Skip to content

Engineering and architecture

Does licensing project data affect professional liability insurance?

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

Licensing project data can affect professional liability insurance because a data license is usually not a professional service, so a PL policy may not respond to claims arising from it. Before signing, ask your broker in writing how the PL, cyber and general liability policies would treat the license, and keep contract indemnities within what those policies cover.

Key takeaways

  • A professional liability policy responds to claims arising from professional services, and a data license may well fall outside that definition.
  • Cyber, general liability and media or IP coverage may each touch part of a data license, or none of them may.
  • A liability cap, a no-reliance clause and a narrow indemnity shrink the gap between contract risk and coverage.
  • Get the broker's answers in writing before signing, and check what renewal applications ask about non-professional revenue.

Why might a PL policy not cover a data license?#

A professional liability policy may not cover a data license because the policy is written around claims arising from professional services, such as design, engineering and construction administration. Licensing de-identified RFIs or review comments to an AI developer is a commercial transaction, not a service performed for a client under a standard of care.

That does not by itself make licensing high-risk. It means the claims that could follow a license, such as a former client alleging breach of confidentiality or a licensee alleging breach of warranty, may land in a different policy or in no policy at all. The answer depends on your forms, endorsements and exclusions, which only your broker and carrier can confirm.

The distinction cuts the other way too. Because a license is not professional work, the firm should make sure no licensee can treat the records as design advice, which is why the contract language covered below matters as much as the policy wording.

Which policies might respond, and to what?#

The policies below are the ones a broker will usually look at when a design firm describes a data license. Coverage is described in general terms; actual forms differ, and exclusions matter as much as the coverage grant.

Which policies might respond, and to what?
PolicyWhat it typically addressesQuestion for a data license
Professional liability (E&O)Claims arising from negligent professional servicesDoes the definition of professional services reach a data license, or is an endorsement available?
Cyber and privacy liabilityData breaches, privacy claims and some regulatory mattersWould a claim that personal details survived de-identification be covered?
Commercial general liabilityBodily injury, property damage, some personal and advertising injuryDo data, IP or contractual liability exclusions apply to licensed records?
Media or IP liabilityCopyright and similar claims over contentIs cover available if a third party claims rights in licensed material?
Directors and officersClaims against leadership over management decisionsCould an owner or investor dispute arise from the decision to license?

Where the exposure actually comes from#

The exposure from licensing project data comes mostly from what is in the records and what the contract promises, not from the act of licensing. Knowing which claims are plausible tells you which policy rows above deserve the closest reading.

  • Client confidentiality: a client argues its project information was used outside the purpose its agreement allowed.
  • Privacy: names, contact details or homeowner addresses remain in records after preparation.
  • Third-party content: subconsultant drawings or manufacturer product data in submittals are licensed without the right to do so.
  • Warranties: the license promises accuracy, completeness or rights the firm cannot fully stand behind.
  • Indemnities: the firm agrees to cover the licensee's losses without a cap or a link to the fees received.
  • Reliance: someone treats licensed design records as current professional advice for a real building.

Questions to send your broker before signing#

The broker questions below are worth sending in writing, with a short description of the license scope, the record families and the preparation method attached. A written reply gives the CFO a record to point to if a claim arrives later.

  • Does our PL policy's definition of professional services include licensing de-identified project records? If not, is an endorsement available?
  • Do any PL, cyber or general liability exclusions for data, privacy, IP or contractual liability apply here?
  • Would our cyber policy respond to a claim that personal information was not fully removed?
  • Is the license a change in operations we must disclose now, or only at renewal?
  • Should licensing fees be reported with professional fees on the application, or listed separately as non-professional revenue?
  • How would the carrier treat an indemnity we give the licensee, and what cap keeps it insurable?
  • If a former client claims a confidentiality breach on an old project, which policy responds?
  • Should we require the licensee to carry its own cyber coverage or indemnify us for its use of the records?

License terms that keep risk inside your coverage#

License terms decide how much of the risk the firm keeps, so draft them with the broker's answers in hand. The aim is that any claim the license could produce is covered, capped or allocated to the licensee.

License terms that keep risk inside your coverage
ClauseWhat to look forWhy the carrier cares
Limitation of liabilityA cap tied to fees received, excluding indirect damagesKeeps contractual exposure finite and insurable
IndemnityNarrow, mutual where possible, limited to defined breachesAssumed contractual liability is a common exclusion
No relianceRecords are provided for model development, not as design adviceSeparates the license from professional services
WarrantiesLimited to authority to license and the described preparationAvoids promises the PL policy will not back
Permitted useDefined uses, no republication, no re-identificationLimits how records can reach third parties
Licensee dutiesSecurity, deletion at the end of the term, its own insuranceShifts misuse risk to the party holding the copy

Do you have to tell your carrier?#

Whether you must tell your carrier depends on the policy's notice and change-in-risk conditions and on what your applications asked. Professional liability applications commonly ask about disciplines, services and revenue sources, so a new licensing revenue line may need to appear at renewal even if no immediate notice is required.

Telling the broker early is usually the safer course. A broker can describe the activity to the carrier in the right terms, confirm whether it changes rating or coverage, and help the firm avoid an application answer that later looks incomplete.

Illustrative: an MEP firm's CFO checks coverage first#

Illustrative: a fictional MEP engineering firm is considering a license of de-identified QA/QC comments and RFI responses from private commercial projects. Before looking at a term sheet, the CFO sends the broker a one-page summary of the record families, the excluded project types and the preparation method, with the questions above.

The broker replies that the PL form would not treat the license as a professional service and that the cyber policy's privacy cover is the relevant form, subject to its exclusions. The firm narrows the scope to projects without strict confidentiality terms, caps its liability at fees received, adds a no-reliance clause and plans to disclose the licensing revenue on its next renewal application.

How SourceX supports the insurance conversation#

SourceX does not give insurance advice, but it gives the CFO and broker a documented scope to review. Each package carries a SourceX Evidence Packet recording provenance, licensing rights, permitted use, the privacy record and release authorization, which covers much of what a broker asks about scope and preparation. Within the SourceX five-step transaction, the firm approves each step, and Delivery waits until the Approval step is signed.

Frequently asked questions

Will licensing raise our PL premium?

It may or may not. Carriers rate professional liability mainly on disciplines, project types, claims history and fees, and each carrier may view a licensing revenue line differently. Only your broker and carrier can say how your policy is rated, so ask before the license starts rather than discovering the answer at renewal.

Can a client bring a claim years after we sign a license?

Yes, a claim can arise whenever a client learns its project information was used. Professional liability and cyber policies are commonly written on a claims-made basis, so the policy in force when the claim is made usually responds. Keep the license, the rights review and the de-identification record together so a later claim can be answered from documents.

Should the AI developer carry insurance for our records?

Asking is reasonable. The licensee controls how records are stored and used after delivery, so its own cyber coverage and an indemnity for misuse can be part of the terms. Large developers may resist some requests; if insurance terms cannot be agreed, prioritize security, deletion and no-re-identification obligations.

Does our cyber policy cover a vendor that prepares the data?

That depends on how your policy treats data held by third parties on your behalf. Some cyber forms address incidents at vendors and others limit that cover. If a preparation partner handles records before delivery, ask the broker whether an incident there would be covered and which contract terms the carrier expects.

Does a de-identified dataset still need cyber coverage?

It can. De-identification lowers privacy risk but does not remove it, because unusual details can still point to a person or a project. Cyber privacy cover may matter if a claim alleges re-identification, so describe the preparation method to the broker and keep the record of what was removed.

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify