AI Malpractice Insurance for Law Firms: What Carriers Now Ask

Ankit Dhiman, Co-founder & CTOAugust 6, 20266 min read
Line illustration of an insurance policy checklist connected to a shield representing coverage

Key takeaways

  • Malpractice carriers including CNA now include supplemental AI questionnaires in renewal underwriting, asking about AI tools used, governance policy, training, and incident response.
  • AI-related claims can fall into a coverage gap between cyber policies (which typically exclude professional-services claims) and malpractice policies (which typically exclude data-security incidents), unless a firm has coordinated or endorsed both.
  • More than 25 state bars have issued formal AI guidance as of 2026; California updated its rules in March and May 2026 specifically to address agentic AI.
  • Most states don't require client consent to use AI generally, but do require it when using a tool means disclosing confidential client information to a third party.
  • The same audit trail that makes a secure AI system technically defensible is most of what a written governance policy needs; the missing piece for most firms is turning that log into a document a carrier or bar examiner can read.

If your firm's malpractice policy has come up for renewal recently, you may have already noticed a new section on the form. Carriers including CNA have added supplemental AI questionnaires to renewal underwriting, and the questions are specific: which AI tools does the firm use, is there a written AI governance policy, do attorneys get AI-specific training, how is AI-generated work product reviewed, and does the firm have an incident response plan if something goes wrong. Underwriters are asking a version of the same three questions across the board now: do you use AI, do you police it, do you have protocols. Firms that can't answer clearly are already seeing higher premiums or restrictive endorsements.

That's a different conversation than "is AI safe for privileged documents," which is the one most firms are actually having. Safety is an architecture question. What a carrier or a state bar wants is a policy question, and those aren't the same document.

What your carrier is actually asking for

The practical problem is that most cyber policies exclude claims arising from professional services, and most malpractice policies exclude claims arising from data security incidents. An AI-related data exposure can sit in the gap between the two, covered by neither, unless the firm has coordinated the language across both policies or added an explicit AI endorsement. As of 2026 that coverage is genuinely split across the market: some firms are running on "silent" AI cover, meaning an old professional liability form that's never been amended for AI at all, and others have moved to "affirmative" cover, a separate product or endorsement that explicitly addresses AI-related claims. The Insurance Services Office introduced an optional generative-AI exclusion for 2026 commercial general liability policies, which cuts the other way: some firms may find AI-related claims newly excluded unless they specifically negotiate them back in.

None of this is solved by having good security. It's solved by being able to hand an underwriter a real document: what tools are approved, who approved them, what training happened, and what the firm does when something goes wrong. A firm running secure infrastructure with no written policy is in almost the same position at renewal as a firm running nothing at all, because the underwriter isn't asking to see your architecture diagram.

What your state bar has actually ruled

More than twenty-five state bars have issued formal opinions or guidance on lawyers using generative AI, including California, Florida, New York, Texas, Oregon, New Jersey, Pennsylvania, and Kentucky. This isn't static guidance from a couple of years ago. California's Standing Committee on Professional Responsibility and Conduct approved proposed amendments to six ethics rules at its March 13, 2026 meeting, and replaced its 2023 AI guidance in May 2026 specifically to address agentic AI, tools that plan and execute multi-step tasks on their own rather than just answering a prompt. Florida's Ethics Opinion 24-1 requires informed client consent before using a third-party AI tool that would expose confidential information. The general rule across most states is narrower than people assume: a lawyer doesn't need client consent to use AI on a matter, unless using it means disclosing confidential information to a third party, in which case consent and an understanding of that tool's data handling, sharing, and retention policies both become the lawyer's professional duty.

That last part is where a lot of firms are exposed without realizing it. Knowing a vendor's data policy isn't optional due diligence anymore. In several states it's the specific thing an ethics opinion says you have to know before you're allowed to use the tool on client matters at all.

Where the technical answer and the policy answer diverge

We've made the technical case elsewhere for why self-hosted, zero-retention AI infrastructure is the right architecture for privileged legal work (see our piece on private AI infrastructure and on AI safety for privileged documents). That case still holds. What it doesn't do on its own is answer a carrier's questionnaire or satisfy a bar examiner, because both of those want evidence of governance, not just evidence of good engineering. A firm can be running the most secure possible setup and still fail an AI supplemental questionnaire if nobody wrote down which tools are approved, who's responsible for reviewing AI output, and what happens when a mistake gets caught.

The two problems share an answer, though. The same audit trail that makes a secure AI system defensible from a security standpoint (what was queried, what model version, who reviewed the output) is close to what a carrier's questionnaire and a bar's documentation expectations are actually asking for. The gap most firms have isn't the technology. It's that nobody turned the technical log into a policy document a non-technical underwriter or examiner can actually read.

What this looks like in practice

A written AI use policy doesn't need to be long, but it needs to cover the same ground the questionnaires and opinions are asking about: which tools are approved for which kinds of matters, what data those tools can and can't touch, who signs off on AI-assisted work product before it goes to a client or a court, what training attorneys and staff receive, and what the firm's response looks like if an AI tool is misused or a client's data is exposed. If the firm is already running audit-logged AI infrastructure, most of the raw material for that policy already exists. It just needs to be pulled together into something that isn't buried in a system log.

Frequently asked questions

Does my firm need a separate AI insurance policy?

Not necessarily a separate policy, but you need to know whether your existing malpractice and cyber policies actually cover AI-related claims or are silent on them. That's a conversation to have directly with your broker, since coverage varies by carrier and by how your current policy language is written.

In most states, no, unless using the tool means disclosing the client's confidential information to a third party. At that point, several state bars, including Florida under Opinion 24-1, require informed consent. The safer position is understanding each tool's data policy well enough to know which category it falls into before you use it.

What does an AI governance policy actually need to include?

At minimum: which tools are approved for which use cases, what data those tools can access, who reviews AI-assisted work before it's client-facing, what training staff receive, and an incident response plan for when something goes wrong. Most of this can be pulled from an existing audit trail if the firm's AI infrastructure already logs its activity.

Is this only relevant to large firms?

No. A solo or small firm is personally carrying the same exposure on a smaller malpractice policy, and state bar ethics rules apply regardless of firm size. The main difference is that a mid-market firm is more likely to have a managing partner or GC actually fielding a carrier's questionnaire directly.

Get new articles when they publish

One email per post. No pitch, no spam.

Billing Leakage Calculator Or book a free callMore articles