Does product liability insurance cover software?

Applies nationally Technology & SaaS
Direct answer

Almost never, and the reason is structural: product liability responds to bodily injury and damage to tangible property, while a software failure typically causes financial loss and corrupted data — which general liability policies treat as neither. Software failures are a tech E&O question. The exception is software embedded in physical products that hurt people.

Software companies reach for product liability because the word “product” is right there in the name of what they ship. Insurance doesn’t read it that way. The products coverage in a liability program is triggered by bodily injury or physical damage to tangible property — and when software fails, what it usually destroys is money, uptime, and data. For that harm, product liability is the wrong shelf entirely, and buying it produces the most expensive kind of coverage: the kind that never pays.

Why software rarely triggers products coverage

Three definitional walls, each independently sufficient:

  • The trigger is physical. Products liability (inside general liability as products-completed operations) responds to bodily injury and property damage — defined as physical injury to tangible property, including resulting loss of use. A SaaS outage or a miscalculating module injures no body and breaks no tangible thing.
  • Data doesn’t count as tangible property. Loss of, damage to, or inability to use electronic data is the subject of a standard exclusion in general liability policies. The claim your software is most likely to generate — we corrupted the customer’s data — is written out of the form.
  • Financial loss is E&O territory by design. A customer suing over what your software cost them — lost revenue, a missed close, a failed process — is alleging a professional failure, the exact grant of a technology errors and omissions policy, not a products policy.

Even outside insurance, the law has hesitated to treat standalone software as a “product” for liability purposes: the 2023 National Cybersecurity Strategy went so far as to call for new legislation to shift liability onto makers of insecure software — a proposal that only makes sense because existing product liability law largely doesn’t reach it.

Where software liability actually lives

Tech E&O is the line built for providers of technology products and services, covering the failures those products and services cause — including software that doesn’t do what it was sold to do. It’s typically paired with (or blended into) cyber coverage, and the distinction matters: tech E&O covers harm your technology does to customers; cyber covers what a breach does to you and the people whose data you hold. The boundary gets its own page: cyber insurance vs tech E&O, and the coverage grant is detailed in what does tech E&O insurance cover.

The exception: software in things

Products coverage comes back into the picture the moment code inhabits a physical object. Firmware in a thermostat that overheats and starts a fire; a controller board that lets a machine crush a hand; a medical device whose software doses wrong — these produce bodily injury and tangible property damage, and the products-completed operations coverage of whoever sold the device responds. Practical consequences:

  1. Hardware and IoT companies need both lines. The device can hurt people (products/GL) and the software can fail commercially (tech E&O). One policy does not backstop the other.
  2. Component and embedded-software vendors get pulled in. When the device injures someone, the device maker’s insurer looks upstream — embedded developers see indemnification demands and get named in suits, which is why their contracts and tech E&O terms matter.
  3. Pure SaaS sellers can stop worrying about this branch. If nothing you ship occupies space, your products-completed operations exposure is close to nil — the coverage comes along inside GL anyway, at little cost, which is fine; just don’t mistake it for coverage of your actual product.

What contracts actually ask software companies for

Enterprise MSAs and procurement checklists demand general liability (office-and-operations exposure), tech E&O, and cyber — and occasionally a line item reading “product liability,” usually a template inherited from physical-goods vendors. The answer is not to hunt for a products policy; it’s a GL policy with products-completed operations included plus tech E&O, and a conversation with the counterparty about which exposure they actually mean. How these vendor-contract demands work generally is covered in product liability vs general liability.

Questions people actually ask

Does product liability insurance cover design? Design defects in a physical product are classic products liability. Design as a professional service — plans, drawings, code — is an E&O exposure. Same word, two policies.

Does product liability insurance cover services? No. Products coverage addresses goods; harm done by services is split between general liability (physical) and E&O (financial).

Is general liability enough for a software, tech, or hardware company? For software: GL covers your premises and operations, not your product’s failures — tech E&O does. For hardware: GL’s products coverage is load-bearing and its terms deserve real scrutiny.

Is it common for clients to insist on being named as additional insureds on a custom software firm’s policies? Yes — it’s a standard procurement ask, usually satisfiable on the GL policy. Additional insured status on E&O policies is rarer and often resisted by carriers; expect that negotiation.


Sources are linked below. The tangible-property and electronic-data boundaries follow IRMI’s definitions of the standard liability forms; the observation that liability law struggles to reach standalone software is the federal government’s, not ours.

Thanks — your question is in. If it's public, the best ones become a page here. If it's private, an editor will follow up by email.

Ask us

Ask publicly The best questions become new pages here — sourced, anonymized, never with your email.

Questions may be published in anonymized form. No mailing list, no quotes, no follow-up sales.

Ask privately Confidential — for a policy-specific read, answered by an editor, never published.

Sources

  1. IRMI — Property damage — The liability trigger is physical injury to tangible property (and loss of use) — the definition that keeps pure software failures outside products coverage
  2. IRMI — Electronic data liability — Loss of or damage to electronic data is the subject of an exclusion in standard general liability policies and is separately insured
  3. IRMI — Technology errors and omissions insurance — The line actually built for software: covers providers of technology products and services for the failures those products and services cause
  4. The White House — National Cybersecurity Strategy (March 2023) — Called for legislation to shift liability for insecure software products and services — federal acknowledgment that existing liability law largely does not reach standalone software