Professional indemnity insurers are asking Australian law firms about AI governance at renewal. Here are the five questions, what evidence they want, and what firms that cannot answer them are risking.
PI renewal conversations have changed. Insurers assessing risk for Australian law firms are no longer focused solely on traditional risk indicators such as supervision ratios, matter management processes, and claims history. In 2026, AI governance has joined that list.
The shift is driven by claims data. The Legal Practitioners Liability Committee has identified inadequate technology controls as a contributing factor in a growing proportion of professional indemnity claims. Insurers have responded by asking more specific questions about how firms govern their technology environments, including how they manage AI tool use by staff.
Managing partners approaching renewal who have not addressed AI governance are walking into a conversation they are not prepared for. This article maps the five questions you are most likely to face, the evidence insurers want behind each answer, and what a firm that can answer them looks like in practice.
- FREE GUIDE -
AI Governance Checklist for Australian Businesses
Not sure if your organisation's AI use is putting sensitive data, compliance obligations, or client trust at risk?
Download our free AI Governance Checklist and assess your readiness across governance, data protection, staff behaviour, compliance, and incident response. Score your organisation in minutes and identify the gaps that need attention.
✅ 30 practical assessment questions
✅ Board and leadership team friendly
✅ Identify Shadow AI and compliance risks
✅ Instant self-assessment scoring framework
Question 1: Does Your Firm Have a Documented AI Governance Policy?
This is the foundational question. Insurers are not asking whether your firm has banned AI or whether you have approved AI. They are asking whether you have made a documented decision about AI governance and committed it to writing.
A documented AI governance policy defines which AI tools are approved for use with client data, which are approved for internal use only, and which are prohibited. It sets out what staff must not do with client information when using AI tools, and it establishes a process for assessing new tools before they enter the workflow.
What insurers want to see: A written policy that has been dated, approved by firm leadership, and distributed to all staff. A policy that exists in draft form or has not been formally adopted does not provide the same protection.
What firms without this answer: If you cannot confirm that a documented policy exists, the insurer has no basis to assess your governance position. This is the question that most directly affects whether coverage terms are affected.
Question 2: Have You Assessed Which AI Tools Staff Are Actually Using?
A policy that governs tools you do not know about is not a control. Insurers understand that Shadow AI use is widespread, and they will ask whether you have taken steps to establish a baseline picture of what is actually in use across your firm.
This question is designed to test whether your governance framework is based on evidence or assumption. A managing partner who has issued a policy but has not verified what tools staff are accessing is, from an insurer’s perspective, operating with an unverified control.
What insurers want to see: Evidence that the firm has conducted a Shadow AI assessment or IT audit to identify which AI platforms are being accessed across the network. This does not need to be a large exercise. A one-day assessment by your IT team or IT partner produces a defensible baseline.
What firms without this answer: If your response is that you assume staff are following the policy but you have not verified it, the insurer will treat your AI governance controls as unverified.
For a plain-English account of what Shadow AI is and why the assessment matters, see Shadow AI in Law Firms: What Managing Partners Need to Know.
Question 3: Have You Assessed the AI Tools You Have Approved Against Your Privacy and Professional Conduct Obligations?
Approving a tool without assessing it is not governance. Insurers will ask whether the tools the firm has approved for use with client data have been assessed against the firm’s obligations under the ASCR, the Privacy Act, and the expectations of the VLSB+C and LPLC.
The specific areas of assessment that matter are: whether the vendor provides a data processing agreement, whether client data is used for model training, and whether data residency commitments are consistent with the firm’s Privacy Act obligations.
What insurers want to see: A record that the firm has reviewed the data processing terms of each approved AI tool, confirmed that client data is not used for model training, and verified the vendor’s data residency position. This does not need to be a lengthy document. A one-page assessment record per tool is sufficient.
What firms without this answer: Approving tools without documented assessment means the firm cannot demonstrate that its approved tools meet its professional obligations. This is the question that most directly affects claims arising from a specific tool’s data handling.
For a detailed guide to assessing and selecting AI platforms appropriate for legal practice, see How to Choose an Approved AI Platform for Your Law Firm and Restrict Everything Else.
Question 4: Do You Have Technical Controls in Place to Prevent Staff Using Unapproved AI Tools with Client Data?
A policy that relies entirely on staff compliance is not a control. Insurers are asking whether the firm has implemented technical measures that enforce the policy without relying on individual decision-making at the moment of use.
This question reflects the LPLC’s published guidance that adequate technology controls require more than a written policy. Technical enforcement is the layer that converts a policy into a governance framework.
What insurers want to see: Evidence that the firm has implemented browser-level or network-level controls that block access to unapproved AI platforms and prevent file uploads to unapproved external tools. A firm that can describe its technical enforcement layer is in a materially stronger position than one that cannot.
What firms without this answer: If the firm’s only control is a policy document and a staff communication, the insurer will assess the firm’s AI governance as having a significant implementation gap.
Question 5: Do You Have an Audit Trail That Would Support a Claims Investigation?
