Future Proof The Authority Stack
Operator Edition · Legal Sector Coverage Guide Part of the Agent Liability Network
Published by Future Proof Intelligence
Insure Your Agent The Coverage Guide

AI liability for law firms: what legal practices need to know

Law firms are using AI to draft documents, research case law, review contracts, and prepare client correspondence. The professional liability picture that follows is specific to legal practice: verification duties under Mata v. Avianca, SRA and Bar Council expectations, confidentiality obligations when client data enters an AI tool, AI exclusions appearing in professional indemnity renewals, and the five broker questions that will determine whether your PII programme actually responds to an AI-related claim. This guide sets out the analysis in plain English for solicitors, barristers, and legal support firms operating without a dedicated risk function.

Key takeaways

  • The Mata v. Avianca sanctions order (SDNY, 2023) established a direct precedent: submitting AI-generated content without independent verification is a professional failure attributable to the lawyer, not the AI tool. Judge Kevin Castel sanctioned the attorneys under Federal Rule of Civil Procedure 11 for submitting fabricated case citations that they had not verified. The principle transfers directly to any legal professional who relies on AI output in court filings, client advice, or legal documents without independent checking.[1]
  • The SRA does not prohibit AI use, and the obligations that bite are in the Code of Conduct rather than in the Principles: paragraph 3.2 (competent service), 3.3 (maintaining your own competence) and 6.3 (confidentiality of client affairs). The SRA's Risk Outlook report on AI in the legal market, 20 November 2023, states plainly that "you will remain responsible and accountable for the outputs from AI you are using". A previous version of this article cited SRA Principles 4 and 6 for competence and confidentiality; Principle 4 is honesty and Principle 6 is equality, diversity and inclusion, and the citation was corrected on 17 August 2026.[2]
  • Professional indemnity policies for law firms are subject to the SRA Minimum Terms and Conditions, which set a coverage floor. However, AI exclusions and sublimits are appearing in excess layer policies and in non-SRA-required coverage. Ask your broker to confirm the AI position in every layer of your programme, not just the primary layer.[3]
  • The SRA expects firms to tell clients when AI will be used on their matter and to explain how it works. This is the obligation most firms have not operationalised, and it costs nothing to fix: a paragraph in the engagement letter. Client confidentiality under Code paragraph 6.3 and UK GDPR Article 28 applies whenever client data is processed by a third-party AI tool. A firm that submits client-identifiable information to a cloud AI service without a Data Processing Agreement and without having assessed the provider's data retention and training terms is in breach of two separate obligations, regardless of whether any claim arises.[4]
  • The EU AI Act (Regulation 2024/1689) classifies AI systems used in the administration of justice as high-risk under Annex III, point 8. For firms in EU member states deploying such a system, the Article 26 deployer obligations now apply from 2 December 2027, not 2 August 2026: the Digital Omnibus on AI entered into force on 27 July 2026 and moved them. Article 50 transparency did not move and applies from 2 August 2026. Most general-purpose drafting assistants are not Annex III systems; the classification turns on whether the output is used in a judicial or quasi-judicial determination.[5]
  • Five broker questions matter at renewal: the presence of any AI exclusion or sublimit in any layer of the programme, the policy's response to a claim arising from verified versus unverified AI use, changes to the renewal wording versus the prior year, whether the proposal form contains any AI warranty, and whether specialist AI liability coverage is available as a complement to the PII programme.[6]

The verification duty: what Mata v. Avianca means for legal practice

On 22 June 2023, Judge P. Kevin Castel of the Southern District of New York issued a sanctions order against Steven A. Schwartz and Peter LoDuca of Levidow, Levidow and Oberman, together with the firm. Roberto Mata was the plaintiff, not one of the sanctioned lawyers; a previous version of this article named him as an attorney, which was wrong, and it was corrected on 17 August 2026. The firm had filed a brief in a personal injury case against Avianca citing judicial decisions that did not exist. The citations had been generated by ChatGPT. When opposing counsel could not locate the cases and the court ordered copies, none could be produced. The court found a violation of Federal Rule of Civil Procedure 11 in signing and submitting a document containing representations the signatories had not verified, and imposed a joint fine of USD 5,000.[1]

The sanctions order is routinely cited as an AI cautionary tale, but its professional liability implications are more precise than the general lesson about "checking AI output." The court's analysis turned on the attorney's duty to independently confirm that citations existed and accurately stood for the propositions they were cited for, before signing and submitting the document. The AI tool's failure to produce accurate citations was the mechanism of the error. The attorney's failure to verify was the professional breach. These are different things, and the distinction matters for insurance purposes.

