In short
  • Professional indemnity is the policy most likely to respond, and it responds because you owed a client a duty, not because AI was involved. The live question is whether the professional services definition reaches an output nobody in the practice reviewed.
  • Cyber is the wrong policy for this. It is built around security failure and data breach, and the published affirmative AI wording in the cyber market points the same way.
  • Commercial general liability is also the wrong policy. It answers bodily injury and property damage, and a wrong figure in a return is economic loss.
  • The most damaging mistake in this sector is not a dramatic one. It is a plausible one: a classification that looks right, is wrong, and is repeated across a client base until someone reconciles.
  • One page, listing what AI may touch and what may never leave the practice without a named person checking it, is the highest-value document a small practice can produce. It is a control, a submission and a record at the same time.
  • Do not buy a product because it says AI on it. Read what its perils actually are. Several SME AI products cover bodily injury and property damage, which is not the loss a bookkeeping error causes.

What an AI mistake looks like in this work

The examples that circulate in AI liability coverage tend to be dramatic: a chatbot inventing a refund policy, a hallucinated legal citation reaching a court. Those happen, and one of them is the most useful cautionary case in professional services. But they are not what a claim against an accountancy practice usually looks like.

What it looks like is quieter. A classifier assigns a category of expenditure consistently and consistently wrongly across eleven months of a client's transactions, and nothing about the output looks unusual until a reconciliation. A drafting assistant produces a clear, confident paragraph in a client letter explaining a treatment that does not apply to that client's circumstances. A chatbot on the practice website answers a prospective client's question about a deadline with the general position rather than their position, and they act on it.

Three properties make these harder than they look. They are plausible, so they pass the glance that catches an obvious error. They are systematic, so one wrong rule produces many wrong outputs rather than one. And they are silent, in the sense that nothing in the workflow raises its hand: the tool does not report that it was uncertain, because the interface was not built to.

The practical consequence is that the size of the eventual claim is set less by the sophistication of the mistake than by how long it ran before anyone reconciled. That is a review question, not an AI question, which is the first useful thing to notice.

The one case worth knowing about

In Mata v. Avianca, decided in the United States District Court for the Southern District of New York in 2023, lawyers filed a brief containing case citations that did not exist, produced by a generative AI tool. The court sanctioned the lawyers and their firm.

It is a legal-sector case, not an accountancy one, and we are not offering it as precedent for anything in Europe. It is worth knowing for one reason only, and it transfers cleanly to any professional practice: the sanction attached to the professionals, not to the tool. The failure the court was concerned with was the failure to verify, in circumstances where verification was the professional's job. That principle does not depend on the jurisdiction or the profession, and it is the principle a client's advisers will reach for.

The reframe that helps. Stop asking whether AI is allowed in the work and start asking what the practice's verification step is, who performs it, and whether it exists in a form anybody could describe afterwards. Almost every question on this page resolves faster once that step is written down.

Which policy actually responds

Policy Will it respond to an AI error in client work? Why
Professional indemnity Most likely, and this is the conversation to have It answers negligent acts, errors and omissions in the course of professional services. The question is definitional: does professional services reach an output no member of the practice reviewed?
Cyber Usually not Built around security failure and data breach. The affirmative AI wording published in this market extends to AI as attack surface, not AI as a source of error.
Commercial general liability No Answers bodily injury and property damage. A misstated figure is economic loss.
Directors and officers Not for the client claim It answers claims against individuals in their management capacity, which is a different claim from the client's.
An AI-specific SME product Read the perils before assuming HSB's AI Liability Insurance, introduced 18 March 2026 for small and mid-sized businesses, covers bodily injury, property damage, and personal and advertising injury arising from the insured's use of AI. Those are not the perils a bookkeeping error produces.

The cyber row deserves its evidence rather than an assertion, because the intuition runs the other way. The clearest published affirmative AI wording in the cyber market is Coalition's endorsement of 26 March 2024, on United States surplus and Canada cyber policies. It has exactly two limbs: security failure and data breach extended to an AI security event, and funds transfer fraud extended to fraudulent instruction by deepfake or other AI. A separate Coalition endorsement covers deepfake response, with forensics, legal takedown and crisis communications. All of it is about AI being used against you. None of it reaches an AI being wrong on your behalf.

