Guide · 2026

Technology Company Insurance: The 2026 Liability Playbook

Executive summary

A technology company's insurance is rarely a risk decision. It is a condition of the deals you need to close — the enterprise customer's contract, the office lease, the data you hold, and the products you ship. Those requirements decide most of what you carry. This playbook maps the five exposures that generate technology claims to the liability line each one belongs to, who can assert it, and what the other party will demand before they sign.

Most technology companies meet commercial insurance not by asking “what’s my risk?” but by finding a coverage requirement inside a deal they need to close. The enterprise customer’s contract asks for technology E&O and cyber. The lease asks for general liability. The data you hold invites state regulators in whether or not a customer complained. By the time you are reading policies, much of what you carry has already been decided by the people whose signatures you need.

That reframe is the point of this playbook. It is not a catalog of what each policy does — that work belongs on the sister library, isthiscovered.org. This is the professional-liability map: five exposures that generate claims at a technology company, who can assert each one, and which line of coverage is supposed to answer it. The venture-backed startup has its own playbook; this one covers the broader vertical — SaaS, hardware, AI products, and technology services.

Where these hit your timeline. Few arrive at founding. They attach to milestones.

MilestoneWhat entersWhy then
Sole operator or small teamDefer most coverageNo outside party is demanding anything; no employees generate claims
First enterprise customerTech E&O + cyberThe customer’s contract conditions the deal on proof of both
Shipping hardware or an AI productProduct liabilityA physical product, or an AI output that causes harm, activates a different line
Outside funding, outside directorD&OInvestors require it before the board seat; often a closing condition
Office or physical operationsGeneral liability + propertyThe lease demands it; any premises exposure activates GL

1. Your software or service fails and costs a customer money

A client says your platform went down, your migration corrupted their records, or your model steered them wrong — and the financial loss traced to it is what they want back. They sue. This is the defining exposure of a technology business, and the coverage that answers it is technology E&O — professional liability written for companies whose product is technology. It pays to defend and settle claims that your service failed a client: negligence, a bug that cascaded into financial loss, a project that did not meet the contract.

What trips companies is the line next door. General liability covers bodily injury and property damage to third parties; it does not turn a customer’s economic loss into a covered claim. A missed deadline, a bad configuration, or a defective analysis is a professional-liability matter, and the boundary between the two is read from the policy, not assumed. A federal court opinion on the professional-services boundary — General Star National Insurance Co. v. Sotheby’s — shows how a duty-to-defend question turns on whether the work counts as a professional service under the form.

In practice you carry this one because a customer made you. Enterprise and regulated customers require proof of specific E&O limits before signing, and the number in your largest contract’s insurance clause is the floor, not a suggestion. Two details earn the attention they rarely get. First, whether the policy’s definition of “technology services” actually includes what you do. Second, whether a contract-liability exclusion pushes a breach-of-contract suit back outside coverage — forms advertise “failure to perform” while carrying exclusions that can cut the other way. For AI-dependent products, underwriters are asking pointed questions about how the service is described, so match the policy’s definition to your actual offering before you certificate it to a customer.

2. Customer or user data is breached

A breach, a vendor failure, or a privacy misstep exposes data you held on behalf of customers or users. Two enforcement paths converge on you, and that is what sets this exposure apart from a service-failure claim. Your customer can sue or demand proof of coverage under the contract — but your state’s attorney general can also act under state privacy law, whether or not any customer complained. The contract is one trigger; the statute is another.

The coverage is cyber, and most technology companies buy it blended with technology E&O in a single policy. The distinction that matters is first-party versus third-party. The lawsuits that follow a breach of your product sit on the E&O side; the cost of your own forensic, notification, and ransomware response is first-party cyber, and a standalone E&O form leaves that side bare. The boundary is mapped in cyber insurance versus tech E&O; the mechanics of what cyber responds to live on the sister library, isthiscovered.org.

3. You ship hardware or your AI product causes harm

A device you manufacture catches fire. An AI tool’s output drives a decision — a medical recommendation, an autonomous action, a financial screen — that leads to physical injury or financial ruin. The coverage that answers a product you made causing bodily injury or property damage is product liability, a line distinct from both technology E&O and general liability. It responds when a product you manufactured, distributed, or put your brand on causes harm.

The boundary between software and product liability is unsettled, and that is where technology companies get caught. Pure software that causes financial loss is an E&O matter; software embedded in a device that causes physical harm pushes toward product liability. General liability excludes your own product; product liability excludes financial loss without physical harm; technology E&O excludes bodily injury. For AI-dependent products the question is sharper still, because underwriters and courts are still sorting which line responds when a model’s output — not a human’s act — is the proximate cause. Read all three forms before assuming any one of them answers your worst case.

