AI Legal Malpractice Insurance: What LPL Carriers Now Ask About Generative AI on Renewal
The audience for this piece is not the litigating attorney. It is the risk manager, the managing partner, and the office administrator who fills out the renewal application each year. The thesis is short. The lawyers' professional liability market, the layer practitioners commonly call AI legal malpractice insurance, has begun to underwrite AI risk. The operational artifacts a firm carries between renewals (written policies, verification logs, certificates produced per filing) are increasingly material to that process.
A policy on a shelf is one thing. A contemporaneous record of compliance with the policy is another. The distinction is what this piece is about.
The underwriting cycle and emerging risks
Lawyers' professional liability is a specialty line. Carriers underwrite firms based on practice area mix, claim history, headcount, and the operational controls the firm represents on its application. Premiums move with claim frequency and severity in the book of business, and the lines on the application track the risks the carrier has begun to take seriously.
The application is a lagging indicator. A question appears on a renewal form when the carrier has seen enough claim activity, or enough adjacent risk signal, to treat the topic as material. The questions about cybersecurity controls that appeared a decade ago followed the first wave of firm-level breaches. The questions about cloud document storage followed the migration. The pattern is consistent. The application catches up to the operational reality.
Generative AI has now reached that threshold. The Mata v. Aviancasanctions order in 2023 was the first widely-reported event. The sanctions orders that followed it, across multiple federal districts, several state courts, and a handful of administrative tribunals, established a recognizable failure mode. A citation produced by a model, not checked against the reporter, filed in a brief. The carriers read those orders. The application followed.
What LPL carriers have started asking applicants about
At the category level, renewal applications across the LPL market have begun to include questions about AI use. The phrasing varies by carrier and the specific text is not the subject of this piece. The structure of the questions is consistent.
The first question is the disclosure question. Does the firm use generative AI tools in client work. The answer is yes for an increasing share of firms. The answer is not by itself a problem. The answer opens the next set of questions.
The second question is the policy question. Does the firm have a written AI policy aligned with ABA Formal Opinion 512. The policy is expected to describe which tools are permitted, what categories of work the tools may be used for, what supervision applies, and how citations and factual claims in AI-assisted output are verified before filing.
The third question is the supervision question. What protocols govern the review of AI-assisted output. The carrier is asking who reviews the work, at what stage, and against what standard. A boilerplate answer that the partner reviews everything is no longer the answer the carrier is looking for. The carrier is looking for a process.
The fourth question is the verification question. How does the firm confirm that citations in AI-assisted drafts can be located in the reporters they name. This is the question that maps most directly to the Mata fact pattern. It is also the question that has the cleanest operational answer.
Why a policy on a shelf is not enough
A firm can produce a written AI policy in an afternoon. The policy can be three pages or thirty. The policy can be uploaded to the firm intranet, attached to the renewal application, and forwarded to the carrier with a cover note. None of that proves the policy was followed on any particular filing.
A claim, when it arrives, does not arrive at the policy level. It arrives at the filing level. A specific brief, in a specific matter, contained a specific citation that was not what the brief said it was. The question the claims adjuster will ask, and the question the court will ask if it reaches that stage, is not whether the firm had a policy. The question is whether the policy was followed on that brief, on that day, by that attorney.
The answer to that question lives in the matter file. If the matter file contains a contemporaneous record of the verification step, the answer is yes and the record is the proof. If the matter file contains only the brief and the partner's recollection, the answer is whatever the partner can reconstruct under questioning. The two postures are different and the carrier knows it.
The general principle is the same one that governs every other form of risk-mitigation documentation. A representation that the firm runs conflict checks is worth less than a conflict report dated before the engagement letter. A representation that the firm verifies citations is worth less than a certificate dated before the filing under Rule 11.
The Verification Certificate as the artifact underwriters care about
A Verification Certificate is the structured record produced by a pre-filing citation check. The certificate lists the citations extracted from the draft, the verification status for each, the source records consulted, a SHA-256 hash of the certificate content, a public token URL, and the timestamp of generation. The certificate is filed in the matter file alongside the brief. See What a Verification Certificate Contains for the full anatomy.
The certificate is a per-filing artifact. The firm does not produce one certificate at renewal. The firm produces a certificate each time a brief leaves the office. Over a year, the certificates aggregate into a firm-level record of verification activity. The record is what the carrier can read, in summary or in detail, when the underwriter asks the verification question.
The aggregation matters because the carrier's question is not whether the firm verified one citation in one brief. The carrier is asking what the firm does on every filing. A record that shows certificates produced on every filing is the answer. The hash on each certificate confirms the record has not been altered. The timestamp confirms when the verification ran. The public token URL confirms the certificate can be checked by someone other than the firm.
The claim posture: with the record and without
Consider two firms that face the same claim. The claim alleges that a citation in a filed brief did not support the proposition for which it was offered, and that the attorney did not verify the citation before filing. The brief was drafted with generative AI assistance. The claim is the kind of claim that has appeared in published sanctions orders since 2023. See Anatomy of a Hallucination for the canonical fact pattern.
The first firm has a written AI policy. The policy is on the intranet. The partner remembers reviewing the brief but cannot point to a specific record of citation verification on that filing. The defense to the claim depends on reconstruction of what the partner did at the time. The reconstruction is testimony, not evidence.
The second firm has the same written policy and also has a Verification Certificate in the matter file for the brief in question. The certificate is dated before the filing. The certificate lists the citation that is now disputed and the verification status the scanner returned at the time. The certificate hash matches the public record. The defense to the claim is the certificate.
The two postures are not equivalent. The first firm has a contestable defense. The second firm has a documentary defense. The carrier prefers the documentary one, and the carrier's preference shows up in the underwriting decision.
What a firm should be ready to produce at renewal
A firm that uses generative AI in client work should expect to answer four practical questions at renewal. The first is the written policy. The firm should be able to produce the policy document, the date it was adopted, and the date it was last reviewed.
The second is the tool inventory. The firm should be able to describe which AI tools are permitted for which categories of work, and how the firm tracks that the tools in use are the tools the policy permits.
The third is the supervision protocol. The firm should be able to describe who reviews AI-assisted output, at what stage of the workflow, and against what standard. The protocol should be written, not described from memory.
The fourth is the verification record. The firm should be able to produce, on request, the contemporaneous record of citation verification for any filing the carrier asks about. The record is the artifact, not the policy. The artifact is per-filing, dated, hashed, and stable.
The first three questions are policy questions. The fourth is an operational one. The first three can be answered with a memo. The fourth cannot. The fourth is the one that turns the representation into evidence, and the fourth is the one the market has started to weigh.
Veritas runs the verification step and produces the certificate. The certificate is the per-filing artifact that accumulates into the firm-level audit trail. The trail is the answer to the fourth question. The product does not write the policy, does not supervise the associates, and does not replace the partner's judgment. The product produces the record.