That is not a criticism of the product. It is the correct shape for a cyber policy. It just means the cyber tower is not the answer to the risk this article is about, and a practice that assumed otherwise has a gap it does not know about. The broader treatment of that gap is in do I need AI insurance if I have cyber insurance.

The professional indemnity question, put precisely

Do not ask your broker whether your PI policy covers AI. The answer will be reassuring and will not tell you anything, because AI is not the operative concept in most wordings.

Ask this instead: if a client suffers loss because of work that was produced by a software tool and sent without a member of the practice reviewing it, does the professional services definition in this policy reach that work? Then ask for the answer in writing.

Three things follow from how that question is answered. If the definition clearly reaches it, you are in familiar territory and your existing cover is doing its job. If it clearly does not, you have identified the gap and can decide whether to close it by changing the wording or by changing the workflow, and changing the workflow is usually cheaper. If the answer is that it depends on the facts, which is the most common answer, then the facts are the thing to manage, and the facts are your verification step.

Two further points are worth raising in the same conversation. Ask whether any endorsement has been added at renewal that touches software, automated processes or artificial intelligence, and if so, ask for the reference and the edition date rather than a summary. Ask separately whether there is a sublimit, and what the number is. Affirmative language without a stated sublimit is worth less than it reads.

Telling clients, and the two rules that govern it

Two separate obligations are usually mixed together here, and separating them makes both easier.

The first is regulatory. The EU AI Act's transparency obligations in Article 50 have applied since 2 August 2026 and were not deferred when the AI Omnibus moved the high-risk obligations to 2027 and 2028. They reach, among other things, a person interacting with an AI system, and certain generated or manipulated content being disclosed as such. A practice running a chatbot on its website is in scope of that conversation in a way that a practice using a classifier internally is not.

The second is professional and contractual, and in a practice it usually bites first. Your engagement letter sets out what you are doing for the client, and your professional body's rules govern how work may be delegated and supervised. Whether an AI tool sits inside or outside that is a question for those rules and that letter, and it is not answered by the AI Act. We deliberately do not summarise any professional body's position here, because those rules differ by body and by jurisdiction and a summary that is nearly right is worse than no summary. Read yours, or ask them.

What we would say generally is that the engagement letter is the right place for the answer to live. An internal AI policy is a document nobody outside the practice will ever see. The engagement letter is the document that describes the deal, and if the deal now involves software producing part of the work, that is where it belongs.

The one page worth writing

Practices this size do not need a governance programme and will not build one. What they can build in an afternoon is a single page, and it does three jobs at once.

The page

  1. What AI touches. List the tools actually in use, including the ones embedded in software you already pay for. Most practices under-count here by half, because the embedded ones were never a decision.
  2. What it may never send. The categories of output that do not leave the practice without a named person reviewing them. Be specific about categories rather than writing a general principle.
  3. Who that person is. By name or by a role with a defined roster, plus what happens when they are away.
  4. What we do when it is wrong. Two lines. Who is told, and how far back the practice looks. The second line is the one that limits the size of the eventual claim.
  5. When we revisit this. A trigger, not a date. When the tool changes, when the scope changes, when someone leaves.

The three jobs: it is the practice's own control, so mistakes get caught earlier and cost less. It is most of what a specialist underwriter asks for, in different vocabulary, so it shortens a submission. And it is the record of what the process was on the day, which matters because after an incident the practice's account of its own process is exactly what will be tested. A practice that cannot produce it is asking to be priced, and judged, for an unknown.