In PI terms, the claim against a lawyer who submits unverified AI output is a negligence claim: the lawyer failed to exercise the standard of care that a competent practitioner would apply to research, drafting, or advice in the circumstances. The AI is not the defendant and the AI's terms of service are not a defence. If the standard of care required independent verification, and you did not verify, the claim is straightforward professional negligence.

The PI risk compounds when the failure is characterised not merely as negligence but as reckless disregard of a known risk. By 2024, the risks of AI hallucination in legal research were publicly documented through the Mata sanctions order itself, the Law Society's guidance on AI tools, and extensive legal press coverage. An insurer writing a renewal in 2025 or 2026 may take the position that a solicitor who relied on unverified AI output for legal citations was not making an inadvertent error but was knowingly disregarding a risk that the profession had been publicly warned about. Some PI policy wordings exclude or limit claims arising from deliberate or reckless disregard of known risks. Whether a specific claim falls into this category depends on the facts and the policy wording, but the risk exists and is not theoretical.

The practical response is documented verification. When you use an AI tool to draft or research legal content, record what you checked, against what source, and when. The record does not need to be elaborate: a case note or matter file entry noting that AI-generated citations were cross-checked against a named legal database at a specific date is sufficient for most purposes. This record serves two functions: it provides evidence of reasonable care if a claim arises, and it helps the insurer characterise a claim as inadvertent error rather than reckless reliance on a known-unreliable tool.

For the broader framework on what documentation an AI-using business should maintain for insurance purposes, see the documentation guide for SME operators, which sets out the minimum record structure applicable to any professional services use case.

SRA and Bar Council expectations: what the regulators actually require

Neither the SRA nor the Bar Council has prohibited AI use in legal practice. Both have issued guidance that confirms AI use is permitted subject to the application of existing professional duties without modification. The practical effect is that the same standards of competence, accuracy, and client care that govern a solicitor drafting a document manually apply equally when an AI tool is used to produce a first draft.

The SRA set out its position in a Risk Outlook report, "The use of artificial intelligence in the legal market", published 20 November 2023. Four things in it matter for a firm's liability position, and they are worth quoting rather than paraphrasing.[2]

On responsibility: "As with any other technology or system in your firm, you will remain responsible and accountable for the outputs from AI you are using." That responsibility is not delegable to the vendor or to the IT function.

On why hallucination happens, which is the part most guidance skips: these systems anticipate text without a model of what is true, so they can produce "highly plausible but incorrect results", and the report notes that AI-drafted legal arguments have included non-existent cases. The formatting of a citation is a pattern the model has learned; the existence of the case is not.

On supervision: firms must supervise AI systems and staff use of them "to make sure that they are working as expected and providing accurate results", and should "not trust an AI system to judge its own accuracy". That last clause is the one to put in your firm policy. A verification step that consists of asking the model whether it is sure is not a verification step.

On clients: the SRA expects firms to inform clients when AI will be used and to explain how it operates. Most firms have not done this. It is a paragraph in an engagement letter, and it also does useful work on the data protection question below, since it moves AI use from something the client might not have expected into something disclosed.

The obligations these attach to sit in the Code of Conduct for Solicitors, RELs and RFLs, not in the Principles. Paragraph 3.2 requires that the service you provide to clients is competent and delivered in a timely manner. Paragraph 3.3 requires that you maintain your competence and keep your professional knowledge and skills up to date. Paragraph 6.3 requires that you keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.

For barristers the equivalent document is the Bar Council's ethics guidance, "Considerations when using ChatGPT and Generative AI Software based on large language models", last reviewed 25 November 2025. Its central instruction is that a barrister should understand the underlying model and acknowledge its limitations before using it. Note its own status: the Bar Council states that the document is not "guidance" for the purposes of the BSB Handbook, so it is not itself a disciplinary standard. What binds a barrister is the Core Duties in the BSB Handbook, the duty to the court in the administration of justice foremost among them, and those apply to a submission regardless of how it was drafted. A previous version of this article described that duty as the cab rank rule; the cab rank rule governs the acceptance of instructions, not conduct toward the court, and the description was corrected on 17 August 2026.[7]

For PI purposes, the regulatory guidance matters in two ways. First, it establishes what the professional standard of care requires when AI tools are used, which is the benchmark against which a negligence claim will be assessed. A solicitor who followed the SRA AI guidance, documented their verification process, and maintained a clear firm policy on AI use is in a substantially stronger position on a negligence analysis than one who used AI without any governance framework. Second, a finding by the SRA that a firm breached its professional duties in connection with AI use would be relevant evidence in a subsequent PI claim or coverage dispute, and could affect the insurer's willingness to defend and settle the claim.

