“8/10 times, we are instructing them for their PI cover, not because we can’t find the answer in-house.” A finance general counsel said that to RollOnFriday about the firms they hire. For a growing share of clients, then, the product is your professional indemnity policy, which turns the question every renewal now asks, whether legal malpractice insurance covers AI mistakes, into a question about the product itself.

The answer in September 2026 is more reassuring, and more demanding, than the headlines. No major US lawyers’ professional liability writer has filed an AI exclusion and premiums have not moved. But underwriters now ask “Do you police it?”, a single sanctions order has passed $100,000, and a client whose claims were dismissed over fabricated citations is the malpractice fact pattern insurers have been waiting for.

The Daily Record’s 25 August 2026 survey of carriers found no flood of claims.

“We’re not seeing a lot of what I would call direct AI claims at this point.” — Chris Newbold, Chief Operating Officer, ALPS (Daily Record, 25 August 2026)

Newbold called it “an early signal rather than a clear trend” and added the line for every firm’s first training slide: “I think we’re in this interesting transition period where adoption might be moving faster than governance.” Aon’s Stan Sterna, April 2026, on the new questions: “They’re asking firms, ‘Do you use AI? Do you police it? Do you have protocols in place?’” Berkley Select had no supplemental AI questions and no exclusion as of August 2026.

Lee Norcross, president of the broker L Squared Insurance Agency, reported that AI “has not directly affected malpractice premiums” and that the one nonstandard surplus-lines insurer with an AI exclusion endorsement is “the exception, not the rule”.

“Attorneys using AI need to remember that they are the ones that can be sanctioned and possibly disbarred for not verifying an AI-generated brief… AI does not have a law license to lose.” — Lee Norcross, L Squared Insurance Agency (Daily Record, 25 August 2026)

ISO and other AI exclusions: what exists and on which policies

Most AI exclusions sit on other lines. Legal AI Governance’s primary-source review, verified against filings on 4 May 2026, states: “No major US LPL writer (CNA, Travelers, Chubb, Hartford, Markel, ALPS, or any state mutual) has publicly filed an explicit AI exclusion endorsement on lawyers professional liability paper.”

Form or carrier Line What it excludes Your LPL policy?
Verisk/ISO CG 40 47, CG 40 48, CG 35 08 (effective 1 January 2026) Commercial general liability Injury and damage “arising from” generative AI, broadly defined No; CGL is not professional services
Hamilton Select generative-AI exclusion Professional liability Generative-AI-related professional claims Only if placed with that carrier
Tech E&O market generally (Honigman) Technology errors and omissions “hallucination-related losses, IP infringement, and data disclosure through outputs” Your AI vendor’s cover, not yours

The Honigman analysis adds a point for law firms: when your legal-AI vendor’s indemnity is capped at a year of fees and its own E&O excludes hallucination losses, its promise to stand behind its output is worth roughly nothing. Your policy responds; read it for the definition of professional services and any exclusion for unauthorised disclosure, because the exclusion that bites is often not labelled AI.

Sanctions and malpractice claims are different exposures

A sanction is an order against the lawyer or firm; a malpractice claim is the client’s action for the harm the error caused. Whether your policy responds to either, and to court-ordered fee-shifting in particular, is a wording question for your broker. Hallucination cases now produce both at once.

Case Sanction on the lawyers Client-side harm that becomes a claim
Couvrette v. Wisnovsky (D. Or., 2025–26) $15,500 plus $94,704.38 fee-shifting, $110,204.38 across two lawyers; bar referral Briefs struck; claims dismissed with prejudice after 15 fake citations and 8 fabricated quotations
Scott v. Illinois Human Rights Commission, 2026 IL App (1st) 251462 (28 July 2026) $15,000, $1,500 per false citation or quotation; ARDC referral An appeal argued on ten false citations and quotations
In re Martin (Bankr. N.D. Ill., 18 July 2025) $5,500 joint and several with the firm; attendance at the NCBJ AI plenary A bankruptcy debtor’s filings built on four misattributed or non-existent cases

The full list is in the AI hallucination sanctions timeline; here the right-hand column is the point: in Couvrette the clients lost their case, and that is the file a plaintiff’s malpractice lawyer opens. Judge Slade in In re Martin: “any lawyer unaware that using generative AI platforms to do legal research is playing with fire is living in a cloud.”