Five questions for your broker

  1. Does the professional services definition in our PI wording reach work produced by a software tool and issued without review by a member of the practice? Please answer in writing.
  2. Has any endorsement touching software, automated processes or artificial intelligence been added at any renewal in the last three years? Please give the reference and the edition date.
  3. Is there a sublimit that applies to such a claim, and what is the number?
  4. Does anything on our programme respond to loss caused by an AI being wrong, as distinct from an AI being attacked?
  5. What would you need from us to move this from silent to affirmative at the next renewal?

The fifth is the one that changes the outcome, because it converts a coverage question into a submission question, and a submission question has an answer you can act on. Start at least 90 days before renewal if you want the specialist market to be a genuine option; it is slower than standard commercial lines and there are fewer underwriters in it.

Frequently asked questions

If AI gets a client's numbers wrong, does my professional indemnity insurance cover it?

Professional indemnity is the policy most likely to respond, but it does not respond because AI was involved. It responds because you owed a client a duty in the course of professional services and the work was wrong. The live question in most current wordings is whether the professional services definition reaches an output that no person in the practice reviewed before it went out. If a member of the practice checked the work and signed it, you are in familiar territory. If the output went to the client untouched, ask your broker in writing where the definition ends, because that is where the argument will be.

Does cyber insurance cover an AI mistake in bookkeeping work?

Usually not, and the reason is structural rather than a matter of the individual policy. Cyber cover is built around security failure and data breach. The published affirmative AI wording in the cyber market points the same way: Coalition's endorsement of 26 March 2024 has exactly two limbs, an AI security event and funds transfer fraud by deepfake or other AI. Neither limb reaches a loss caused by your AI simply being wrong. Cyber is the right policy for an attack on the practice. It is the wrong policy for a misclassified transaction.

Do I have to tell clients that I use AI in their work?

Two separate questions sit behind that one. The EU AI Act's transparency obligations in Article 50 have applied since 2 August 2026 and reach things like a person interacting with an AI system and certain generated or manipulated content being disclosed as such. Separately, your engagement letter and your professional body's rules govern how you may delegate and supervise work, and those rules are the ones most likely to bite first in a practice. Check both, and treat the engagement letter as the place the answer is recorded rather than an internal policy nobody outside the practice will ever see.

What is the single most useful thing a small practice can write down?

One page: which tasks AI may touch, what it may never send without a named person checking it, and who that person is. That page does three jobs at once. It is the practice's own control, it is what an underwriter asks for in a different vocabulary, and it is the record that shows what your process was on the day the mistake happened rather than what you claim it was afterwards. Practices that cannot produce it are asking to be priced, and judged, for an unknown.

Does an AI tool built into my accounting software change my liability?

It changes who else is in the picture, not whether you are in it. The client engaged your practice, and a duty owed to a client is not discharged by pointing at a software vendor. What the vendor relationship does affect is recovery afterwards, which is a contract question, and it is worth reading the liability and indemnity terms of any tool that touches client figures before you need them. The practical version: assume the claim arrives at your door first, and treat the vendor contract as what happens next rather than as a defence.

Is there an insurance product built for a practice this size?

There are products aimed at smaller businesses, but read what they cover before assuming they answer this risk. HSB introduced AI Liability Insurance for small and mid-sized businesses on 18 March 2026, with standard limits of USD 25,000 or USD 50,000 and a USD 500 deductible, added to partner carriers' business policies rather than sold direct. It covers bodily injury, property damage, and personal and advertising injury arising from the insured's use of AI. Those are not the perils a bookkeeping error produces. For a practice, the productive conversation is almost always about the professional indemnity wording you already buy.

Sources

Questions

If AI gets a client's numbers wrong, does my professional indemnity insurance cover it?

Professional indemnity is the policy most likely to respond, but it does not respond because AI was involved. It responds because you owed a client a duty in the course of professional services and the work was wrong. The live question in most current wordings is whether the professional services definition reaches an output that no person in the practice reviewed before it went out. If a member of the practice checked the work and signed it, you are in familiar territory. If the output went to the client untouched, ask your broker in writing where the definition ends, because that is where the argument will be.

Does cyber insurance cover an AI mistake in bookkeeping work?