Client confidentiality and AI tools: the data processing question

Every legal professional using a cloud AI tool for client work faces a confidentiality question that is separate from, and prior to, the PI liability question. Paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs and RFLs requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents. That obligation covers all client information, not only formally privileged material, and it reaches data shared with third parties including technology providers. Note the shape of the exception: client consent is one of the three routes, which is a second reason the SRA's client-disclosure expectation is worth acting on.

When a solicitor inputs client information, case facts, contract terms, or any other client-identifiable data into a cloud AI tool, that data is processed by the AI provider on their infrastructure under their terms of service. Whether this processing is lawful depends on three things that many firms have not systematically checked.

First, does the AI provider's data processing agreement confirm that client data submitted to the tool will not be retained beyond the session, used to train future models, or accessible to the provider's staff? The public-facing terms of consumer AI products (the free tier of ChatGPT, for example) historically permitted training on submitted content. Enterprise agreements for the same tools typically do not, but the firm must have the enterprise agreement in place and must have confirmed its terms before using the tool with client data.[4]

Second, does the firm have a Data Processing Agreement with the AI provider as required by UK GDPR Article 28 and, for EU matters, EU GDPR Article 28? A controller (the law firm) that transfers personal data to a processor (the AI provider) without a compliant DPA is in breach of the GDPR independently of any harm to the data subject. The ICO has confirmed that law firms processing client personal data must have DPAs in place with all technology service providers who process that data on their behalf.

Third, has the client consented to their data being processed by third-party AI tools, or is there another lawful basis for the processing? Under the GDPR, processing client personal data for the purpose of preparing legal advice may be lawful under Article 6(1)(b) (necessary for the performance of a contract) or Article 6(1)(f) (legitimate interests). Whether the specific processing of inputting client data into an AI tool falls within these bases depends on the scope of the retainer and whether this use was reasonably within the client's expectations. Many firms now include an AI tool disclosure in their engagement letters for this reason.

The confidentiality and data protection analysis is a pre-condition to any AI tool use in client matters. A breach of client confidentiality does not necessarily generate a PI claim, but it can generate a separate SRA disciplinary complaint, an ICO enforcement action, and a client claim for breach of the retainer. These run in parallel to the PI liability exposure, and none of them are covered by the same policy structures.

AI exclusions in legal sector PI policies: what to look for

The SRA Minimum Terms and Conditions for solicitors' professional indemnity insurance set a coverage floor that insurers writing PII for English and Welsh solicitors must meet. The MTC requires cover for claims arising from private legal practice without listed exclusions that would permit an outright AI exclusion in the primary PII layer for matters within the definition of "private legal practice." This provides a degree of protection that professionals in unregulated sectors do not have.

However, the MTC floor does not extend to excess layer policies, to specialist coverage for matters outside the MTC scope, or to the coverage structures of Scottish or Northern Irish practices, which operate under different regulatory frameworks. AI exclusions and sublimits are appearing in the market in several places that legal sector brokers may not flag proactively.[3]

In the excess layer, insurers writing cover above the MTC primary layer are not bound by the MTC terms and can apply AI exclusions or sublimits. A firm with a primary layer of GBP 2 million under MTC terms and an excess layer of GBP 3 million may find that the excess layer excludes or sublimits AI-related claims. This creates a net coverage gap in larger claims where the total exposure exceeds the primary limit.

Some insurers are adding AI warranty questions to proposal forms at renewal. The question typically asks the firm to confirm whether it uses AI tools in client matters, to describe the tools, and to describe the verification procedures in place. An answer that does not accurately reflect the firm's actual practice is a misrepresentation of a material fact. If a claim subsequently arises from AI use and the insurer discovers the proposal form answer was inaccurate, this provides grounds to decline the claim on misrepresentation grounds, even under the primary MTC layer, since the MTC does not protect against fraud or deliberate misrepresentation by the insured.

