W. R. Berkley's announcement of an absolute AI exclusion from commercial general liability policies is not news about insurance. It is news about how far behind the financial services and professional services sectors remain in understanding their own AI risk. UK regulated firms are deploying generative AI tools—Harvey, Legora, Luminance, standard Microsoft Copilot implementations—often without documented governance frameworks, audit trails, or controls that would satisfy either the FCA's Consumer Duty (PS22/9), the SRA Code of Conduct 2019, or the emerging demands of ISO 42001. When insurers start excluding AI claims entirely, they are not being unreasonable; they are admitting they cannot price a risk they cannot measure. For mid-market law firms, accountancies, financial advisors, and insurers themselves operating in the UK, this means your standard policies are now silent on the exact exposures that regulators expect you to control.
This is the inevitable end-state of 'move fast and break things' AI adoption. The industry has spent three years bolting large language models onto existing workflows—due diligence, case research, document review, financial forecasting—without building the upstream controls that underwriters need to see. The result: neither your board nor your insurer nor your regulator can articulate what your AI systems actually do, how they fail, or what the financial consequence would be. Specialized AI liability products will emerge, but they will be expensive and narrow. The firms that avoid this trap are those that invested early in AI governance frameworks: documented policies, model testing before deployment, role-based access controls, and audit logs that show who did what with what system and why. The firms that did not will face either uninsured exposure or very steep premiums.
Trovix's perspective is straightforward: AI governance has to come before AI deployment, not after. We see too many firms buy powerful tools (or worse, build their own) and then scramble to explain to the FCA, PRA, ICO, or SRA what they actually do. The difference between Harvey or Luminance, which are purpose-built for legal and professional services with documented control points, and a generic Copilot instance plugged into a shared drive is not the quality of the model—it is transparency and auditability. That is why Trovix Audit exists: to give you a real-time view of how AI is being used across your firm, what it is processing, whether it is handling data it should not be, and whether it is producing outputs that breach client confidentiality or professional duty. Without that, you cannot even apply for insurance, let alone comply with SRA ISA UK 7.4 or FRC ISA 315(A).
Here is what to do now: (1) Map every AI tool your firm currently uses—including ChatGPT instances, free Copilot access, and any cloud AI features baked into your case management or accounting software. (2) For each tool, document: what data it processes, who can access it, whether it is trained or fine-tuned on your own data, and what happens to the output. (3) If you cannot answer those questions, remove the tool immediately. (4) Implement a formal AI governance policy aligned to ISO 42001 and your sector regulator's expectations (FCA, SRA, PRA, ICO). (5) Deploy an audit and monitoring layer so you can show your insurer, regulator, and clients that you are in control. That layer does not require you to stop using AI. It requires you to be honest about what you are doing with it. W. R. Berkley's exclusion is not the real problem. The real problem is that most firms cannot pass an audit of their own AI use. Until they can, insurance will remain unaffordable and regulatory risk will remain unquantified.
Source: Bloomberg Law