Your professional indemnity insurer now cares how your firm uses AI. Brokers and insurers have started asking about it at renewal, and law firms such as Browne Jacobson have published the questions they think PI insurers should be asking about clients' AI usage (The Word, February 2026), with the insurance market's own commentary (for example LPM's piece on demonstrating responsible AI use to insurers) pointing the same way. Not every insurer asks every question, and cover always turns on your actual policy wording and underwriting assessment - but these five are the questions worth having written answers for before renewal.
Most small firms can answer these questions today, but not in writing. That is the gap that matters. An answer that exists in a partner's head is worth nothing when the proposal form, the broker and (if it comes to it) a claim all need the same answer on paper.
Here are the five questions to prepare for, and the written evidence each one needs.
Direct answer
What should a law firm prepare for an insurer's AI questions?
Insurers want to know five things: which AI tools your firm uses and who approved them, where client data goes when those tools run, what a human checks before output reaches a client, what your written policy and training say, and what happens when something goes wrong. Each answer needs a document behind it - an inventory, a data map, a review record, a policy and an incident route - not a verbal assurance.
1. Which AI tools are in use, and on whose authority?
This includes the tools the firm bought and the ones individuals added themselves. An insurer asking "do you use AI?" is really asking whether you know. LexisNexis's August 2025 survey of UK legal professionals found 61% using generative AI while only 17% had it embedded in firm-wide strategy - the shape of the exposure an insurer prices: use that has outrun governance.
The evidence: a written inventory of every tool approved for firm work, the workflows each is approved for, and the named person who can say no. One page is enough for a firm of twenty.
2. Where does client data go?
If you feed a client matter into an AI tool, an insurer wants to know the data's route: what is sent, where it is processed, who else can access it, and whether it trains someone else's model. These are the same questions a firm should put to any vendor before use - we set out the seven questions to ask a legal AI vendor in an earlier guide, and the written answers double as your insurer pack.
The evidence: a short data map for each approved tool covering data types, locations, subprocessors, retention and model-training terms. Verbal answers from a sales call do not count; ask the vendor to put it in writing.
3. What does a human check before anything reaches a client?
This is the question that separates "uses AI" from "uses AI within a professional process". Insurers are not expecting zero AI use. They are expecting named review: who checks what, at which stage, and how the check is recorded for the work that carries client risk. We covered what meaningful human review looks like in a previous guide.
The evidence: a one-paragraph review rule per workflow (draft review privilege, client-facing output, citations) showing what the model may draft and what a fee earner must verify, with the check recorded in the matter.
4. What does your policy say, and how do people learn it?
A documented AI use policy is fast becoming the minimum renewal artifact. Insurers will ask for the document and then the harder question: how people actually hear about it. A policy that exists in a shared drive answers the first question and fails the second.
The evidence: the written policy (permitted tools, prohibited uses, data rules, review rules), how it is covered at onboarding, and when it is refreshed. A dated page beats a long manual.
5. What happens when it goes wrong?
Every insurer prices the failure case. They will want to know who is the first person to catch an AI-assisted error, how the firm decides whether a client needs to be told, and who talks to the insurer. Preparing the answer calmly for a proposal form is a lot easier than discovering the question during a claim.
The evidence: an incident route - who is told, how the output and source material are preserved, and who owns client and insurer communication. Half a page.
What to do this month
Write down the five answers, even if the first draft is rough. The workshop we run exists for exactly this: in half a day we map your workflows, tests and controls, and you leave with the written answers an insurer, a client or an auditor can read. Margo, our AI assistant for legal teams, is in controlled development rather than general availability; the governance questions above are the same ones it is being built to answer. If you would rather start alone, our answers, tools and standards pages run one workflow through these checks for free.
Frequently asked questions
Will my insurer refuse cover if we use AI?
Nothing published suggests blanket refusals for AI use. Cover always depends on your insurer, your policy wording and the underwriting assessment - and that is the point of preparing: the risk in front of you is an unanswerable question, not the tool itself.
Do these rules apply to a firm of five fee earners?
Yes. The questions scale down fine - the inventory, data map, review rule, policy and incident route fit on a few pages for a small firm.
Is this the same as SRA compliance?
No. This is an operational pack for renewal conversations. It overlaps with good practice but nothing here is regulatory advice, insurance advice or legal advice.
What if we only use Copilot or ChatGPT privately?
Private use is still use of an unapproved tool with work material. Put it on the inventory and either approve it, replace it or prohibit it - insurers read "we don't know" as the worst answer.