Specialist UK insurance for AI companies, SaaS vendors, technology consultancies and digital product businesses. We arrange Technology Errors & Omissions, Cyber and Media Liability cover built around the exposures software businesses actually face — model errors, SLA breaches, data incidents, IP claims and the contractual indemnities you've signed up to.
We're an insurance broker, not an insurer. Everything below describes what specialist policies are generally designed to do and what we look for when we place them — it isn't a statement of what any particular policy will cover. Cover, limits and exclusions are set by the insurer in the policy wording, and we'll go through those with you before anything is placed.
Three developments matter for how software businesses are insured right now. The regulatory timetable moved in 2026, and the insurance market has started treating AI as something to name in a policy rather than leave unsaid.
Until recently, most business policies said nothing about AI at all — neither covering it nor excluding it. That silence only gets tested when a claim arrives. Through 2026 that has started to change in both directions: some insurers are attaching AI exclusions at renewal, while a small specialist market has begun writing cover that names AI explicitly. If your business builds with AI or uses it in client work, the practical question isn't "am I insured?" — it's "what does my wording actually say about AI?" That's the first thing we check.
The EU AI Act applies to UK businesses whose AI systems or outputs touch the EU market, in the same way GDPR does — no EU entity, servers or staff required. In July 2026 the EU adopted the Digital Omnibus on AI, which pushed the heaviest obligations back by more than a year. Some duties moved; others didn't. Here's where it stands.
Obligations for standalone high-risk systems under Annex III were deferred from 2 August 2026 to 2 December 2027. AI embedded in regulated products (Annex I) moved to 2 August 2028. Preparation time, not a reprieve.
Article 50 transparency obligations — telling people they're interacting with AI, labelling synthetic content — were not deferred and applied from 2 August 2026.
The duty to ensure staff working with AI have appropriate AI literacy has applied since February 2025. Documented training is the expectation. Relevant to any consultancy using AI in client work.
Annex III includes recruitment and employment decisions, credit scoring, biometric identification, education assessment, essential services access, and risk assessment and pricing in life and health insurance.
Risk management systems, technical documentation, conformity assessment, CE marking, automatic logging, human oversight and post-market monitoring — plus reporting serious incidents to national authorities.
Up to €35m or 7% of worldwide turnover for prohibited practices; up to €15m or 3% for most other breaches. Where regulatory defence costs are insurable at all, sub-limits are common — worth checking specifically.
AI and SaaS businesses face exposures that general Professional Indemnity wordings weren't drafted around. Technology Errors & Omissions is the specialist line normally looked to, but the scope varies a lot between insurers. These are the six areas we read the wording for before recommending anything.
You build on a third-party model and a customer sues over behaviour that originated upstream. Your supplier's indemnity is usually capped — check what your own policy says about third-party model failure.
A model produces confidently wrong or discriminatory output and a client suffers loss. Particularly live where AI touches HR, credit, healthcare or legal work.
Claims that a model was trained on protected material, or that outputs infringe. An active area of UK and US litigation, and one where IP defence scope varies widely between wordings.
You miss a contractual uptime or response commitment and a customer claims business interruption losses. Service credits and damages are treated differently — the wording matters.
Customer data compromised through your platform, with ICO involvement and third-party claims following. Usually needs Cyber and Tech E&O working together rather than either alone.
A library you ship carries a vulnerability or a licensing problem. Same principle as the model above — the claim lands on you, whatever the upstream terms say.
Tech E&O, Cyber and Media Liability are the three pillars for most software businesses. D&O, IP and contractual liability scope become more important as contracts and funding get bigger.
The core line for software businesses. Designed to respond to claims of negligent technology services, defective software, integration failures and, where the wording allows, AI model errors and SLA breaches.
Data breach, ransomware, business interruption from cyber events, ICO investigation defence, and breach response support such as forensics, notification and PR.
Defamation, copyright and trade mark claims, and content licensing disputes. Increasingly relevant where AI generates published content or user content sits on your platform.
Not a separate product in most cases — it's whether hallucination, bias, model drift and third-party model failure are addressed in your Tech E&O wording, or left silent. We check this specifically.
Liability you've taken on under contract — the data protection, IP and breach indemnities in your customer agreements. Many standard wordings restrict this, which is worth knowing before you sign.
Defence costs for ICO investigations and, for regulated clients, sector regulator action. Fines are only insurable where the law permits, and sub-limits are common.
Protects directors personally against claims arising from management decisions. Usually a priority once there are outside investors or a board.
Employers' Liability is compulsory once you have employees — £5m is the legal minimum, £10m the market standard. Public Liability matters if you visit client sites or have visitors.