4. A funded company’s investors sue the board

A down round, a failed acquisition, or a statement about the business — increasingly, a claim about what your AI can do — that investors later say was wrong. They sue the directors. The coverage is D&O, and the reason it tops every investor’s list is the board seat itself: an outside director is accepting personal liability for decisions they do not control day to day.

This exposure is covered in depth in the startup liability playbook, because the financing forces it: investors typically expect D&O by or shortly after a priced round, and a company’s promise to indemnify its directors is only as good as its balance sheet. Delaware’s indemnification statute (Title 8, §145) sets the corporate side of that bargain; the policy backstops the part the corporation cannot fund. For an established technology company with outside directors, creditor debt, or acquisition activity, the same calculus applies — the Side A portion of the policy is the part that earns its keep when the company cannot indemnify. The financing trigger and the Side A/Side B structure are laid out in the startup guide; the liability question for a mature company is whether the limit has kept pace with a larger balance sheet and a wider set of claimants.

5. Someone is hurt or property is damaged on your premises

A visitor is injured at your office, or property is damaged in the space you lease. The person hurt — or their insurer — looks to your company to pay. The coverage that answers is general liability for bodily injury, property damage, and certain advertising injuries; if a physical product you shipped caused the harm, the product liability line from section 3 governs instead.

For a pure software company this is real but modest — a small physical footprint, low premises exposure. What makes it non-optional is the lease. Commercial landlords require general liability, commonly at $1 million per occurrence, and name the landlord additional insured. Advertising-injury coverage can matter for marketing-heavy companies in ways founders do not expect. This is the one exposure where the contract and the stakes are both comparatively predictable.

The decisions that are actually yours

Strip away the requirements and a pattern emerges across the five. The same three questions decide almost every line, and buyers conflate them constantly:

ExposureLegally required?Someone will require it?Prudent even if not?
Technology E&ONoYes — customer contractJudgment, before enterprise deals
CyberPartly — state privacy lawYes — customer contractYes, if you hold any data
Product liabilityNoSometimes — distributor or retail agreementYes, if you ship hardware
D&ONoYes — investors at the roundYes, with outside directors or creditor debt
General liabilityNoYes — your landlordPremises or product exposure

Those are different reasons to buy the same policy, and they point at different limits. The genuine decisions — the ones a brochure will not make for you — are narrower still. Size limits against your worst single exposure, not a generic tier. The floor is whatever your largest contract demands; the sanity check is the most plausible loss from one failure, defense costs included. Read the claims-made trigger before you switch carriers. Most E&O, D&O, and cyber policies respond when the claim is made, not when the work happened, so a changed retroactive date or a lapsed policy can open a gap over years-old work. Decide where cyber ends and tech E&O begins for an AI-dependent product, because underwriters are drawing that line in real time and your policy’s definition of technology services is where they draw it.

A short checklist

  1. Signing an enterprise contract → read the insurance clause; the limits it names are your Tech E&O and cyber floor.
  2. Shipping hardware or an AI product → map which form responds to physical harm before you launch, not after.
  3. Funded with outside directors → confirm D&O is in place; the startup playbook covers the financing trigger.
  4. Signing a lease → confirm the general-liability limit and the additional-insured endorsement before you take the keys.
  5. Renewing or switching carriers → check the retroactive date and prior-acts language before you replace a policy.

Sources are linked below. This playbook frames the liability exposures; the coverage mechanics — forms, certificates, mandates, claims — are on isthiscovered.org, and each exposure above links to its own question page for the sourcing behind the claim.

Sources

  1. Context source: Founder Shield — Technology E&O guide — Tech E&O claim taxonomy — failure to perform, negligence, software errors causing financial loss — and what the form excludes.
  2. Primary source: General Star National Insurance Co. v. Sotheby's (11th Cir.) — Court opinion on the duty to defend and where the professional-services boundary falls — the line that decides whether a claim sits inside a liability form or outside it.
  3. Context source: IRMI — Directors and officers liability insurance — Professional authority describing D&O claims against directors and officers over management decisions and identifying shareholders, regulators, creditors, competitors, and the company as possible claimants.
  4. Primary source: Delaware Code — Title 8, Chapter 1, Subchapter IV (indemnification) — Section 145 addresses corporate indemnification of directors, officers, employees, and agents — the corporate promise a D&O policy backstops when the balance sheet cannot.
  5. Context source: New York Department of Financial Services — Small businesses — State regulator overview distinguishing common business-insurance exposures and state-required coverage.
  6. Context source: Vouch — What kind of insurance do startups need? — The incumbent baseline; investors typically expect D&O by or shortly after a priced round, alongside general liability and cyber.
  7. Context source: Insureon — General liability FAQ — Incumbent baseline describing what general liability covers and the per-occurrence limits landlords commonly require.