In the event of a claim arising from an AI-related data breach or confidentiality event, the insurer’s investigation will look for evidence of what occurred, when, and whether the firm’s controls were in place and functioning. An audit trail is the evidence base for that investigation.
This means the firm needs logging that records AI platform access across the network, alerts on unapproved tool access attempts, and documentation of the governance decisions made, the policy, the tool assessments, the staff communications.
What insurers want to see: A description of the logging and alerting capability in place, and confirmation that governance decisions are documented and retained.
What firms without this answer: Without an audit trail, the firm cannot demonstrate that its controls were in place at the time of the event. That is a significant gap in any claims investigation.
What a Firm That Can Answer All Five Questions Looks Like
A firm that can answer all five questions has a documented AI governance policy, has assessed which tools staff are using, has reviewed approved tools against its professional obligations, has technical controls enforcing the policy, and has an audit trail supporting any future investigation.
That is not a large programme of work. For most firms it is a structured project of four to six weeks with the right IT partner. The output is a governance position that satisfies the VLSB+C’s adequate systems requirement, meets the LPLC’s evidence expectations at renewal, and supports the firm’s Privacy Act obligations under APP 11.
For the full regulatory picture behind these five questions, see AI Governance for Law Firms: What VLSB+C, LPLC and OAIC Actually Require.
For a look at how directors’ duties obligations apply to managing partners in this context, see Directors’ Duties for Australian Legal Firms.
Download the AI Governance Checklist for Law Firms for a structured starting point covering all five areas.
Frequently Asked Questions
Do PI insurers ask about AI governance at law firm renewals?
Yes. Professional indemnity insurers assessing Australian law firms are increasingly asking about AI governance as part of the renewal process. The shift is driven by the LPLC’s published guidance identifying inadequate technology controls as a contributing factor in a growing proportion of PI claims. Insurers are asking specifically whether firms have a documented AI governance policy, whether they have assessed the tools staff are using, and whether technical controls are in place to enforce the policy.
What AI evidence do PI insurers want from law firms?
PI insurers want to see four categories of evidence. First, a documented AI governance policy that has been formally adopted and distributed to all staff. Second, evidence that the firm has assessed which AI tools staff are actually using, typically through an IT audit or Shadow AI assessment. Third, records showing that approved tools have been assessed against the firm’s data processing obligations including DPA review, data residency confirmation, and training data opt-out. Fourth, a description of the technical controls in place to prevent staff accessing unapproved AI tools with client data.
What happens if a law firm cannot answer PI insurer questions about AI?
A firm that cannot demonstrate documented AI governance controls is in a weaker position at renewal than one that can. Depending on the insurer’s assessment, this may result in coverage conditions being applied, premiums being adjusted, or specific exclusions being introduced for AI-related claims. The LPLC has flagged that inadequate technology governance is a contributing factor in PI claims, which means insurers have a direct basis for treating unmanaged AI use as a risk factor in coverage terms.
How long does it take a law firm to implement AI governance controls?
For most law firms, implementing a governance position that can answer all five PI insurer questions is a structured project of four to six weeks with the right IT partner. The core components are a written policy, a Shadow AI assessment to establish a baseline of tools in use, documented tool assessments for approved platforms, browser-level technical controls to enforce the policy, and logging to provide an audit trail. The AI Governance Checklist for Law Firms provides a structured starting point for each component.
Is Shadow AI covered by law firm PI insurance?
Whether a specific Shadow AI event is covered under a PI policy depends on the terms of that policy and the circumstances of the claim. What is clear from the LPLC’s guidance is that where a firm’s internal controls are found to have been inadequate, this is a factor in claims assessment. A firm that permitted unapproved AI use with client data, had no policy in place, and had no technical controls enforcing a policy is in a materially weaker position in a claims investigation than a firm that had all three. Governance does not guarantee coverage, but its absence creates an exposure.
Shadow AI & AI Governance Protection
For executives and technical leaders who need visibility and control
Your workforce is already using AI tools. The question is whether you can see it, govern it, and prevent data leakage.
If you're concerned about Shadow AI risk, AI governance gaps, or enabling AI safely without blocking innovation, we'll show you exactly what's happening in your organisation and how to protect it.
Request a demo to view real‑time visibility, protection, and governance controls
Request a Demo Today
Author:
Bradley Kaine, CEO and Co-Founder, Kaine Mathrick Tech · Reading time: approximately 8 minutes
Bradley Kaine is CEO and co-founder of Kaine Mathrick Tech, a cyber-first managed IT services provider with offices across Melbourne, Sydney, Brisbane, and Hobart. He advises managing partners and firm principals on AI governance frameworks aligned to Australian professional indemnity and regulatory obligations.
More on Web Filtering and Shadow AI from KMTech
Everything on this topic, in one place.
ARTICLES
KMTech publishes Shadow AI content tailored to the regulatory pressures each industry actually faces. Start with the foundational guide, then go to the piece that matches your sector:
Legal
Financial services
Last updated:





