Why is AI suddenly on the renewal form?

If your last professional indemnity renewal did not ask about artificial intelligence, expect the next one to. Underwriters price uncertainty, and when a new way of producing client work spreads quickly through a profession before any settled claims experience exists, the response is to ask questions and watch how firms answer.

That tells you what kind of answer helps you. The underwriter is not trying to catch you out for using a drafting tool. They want to know whether your firm adopts new methods deliberately, with written rules and a named reviewer, or whether things happen quietly and nobody is quite sure what is going on. The first is a normal risk. The second is an unknown one.

The uncomfortable part is that plenty of firms do not know which they are.

What is the underwriter actually trying to find out?

Strip the question down and five things sit behind it.

  • Where is it used? Which parts of the work touch AI. Drafting a first version of a report is a different risk from a system that reaches a judgement on a client's position.
  • Who checks it? Whether a qualified person approves the output before it leaves the firm, and whether that approval is a real read or a glance.
  • What goes in? Whether client material is entered into tools, which ones, and on what terms.
  • What is written down? Whether a policy exists, whether staff know about it, and whether anyone enforces it.
  • Can you show it? Whether you could set out, after the event, how a given document came to say what it said.

Four of those five have nothing to do with technology. They are questions about supervision, which your regulator already expects you to answer, whether that is the SRA, ICAEW, RICS, the ARB or the FCA. AI has not created a new standard. It has created a new place where the existing standard is tested.

What happens if you answer no and it turns out not to be true?

This is the real exposure, and it is larger than the exposure from using AI at all.

A firm ticks no because the partners never approved a tool and nobody bought a licence. Meanwhile three fee earners paste draft clauses into a free chat assistant on personal logins, a graduate tidies site notes with one, and the bid team has been generating first drafts of method statements for months. Nobody is hiding anything. They are getting on with the work, and no one told them otherwise. That pattern is the subject of shadow AI.

The answer on the form is now wrong, which is a problem in its own right, quite separately from any claim, because placement runs on the accuracy of what you tell the market. So find out what is happening before you write anything. Ask each team, without blame, what they use and why. An hour of honest conversation beats any review of software spend, because the tools people rely on most are often the ones the firm never paid for.

What does a controlled answer look like?

A good answer is short, specific and dull. Something like: AI is used in these named processes, for first drafts only; a named qualified person approves everything before it reaches a client; client material goes only into approved tools under agreed terms; the policy is written, dated and circulated; and we keep a record of inputs and approvals.

Every clause there is a control an underwriter recognises. Compare it with "we are exploring AI", which says only that you have not thought about it.

If no written policy exists yet, that is the first gap to close, and it is a short piece of work rather than a project. Our guide to writing an AI policy sets out what to include. Then agree what review means in practice, because "it gets checked" is the weakest phrase in the whole answer. The guide to reviewing AI output on client work covers how to catch what a fluent draft hides.

Prepare the data question separately. The ICO and UK GDPR sit behind it and an underwriter is likely to probe. Which client information goes into which tool, on what contractual footing, and what becomes of it. Our guide to data protection and AI on client work covers that ground.

Does using AI make a claim more likely?

Not in itself. Claims arise the way they always have: something wrong went out, and nobody with the right expertise read it properly first.

What shifts is the surface of the risk. A weak draft from a tired junior looks weak. It hedges, it has gaps, and a reviewer's eye snags on them. A generated draft reads smoothly, cites the right sort of thing and uses the firm's own vocabulary. It invites skimming. That is the hazard set out in the risk in copy and edit. The remedy is not banning the draft. It is making approval a deliberate act with a defined scope.

There is a case to be made in the other direction too, and your broker should hear it. A rebuilt process yields the same structure, the same checks and the same logged approval every time. Compare that with a firm where every fee earner writes up a matter differently and half the notes are typed a week late. Defending a claim in the second firm is far harder. Audit trails and consistent file notes are risk controls, not admin.

What should we do before the next renewal?

  1. Establish what is genuinely in use. Team by team, no blame, written down.
  2. Decide your position and record it. Approved tools, permitted uses, prohibited inputs, who signs off. Date it and circulate it.
  3. Make approval real. Define what the reviewer is looking for in the two or three processes where AI touches client-facing work, such as technical reports or bids and proposals.
  4. Speak to your broker early. Not on the day the form is due. Time ahead of renewal lets you learn what this market wants to see and put it in place.

Firms that adopt deliberately find the insurance conversation straightforward, because a process designed on purpose can be described on purpose. Firms that drift find it hard, because there is nothing to describe. The same logic governs what you say to clients, covered in telling clients you use AI.

None of this is legal or insurance advice, and your broker should read your wording. The preparation holds either way: know what you do, write it down, make sure it happens. If you are unsure which process to bring under control first, the audit will point at the one doing the most damage.