Usually not, and the reason is structural rather than a matter of the individual policy. Cyber cover is built around security failure and data breach. The published affirmative AI wording in the cyber market points the same way: Coalition's endorsement of 26 March 2024 has exactly two limbs, an AI security event and funds transfer fraud by deepfake or other AI. Neither limb reaches a loss caused by your AI simply being wrong. Cyber is the right policy for an attack on the practice. It is the wrong policy for a misclassified transaction.

Do I have to tell clients that I use AI in their work?

Two separate questions sit behind that one. The EU AI Act's transparency obligations in Article 50 have applied since 2 August 2026 and reach things like a person interacting with an AI system and certain generated or manipulated content being disclosed as such. Separately, your engagement letter and your professional body's rules govern how you may delegate and supervise work, and those rules are the ones most likely to bite first in a practice. Check both, and treat the engagement letter as the place the answer is recorded rather than an internal policy nobody outside the practice will ever see.

What is the single most useful thing a small practice can write down?

One page: which tasks AI may touch, what it may never send without a named person checking it, and who that person is. That page does three jobs at once. It is the practice's own control, it is what an underwriter asks for in a different vocabulary, and it is the record that shows what your process was on the day the mistake happened rather than what you claim it was afterwards. Practices that cannot produce it are asking to be priced, and judged, for an unknown.

Does an AI tool built into my accounting software change my liability?

It changes who else is in the picture, not whether you are in it. The client engaged your practice, and a duty owed to a client is not discharged by pointing at a software vendor. What the vendor relationship does affect is recovery afterwards, which is a contract question, and it is worth reading the liability and indemnity terms of any tool that touches client figures before you need them. The practical version: assume the claim arrives at your door first, and treat the vendor contract as what happens next rather than as a defence.

Is there an insurance product built for a practice this size?

There are products aimed at smaller businesses, but read what they cover before assuming they answer this risk. HSB introduced AI Liability Insurance for small and mid-sized businesses on 18 March 2026, with standard limits of USD 25,000 or USD 50,000 and a USD 500 deductible, added to partner carriers' business policies rather than sold direct. It covers bodily injury, property damage, and personal and advertising injury arising from the insured's use of AI. Those are not the perils a bookkeeping error produces. For a practice, the productive conversation is almost always about the professional indemnity wording you already buy.

Sources

  • Coalition. "Coalition adds new affirmative AI endorsement to cyber policies", 26 March 2024, and the Deepfake Response Endorsement announcement. Two limbs: security failure and data breach extended to an AI security event, and funds transfer fraud extended to fraudulent instruction via deepfakes or other AI. coalitioninc.com, checked 15 August 2026.
  • HSB (Hartford Steam Boiler, a Munich Re company). "Introducing AI Liability Insurance for Small Businesses", 18 March 2026. Standard limits USD 25,000 or USD 50,000, USD 500 deductible, higher limits available; covers bodily injury, property damage, and personal and advertising injury arising from the insured's use of AI; added to partner carriers' business policies, not sold direct; subject to insurance regulatory approval. munichre.com/hsb, checked 15 August 2026.
  • Mata v. Avianca, Inc., United States District Court for the Southern District of New York, 2023. Sanctions imposed on the attorneys and their firm following the filing of a brief containing non-existent case citations produced by a generative AI tool.
  • Regulation (EU) 2024/1689 (EU AI Act), Article 50. Transparency obligations applying from 2 August 2026. European Commission, digital-strategy.ec.europa.eu, checked 17 August 2026.
  • Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force 27 July 2026. Annex III high-risk obligations from 2 December 2027, Annex I from 2 August 2028; transparency and governance rules unaffected and applying from 2 August 2026. European Commission, AI Omnibus enters into force, checked 17 August 2026.
  • Deliberately not stated on this page: any premium figure for professional indemnity or AI cover, any percentage by which documentation reduces a premium, and any professional body's specific rules on the use of AI in client work. No carrier publishes the first two. The third differs by body and jurisdiction, and a summary that is nearly right is worse than none. See the corrections log for figures withdrawn from this site.