Defence costs and, depending on the wording, damages for intellectual property claims — a growing concern for AI businesses given current litigation over training data and outputs.
Select your business profile to see what we'd usually discuss at quotation stage
A guide to what we'd normally discuss — not a recommendation. What you actually need depends on your contracts, clients and how AI sits in your product.
A guide to what we'd normally discuss — not a recommendation. Your customer contracts are usually what drives the limits.
A guide to what we'd normally discuss — not a recommendation. If your AI touches EU credit, employment or health decisions, EU AI Act classification is worth establishing early.
A guide to what we'd normally discuss — not a recommendation. Client contract terms usually set the limit you need.
A guide to what we'd normally discuss — not a recommendation. Access to customer environments is usually the biggest driver here.
A guide to what we'd normally discuss — not a recommendation. Many general Tech E&O wordings exclude liability arising between platform users, so this one needs checking closely.
General PI and off-the-shelf cyber cover weren't drafted around third-party model dependency, SaaS contractual indemnities or AI-specific wording gaps. Reading the wording properly is the difference.
Miller & Partner Ltd, FRN 1029698 — an Appointed Representative of Gauntlet Risk Management Ltd (FRN 308081), which is authorised and regulated by the FCA.
We place technology, cyber and Tech E&O risks with specialist insurers who understand software and AI businesses.
EU AI Act timetable, the DUAA 2025 changes, and how insurers are starting to treat AI in wordings — we keep on top of it so you don't have to.
If a customer claim, an ICO notification or a contractual indemnity is triggered, we help you notify properly and deal with insurers.
Premiums for software businesses vary far too widely to publish a meaningful figure — two companies with the same turnover can be quoted very differently depending on their contracts and controls. These are the factors that move it.
If you want a number, the quickest route is a quote — but knowing what moves it means fewer surprises when it lands.
Most software businesses start with three lines. Technology Errors & Omissions is the core — it's designed to respond to claims that your technology or advice caused a client loss, covering things like software defects, integration failures and, where the wording addresses it, AI model errors. Cyber Liability deals with data breach, ransomware and ICO investigation defence. Media Liability covers defamation, copyright and content claims. Beyond that, Directors & Officers matters once you have investors, and Employers' Liability is compulsory once you have employees. The single biggest driver of the limits you need is the liability cap in your largest customer contract.
Historically most wordings said nothing about AI either way — it was covered by silence rather than by grant, which means the argument only happens at claim time. That's changing. Through 2026, some insurers have started attaching AI exclusions at renewal, while a small specialist market has begun offering cover that names AI explicitly. Neither is universal yet, so the honest answer for any individual business is: it depends entirely on your wording. If you build with AI or use it in client-facing work, ask your broker to show you what your policy says about it in writing. If nothing turns up, that's the answer — and it's worth knowing before a claim rather than after.
It can. The Act reaches beyond the EU in much the same way GDPR does — a UK business is potentially in scope if it places an AI system on the EU market or if the outputs of its AI system are used in the EU. No EU entity, servers or staff are needed. The timetable changed in July 2026: the Digital Omnibus on AI deferred obligations for standalone high-risk systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. What did not move: the Article 50 transparency duties applied from 2 August 2026, and the AI literacy duty has applied since February 2025. Penalties run up to €35m or 7% of worldwide turnover for prohibited practices, and up to €15m or 3% for most other breaches. This is a summary, not legal advice — if you think you're in scope, take proper advice on classification.
If you build your product on someone else's model and a customer sues over the result, the claim still lands on you — your customer's contract is with you, not with the model provider. Model providers' own terms typically cap what they'll indemnify, and that cap is often well below the exposure. A properly structured Tech E&O policy is normally what you'd look to in that situation, but whether it responds depends on how the wording treats third-party technology and AI specifically. This is one of the first things we check on an AI risk, alongside what your supplier terms actually promise and whether your customer contract caps line up with your cover.
Hallucination claims arise where a model states something confidently wrong and a client relies on it — incorrect analysis, fabricated references, bad guidance. Bias claims arise where an AI system produces discriminatory outcomes, which is most acute where AI touches decisions about people. In the UK, the Equality Act 2010 applies, and the Data (Use and Access) Act 2025 reformed the UK GDPR rules on automated decision-making. Some specialist Tech E&O wordings address these exposures; many don't, and it has to be looked for rather than assumed. Practically: expect to be asked at proposal stage about your AI use cases, what testing you do, and where a human reviews output. Firms who can answer those questions clearly tend to get better terms.
