Skip to content

有紧急法律疑难?请立即致电 (852) 3416 1711 与本行联系。

Silent AI, loud disputes: a litigator’s view

By Stepanie Lai

Hong Kong, 29 September 2026: Much of the current commentary on “silent AI” risk asks whether insurers have priced AI exposure correctly, and whether policy wordings should be updated to address it expressly. Those are legitimate questions for underwriters and brokers. But from a litigation standpoint, the more pressing question is different: when an AI-related loss occurs under a policy that says nothing about AI, who wins the coverage argument, and on what evidence?

That question will not be answered by market commentary. It will be answered – the first few times, at real cost to whoever tests it – in a courtroom or an arbitration, construing definitions and exclusions that were drafted by people who never contemplated an autonomous system acting as the proximate cause of a loss.

For the uninitiated, silent AI refers to artificial intelligence risks that sit inside a standard business insurance policy without being explicitly included or excluded. This is because such policies were typically written before AI became a core business tool.

The 2026 AI Adoption and Risk Survey from global insurance broker Gallagher found that one in five insurance professionals surveyed already have clients who have suffered an AI-linked loss, and just over half of those losses were fully covered. That leaves a meaningful proportion of claims where coverage was contested, partial, or denied – and disputes of that kind do not resolve themselves quietly.

The Hugging Face incident

The OpenAI–Hugging Face incident is instructive precisely because of how it defies tidy categorisation. OpenAI’s own models reportedly escaped a sandboxed testing environment, reached the internet, and compromised Hugging Face’s systems without human direction – OpenAI called it an “unprecedented cyber incident”. For a litigator, the immediate reaction to a fact pattern like this isn’t “How do we price this risk?” – it’s “How would this get pleaded, and what would each side need to prove?”

That framing exposes at least four battlegrounds that are likely to define the first wave of AI coverage litigation, well before any Hong Kong court has had the chance to lay down guiding authority:

Definitional disputes: Most cyber and liability wordings define terms like “computer system”, “authorised user” or “employee” using language drafted long before autonomous agents existed. Whether an AI agent’s conduct falls inside or outside those definitions is a question of construction – and, in the absence of express AI wording, Hong Kong courts will likely fall back on ordinary principles of contractual interpretation: the natural and ordinary meaning of the words, read in their context, and (where genuine ambiguity remains) the reasonable expectations of the parties at the time the policy was written. Litigators advising on early AI coverage disputes should expect this exercise to turn heavily on expert and contemporaneous evidence of how the parties understood these terms, since there’s no established local authority to anchor an interpretation either way yet.

Causation disputes: Where an AI system acts autonomously, “What caused the loss?” becomes genuinely contested in a way it rarely is in conventional claims. Was the operative cause the AI’s own decision, the inadequate guardrails that allowed it to act unsupervised, or the human decision to deploy the system in the first place? Multiple candidate causes, arising at different points in the causal chain, is exactly the kind of scenario that produces hard-fought “proximate cause” litigation – and where several actors (developer, deployer, end user, third-party integrator) each contributed something to the eventual loss, expect this to generate contribution and apportionment disputes between defendants as well as coverage disputes with insurers, not unlike multi-party product liability or professional negligence claims.

Exclusion disputes cutting both ways: Many liability and cyber wordings exclude “intentional”, “dishonest” or “criminal” acts, or specifically address “malicious code”. An AI model that autonomously exploits a vulnerability wasn’t instructed to do so by any human, which arguably takes it outside exclusions premised on human intent – potentially widening cover unexpectedly for insurers. Conversely, insurers may argue the deploying organisation’s decision to run an inadequately supervised model was itself the relevant “act”, reframing what looks like an AI failure as an ordinary governance failure that falls squarely within existing exclusions for inadequate security practices. Which characterisation prevails will likely turn on how the loss is pleaded and proved, not on any settled principle.

Notification and cooperation disputes: AI-driven incidents can unfold, as in the Hugging Face case, “at machine speed” – reportedly compressing what would normally be a slower-moving intrusion into a matter of hours. Most policies require notification “as soon as reasonably practicable” after the insured becomes aware of a circumstance likely to give rise to a claim. Where an incident is genuinely difficult to detect or characterise quickly because of its autonomous, AI-native nature, insureds may find themselves exposed to late-notification arguments through no real fault of their own – an issue likely to generate its own satellite disputes independent of the underlying coverage question.

The evidentiary problem

Even once the legal question is framed correctly, proving what actually happened in an AI-related incident is a materially harder evidentiary exercise than in a conventional claim. Discovery in a dispute like this will likely need to reach into model logs, training data, decision trees, and system architecture documentation – material that is often proprietary, technically dense, and controlled by a third party (the AI developer) who isn’t a party to the coverage dispute at all. Expect early disputes to also generate satellite battles over third-party disclosure, expert access to source material, and the qualifications needed to give reliable expert evidence on what an autonomous system did and why. Hong Kong’s courts and arbitral tribunals have limited precedent to draw on here, which means the first properly contested case is likely to be unusually resource-intensive for whoever runs it – and unusually influential for everyone who comes after.

What this means in practice

For insurers, the lesson from “silent cyber” a decade ago – referring to cyber-related loss exposures hidden inside traditional insurance policies – is that ambiguity left unaddressed doesn’t disappear, it simply gets resolved later, more expensively, and less predictably, through litigation rather than underwriting. Reviewing and, where necessary, clarifying definitions and exclusions now is materially cheaper than litigating their meaning against a real loss.

For policyholders, the practical takeaway is evidentiary as much as it is about coverage: robust, contemporaneous documentation of AI governance, oversight, and risk controls will likely become the decisive evidence in any future dispute over whether a loss was reasonably foreseeable, whether the insured exercised reasonable care, or whether an exclusion should apply. Waiting until after a loss to reconstruct what governance was actually in place is a considerably weaker position than having it documented in real time.

For both sides, the absence of Hong Kong authority on any of this means the first real test cases will carry outsized weight. Anyone facing an AI-related claim under a “silent” policy right now should treat it accordingly – not as a routine coverage question, but as a dispute that may end up shaping how these issues are decided for everyone who follows.

Stephanie Lai is a Partner with BC&C. She focuses primarily on Insurance & Personal Injury work, including claims arising from workplace injuries on construction sites. As well, she has experience across a broad spectrum of practice areas including commercial matters, employment, criminal law, debt recovery and wills and probate. She can be contacted at StephanieLai@boasecohencollins.com.

按此了解本行逾40年的专业法律经验。

本行的律师团队友好亲切、平易近人,乐于解答您的疑问,并为您提供合理的建议。

联系我們

BC&C-contact-us

新闻及知识

了解更多關于本行的工作和其他咨询。订阅本行的企业通讯,以确保您收到我们的最新消息。

  • 这个字段是用于验证目的,应该保持不变。

Silent AI, loud disputes: a litigator’s view

By Stepanie Lai Hong Kong, 29 September 2026: Much of t […]

Read more

Adoption of AI becomes hit and myth

Hong Kong, 23 September 2026: Chilean-American novelist […]

Read more

Law & More: Episode 71 – Neil Jensen

Hong Kong, 21 September 2026: Today’s guest is Neil Jen […]

Read more

Shenzhen expo offers legal opportunities

Hong Kong, 7 September 2026: Our Managing Partner Alex […]

Read more

Law & More: Episode 70 – Highlights, Part 2

Hong Kong, 1 September 2026: In this second special hig […]

Read more