Scott v. IHRC and Butler Snow: the defences that do not work

Scott matters beyond its arithmetic. The lawyer had used a “premier corporate subscription of ChatGPT”, and the Illinois Appellate Court refused to let that count: “no matter how much one pays for ‘premier’ or ‘corporate’ versions of AI products, it does not negate an attorney’s obligation to verify all citations of authority.” “The only acceptable standard is zero false citations.” And since Whiting v. City of Athens (6th Cir., March 2026), where two lawyers paid $15,000 each plus the other side’s fees because “smaller fines have plainly been inadequate”, courts also shift the opponent’s costs onto the offending lawyers, exactly the kind of order a firm looks to its policy for.

The second failed defence is the policy in the drawer.

In Wadsworth v. Walmart (D. Wyo., February 2025) a Morgan & Morgan partner and local counsel e-signed a motion with eight fake cases out of nine without reading it and paid $1,000 each; Judge Kelly Rankin: “Blind reliance on another attorney can be an improper delegation of this duty and a violation of Rule 11.” Rule 5.1 and 5.3 failures are why underwriters ask about protocols rather than habits.

What preserves coverage: the records underwriters ask for

Legal AI Governance’s list of renewal artefacts to keep: a written AI policy, a vendor due-diligence file, informed-consent language, training records, a pre-filing verification log, a usage log and an incident-response procedure. The baseline is thin: the 8am 2026 Legal Industry Report (via LawSites) found 69% of legal professionals using generative AI for work, 54% with no training and none planned, and 9% with a written, enforced policy; Thomson Reuters found 34% using unsanctioned “shadow AI” in 2026.

Three prompts produce three of those records:

Pre-filing verification log for a brief
Below is a brief I am about to file in [court]. Build a verification log as a table: Citation as it appears | Page | Proposition cited for | Quotation (Y/N) | Existence: NOT YET VERIFIED | Pin cite and quote confirmed: NOT YET VERIFIED | Citator status: NOT YET VERIFIED | Checked by / date.
Do not verify, correct or add anything; flag malformed citations "CHECK FORMAT". I will complete the columns in the database before signing.

Brief:
[paste]
Renewal-questionnaire answers from our actual practice
Here are our firm's AI policy, approved-tool list with contract terms, and training register: [paste]. Our professional liability insurer's supplemental questions are: [paste].
Answer each question accurately to the documents and nothing more. Where they do not support a "yes", give the honest answer and a bracketed note of the record we would need to create. Do not invent controls, dates or training. Finish with the five gaps most likely to concern an underwriter.
Incident memo after a suspected fabricated citation
A [motion / brief] filed on [date] in [court] may contain a citation that does not exist or does not support the proposition. Draft an internal incident memo: what was filed and when; how the error was identified; which tool and tier were used, and by whom; what has been verified so far (VERIFIED / NOT YET VERIFIED per authority); immediate steps to correct the record and inform the client; who signs off. Use only these facts: [facts]. Do not speculate about the court's reaction.

The log turns how to verify AI legal citations into evidence; the memo is the first document you need after you have found a fake citation. More templates: the prompt library.

Two exposures the questionnaire misses

Confidentiality may fall between two policies. In United States v. Heppner (S.D.N.Y., February 2026) a criminal defendant’s own exchanges with consumer Claude were held to fall outside both attorney-client privilege and work-product protection. Imagine an associate pastes a settlement memo into a personal chatbot account and it later surfaces in litigation: is that “professional services” under the LPL form, an unauthorised disclosure for a cyber policy, or excluded under both? The market has not settled it, which is why Covington ran a panel on legacy, cyber and specialty AI policies in October 2025. Ask before the incident; is ChatGPT confidential for lawyers? belongs in the vendor file.