For legal practices that use AI agents rather than AI tools, the exposure is structurally different. An AI agent that autonomously drafts and sends client communications, reviews documents, or takes consequential actions without a solicitor's review at each step is not performing professional services under the solicitor's direct oversight. The PI policy covers the solicitor's professional work. An AI agent's independent actions may fall outside the professional services definition entirely, leaving the firm exposed without any coverage. For this reason, legal practices deploying AI agents rather than AI drafting assistants should specifically ask their broker about technology errors and omissions coverage as a complement to their PII programme. See the related analysis of AI policy exclusions for SME operators for the full landscape of exclusion language types across policy categories.

The EU AI Act and law firms in EU member states

The EU AI Act (Regulation 2024/1689, entered into force 1 August 2024) classifies AI systems used to administer justice, interpret the law, or assist judicial authorities in resolving legal disputes as high-risk AI systems under Annex III, Category 8. Law firms in EU member states that operate as deployers (operators) of such systems, rather than as developers, are subject to the operator obligations in Article 26 of the Regulation.[5]

Article 26 obligations for operators of high-risk AI systems include: using the system in accordance with the instructions provided by the provider, ensuring that natural persons overseeing the system have the necessary competence and authority to intervene and override AI decisions, conducting a Fundamental Rights Impact Assessment before deploying the system in certain contexts, maintaining logs of the system's operation to the extent permitted by the provider's architecture, and reporting serious incidents to the relevant national market surveillance authority.

Not every AI tool used by a law firm will be classified as high-risk under Annex III Category 8. The classification applies to AI systems specifically designed to assist in judicial or quasi-judicial decision-making, legal research within those contexts, or document review and analysis where the output directly influences a legal determination. General-purpose AI models used as drafting assistants are not automatically high-risk systems under this classification, though the boundary is fact-specific and will require regulatory clarification in each member state.

The high-risk obligations were due to apply from 2 August 2026. The Digital Omnibus package, agreed at trilogue on 7 May 2026, deferred the high-risk obligations deadline to 2 December 2027, and the AI Omnibus entered into force on 27 July 2026. That is the applicable date for Annex III high-risk systems. It is a deferral of the high-risk obligations only: Article 50 transparency obligations still apply from 2 August 2026, and the revised Product Liability Directive still transposes by 9 December 2026, so a firm that treats December 2027 as breathing room is reading it wrong.

UK law firms are not directly subject to the EU AI Act following the UK's departure from the EU. The UK AI Regulation White Paper (published March 2023) proposed a principles-based approach applied through sector regulators rather than a cross-sector AI statute. The SRA and the Bar Council are the relevant sector regulators for UK legal professionals, and their existing guidance on AI competence and verification reflects the principles-based approach the White Paper anticipated.

What the market provides: carriers and products relevant to legal sector AI

The SRA Minimum Terms and Conditions require solicitors to obtain PII from a participating insurer on the SRA's published list. Within that market, the AI position varies by insurer and requires explicit broker inquiry at renewal. The following market participants and products are relevant to legal practices seeking cleaner AI coverage beyond the baseline PII programme.

A caution before the names. On 17 August 2026 we removed a set of statements from this section that described the conditions attached to each carrier's AI coverage: that Armilla's cover responds "where the insured can demonstrate reasonable verification steps were taken", that Counterpart's requires "a defined verification standard was met", and that AIUC-1 certification unlocks terms unavailable to uncertified systems. None of those conditions is published by the party concerned. They read as underwriting detail, they would change a firm's buying decision, and we could not stand behind any of them. What follows is what each provider actually publishes.

