Choose your location?
  • Global Global
  • Australian flag Australia
  • Canadian flag Canada (FR)
  • French flag France
  • German flag Germany
  • Irish flag Ireland
  • Italian flag Italy
  • Polish flag Poland
  • Qatar flag Qatar
  • Spanish flag Spain
  • UAE flag UAE
  • UK flag UK

Beyond the black box: AI, accountability and professional liability

29 September 2026

As Artificial Intelligence becomes routinely used in the delivery of professional services, future claims may turn on governance, evidence, record-keeping, causation and AI maturity. Liability may depend on whether the professional's AI strategy, deployment and supervision were reasonable in the circumstances. 

As we noted in our September 2025 article ‘Professional liability risks in the age of artificial intelligence’,  AI is rapidly becoming embedded in the delivery of all professional services. Lawyers, surveyors, accountants, and financial advisers are increasingly using AI to assist with research, document review, analysis, drafting and risk management. The discussion has therefore moved beyond whether professionals should use AI or not, and towards a more difficult question: when, and under what circumstances, is AI use appropriate, and how will a professional’s liability be assessed if something goes wrong?

The UK's approach: Existing law can accommodate AI harms – but then what?

The UK Jurisdiction Taskforce's (UKJT) Legal Statement on liability for AI harms  (which was issued in July 2026) suggests that existing English common law, particularly contract and negligence principles, are largely capable of addressing harms caused by the use of AI, without the need for the creation of a new bespoke AI liability regime. The harder questions concern governance,oversight and evidence. The UKJT has noted that AI has no distinct legal personality; it cannot owe duties, assume responsibility or be sued in its own right. Instead, liability continues to attach to the people and organisations that are deploying the technology. Existing (and familiar) legal concepts such as duty of care, breach, causation and loss are considered to be capable of dealing with AI-related disputes.  That conclusion is reassuring, but it does not mean that the use of AI creates no new challenges. Rather, the complexity lies in applying established legal principles to systems that are often opaque, rapidly evolving, and are capable of influencing decision-making in ways that are difficult to fully understand, and in circumstances in which sophisticated AI systems often cannot adequately explain their reasoning. For professional indemnity insurers, brokers and professionals alike, the issue is becoming less about AI adoption and more about whether AI is being deployed, supervised and documented appropriately and reasonably.

The real question is not "Did you use AI?" but "Was your AI strategy reasonable?"

Much of the discussion surrounding AI to date has focused on its adoption. Some organisations have sought to demonstrate technological innovation and leadership, while others have feared being left behind.

The starting point in assessing negligence or breach of contract on the part of a professional organisation will be whether the organisation exercised reasonable skill and care in all the circumstances. Guidance from regulators such as the SRA, FCA and RICS may become influential evidence of reasonable practice, even where this does not create a freestanding legal duty. Further, what constitutes reasonable skill and care is not static. As AI tools become more reliable, affordable and widely adopted, professional standards may evolve alongside them.

Increasingly, courts, regulators, insurers and claimants are likely to focus less on simply whether AI was used, and more on the decisions that were taken surrounding its use. A professional negligence claim may ultimately turn not on the technology itself, but on questions such as:

  • Why was AI used?
  • Why was it not used?
  • What AI solution was selected and who approved its deployment?
  • What due diligence was undertaken as to the AI system?
  • What testing of that AI system took place?
  • What human oversight existed?
  • What records were retained?

In short, liability is likely to focus on issues of governance rather than the technology itself.

This distinction is important because clients of professionals do not simply purchase technical outputs. They also buy experience, judgement, accountability and, in many cases, reassurance. AI may improve efficiency in some areas of work, while being entirely unsuited to others. The challenge for professionals is identifying where that line should be drawn.

The emerging spectrum: When might it be negligent not to use AI?

One of the more interesting topics in discussions concerning AI and professional negligence is the possibility that future claims may arise not from the use or misuse of AI but from a failure to use it. A useful framework is to view AI applications along a spectrum of risk and acceptance set out below, taking the use of AI by legal professionals as an example.

Category One: Use of AI may become expected

The first category includes tasks that are centred on managing large volumes of information.

