Skip to content
OnPrem

AI and your PI insurance — six questions worth asking your broker

The right time to find out your PI policy has an AI exclusion is not while you're notifying the client.

Published 26 July 2026

Professional indemnity insurance is a place where the AI question comes into unusually sharp focus. Insurers are actively rewriting policy language in response to the risks they see, and different insurers are landing in different places. The result is that firms who have not specifically asked how their PI responds to AI-related incidents often do not know — and the discovery moment is the wrong moment.

This is a short article about six specific questions to put to your broker. This is not insurance advice. Your broker is; this is a prompt to have the conversation.

Why this matters more than it did

Two dynamics are shifting the ground.

The nature of AI incidents is becoming familiar. Insurers are seeing enough claims involving AI-related disclosure that they are forming views on how their policies should respond. Those views are not always aligned with what a firm might assume.

Cyber and PI are colliding at the boundary. AI-related incidents can trigger both PI and cyber exposures — or fall in the gap between them. Where your PI policy assumes cyber coverage picks up certain scenarios, and your cyber policy assumes PI does, you can end up uncovered.

The questions below are structured around this reality.

The six questions

1. Does our policy have any AI-specific exclusions or conditions?

Some policies now include explicit AI-related exclusions or condition compliance on specific AI-related requirements. Some are silent on AI but rely on general exclusions (unauthorised acts, breach of policy, etc.) to potentially decline AI-related claims.

If your policy has AI-specific language, understand exactly what it says. If it does not, understand which general provisions could plausibly be applied to an AI incident, and how.

2. If a staff member’s use of a personal AI account causes an incident, how does the policy respond?

The scenario: an associate uses her personal ChatGPT account to summarise a discovery bundle. A client learns about it and complains. There is a costs order or a notifiable data breach follows.

Was this use “in the course of professional practice” as the policy defines that? Was it authorised by the firm? Would the “unauthorised acts of employees” or similar provisions be triggered? Would the “reasonable steps to prevent” defence be available to the insurer against your claim?

The answers vary considerably by policy and by facts. The wrong time to find out is when you are already notifying the client.

3. What does the policy require by way of AI governance or policy?

Some policies now include, as a policy condition, that the firm maintain and enforce a written AI use policy. Others reference broader “documented risk management” that is being interpreted by insurers to include AI.

Where these conditions exist, non-compliance with them can be a basis for decline. Understand what your policy requires, and confirm you actually have it. A policy document that exists but has not been circulated, or that references processes that no longer occur, is not the compliance the insurer thinks they have obtained.

4. How does the policy interact with our cyber policy on AI incidents?

For a data disclosure caused by AI use, does the incident fall under PI (professional liability arising from advice given or work performed) or cyber (data breach and privacy violation)?

Some incidents plausibly fall under both. Some fall in gaps between them. Some fall clearly under one, and firms discover during notification that the “coverage” they assumed under the other does not exist.

Have your broker walk you through concrete AI-incident scenarios and identify which policy responds to which element. Legal defence costs, first-party investigation costs, third-party liability, regulatory fines, notification costs — each may sit differently.

Insurers are asking about AI on renewal proposals in ways they were not two years ago. Understanding what is being asked, what your answers imply, and what verification is expected matters.

Some proposal questions are open enough that a truthful answer may or may not lead to declines or increased premiums; how you frame the answer, and what evidence you can produce for it, will affect your renewal position. A broker who understands the AI-specific questioning will help you present accurately without volunteering unnecessary vulnerability.

6. What would the insurer want us to do in the first 24 hours after an incident?

Insurers usually have specific expectations around notification, evidence preservation, and communication after an incident. AI-related incidents create particular preservation and evidence questions — the conversation history is often the only record of what was actually disclosed, and premature deletion may compromise both the notification obligation and the insurance claim.

Establish the specific expected sequence before the incident. It will substantially change how you handle the first day when it happens.

What the answers usually reveal

We are not in the insurance business and cannot give you industry averages, but the pattern we see across firms who ask these questions is consistent.

Most firms discover that their policy position on AI is less clear than they assumed. Some discover explicit exclusions they were unaware of. Others discover that scenarios they assumed were covered fall in gaps between policies. A few discover that their coverage is genuinely comprehensive, but only because they have already done the governance work required to keep it that way.

None of the outcomes is a reason to panic. All of them are a reason to have the conversation before an incident, not after.

The broker relationship worth investing in

The specific broker matters here more than it did five years ago.

A broker who understands AI-related risk exposure specifically — as opposed to generic professional indemnity — can help you structure coverage that responds appropriately, and can advise on what governance investments will improve your position. A broker who is still relying on standard product templates from the mid-2020s may not be equipped for the current environment.

If your broker cannot walk you through the six questions above and give you specific answers referenced to your actual policy wording, that is data about the broker relationship. You may be better served by a specialist.

What we do about this on our side

For clients who ask, we can walk through the specific AI-use patterns our systems enable and support conversations with your broker about how those patterns interact with the policy. That is not insurance advice — but it is enough factual detail about the technology for your broker to give you good insurance advice.

Firms that have done this well have generally found that a well-governed AI environment — whether cloud, on-premise, or hybrid — actually improves their PI position rather than worsening it. Insurers are more comfortable insuring a firm that has thought about AI risk than one that has not. Getting the governance right is a defensive move as well as an offensive one.

This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.

Want to know what your firm is actually exposing?

We will walk through where confidential material is most likely leaving, and tell you plainly whether an on-premise system is worth it for a firm your size.

Request an assessment