Breaking
Loading headlines…
AI Business Dispatch.

AI Errors Now the Number-One PI Risk for UK Consultants - and Most Policies Won't Pay

A new survey puts AI mistakes ahead of cyber and compliance failures as the leading professional indemnity threat facing UK consulting and advisory firms. The gap between what those firms think their policy covers and what it actually covers is where the next wave of claims will land.

N
Nathaniel Frost · 17 September 2026 · 4 min read
Share:·X·LinkedIn
AI Errors Now the Number-One PI Risk for UK Consultants - and Most Policies Won't Pay
Nathaniel Frost

Four decades of professional indemnity law was built on a simple premise: a person gave bad advice, and that person's firm carried the liability. That architecture is cracking. According to a survey by insurance broker Everywhen, 41% of insurance and risk experts at UK firms now identify AI mistakes as the single biggest PI risk facing their organisations, putting it ahead of cyber threats (35%) and compliance failures (23%). Vendor failures barely registered at 1%.

The figures are striking in themselves, but the subtext is more unsettling. AI and cyber together command 76% of respondents' concerns, pointing to something structural: professional risk is increasingly perceived as a technology problem, not a people problem. That shift hasn't yet reached the policy wordings sitting on most consultants' desks.

Advertisement

TrademarkDashboard: Stop counterfeits before they hijack your brand.

The Silent Exclusion Problem

Most PI policies in circulation were drafted before agentic AI or large language models featured in a typical consulting engagement. The practical consequence is that many policies simply don't mention AI at all. When they don't, the question of whether a claim triggered by an AI-generated output is covered gets resolved at claim time, not at renewal time. That is precisely the wrong moment to discover a gap.

UK insurers are moving, but not fast enough to match deployment rates. Carriers are adding AI exclusions and endorsements quietly to renewal schedules through 2026, often in sections that broker summary letters don't flag. A typical mid-sized UK consultancy now ships deliverables that integrate with clients' data pipelines and rely partly on AI outputs whose authorship and accuracy remain legally unsettled. The contract behind that engagement has grown accordingly: heavyweight MSAs with data-protection annexes, audit rights, and IP indemnities that didn't exist in equivalent engagements five years ago. The policy has not kept pace.

For firms using AI in document review, suitability scoring, or strategic modelling, the liability chain is unambiguous: AI-driven insights remain the firm's advice. If a recommendation based on an AI output causes client losses, the liability sits with the firm that issued it, regardless of what the model produced.

Recruitment as the Canary

The PI exposure is sharpest in recruitment and HR consulting, where regulators have already intervened. The ICO's March 2026 "Recruitment Rewired" report, drawing on voluntary engagement with more than 30 employers, concluded that many employers using AI to screen and score candidates are carrying out automated decision-making under UK data protection law without acknowledging it. The ICO found that tools were making substantive decisions while human review amounted to little more than rubber-stamping. The regulator made almost 300 recommendations to AI recruitment tool providers and developers following 2024 audits, and sent direct letters to 16 named organisations.

The Data (Use and Access) Act 2025, which came into force on 5 February 2026, replaced the near-total restriction on solely automated decisions with a permissive but safeguard-heavy regime. UK agencies can now use AI screening tools under legitimate interests, but only with transparency, meaningful human review, and a documented right for candidates to contest outcomes. A data protection impact assessment is expected as standard. The ICO is developing a statutory AI and ADM code of practice, with the government building the secondary legislation required to underpin it.

For recruiting consultancies operating across SIC 78.20, this is an unfamiliar compliance posture. The sector's fastest-growing cohort of newly formed businesses, concentrated precisely in the 70.22 and 82.99 formation bands that dominate UK professional and business services, are deploying AI tools without the governance infrastructure that larger incumbents are scrambling to build. That asymmetry is a PI exposure waiting to materialise.

The Trademark Signal

One indirect indicator is worth tracking. AIBD analysis of IPO trademark data shows 7,469 Class 41 filings in Q3 2026, an 11.8% decline on the prior period. Class 41 covers education, training, and entertainment services: the broad envelope under which AI-powered training tools, upskilling platforms, and assessment services file for brand protection. A contraction in filing activity can mean several things: consolidation among platform providers, market hesitation, or simply that the cohort that rushed to register brands in 2024-25 has worked through its backlog. What it doesn't suggest is a sector confidently expanding. For corporate learning and training businesses, already squeezed by AI tools that commoditise content production, brand investment is a reasonable proxy for growth appetite. The signal here is cautious.

What Firms Should Actually Do

The uncomfortable arithmetic is this: professional services adoption of AI went from 31.4% of UK PBS firms in December 2024 to 43.4% by December 2025, according to government data. The policy market, the regulatory framework, and in-house governance have not moved at the same speed.

Firms that want to close the gap before renewal need to do three things. First, inventory every AI tool that touches a client deliverable and establish whether the policy wording responds if the negligent act was performed by software rather than a person. Second, log AI interactions with sufficient detail to reconstruct the decision chain: a claim you can reconstruct is defensible; one you can't is typically a settlement. Third, don't treat human sign-off as automatic protection. A reviewer who lacks the authority or competence to change an AI-generated output before it reaches the client is not providing meaningful human involvement under either the ICO's framework or most PI policy conditions.

The claims that worry PI underwriters most are long-tail. The AI deployments happening now will generate disputes over an extended horizon. The firms that understand this earliest will price it into their governance. The rest will read about it in a coverage denial letter.

professional indemnityAI riskconsultingrecruitmentICOData Use and Access Actautomated decision-makingUK business servicesPI insurancetrademark filings