Examples include:

  • e-disclosure;
  • document classification;
  • Technology Assisted Review (TAR);
  • large-scale document review; and
  • information retrieval exercises.

Courts have generally appeared comfortable with the developing use of AI in these areas, provided there remains meaningful human oversight. The rationale is straightforward: AI can process vast quantities of information more quickly and efficiently than human reviewers, potentially reducing cost while improving consistency.

TAR already occupies an established position within disclosure exercises, and is specifically encouraged in the Business and Property Courts under Practice Direction 57AD of the Civil Procedure Rules. The use of AI in data-heavy tasks may become increasingly difficult to ignore.

As AI becomes accepted infrastructure for information management, it may become harder for professionals to justify not considering it as part of their workflow.

Category Two: AI may assist but not decide

The second category encompasses tasks where AI can add value but professional judgement remains central.|

Examples include:

  • legal research;
  • technical analysis;
  • drafting assistance;
  • chronology preparation;
  • issue identification; and
  • risk assessment support.

These are areas where AI may enhance efficiency and support decision-making. However, the output of any particular AI system remains only one source of information among a large number of sources of information to be considered by the professional.

This aligns with the UKJT's broader emphasis on supervision and accountability. AI is a tool which may assist a professional in exercising professional judgement but it does not remove responsibility for evaluating the work product, identifying any errors and reaching a final conclusion.

Category Three: AI may be prohibited or heavily restricted

At the opposite end of the spectrum are activities involving the preparation of witness evidence, along with aspects of professional judgement and core decision-making functions.

Recent court decisions concerning witness preparation have demonstrated judicial concern regarding the potential misuse of AI in this area. The Civil Justice Council is currently considering the use of AI in the preparation of witness statements. Witness evidence that is prepared or materially influenced by the use of AI will not reflect the witness’s own words or recollections and may risk straying beyond the witness’s personal knowledge, potentially in breach of CPR Part 32 and  Practice Directions 32 and 57AC. 

The risks are obvious. AI may influence recollection, shape evidence or effectively coach a witness. In such circumstances, courts are likely to approach the use of AI with considerable caution. 
Professionals should be wary of treating AI as a substitute for legal analysis, expert judgement or other functions requiring independent professional assessment.

The current position appears to be that courts are increasingly comfortable with AI as a tool for processing large numbers of documents, provided there is meaningful human oversight, but considerably less so where it influences evidence that is attested to by a Statement of Truth or if it replaces professional reasoning.

Governance failures may be more dangerous than technology failures

Much of the public discussion surrounding AI focuses on technological shortcomings, particularly hallucinations. However, from a professional negligence perspective, governance failures may prove far more significant.

When a loss occurs, claimants are unlikely to focus solely on whether an AI output was wrong. They are also likely to ask of the professional:

  • Why was this particular AI tool selected for this task?
  • What testing was undertaken?
  • What limitations were identified?
  • What training had users received?
  • What level of oversight was required?
  • Was the output independently verified?

Many future disputes may concern process rather than outcome.

A flawed answer generated by an appropriately selected, carefully tested and properly supervised system presents a very different liability picture from the same answer generated by an untested tool deployed without governance controls. The distinction could be critical when courts assess a firm's overall AI strategy.

The hidden risk: So called “Shadow AI”

One of the most significant AI risks facing organisations may not be approved AI systems, but those operating outside formal controls.

"Shadow AI" refers to the use of unauthorised AI tools by employees, contractors, consultants or third parties.

Information may leave organisational control unnoticed. Sensitive client data may be uploaded to external systems. Privileged material may be exposed, with attendant loss of that privilege. Crucially, when issues arise later, there may be little or no audit trail available. 

From a professional indemnity defence perspective, shadow AI raises significant risk management and governance concerns. It is no longer sufficient to ask whether an organisation has an AI policy. 

Organisations may increasingly need to demonstrate that policies are supported by training, understood by users, monitored and effectively enforced.