Armilla is a coverholder at Lloyd's writing a standalone affirmative AI liability policy, underwritten by certain underwriters at Lloyd's including Chaucer, with limits up to USD 25 million per organisation. Its published scope covers AI regulatory violations including defence costs and insurable fines under the EU AI Act. It is built for organisations with complex AI deployments rather than for a five-partner practice, and it publishes no premium.[8]

Munich Re aiSure, underwritten and marketed by Mosaic since 26 February 2026 with EUR, USD or CAD 15 million of initial capacity, is a performance product for AI developers and vendors that settles on measurable performance data. If your firm has built its own AI legal product it is relevant. If your firm uses commercial AI tools in client work it is not the right instrument, whatever a summary elsewhere suggests.[8]

Counterpart announced affirmative AI coverage and a technology errors and omissions insuring agreement on 24 November 2025, across miscellaneous professional liability and allied health. Note the lines it names: miscellaneous professional liability, not management liability. Counterpart's own site does not describe the AI coverage in detail, so ask for the wording.[8]

AIUC, the Artificial Intelligence Underwriting Company, publishes AIUC-1, a standard for AI agents with 51 requirements and 130 controls across six pillars, and certificates running twelve months with at least quarterly testing. The first AIUC-1-backed policy was placed for ElevenLabs in February 2026 through Lloyd's of London. AIUC is a standards and underwriting company rather than an insurer, no carrier is named at source for the ElevenLabs placement, and no limits are published. For a law firm this is context on where the market is heading, not a product you can currently buy for a legal research tool.[8]

The honest summary for a firm of ten to two hundred people: none of these is built for you. The specialist AI market is priced and scoped for enterprises and for AI vendors. The realistic route for a legal practice in 2026 is not a standalone AI policy, it is making sure your existing professional indemnity programme responds, checking every layer for AI language, and if your practice deploys AI agents that act rather than AI tools that draft, adding technology errors and omissions cover alongside the PII. Access to specialist Lloyd's placements varies by broker; if yours cannot reach that market, that is worth knowing, but it is the second question, not the first.

The two documents that do most of the work

Everything above resolves into two short pieces of paper. Neither needs outside advice, and between them they answer the SRA on supervision and transparency, and answer an insurer on whether an error was inadvertent or reckless.

1. The verification note on the matter file

A negligence claim following an AI-assisted error turns on the standard of care. What separates an inadvertent error from reliance on a tool the profession has been publicly warned about is a contemporaneous record. It does not need to be long. Four lines on the matter file, at the point of use:

Two habits to avoid. Do not create the note retrospectively when a complaint arrives; a file entry dated after the letter of claim is worse than no entry. And do not record that you asked the model to confirm its own citations. The SRA's own report says a firm should not trust an AI system to judge its own accuracy, so a record of having done exactly that is a record of the wrong procedure.

2. The AI paragraph in the engagement letter

The SRA expects firms to tell clients when AI will be used and to explain how it operates. Most firms have not done this, and it is the cheapest item on the whole list. It also does work on two other fronts: client consent is one of the three routes through the confidentiality duty in paragraph 6.3, and a disclosed use is much harder to characterise later as outside the client's reasonable expectations under the retainer.

The paragraph needs to cover four things: that the firm uses AI tools in the course of delivering legal services; broadly what for, such as drafting, research or document review; that all output is reviewed by a qualified fee earner before it is relied on or sent; and what happens to client information, meaning whether identifiable client data is entered into third-party tools at all and, if it is, that the provider is contracted not to retain it or train on it. If you cannot honestly write the fourth sentence, that is a finding about your tooling rather than about your drafting, and it should be resolved before the letter goes out.

A firm that has both documents in place has answered the two questions an insurer and a regulator will each ask first, and it has done so before either of them asks.

Five questions to ask your broker at renewal

A general question about "AI coverage" will produce a general answer. The following five specific questions will produce the information you actually need to understand your position.

First: Does the current programme contain any exclusion, sublimit, or condition that applies specifically to AI-generated content, automated outputs, or machine learning tools, in any layer of the programme? Ask the broker to check the actual policy wording in both the primary layer and any excess layers, not just the product summaries.

Second: If a solicitor uses an AI tool to draft a legal document or research case law, reviews and verifies the AI output against independent sources, and then the client claims the advice was wrong, would the policy respond to that claim? This is a specific factual scenario designed to elicit a specific coverage position, not a general assurance.

Third: Has the insurer added any new AI-related language to the renewal wording compared to the prior year? Request a side-by-side comparison of the previous year's insuring clause and exclusions against the new wording if the broker cannot confirm there are no changes.

Fourth: Does the proposal form include any warranty or question about AI tool usage or automated systems, and if so, does the firm's current disclosure in the proposal form accurately reflect its practice? A mismatch here is a material misrepresentation risk that can affect the entire programme.

