FCA authorised · FRN 7249520117 325 0027Quote & buy →
Apex Insurance Brokers
Speak to a brokerGet a quote →
APEX INSURANCE
Technology & regulation

AI in insurance

Category: Insurance and technology · Reviewed by the Apex broking team · Last reviewed 2026-08-22 · ~5 min read

In short: Artificial intelligence is used across UK insurance in pricing and underwriting, claims triage and fraud detection, document handling and customer service. The FCA has taken a technology-neutral, outcomes-focused approach rather than writing an AI rulebook: existing requirements on governance, systems and controls, senior manager accountability and consumer outcomes apply to AI as they apply to anything else. The harder commercial questions are about liability — who answers when an AI-assisted output is wrong, and whether professional indemnity responds.

Category: Insurance and technology
Also known as: artificial intelligence in insurance, machine learning underwriting, automated claims handling
Related concepts: AI underwriting, AI in claims processing, Consumer Duty

Where it is actually used

Underwriting and pricing is the most mature area. Models are used to score risks, to price at a granular level, to detect inconsistencies in submitted data and to route referrals to human underwriters. The general treatment is covered under AI underwriting.

Claims is the second. Automated triage sorts incoming notifications by severity and complexity, image recognition assesses damage from photographs, and pattern detection flags files for fraud investigation. This is covered under AI in claims processing.

Beyond those, the uses are largely administrative: extracting data from submissions and policy documents, drafting correspondence, summarising files, answering customer queries, and supporting broker research. These are the applications spreading fastest, because they attach to existing processes rather than replacing decisions.

The regulatory position

The FCA’s stated approach is technology-agnostic, principles-based and outcomes-focused. Its published position is that its rules do not usually mandate or prohibit specific technologies, and that rather than creating a dedicated AI rulebook it will apply existing frameworks to how firms deploy AI, while building its empirical understanding of use and monitoring whether adaptations become necessary.

The frameworks it identifies as already applying include the Consumer Duty, which requires firms to deliver good outcomes and not to embed bias in the way risks and customers are assessed; the Senior Managers and Certification Regime, which locates accountability for AI use with existing senior management functions rather than a new dedicated role; the systems and controls requirements covering governance, risk management, security, outsourcing and operational resilience; and the threshold conditions requiring a sound business model and prudent management.

The practical consequence for a regulated firm is that “the model did it” is not an answer. An accountable individual owns the outcome, the governance around the model has to be demonstrable, and third-party model providers are an outsourcing question.

The liability question

For businesses outside insurance, the live issue is professional liability. Where a professional uses an AI tool to produce or check work — a design calculation, a piece of research, a draft report, a set of accounts — and the output is wrong, the duty owed to the client is unchanged. The professional remains responsible for the work; the tool is not a defence and, in general, has no meaningful liability of its own to the client.

That leaves two insurance questions. Does the professional indemnity policy respond to a claim arising from AI-assisted work? And does the policy contain an exclusion aimed at artificial intelligence, automated decision-making or unverified third-party output? Both are covered in detail in our guides on whether professional indemnity covers AI mistakes and on AI exclusions and clauses in policies.

A third question is emerging in liability and cyber lines: whether use of a generative tool that has ingested confidential client material creates a confidentiality or data exposure, and whether that sits in the professional indemnity policy, the cyber policy, or the gap between them.

What tends to go wrong

The failure modes are not exotic. Outputs that are fluent and wrong, and are not checked because they read well. Confidential or personal data placed into a tool whose terms permit retention or training. Reliance on a supplier’s model with no contractual allocation of responsibility for its errors. Absence of any record of what the tool produced and what the human changed, so that when a claim comes, the firm cannot show what it actually did. And, in regulated firms, a decision-making process that cannot be explained to a customer or to a regulator.

Each of these is a governance failure rather than a technology failure, which is consistent with the regulator’s position that existing rules already reach the conduct.

Practical steps for a business

Write down where AI is used and for what, distinguishing tools that assist a human from tools that make or effectively determine a decision. Name an accountable owner for each. Require and record human review of anything that goes to a client or affects a customer outcome. Check supplier terms for data retention, training use and liability caps, and check whether they sit within your existing outsourcing controls. Tell your broker — proposal forms increasingly ask, and an inaccurate answer is a disclosure problem in its own right.

Then read the policy. Ask specifically whether any exclusion touches AI, algorithmic decision-making or automated output; whether cover extends to work produced with the assistance of tools; and how the professional indemnity and cyber policies interact where the loss involves both defective work and a data exposure.

Why it matters now

Adoption has outrun documentation in most businesses. Tools arrive through individual employees and departments rather than through a procurement process, which means the exposure exists before anyone has decided who owns it. The insurance market has responded unevenly — some wordings are silent, some carry broad exclusions, some address it expressly — so the position varies significantly between insurers and cannot be assumed from last year’s policy.

Frequently asked questions

Has the FCA made special rules for AI?

No. Its published approach is technology-agnostic and outcomes-focused: rather than a dedicated AI rulebook, it applies existing requirements — the Consumer Duty, senior manager accountability, systems and controls, and the threshold conditions — to how firms deploy AI.

If an AI tool causes a professional's mistake, who is liable?

The professional. The duty owed to the client does not change because a tool was used to produce or check the work, and the tool generally has no meaningful liability to the client. The insurance question is whether the professional indemnity policy responds.

Do professional indemnity policies exclude AI?

Some do, some are silent, and some address it expressly. Wordings vary considerably between insurers and between years, so the position has to be read on the actual policy rather than assumed.

What is the most common AI-related exposure in practice?

Unchecked output going to a client, and confidential or personal data being put into a tool whose terms allow retention. Both are governance failures rather than technology failures, and both are avoidable with a written policy and a record of human review.

Related entries


This entry is part of the Apex Insurance Wiki. This entry states the position as at August 2026. It is insurance information, not legal advice. Last reviewed 2026-08-22. Next review: 2027-02-22.

Does your policy say anything about AI? Most people do not know.
AI exclusions, wordings and disclosure questions checked before renewal. Bristol-based, FCA-regulated.
Call 0117 325 0027  info@apexinsurancebrokers.co.uk

Apex Insurance Brokers Limited is authorised and regulated by the Financial Conduct Authority (FRN 724952). This page is general information, not advice on a specific policy.

Want a broker to look at your commercial cover?
If you have your renewal pack, Statement of Fact or schedule, send it over and we’ll come back with options — no forms to fill in. Arranging cover for the first time? That works too. Or call 0117 325 0027.
Start a commercial quote →
Larger or multi-site risk? We’ll come and see you.
Get a quote →