Artificial intelligence is becoming increasingly embedded in incident investigations, root cause analysis, and corrective and preventive action planning.

The benefits are significant. AI can help teams organize evidence faster, reconstruct timelines, identify overlooked causal factors, surface patterns across incidents, and develop stronger corrective action options.

But as those capabilities become more powerful, another question is moving quickly up the agenda for EHS leaders, corporate counsel, and risk teams:

What happens when AI identifies a risk, recommends an action, or creates an investigative record that later becomes relevant in litigation, a regulatory inquiry, or an insurance claim?

A new whitepaper from Reed Smith and Haven Safety AI examines that question in detail. Its central conclusion is important: AI does not fundamentally create a new theory of liability. What it changes is the volume, clarity, structure, and traceability of the information an organization creates about what it knew and how it responded.

Recent developments in insurance coverage and attorney-client privilege make that distinction increasingly important.

The issue is not that AI creates new liability

Courts and regulators have always examined internal investigation reports, audits, engineering studies, consultant recommendations, and corrective action records.

The underlying questions have not changed much:

What did the organization know? What hazards had it recognized? What corrective measures were available? And did it respond reasonably to the information it had?

AI does not create a new duty of care simply because it generates a hypothesis or recommends a control. But it can create a much clearer documentary trail of the organization's analysis.

An AI-assisted investigation may contain alternative causal hypotheses, candidate corrective actions, transcripts, working notes, comments, audit logs, and other electronically stored information. That material may become discoverable even if it never appears in the final investigation report.

That changes the governance challenge.

The risk is not simply that the AI produced a recommendation. The greater risk is having no disciplined process for evaluating, approving, rejecting, deferring, or otherwise resolving what the system produces.

A growing backlog of unresolved recommendations can tell a very different story than a documented record showing that each recommendation was evaluated, assigned, dispositioned, and verified.

Insurance is becoming part of the AI governance conversation

Insurance creates a separate layer of risk.

Many commercial insurance programs were designed before generative AI became part of operational safety workflows. As a result, organizations may face ambiguity over whether and how existing policies respond when AI-generated analysis or recommendations contribute to a claim.

That ambiguity is beginning to become more explicit.

Beginning in 2026, Insurance Services Office forms have given commercial general liability insurers new mechanisms to exclude certain claims arising from generative AI. Major carriers can now attach AI-related exclusions that may affect bodily injury, property damage, and other claims tied to generative AI.

For safety leaders, this introduces a practical consideration that historically may have sat outside the investigation workflow.

If an AI system recommends a corrective action, the organization evaluates that recommendation, and a subsequent incident occurs, how will the company's insurance program respond?

The answer will depend on the specific policy, endorsements, facts, and circumstances. But the broader implication is clear: organizations adopting AI in safety should involve insurance, risk management, brokers, and coverage counsel as part of their governance process rather than treating coverage as an issue to examine only after a claim occurs.

The whitepaper recommends periodic review of insurance programs as AI use expands, models change, new data sources are introduced, or AI-supported decisions move into additional operational areas.

Privilege depends on how the investigation is structured

A second development involves attorney-client privilege.

A February 2026 ruling from the U.S. District Court for the Southern District of New York addressed whether AI-generated work could receive attorney-client privilege protection. The specific AI interactions at issue were not protected, but the court's reasoning suggested that different facts, including AI work genuinely performed at the direction of counsel, could produce a different result.

That reinforces a principle that already applies to traditional corporate investigations:

Privilege depends on process, not simply on labeling an investigation "privileged."

AI does not inherently destroy privilege. But privilege can become harder to defend when working outputs are broadly distributed, copied into normal business channels, mixed with routine operational records, or stored without clear access and workflow controls.

This becomes particularly important because AI can produce substantially more intermediate material than a traditional investigation.

More drafts. More hypotheses. More analysis. More recommendations. More electronically stored information.

Organizations therefore need to think deliberately about which investigations are routine operational safety work and which require counsel-directed treatment.

A practical answer: two investigation lanes

The whitepaper proposes a straightforward operating model.

Lane A: Operational learning

For routine incidents where litigation is not reasonably anticipated, AI can support evidence organization, timeline reconstruction, causal analysis, RCA, and CAPA development as part of the normal safety process.

