customary for the target to buy extended reporting period coverage, also called runoff or tail, which prolongs the window for reporting claims about earlier conduct, while the acquirer buys a go-forward policy effective at or around closing for conduct after the deal [7]. Tail policies often exclude claims involving any conduct after the cutoff date, and the go-forward policy may decline the same claim because it also involves pre-merger conduct [8]. A claim alleging wrongful acts on both sides of the cutoff has three possible outcomes, including one where neither policy responds [17]. David Halbreich, an insurance recovery partner at Reed Smith [1], says this catches sophisticated deal and in-house counsel who thought procuring both policies was enough [10]. His fix is to review both policies and their exclusions in tandem, then get clarifications or enhancements that assign straddle claims squarely to one of them [11].
A second mechanism runs through underwriting itself. Underwriters are now asking for bias testing records, human-in-the-loop protocols, model cards and evaluation results [12]. Those answers get incorporated into the policy by reference, which is the step that turns a description of your governance into something a carrier can use against you at claim time [13]. Halbreich's drafting answer is to require knowledge or intent and materiality before a misstatement bites, and to limit the consequences to the covered individuals responsible for it [14]. Read that against who actually writes the answers: the bias testing record comes from the ML team, and the human-in-the-loop protocol comes from whoever owns the workflow. The interview treats sign-off authority on AI use questions as an open question [15].
On the slow failure, the material is thinner than the topic deserves. Help Net Security's summary says Halbreich addresses when the claim clock starts for slow-building model degradation, and how business interruption coverage applies to outages at cloud and compute vendors [15]. The answers carried in the published excerpt develop straddle claims and the warranty language. The degradation trigger remains a question a practitioner has raised, without a settled position behind it yet.
Scope decides how much of this you should care about. If your company is not buying or being bought, straddle claims are somebody else's problem. The application-as-warranty problem arrives at every renewal [12][13], and by the interviewer's account the first call to coverage counsel usually comes after a demand letter has landed [16]. Dates and paperwork fixed long before any incident decide the bill, and they sit in documents most security teams never open.
Ranked by verification strength, evidence, and original report placement.
Tail policies often contain broad exclusions for claims involving any conduct after the cutoff date, and such claims may not be covered by the go-forward policy either insofar as they also involve pre-merger conduct.
Claims alleging both pre- and post-transaction wrongful acts straddle the cutoff point between tail and go-forward policies, and the policyholder can be caught in the middle with no coverage.
The interview also covers who should sign off on AI use questions, when the claim clock starts for slow-building model degradation, and how business interruption coverage applies to outages at cloud and compute vendors.
David Halbreich is an insurance recovery partner at Reed Smith.
Halbreich says the most common misconception he encounters is not about the "what" of coverage but the "when".
D&O coverage applies to liability for wrongful acts by company leadership in the course of running the business; E&O applies to liability for lapses in professional services provided by the company.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One practitioner, no case file
The insurance mechanics are the strong part: claims-made triggers, retroactive dates, runoff versus go-forward towers, and the paired exclusions that create the straddle are textbook, internally consistent, and described by someone who litigates them for a living. Everything beyond the doctrine is unsupported. Help Net Security produces no coverage dispute, no denial letter, no decided case in which an AI acquirer was actually left uninsured, and the text we have breaks off mid-answer, so two of the three questions flagged at the top are never answered on the page.
Nothing anyone counted
Two statements here would be adoption facts if a number were attached to either: that AI merger volume has revived attention on straddle claims, and that underwriters now routinely demand bias tests, human-in-the-loop protocols, model cards, and eval results. Neither arrives with a carrier, a submission, a deal, or a matter count — one is a practitioner's impression, the other is the interviewer's premise. We decline to convert that into a measurement.
Hedged, for a lawyer selling the cure
Restraint is the surprise. A recovery lawyer describing a gap he is offering to close could have reached for horror stories and dollar figures; instead the language is 'can arise', 'often contain', 'may not be covered', and the fix is a policy review. The small overstatement lives in the trend framing — 'renewed focus', 'underwriters are now asking' — which carries weight the reporting never earns, and in a headline exposure that remains a structural possibility rather than a documented loss.
Recovery-side counsel, unopposed forum
Halbreich gets paid to pry money out of carriers on behalf of policyholders, and the natural reader of this piece — a general counsel who now suspects their tail and go-forward towers do not meet in the middle — is a prospective engagement. The prescribed remedy, review both policies in tandem and negotiate clarifying language, is precisely coverage counsel's product. Help Net Security's Q&A format leaves that unchallenged: no underwriter or carrier-side lawyer is present to argue that straddle claims are in fact being paid.
Solid on doctrine, thin on the world
Two layers, two verdicts. How claims-made policies, retroactive dates, and runoff towers interact is easy to verify and hard to get wrong, and we would defend the structural warning about straddle claims fairly firmly. How often that structure actually strands an AI acquirer, and whether carriers are really denying on incorporated governance representations, rests on one interested voice speaking in generalities — and the truncated text carries off two of the topics that would have tested him.