Fifth: Is there a specialist AI liability policy or endorsement available from Armilla, Counterpart, AIUC, or Lloyd's market syndicates that would provide cleaner affirmative coverage for AI-assisted legal work beyond what the standard PII programme provides, and what would adding this to the programme cost?


Frequently asked questions

Does professional indemnity insurance cover an AI hallucination in a legal document or court filing?

It depends on the policy wording and what verification the solicitor or barrister performed before submitting the document. Standard PI policies cover negligent acts, errors, and omissions by the insured. If you used an AI tool to draft a filing and submitted it without verifying citations or legal propositions independently, the claim against you runs on your negligence in failing to verify. Whether the policy responds depends on whether the wording contains an AI exclusion or a reckless-disregard exclusion, and whether you disclosed your AI use to the insurer at renewal. The Mata v. Avianca sanctions order (SDNY, 2023) established that submitting unverified AI output is a professional failure attributable to the lawyer, not the tool.

What do the SRA and the Bar Council expect of legal professionals using AI?

The SRA's Risk Outlook report on AI in the legal market, 20 November 2023, states that "you will remain responsible and accountable for the outputs from AI you are using", that firms must supervise both the systems and staff use of them, and that a firm should "not trust an AI system to judge its own accuracy". It also expects firms to tell clients when AI will be used and explain how it operates. The obligations sit in the Code of Conduct: paragraph 3.2 and 3.3 on competence, paragraph 6.3 on confidentiality. They are not SRA Principles; Principle 4 is honesty and Principle 6 is equality, diversity and inclusion. For barristers, the Bar Council's ethics guidance "Considerations when using ChatGPT and Generative AI Software based on large language models", last reviewed 25 November 2025, asks that the barrister understand the model and acknowledge its limitations before use, and notes that it is not itself BSB Handbook guidance. Neither regulator prohibits AI use.

Does using AI in client work breach solicitor-client confidentiality?

It can, if client data is processed by a cloud AI tool whose terms permit the provider to retain, train on, or access submitted content. Paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs and RFLs requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents, and that duty extends to data shared with third-party technology providers. Before submitting any client-identifiable information to an AI tool, solicitors should review the provider's data processing terms, confirm that a Data Processing Agreement is in place as required under UK GDPR Article 28, and assess whether the client has consented to this processing. Many firms use anonymised or synthetic data with AI tools for this reason.

Are AI exclusions appearing in legal sector professional indemnity policies?

Yes. The SRA Minimum Terms and Conditions constrain outright AI exclusions in the primary PII layer for solicitors in England and Wales, but AI exclusions and sublimits are appearing in excess layer policies and in non-MTC coverage. Some insurers are also adding AI warranty questions to proposal forms at renewal: an inaccurate answer to a proposal form warranty can create grounds to decline a claim even in the primary MTC layer. Ask your broker to confirm the AI position in every layer of your programme, not just the primary layer.

What five questions should a law firm ask its broker about AI and professional indemnity?

First: does the current programme contain any exclusion, sublimit, or condition that applies to AI-generated content in any layer? Second: if a solicitor uses and verifies AI output before submitting to a client or court, and a claim arises from an error in that output, would the policy respond? Third: has the insurer added any new AI-related language to the renewal wording versus the prior year? Fourth: does the proposal form contain any warranty about AI tool usage, and does the firm's current disclosure accurately reflect its practice? Fifth: is there a specialist AI liability policy or endorsement available that would provide cleaner coverage for AI-assisted legal work beyond the standard PII programme?

How does the EU AI Act apply to law firms using AI in 2026?

The EU AI Act (Regulation 2024/1689) classifies AI systems used to administer justice or interpret law as high-risk under Annex III. Law firms in EU member states deploying such systems have operator obligations under Article 26, including fundamental rights impact assessments, human oversight requirements, and incident reporting. The original deadline was 2 August 2026. The Digital Omnibus package agreed at trilogue on 7 May 2026 deferred that to 2 December 2027, and the AI Omnibus entered into force on 27 July 2026. UK firms are not directly subject to the EU AI Act but should monitor SRA and Bar Council positions as UK AI regulation develops.


Related reading

Review your current coverage

Use the Coverage Audit tool to map your current policies against your AI tool and AI agent exposure. It takes ten minutes and produces the document your broker needs to review your position at renewal.

