Berkshire Hathaway, Chubb, and Travelers have all won approval to add AI exclusion clauses to their commercial liability policies. Generative AI-related lawsuits in the United States grew 978% between 2021 and 2025. The maths is simple: insurers cannot price what they cannot predict, so they are walking away. For UK regulated firms — law practices bound by SRA Code, insurers under PRA SS1/23, financial services firms under FCA Consumer Duty PS22/9 — this is not academic. It means you are now holding AI risk on your own balance sheet. If a large language model like those powering Harvey or Luminance makes a mistake in a critical document, and someone sues, your professional indemnity insurer may simply exclude it. You need to know whether your firm is already exposed.
This pattern reveals something deeper than insurance market dysfunction. Generative AI products have been marketed to professional services firms on a narrative of productivity gain and cost reduction. But the legal, financial, and accountancy sectors operate under strict regulatory frameworks designed to protect clients and markets. The AI Act is coming. Lloyd's Blueprint Two is already here. ISA UK (FRC) and ICO UK GDPR requirements around data handling and algorithmic bias are tightening. Most AI implementations — particularly the consumer-grade tools and off-the-shelf large language models — were not designed with this environment in mind. They were designed for speed. Insurers are now betting that the gap between 'fast' and 'safe' in these sectors is wider than most firms have acknowledged.
Trovix's view is direct: the firms that will survive the next three years of regulatory tightening are not those that deploy the most AI. They are those that deploy AI with documented governance. When you use Luminance or Harvey or Microsoft Copilot, you are trusting a vendor's bias testing and data governance. That may not be enough. You need to know what your AI is doing, why it is doing it, who is responsible when it fails, and whether your insurance will actually cover you. We see daily that mid-market firms are running AI in production with almost no internal audit trail — no record of which matters used which models, no bias testing, no quality assurance tied to regulatory outcomes. That is not a technology problem. It is a governance problem. And governance is not something you can bolt on after launch.
Here is what you should do right now. First, audit your current AI use — every tool, every process, every vendor integration. Second, check your professional indemnity terms explicitly. Ask your broker whether AI is excluded or carved out. Do not assume. Third, map your AI governance against FCA Consumer Duty PS22/9 (for financial services), SRA Code (for law firms), or your own regulator's expectations around algorithmic accountability. Finally, if you are planning new AI implementation, build governance into the procurement brief before you evaluate tools. This is not about choosing Harvey over Luminance or Copilot over Legora. It is about choosing implementations that you can document, defend, and insure. Trovix Audit exists precisely because mid-market firms need a way to track AI governance continuously without treating it as a separate compliance burden.
Source: Fast Company