What underwriters are actually asking is on the record, so we will use that rather than anecdote. Howden's 1 April 2026 solicitors' PII renewal review reports underwriters focusing on how AI is being applied across practice areas, what governance policies and procedures are in place, and whether staff have been trained. The same review describes a soft market: no insurers left this year, several new entrants, and 52 participating insurers on the SRA's list for 2025/26, the highest it has ever been. It also notes that full proposal forms are typically required only every three years, with short-form declarations increasingly accepted.
So this is not a squeeze, and we are not going to tell you it is. It is a question you should expect to be asked and should be able to answer. The cost of a blank answer is not a premium hike, it is a conversation you cannot finish, at the exact moment you would rather be talking about something else.
What is "Silent AI Risk" and why are UK legal underwriters actively auditing it?
Silent AI risk represents professional indemnity and cyber liability exposures falling into ambiguous regulatory gaps. UK insurance underwriters actively audit these risks because unmanaged generative AI tools in high-volume conveyancing can introduce systemic defects, such as missed restrictive covenants or leasehold title errors, that contaminate thousands of matters before detection.
The core exposure confronting underwriters is the "liability gap" created by consumer-grade tech providers who explicitly waive all downstream liabilities in their Terms of Service. If a paralegal uploads an 80-page commercial lease into a public LLM, and the system "hallucinates" or drops a critical clause, the software vendor carries zero legal liability. The entire six-figure negligence claim rests squarely on the law firm's professional indemnity policy.
In high-volume conveyancing, this aggregation risk is magnified. Unlike traditional human error, which is typically isolated to a single matter, an automated workflow defect is systemic. A single unmapped prompt parameter or unchecked document triage engine can replicate the exact same land registry omission across hundreds of files in a single month, creating a massive, correlated liability pool that insurers refuse to absorb blindly.
What do underwriters actually ask about AI governance at renewal?
According to the Howden April 2026 Professional Indemnity Review, underwriters are now including AI governance questions in legal PI proposal forms as standard practice. The focus is on what AI tools are in use, what governance policies exist, whether staff have been trained, and whether client data is processed through zero-retention enterprise infrastructure.
Howden reports the focus is on application, governance and training. Beyond that published position, what follows is our own view of what a good answer looks like, built from the SRA provisions rather than from insurer statements we cannot show you:
| Audit Focus Area | What Underwriters Are Asking | What "Preferred Risk" Looks Like |
|---|---|---|
| AI Tool Inventory | What AI tools are your conveyancers using, and are they approved? | Classified AI risk register (Red/Amber/Green) on file. |
| Data Governance | Is client data being processed by third-party AI without consent or zero-retention contracts? | Signed DPAs with zero-retention guarantees for all AI vendors. |
| Policy & Training | Do you have a written AI acceptable use policy, and has staff been trained on it? | Dated training completion records and signed policy acknowledgements. |
| Supervision Controls | What formal process governs AI outputs before they reach clients or are filed? | Human-in-the-loop gate with timestamped practitioner sign-off audit log. |
| COLP Accountability | Has the COLP formally signed off on the AI governance framework? | A dated supervision attestation the COLP signs and can produce on request. |
What governance actually helps at renewal?
There is no such thing as a broker-approved framework, and anyone offering you one is overselling. What helps is being able to evidence four things: which tools are approved and for what, that client data is not leaving your control, that a named person owns the output, and that review is recorded rather than assumed. Those map to the provisions the SRA itself lists as relevant to AI: supervision (paragraph 3.5), confidentiality (paragraph 6.3), governance systems and controls (paragraph 2.1 of the Code for Firms) and the COLP duty at 9.1. Evidence does not convert negligence into good judgement. It lets you show which one it was.
Below are the six controls we design in an installation. Two points of honesty before you read them. We specify the technical controls and your own IT provider implements them in your tenant; our reference architecture has not yet been deployed in a live client environment. And these are our design, not anything a broker or insurer has certified.
1. A record that survives being questioned
When an error occurs, underwriters immediately ask: "Was this a case of gross negligence, or a defensible exercise of professional judgment?" A Deterministic Audit Vault records the exact "Prompt + Source Matter Context + Qualified Solicitor Validation" triplet for every automated event. This immutable trail proves to both your insurer and the SRA that the technology was used as a governed advisory assistant, protecting your liability coverage.
2. Zero Data Retention (ZDR) Architecture
To remain compliant with SRA Risk Outlook requirements regarding client confidentiality, you must mechanically block data leaks. By routing all AI operations through secure pipelines with Zero Data Retention policies, you ensure that sensitive client data (PII) is processed strictly inside UK/EU memory cells and never ingested, stored, or used to train public foundational models. We call this shifting from a "Black Box" to a "Glass Pipeline."
3. Hard-Coded CMS Supervisory Gates
SRA Code of Conduct paragraph 3.5 requires solicitors to "effectively supervise work being done for clients," and that duty applies directly to AI-assisted output. To close the gap we specify gatekeepers inside your case management system, whichever platform you run. All AI-assisted summaries, TR1 reviews and contract triage drafts are locked. They cannot be executed, printed, or emailed to clients until a qualified, named conveyancer checks off a physical verification screen, documenting their mandatory oversight.
4. Financial Partitioning (Client Account Protection)
Insurers are concerned about "rogue automation" accessing accounting ledgers and client accounts, which could trigger immediate regulatory intervention. Our architecture enforces strict financial partitioning, restricting any AI analysis of ledger files to "read-only" pipelines. The technology is structurally blocked from initiating payments or misallocating client funds, maintaining compliance with the SRA Accounts Rules' requirements for safeguarding client money.
5. Documented Systems of Control
Underwriters prioritise auditable risk-management over checklist assurances. We establish your three core systems of control: a Vendor and Tool Vetting System (for procurement analysis), a Human-in-the-Loop (HITL) Verification System (mandating solicitor-oversight review gates), and an auditable, SRA and CLC Code of Conduct compliant AI Governance Logging System. Together, these systems construct the transparent operational audit trail that professional indemnity insurers require to approve preferred risk status.
6. Client Disclosure & Transparency
Transparency is your primary shield. We update your firm's standard Terms of Engagement to include clear AI usage disclosures. Clients are notified in writing when governed AI tools will assist with their matter, the parameters of the firm's supervision of those tools, and are given a clear pathway to opt out if they prefer purely manual work. For RICS-regulated surveyors, this also aligns with the Responsible Use of AI in Surveying Practice standard (effective March 2026).
Regain Absolute Control of Your Risk Profile
Do not treat your next professional indemnity renewal as a roll of the dice. Document your governance systems, give your broker the evidence they need, and secure your panel status.
Start AI Reality Check