Gallagher Re put generative-AI litigation in the United States up 978% between 2012 and 2025 - reported by Intelligent Insurer on 25 March 2026, and the figure now travelling around LinkedIn. It is real. The number underneath it is the one that should move a board: the rise from 2024 to 2025 alone was 137%.
What the counts actually show
The same series carries a 59% rise from 2023 to 2024 before that 137% jump, so the curve is steepening rather than merely climbing. Two further counts, built independently and on different definitions, point the same way.
The underlying white paper - Gallagher Re with the AI underwriter Testudo Global - also breaks the US caseload down by claim type: patent infringement 11.9%, copyright infringement 11.2%, personal injury 10.2%. The third of those deserves a second look. Bodily-harm claims are already a tenth of generative-AI litigation, and they are precisely what the new insurance exclusions described below carve out.
There is no authoritative database of AI litigation. What exists are hand-counts, and they should be read as such.
The litigation consultancy DOAR, publishing on 20 April 2026, counted US federal district court cases involving companies clearly engaged in artificial intelligence: 7 in 2022, 19 in 2023, 22 in 2024, and 94 in 2025, with 26 more by the date of publication. That is a thirteenfold rise in three years - from a base of seven. OpenAI is named in more than 40% of them.
J.S. Held’s AI Disputes Monitor, second-quarter edition of 15 July 2026, tracks 426 matters in total: roughly 85 in 2025, and 73 in the first half of 2026 alone, with the second quarter 35% ahead of the first. On pace, it says, to more than double last year.
Those two disagree about 2025 - 94 against 85 - because neither publishes a methodology the other can be reconciled with. We are telling you that rather than picking the bigger number. The direction survives the disagreement.
The one rigorous count is narrower and, for a board, more pointed. Cornerstone Research and the Stanford Law School Securities Class Action Clearinghouse, reporting on 29 July 2026: 15 AI-related securities class actions in the first half of 2026, against 16 in the whole of 2025. They were 13% of filings - and 73% of the Disclosure Dollar Loss Index, some $385 billion, and 73% of Maximum Dollar Loss at $1.3 trillion. A small number of cases carrying most of the alleged value.
The regulator is not yet the thing to be afraid of
The EU AI Act carries penalties of up to EUR 35 million or 7% of worldwide turnover, with tiers at EUR 15 million or 3% and EUR 7.5 million or 1%. The penalty regime has applied since 2 August 2025.
As of September 2026 we can find no AI Act fine anywhere in the Union.
The picture elsewhere is similar. The SEC’s entire take from AI-washing enforcement is $400,000 - Delphia at $225,000 and Global Predictions at $175,000, in March 2024. Presto Automation, the first public company charged, in January 2025, paid nothing: a cease-and-desist, with credit for cooperation. The largest FTC penalty in an AI case we can find is $880,000, against CMG Media Corporation in May 2026, over an “Active Listening” product advertised as AI that listened through smart devices and which turned out to be a purchased email list.
Europe’s two real AI fines are both data protection, not AI Act: Italy’s Garante fined Luka Inc. EUR 5 million over the Replika chatbot in April 2025, and Character Technologies EUR 158,000 in July 2026. The UK ICO has issued no AI fine. Ireland’s Data Protection Commission has two open inquiries into X over Grok and no decision in either.
Read that honestly rather than comfortably. The ceiling is enormous and the record is thin. Anyone briefing a board on regulatory fines alone is briefing the wrong risk.
The people who price risk for a living have already moved
While regulators deliberate, insurers have acted - and an insurer acting is a market judgement about frequency and severity, made by people with money on it.
ISO/Verisk issued new commercial general liability endorsements effective 1 January 2026. CG 40 47 excludes generative AI outright from bodily injury, property damage and personal and advertising injury cover. CG 40 48 and CG 35 08 sit alongside it. W. R. Berkley has an AI exclusion for directors and officers and errors and omissions lines, form PC 51380, drafted with “based upon, arising out of, or attributable to” wording and a very broad definition of AI. Hamilton’s exclusion names ChatGPT, Bard, Midjourney and DALL-E by product.