We don't publish premium figures for this sector, because they'd be misleading. Two businesses with identical turnover can be priced very differently depending on their customer contracts, their data, their claims history and whether AI sits anywhere near decisions about people. What we can tell you is what moves the number: contract liability caps, US exposure, the limits you need, the sensitivity of the data you hold, your claims record, and how much documented governance you can show an underwriter. The section above sets those out. For an actual figure, a quote takes a few minutes and costs nothing.
Sometimes, and it depends on the wording. SaaS contracts routinely commit to uptime and response times, with service credits as the contractual remedy. Service credits and damages for a customer's actual losses are treated differently by insurers, and many wordings restrict cover for liability assumed purely by contract. Where downtime is caused by a cyber event, Cyber Liability is usually the more relevant line, and you may also want business interruption cover for your own lost revenue. The practical step is to check your SLA commitments against your policy before you sign the next big customer contract, not after an outage.
This is an active area of litigation in the UK and US, with cases brought by publishers, authors, image rights holders and music rights holders over both training data and model outputs. Some specialist Tech E&O wordings include intellectual property defence; others exclude it or sub-limit it heavily, so it's worth confirming rather than assuming. On the risk management side, insurers respond well to documented training data provenance, licences for material you rely on, and a clear record of what your supplier terms indemnify you for. For related cover, see our cyber insurance page.
It's worth understanding, though it's a tax question rather than an insurance one. IR35 determines whether someone working through their own limited company is treated as employed for tax purposes. Since April 2021, medium and large private sector clients have been responsible for making that determination and issuing a Status Determination Statement. It doesn't change your insurance cover directly, but it does indicate how you work — and consultancy advisory work and deliverable-based project work aren't always covered by the same wording, so it's worth being clear about which you're doing. For more, see our tech contractors page.
Generally yes for the traditional exposures — a data breach is a data breach whether or not AI was involved, and ransomware affecting your systems is covered on normal terms. Where it gets less certain is AI-specific attacks: model poisoning, adversarial attacks, prompt injection, model theft. Some insurers now address these explicitly; others have started adding AI-related exclusions. Cyber underwriters are also asking more detailed questions about how AI systems are secured and who has access to them. As with everything else on this page, the answer for your business is in your wording — and if you can't find AI mentioned at all, that itself is worth raising at renewal.
Platforms carry exposures that ordinary SaaS wordings often exclude — in particular, liability arising from what your users do to each other. Add user-generated content risk (defamation, IP, harmful content), Online Safety Act obligations, and account compromise, and a general Tech E&O policy can leave real gaps. Media Liability usually becomes essential rather than optional, and platform liability needs to be looked for specifically in the Tech E&O wording. If you handle payments between users, fraud and chargeback exposure is worth a separate conversation.
The things that consistently help: a security certification an underwriter recognises, such as Cyber Essentials Plus, ISO 27001 or SOC 2; written AI governance showing how models are selected, tested and overseen and where humans review output; negotiating sensible liability caps into customer contracts rather than accepting uncapped exposure; a documented and tested incident response plan; and a complete, well-presented proposal form, because underwriters price uncertainty. None of these are quick wins on their own, but together they change the conversation — and the governance documentation is increasingly what separates a quote from a decline on AI risks.
General information, not advice. This page describes the types of cover we arrange. It is not personalised advice, a personal recommendation or an offer of cover, and it does not take account of your own circumstances. Cover is subject to insurer acceptance, underwriting criteria and the full terms, conditions, limits and exclusions of the policy issued. Any figures shown are illustrative and are not quotations. Our full regulatory status and complaints information are set out in the footer of every page.
Ready to protect your business?
Get expert advice and a tailored commercial insurance quote today.
✔ Independent broker
✔ Access to leading UK insurers
✔ Fast turnaround
Let us review your current insurance and see if we can improve your cover while reducing the cost.
Thanks for requesting your free review. We'll be in touch shortly.
We're an Appointed Representative of Gauntlet Risk Management Ltd, which is authorised and regulated by the FCA. You can check our entry on the FCA Register.
Hey, I'm John!
I started Miller & Partner with the aim to bring back personable, approachable broking to UK businesses who were tired of large corporate brokers and feeling like they were just another number.
I have built this brokerage up with no pushy sales techniques or big business tactics, just honest, approachable and professional relationships with my clients.
Over 13 years experience in business insurance
Client first approach
5* rated broker on Google
Office: Vivian House, Roman Bridge Close, Mumbles, Swansea, SA3 5BG
Call 01792 001350
Email: [email protected]

Instagram
LinkedIn