Start the Coverage Audit

Footnotes

  1. Mata v. Avianca, Inc., No. 1:22-cv-01461 (PKC) (S.D.N.Y.). Opinion and order on sanctions, 22 June 2023, Judge P. Kevin Castel. Sanctions imposed under Federal Rule of Civil Procedure 11 on Steven A. Schwartz and Peter LoDuca and on Levidow, Levidow & Oberman, jointly USD 5,000, for submitting fabricated case citations without verification. Roberto Mata was the plaintiff. A previous version of this note named him as a sanctioned attorney; corrected 17 August 2026.
  2. Solicitors Regulation Authority, "Risk Outlook report: The use of artificial intelligence in the legal market", published 20 November 2023, at sra.org.uk (read 17 August 2026). Quotations in the text are from that report. The relevant conduct obligations are in the SRA Code of Conduct for Solicitors, RELs and RFLs, paragraphs 3.2, 3.3 and 6.3, at sra.org.uk (read 17 August 2026). A previous version of this note cited "SRA approach to the use of AI (2024 update)" and attributed competence, integrity and confidentiality to SRA Principles 4, 5 and 6. The SRA Principles are seven and do not include competence or confidentiality: Principle 4 is honesty, Principle 5 is integrity and Principle 6 is equality, diversity and inclusion. Corrected 17 August 2026.
  3. SRA Minimum Terms and Conditions for professional indemnity insurance. The MTC sets the minimum cover a participating insurer must provide for claims arising from private legal practice, including minimum indemnity limits and the permitted exclusions. That constraint applies to the primary layer written to the MTC standard. Excess layers are not written to the MTC and are not subject to it. Confirm the current MTC text with your broker before relying on any summary of it, including this one.
  4. SRA Code of Conduct for Solicitors, RELs and RFLs, paragraph 6.3 (confidentiality). UK General Data Protection Regulation, Article 28 (processor obligations), as retained in UK law by the European Union (Withdrawal) Act 2018. For EU-based practices: Regulation (EU) 2016/679, Article 28. A previous version of this note cited "Principle 6 and Chapter 6"; the 2019 Code is not divided into chapters and Principle 6 is equality, diversity and inclusion. Corrected 17 August 2026.
  5. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence. Annex III, point 8: AI systems intended to be used in the administration of justice and democratic processes. Article 26: obligations of deployers of high-risk AI systems. Article 6(2): classification rules for Annex III systems. The Digital Omnibus on AI entered into force on 27 July 2026, moving Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028; Article 50 transparency obligations still apply from 2 August 2026, with a grace period to 2 December 2026 limited to the Article 50(2) marking obligation for systems already on the market. Sources: consilium.europa.eu and digital-strategy.ec.europa.eu (read 17 August 2026).
  6. Removed 17 August 2026. This note previously cited a Lloyd's publication titled "Artificial Intelligence: Underwriting Considerations" (2023) and a Chartered Insurance Institute guidance note "AI and Professional Liability: A Guidance Note for Brokers" (2025). Neither could be located at lloyds.com or cii.co.uk, and a citation that cannot be found is worse than none. The five broker questions in the text stand on their own; they do not need an authority behind them.
  7. Bar Council of England and Wales, "Considerations when using ChatGPT and Generative AI Software based on large language models", ethics guidance, last reviewed 25 November 2025, at barcouncilethics.co.uk (read 17 August 2026). The Bar Council states the document is not "guidance" for the purposes of the BSB Handbook. A previous version of this note cited a differently titled 2023 document with section numbers; corrected 17 August 2026.
  8. All read 17 August 2026. Armilla, armilla.ai/ai-insurance: coverholder at Lloyd's, standalone AI liability up to USD 25 million per organisation, underwritten by certain underwriters at Lloyd's. Munich Re and Mosaic, aiSure, announced 26 February 2026, initial capacity EUR / USD / CAD 15 million, munichre.com and mosaicinsurance.com. Counterpart, affirmative AI coverage plus a technology E&O insuring agreement announced 24 November 2025 across miscellaneous professional liability and allied health; Counterpart's own site does not describe the AI coverage. AIUC, aiuc.com: AIUC-1, 51 requirements and 130 controls across six pillars, certificates of twelve months with at least quarterly testing; first AIUC-1-backed policy placed for ElevenLabs in February 2026 through Lloyd's of London, with no carrier named at source and no limits published. The coverage conditions previously described in this note for Armilla, Counterpart and AIUC are not published by any of them and were removed in this revision.