Those outputs should be treated as ordinary business records and governed accordingly.

Lane B: Counsel-directed investigations

For severe incidents or circumstances involving credible litigation exposure, counsel directs the purpose, scope, access, and communications surrounding the investigation. Workspaces should be segregated, distribution minimized, and appropriate privilege and work-product controls applied.

The paper also provides an example trigger guide for escalation into Lane B, including fatalities or life-altering injuries, catastrophic property loss, credible third-party claims, credible criminal exposure, allegations of intentional misconduct, or circumstances where litigation is reasonably anticipated.

The goal is not to make every investigation a legal matter.

It is to establish the escalation rules before the serious incident happens.

AI drafts should not automatically become company conclusions

One of the most important governance principles in the paper is simple:

AI generates candidate hypotheses and candidate corrective actions. Humans approve findings, conclusions, and final CAPA decisions.

Only approved outputs should represent the organization's position.

That distinction needs to exist in the technology itself, not just in policy language.

An AI-generated contributing factor should be identifiable as a candidate. A proposed corrective action should remain a proposal until reviewed. Investigation working material should remain separate from the approved record.

The whitepaper recommends separating investigation artifacts into three categories:

  1. Evidence record
  2. AI working outputs
  3. Final approved record

It also recommends explicit approval gates and consistent labeling so that drafts cannot easily be mistaken for adopted company findings.

This is an important principle for responsible AI in safety more broadly.

The objective is not AI decides.

The objective is AI reasons, surfaces evidence, proposes alternatives, and helps qualified professionals make better decisions.

CAPA disposition becomes more important, not less

AI can dramatically increase an organization's ability to identify potential improvements.

That is valuable, but it also creates a governance obligation.

If a system produces 20 potential corrective actions and none has a clear disposition, the organization may simply have created a more sophisticated backlog.

The paper recommends requiring a defined outcome for every material recommendation: adopt it, modify it, reject it with rationale, defer it with a defined re-review date, or address the risk through a documented alternative control.

That discipline has value well beyond litigation.

Under OSHA Process Safety Management and EPA Risk Management Program requirements, certain organizations already have explicit obligations to address and resolve investigation findings and recommendations and document those resolutions. AI can improve the completeness and traceability of that process, but it can also increase the volume of recommendations that must be managed.

In other words, the more effectively AI helps an organization identify risk, the more important the decision and learning system around the AI becomes.

What safety leaders should expect from an AI investigation platform

These issues also change what organizations should look for when evaluating AI technology for investigations.

A high-consequence investigation platform cannot simply be a chatbot sitting on top of incident data.

The whitepaper identifies capabilities such as:

These are not peripheral compliance features.

As AI becomes more central to investigation, RCA, and organizational learning, they become part of the architecture required to make AI usable in a high-consequence environment.

The answer is better governance, not less AI

It would be easy to interpret these developments as an argument for slowing down AI adoption in safety.

We believe the opposite conclusion is more useful.

AI-assisted investigations can improve investigative rigor, detect recurring hazards earlier, strengthen corrective action decisions, and make organizational learning possible at a scale that traditional manual processes simply cannot achieve.

But those advantages need to be paired with governance.

Organizations that distinguish working analysis from approved conclusions, maintain clear decision rights, resolve recommendations systematically, preserve evidence appropriately, establish counsel-directed escalation paths, and understand their insurance coverage can create a more defensible record, not a less defensible one.

The question for safety leaders is therefore becoming less about whether AI belongs in incident investigations and more about how to build an operating model that allows the organization to use it responsibly.

That is the focus of our new whitepaper with Reed Smith, "Legal, Regulatory, and Insurance Considerations When Leveraging AI in Investigations, RCA, and CAPA."

Download the full whitepaper: havensafety.com/resources#ai-governance-whitepaper

The paper includes a practical implementation checklist for safety leadership, a proposed two-lane governance model, system requirements for AI-enabled investigation platforms, an example trigger guide for counsel-directed investigations, and recommended language for distinguishing AI-generated drafts from approved company findings.

This article and the whitepaper are provided for general informational purposes and are not legal, insurance, or coverage advice.