Causation and the “black box” problem

If duty and breach are broadly familiar concepts, causation may be the area where future AI-related professional negligence claims become most challenging, particularly due to the so-called "black box" problem. Many AI systems provide little visibility into how an output was generated. Even where reasoning is displayed, it may not fully explain how the conclusion was reached. As a result, post-loss reconstructions of what happened can be extremely difficult.  A firm's ability to preserve and retrieve AI-related evidence may become almost as important as the underlying merits of the claim itself.

Some cases will remain relatively straightforward. If a professional relies upon obviously fabricated authorities, the issue is unlikely to be the AI system itself. The issue will be the failure on the part of the professional to identify an obvious error.

More complicated claims may involve allegations that:

  • the wrong AI system was selected;
  • an alternative system would have produced a different outcome;
  • monitoring arrangements were inadequate;
  • training was insufficient; or
  • AI should have been deployed and was not.

In such cases, courts may be asked to consider what a reasonably competent professional would have done using different technology.

The “apples-to-apples” problem

  • One particularly important issue is ensuring that comparisons are fair.

    In much the same way that a professional’s conduct is assessed against the knowledge and standards of the time, a claimant cannot simply take a highly sophisticated AI model available in, say, 2032 at the time of a trial and use it to criticise decisions that were made by the defendant professional in 2026 based on a less sophisticated model.

    Any assessment must be conducted on an "apples-to-apples" basis.

    Relevant questions being posed to assess liability are likely to include:

  • What technology was available at the time?
  • What was accepted market practice?
  • What guidance existed?
  • What systems were reasonably accessible?
  • What costs would have been involved?

Future negligence claims may therefore involve extensive expert evidence concerning the capabilities of historic AI systems rather than simply evaluating current technology.

Evidence, disclosure and record keeping

The black box problem has a second consequence: evidence preservation.

Future claimants may seek disclosure of:

  • prompts;
  • outputs;
  • audit logs;
  • governance documentation;
  • testing records;
  • AI policies; and
  • deployment decisions.

This creates practical challenges.  Do records exist? Were prompts retained? Is the information held by a third-party provider? Can it still be retrieved? The ability to answer these questions may materially affect the defence of a future claim.

More fundamentally, organisations may need to be able to reconstruct and explain their decision-making process after the event. This is likely to require evidence of which AI model was used, when it was used, why it was selected, who approved its deployment, what prompts and outputs were involved, and what review or verification process followed.

In many future disputes, the organisation capable of reconstructing its decision-making process may have a substantial advantage over one that cannot.

AI maturity rather than AI usage

For insurers and risk managers, a more useful question may be shifting from:

"Do you use AI?"   to  "How mature is your AI governance framework?"

Indicators of maturity may include:

  • an AI inventory;
  • approved use cases;
  • documented policies;
  • testing protocols;
  • review processes;
  • retention practices relating to prompts;
  • training programmes;
  • incident response procedures; and
  • governance oversight.

One of the clearest indicators of where the expectations of professionals’ regulators may be heading is the RICS Standard for surveyors: Responsible use of AI in surveying practice. Although its guidance is profession-specific, its significance arguably extends beyond the surveying profession.

The RICS Standard places considerable emphasis on governance, transparency, accountability and record keeping. In particular, it requires firms to be able to explain how AI is being used, who is responsible for its deployment and what oversight mechanisms are in place.

From a professional indemnity defence perspective, what is striking is that many of these requirements align closely with the issues likely to arise in future professional negligence claims. Questions surrounding model selection, testing, accountability and audit trails are also likely to be asked by the courts, regulators and insurers after a loss.

The RICS approach may therefore provide an early indication of how other professional bodies and regulators will approach AI governance in the future: less focus on whether AI is used at all, and greater focus on whether its use can be properly justified, supervised and evidenced.

Final thoughts: The emerging standard is appropriate adoption

As AI becomes part of everyday professional practice, the greatest liability risks and significant claims may arise not because a machine made a mistake, but because organisations failed to make defensible decisions about when, where and how it should be used.

The emerging standard is unlikely to be one of blanket adoption or complete avoidance. Rather, the focus is likely to be on whether AI was deployed appropriately, supervised effectively and supported by adequate governance and evidence.

Further Reading