Enterprise AI Liability Claim Process
This guide outlines the official process for enterprises to claim financial relief after a qualifying cyber or AI-related incident under the Enterprise AI Compensation Fund. This process is supported and managed by SAEPRIS in partnership with accredited insurance providers.
Eligibility Criteria
- Registered enterprise with valid business license and tax number
- Active AI system or digital infrastructure in operation during the incident
- Incident involves measurable financial loss or system breach directly linked to AI or cyber attack
- Prior SAEPRIS compliance audit (or waiver in special sectors)
- Notified SAEPRIS AI Incident Registry within 72 hours of attack
Step-by-Step Claims Process
-
1. Incident Detection & Emergency Containment
Notify internal IT, legal, and compliance teams. Engage cybersecurity incident response vendors if applicable.
-
2. File Immediate Incident Report
Submit notification to the SAEPRIS AI Incident Registry via saepris.co.za/incident-report within 72 hours.
-
3. Submit Initial Claim Application
Access the AI Compensation Fund Portal and submit Form AICF-01 with:
- Company details and registration info
- AI system description (vendor, model type, deployment scope)
- Preliminary loss estimate and attack vector
-
4. Provide Evidence Bundle
Upload required documentation:
- Forensic IT report or log analysis
- Proof of AI-related causation (e.g., failed LLM prompt guardrails, algorithmic misfire)
- Financial statements showing loss
- Communication with insurers and/or authorities
-
5. Joint Verification Process
SAEPRIS Compliance and the assigned insurer initiate a joint investigation within 15 business days.
-
6. Compensation Determination
Final ruling issued within 30β45 business days. Compensation will be:
- Paid directly to enterprise for direct losses
- Or split between enterprise and third-party vendors for recovery support
-
7. Post-Incident Audit (Required)
All successful claimants must complete a mandatory SAEPRIS cyber-AI risk remediation plan within 60 days.
What Is Not Covered
- Incidents stemming from known negligence or non-compliance with previous audit directives
- Losses not traceable to AI systems or cyber breach activity
- Double-claiming across multiple insurers or compensation channels
- Deliberate misrepresentation of damages or systems