Not using AI is becoming a standard-of-care question. The UK Jurisdiction Taskforce’s July 2026 Legal Statement on Liability for AI Harms says at paragraph 67 that “a professional could also be liable for failing to use AI for a task when a professional exercising reasonable care and skill would have done so”. “We did it by hand to be safe” stops being a complete answer once competent peers use validated tools for review. AI training for lawyers covers the competence half of that standard.

Four questions to ask your broker

  1. Does our LPL form contain any exclusion, endorsement or definition that mentions artificial intelligence, automated tools or software-generated content?
  2. Are court-ordered fee-shifting awards, as opposed to fines, covered as damages or defence costs?
  3. Does “professional services” include supervising an AI tool’s output?
  4. Which AI governance records will the renewal application ask for?

Where to go next: AI ethics rules by jurisdiction covers the supervision and competence duties underwriters are indirectly testing; the other ethics and regulation guides cover disclosure, court orders and the UK regulator. A dated training record is the artefact most firms lack, and AI Lab for Lawyers produces one for every participant: four live two-hour sessions, recorded, with a certificate of completion.

Frequently asked questions

Does malpractice insurance cover AI mistakes?

In most cases yes, in the same way it covers any other negligent error. As of a May 2026 primary-source review, no major US lawyers' professional liability writer (CNA, Travelers, Chubb, Hartford, Markel, ALPS or any state mutual) had filed an AI exclusion, and ALPS reported in August 2026 that it is 'not seeing a lot of ... direct AI claims'. Court fines and sanctions are a separate question from a client's claim; read your form and ask your broker.

Are there AI exclusions in lawyer liability policies?

Rarely on lawyers' professional liability paper. Verisk/ISO's generative-AI exclusions (CG 40 47, CG 40 48 and CG 35 08, effective 1 January 2026) apply to commercial general liability, and W.R. Berkley's absolute AI exclusion sits on management liability forms. One nonstandard surplus-lines insurer has an AI exclusion endorsement, which broker Lee Norcross called 'the exception, not the rule'. Check instead for any exclusion for unauthorised disclosure of confidential information.

Will my insurer ask about AI use at renewal?

Increasingly. Aon's Stan Sterna said in April 2026 that carriers are asking 'Do you use AI? Do you police it? Do you have protocols in place?', and ALPS says it is likely to move towards more detailed questions about how firms use AI. Berkley Select had no supplemental AI questions as of August 2026. Expect requests for a written policy, an approved-tool list, training records and a verification procedure.

Can I be sued for not using AI?

In principle, yes. The UK Jurisdiction Taskforce's July 2026 Legal Statement says a professional 'could also be liable for failing to use AI for a task when a professional exercising reasonable care and skill would have done so', and ABA Formal Opinion 512 says it is 'conceivable that lawyers will eventually have to use' such tools to complete certain tasks competently. The standard is what a competent peer does, which now often includes validated tools for review.

How do I keep coverage while using AI?

Keep the records underwriters ask for: a written AI policy that cites the rules it implements, a vendor due-diligence file with each tool's no-training and retention terms, informed-consent language where client data is used, dated training records, a pre-filing verification log for every authority, a usage log and an incident-response procedure. Then follow them; Butler Snow's two-year-old policy did not stop three partners being disqualified in 2025.

Written by

Dr. Niklas Schmidt, Partner at Wolf Theiss

Partner at Wolf Theiss Attorneys-at-Law, where he heads the firm-wide tax team; lawyer, author, TEDx speaker and technologist. He has spent well over 1,000 hours testing practical AI applications for legal work, runs a toolkit of roughly 80 AI tools in daily practice, founded the WT Crypto Academy (1,000+ participating lawyers) and has given around 450 talks over 20 years. He teaches the live course AI Lab for Lawyers on Maven.