Affirmative cover has appeared to fill the hole. Armilla launched an AI liability policy with the Lloyd’s underwriter Chaucer in April 2025 - failure to perform as intended, hallucinations, critical errors, defence costs - and has since taken limits to $25 million per organisation.
The number that should concentrate attention is from Gallagher’s 2026 benchmarking: one in five insurance professionals reported clients suffering AI-related losses or claims in the past year, and just over half of those claims were fully covered.
And the defendants are not who you expect
This is the part that matters if you bought AI rather than built it.
Harper v. Sirius XM Radio, Eastern District of Michigan, filed 4 August 2025. The defendant is the employer, not the software vendor - a Title VII claim over a commercial résumé screener, with school, employment history and postcode alleged as proxies.
Huskey v. State Farm, Northern District of Illinois. The insurer, for deploying a machine-learning fraud model against homeowners’ claims. The Fair Housing Act claim survived dismissal in September 2023 and the case is in discovery.
Louis v. SafeRent Solutions named the scoring vendor and Metropolitan Management Group, the housing provider that used the score. Settled in 2024 for over $2 million plus injunctive terms. Open Communities v. Harbor Group Management put apartment owners in front of a court over a third party’s conversational leasing agent; it settled with an outside review of the system.
RealPage is the clearest illustration. The software company’s antitrust settlement with the Department of Justice was conduct-only, no damages. The landlords using the software paid $141 million, announced in October 2025.
In the UnitedHealth nH Predict litigation, the court ordered the payer to disclose the algorithm’s details in March 2026 - a reminder that “the model is the vendor’s” does not keep it out of discovery.
The pattern is not uniform. Kistler v. Eightfold AI names only the vendor. But “our supplier’s model did it” is not the defence that procurement decks assume it is, and no indemnity clause yet written stops your name appearing on the complaint.
For completeness, the largest number in the field is still a developer number: Bartz v. Anthropic, $1.5 billion, finally approved on 20 July 2026 - roughly $3,000 a work, with some 595,000 potential class members. The largest copyright settlement on record.
The gap that produces all of this
EY surveyed 202 senior AI decision-makers at listed companies above $1 billion in revenue and published on 15 September 2026. 91% are running agentic AI. 51% have updated their governance frameworks for it. 85% run agentic systems without real-time human oversight. 26% cannot detect unauthorised AI agents inside their own organisation. 47% have bypassed their own AI governance process to get something deployed in a hurry. 89% hit an AI-related risk in the past year, and 36% suffered a materially negative AI incident.
Gallagher’s 2026 benchmarking found 63% have operationalised AI in some form, up from 45% a year earlier, while fewer than half have a formal risk management framework, an ethical impact assessment, or an AI incident response plan. WTW’s 2026 directors and officers survey found that only 51% of boards report sufficient skill to oversee AI at all.
And the incidents cost. IBM’s July 2026 study of 602 organisations put the average breach at $4.99 million and an AI-enabled breach at $6 million, with a quarter of malicious breaches now AI-enabled - up 56% on the year.
Set those side by side. A third of large companies have had a materially negative AI incident. Fewer than half can describe how they govern the thing that caused it. That is not a compliance gap. That is a litigation pipeline.
What an audit is for, and what it is not
An audit is not a certificate. ISO/IEC 42001 is voluntary in the EU, the UK, the United States and Australia alike, and where a certificate was once offered as a defence - Colorado’s original AI Act - the replacement statute dropped it.
What defends a company is the record: which systems it runs, what each one decides and about whom, which role it holds for each - provider or deployer - what was tested and when, who reviewed the output, what it chose not to deploy and why. Every case above turns on evidence somebody either had or did not have, produced under a timetable somebody else set.
That record cannot be assembled retrospectively in the fortnight after a letter arrives. It is the single artefact that is cheap to build in advance and impossible to build late. Our AI audit produces it: the system inventory, the role and risk classification, obligations mapped to named articles rather than themes, the evidence pack, and a remediation plan with owners and dates. How to build an AI system inventory sets out the first step if you would rather start it yourself.
