The interesting development in professional indemnity insurance is not an exclusion. According to the Lockton Solicitors PII Market Report 2026, there are no blanket AI exclusions in UK solicitors' policies, but insurers are asking more detailed questions about AI governance, documentation and human oversight. WTW wrote on AI and professional indemnity insurance in May 2025. Read together, the direction is clear enough: the question at renewal is moving from whether you use these tools to how you supervise them, and the answer has to be evidence rather than intention.
Three parties want the same record
Your insurer wants it at renewal, in a proposal form, with a deadline. A client's in-house team wants it in an outside-counsel questionnaire, usually in a spreadsheet with fields too small for the honest answer. Your own COLP wants it when something goes wrong, at speed, on a specific matter.
The three ask in different formats but want the same underlying thing, and none of them can be satisfied retrospectively. Either the record was made when the work was done or it was not. This is the whole argument for making the trail a by-product of the work rather than an administrative task somebody performs afterwards, because tasks performed afterwards are performed inconsistently and then not at all.
What insurers are actually asking about
Three themes recur in the Lockton report's account of the questions: governance, documentation and human oversight. Governance means somebody owns the decision about which tools are used. Documentation means the use is recorded rather than remembered. Human oversight means a qualified person read the output and can say what they did with it.
Notice that none of those is a question about the model. An underwriter is not interested in which system you use or how it was trained. They are interested in whether a firm that produced a bad piece of work using one could explain, afterwards, how it happened. That is a question about process, and it is answerable by a small firm as easily as a large one.
The six parts of a defensible record
A record that survives a hard question contains six things. The plan: what the run was asked to do, before it did it. The redactions: what was removed before any model saw the prompt. The sources: which were searched, not merely which were cited. The verdicts: which authorities were confirmed, which were not, and what was done about the ones that were not.
Then the two human elements. Who authorised the run, and who read the output and signed it off. Software can produce the first four reliably and can record the last two, but it cannot perform them. A record with four parts and two blanks tells its reader exactly what was missing, which is a useful thing for a supervising partner to see on a Monday morning rather than in a complaint.
What the 'How this was made' tab holds
Every agent run returns six tabs: Summary, Files, Action items, Authorities, Open questions, and How this was made. The last one is the record. It shows the screening that ran before any model saw the prompt, including the personal and client data that was redacted, so that a neutral citation number appears as a reference. It shows the jurisdiction that was confirmed in scope.
For a research run, it shows the plan the agent proposed and the fact that a person chose to Approve and run, Modify or Cancel it. That last element is the one insurers' oversight questions are aimed at, because it is the point where a human decided something. A run nobody approved and a run somebody approved look identical in the output and completely different in the record.
The register, and the digest on the printed copy
Alongside the per-run record sits the audit and compliance register: every piece of AI work, who authorised it, whether the checks passed, and the credits drawn. You can filter by period, matter or person, which maps directly onto the three questions above, and export as a spreadsheet or as a printable audit bundle.
That bundle carries a SHA-256 content digest computed over the exact rows exported. The digest lets you show that the copy in somebody's hand is the copy the register produced. That is the whole claim. It is not a blockchain and it is not a tamper-evident chain, and we do not describe it as one, because a smaller true claim is worth more in a regulatory conversation than a larger one that does not hold up.
The two lines only a person can write
Every record described so far is produced by the system. The part that makes it defensible is not. When a supervising solicitor signs off, two lines are worth writing in their own words: which authorities they checked personally, and which points they are relying on the run for.
Those two lines take ninety seconds and do more work than anything else on the file. They show a reader in a year's time that a qualified person applied judgement, and where. The SRA added AI-specific sections to its Effective Supervision guidance in June 2026, and its guidance update on new technology and COLP responsibility in February 2026 addresses the compliance officer's position. Both are about the same thing: the human step, evidenced.
What this does not do
A record is not a policy, and it will not tell you whether the work should have been done with AI at all. It will not tell you which practice areas are out of scope, or how long you keep any of it. Retention controls are available on the Business plan, but the retention decision is your firm's, and no register makes it for you.
The register also only knows what happened inside this product. Work done in a consumer chatbot on somebody's phone leaves no trace here or anywhere else, which is the real limit on any audit trail. And a digest is not a certification: we hold no ISO 27001, SOC 2 or Cyber Essentials today. If your insurer's proposal form asks for one, the honest answer is that we do not have it.


