
Demonstrating responsible use of AI to your insurers
Sam Pye, director – professional and financial risks – at Miller Insurance Services, explores strategies for responsible AI use that assure underwriters during professional indemnity insurance renewals
LPM Frontiers 2026 found that 57% of law firms are at an early stage of genAI adoption, and PWC has said that AI adoption is accelerating rapidly: it’s clear that AI in the legal sector is moving rapidly from theory to real-world application.
For the legal profession, the question is no longer whether the technology is relevant, but whether they can show insurers and other stakeholders that its use is appropriate, properly governed, understood and controlled.
To provide assurance to underwriters during your professional indemnity insurance (PII) renewal, you should be able to evidence a careful, risk managed approach to AI adoption and explain how it will be used in the provision of professional services to your clients. Insurers are particularly interested to understand the journey your firm has gone on in adopting AI tools, in deciding which tools to use and for what purpose, what training has been and continues to be provided, and the governance and oversight regime that has been put in place to ensure you meet regulatory requirements.
Key areas to address for insurers
Scope and purpose of AI
- Clearly define where and how AI is used in your firm, distinguishing between routine, low-risk tasks (such as low-risk administrative tasks) and higher-risk functions (such as decision support for professional legal advice, undertaking legal research or for critical systems).
- Explain how AI is integrated into your processes, i.e. whether it is fully embedded or used for specific tasks. If possible, record AI inputs and outputs.
- Where appropriate, inform clients about AI involvement and what this means to them.
Governance and oversight
- Establish robust internal policies and risk frameworks governing AI use, ensuring these are regularly updated as technology and its applications evolve.
- Assign clear accountability for AI outcomes, ensuring a human always reviews and approves important outputs, particularly those with legal or regulatory implications. If your working practices and AI policies allow for non-human oversight, then it is imperative that insurers are made aware of this and have opportunity to understand the safeguards you have in place.
- Demonstrate compliance with relevant regulatory requirements and guidance.
- Have an acceptable use policy which covers when AI can be used, in what context and by who. Miller can review your existing policy, or provide some exemplar templates, which can provide a starting point if you do not already have a policy in place.
Data privacy and cyber security
- Detail how you protect client confidentiality and data integrity, complying with UK GDPR and related standards.
- Specify if AI tools are used in closed systems or if data is processed or stored externally, particularly when using third-party tools.
- Address how you select and monitor vendor practices (especially regarding data ownership, handling and security), and mitigate cyber risks associated with external AI providers.
Staff training and supervision
- Ensure all personnel using AI receive comprehensive training on both the opportunities and risks, including how to check for errors and prevent overreliance on AI-generated content.
- Emphasise ongoing education and supervision to maintain high standards of competence and care.
Vendor contracts and liability
- Understand and disclose the limitations of liability in contracts with AI vendors, as these may affect the insurer’s recovery rights in the event of a claim related to faulty AI.
- Review and adapt your insurance arrangements to reflect any contractual restrictions on liability with software suppliers.