Risk management is a dimension, not a document
Here is why an AI audit alone is usually not enough. Look again at the cases. A résumé screener is a hiring failure. A claims model is an underwriting failure. A rent-setting tool is a pricing failure. A care-authorisation algorithm is a clinical governance failure. In every one, the technology was the instrument and the exposure came from a decision right, a policy, a supplier contract or a control that was not where it should have been.
Our framework, Total Change Management, holds a register of 42 dimensions across three families - People, Process and Technology. Risk Management is one of them. Governance, Risk and Compliance is another. AI Governance and AI Compliance and Risk Management are two more. Four of forty-two bear on this directly, and they sit in the same register as data quality, decision rights, supplier and procurement, legal and regulatory, and capability - because an AI liability problem is almost never only an AI problem.
The method is two questions. The horizontal gap analysis asks which of the 42 actually fire for this organisation, in this industry, at this moment, and which instruments apply inside each - ISO/IEC 23894 for AI risk guidance, ISO 31000, the NIST AI Risk Management Framework, and COSO’s generative-AI internal control guidance published on 23 February 2026, among more than three hundred mapped standards. The vertical gap analysis asks how far each live dimension has to move: current maturity level, target level - deliberately not always the top - and the practices that close the distance, with a cost attached.
The output is a costed, owned, dated plan, and a list of the dimensions ruled out with the reason given. Two dimensions, ten dimensions, forty dimensions explains why the ones nobody assessed are where programmes fail, and the engagement page sets out what the fixed-price week produces.
If you are outside the European Union
Almost every case above is American, and that is the point. The United States has no comprehensive federal AI statute and the most active AI liability environment in the world. Liability does not wait for legislation; it arrives through discrimination law, consumer protection, securities disclosure, contract and tort, all of which already exist everywhere.
United Kingdom: no AI Act, and none in prospect after the May 2026 King’s Speech. But UK GDPR Articles 22A to 22D have applied since 5 February 2026, requiring you to know which decisions are solely automated and significant, and to offer human intervention - and Equality Act awards are uncapped.
Australia: no AI Act either, though mandatory Australian Standards for AI were announced in July 2026 and are expected to be legislated in 2027. Privacy Act transparency duties over automated decisions commence 10 December 2026, and the Australian Consumer Law and directors’ duties apply today.
We work in all four jurisdictions, with representation in the United Kingdom, the United States and Australia.
Read what the number counts
Every figure above carries a period, a jurisdiction and a definition, and they are not interchangeable. Gallagher Re’s 978% spans thirteen years. Its 137% spans one. DOAR’s thirteenfold rise runs from a base of seven cases. Cornerstone counts only securities class actions and finds fifteen. All four are true, and a board briefed on the largest of them alone has been briefed on the least useful.
Asking what a number counts before repeating it is the same habit that decides whether an AI system survives a regulator’s question or a plaintiff’s request for discovery. It is, more or less, the whole of what an audit is.
Where these numbers come from
Headline figure and claim-type mix: white paper by Gallagher Re in association with Testudo Global, reported in Intelligent Insurer, 25 March 2026. Case counts: DOAR, AI Litigation Trends, 20 April 2026; J.S. Held AI Disputes Monitor, Q2 2026, 15 July 2026. Securities: Cornerstone Research and Stanford Securities Class Action Clearinghouse, 29 July 2026. Penalties: SEC press release 2024-36; FTC Operation AI Comply; EDPB on the Garante Replika decision; Irish Data Protection Commission. Settlement: Authors Guild on Bartz v. Anthropic. Governance: EY, 15 September 2026; Gallagher AI Adoption and Risk Benchmarking 2026; WTW Global D&O Survey 2026; IBM, 29 July 2026. Insurance endorsements: ISO/Verisk CG 40 47, CG 40 48 and CG 35 08, effective 1 January 2026; W. R. Berkley form PC 51380. Case details are from the public docket and from contemporaneous reporting by the firms named in each instance.