FS Register FRN 1029698

5* rated broker on Google

13+ years specialist broking experience

UK Specialist AI, SaaS & Tech Insurance Broker

AI, SaaS & Tech Business Insurance UK — Specialist Cover for AI Companies, SaaS Vendors & Tech Consultancies

Specialist UK insurance for AI companies, SaaS vendors, technology consultancies and digital product businesses. We arrange Technology Errors & Omissions, Cyber and Media Liability cover built around the exposures software businesses actually face — model errors, SLA breaches, data incidents, IP claims and the contractual indemnities you've signed up to.

AI, SaaS & tech specialist Independent commercial broker 13+ years' broking experience We read the wording, not just the price
How to read this page

We're an insurance broker, not an insurer. Everything below describes what specialist policies are generally designed to do and what we look for when we place them — it isn't a statement of what any particular policy will cover. Cover, limits and exclusions are set by the insurer in the policy wording, and we'll go through those with you before anything is placed.

We arrange cover for
AI startups & foundation model wrappers AI consultancies B2B SaaS vendors B2C SaaS platforms PaaS / IaaS providers FinTech HealthTech LegalTech EdTech PropTech MarTech & AdTech RegTech DevOps & managed services App developers ML engineers Data scientists & analysts IT consultants Marketplaces

What's actually changed for AI and SaaS businesses

Three developments matter for how software businesses are insured right now. The regulatory timetable moved in 2026, and the insurance market has started treating AI as something to name in a policy rather than leave unsaid.

EU AI Act deadlines moved The heaviest high-risk obligations were deferred in July 2026 — but transparency and AI literacy duties still apply now
AI is being named in wordings Insurers are moving away from silence — some adding AI exclusions at renewal, others offering explicit AI cover
DUAA 2025 The Data (Use and Access) Act 2025 reformed UK GDPR rules on automated decision-making
Silent AI: the question we ask on every renewal

Until recently, most business policies said nothing about AI at all — neither covering it nor excluding it. That silence only gets tested when a claim arrives. Through 2026 that has started to change in both directions: some insurers are attaching AI exclusions at renewal, while a small specialist market has begun writing cover that names AI explicitly. If your business builds with AI or uses it in client work, the practical question isn't "am I insured?" — it's "what does my wording actually say about AI?" That's the first thing we check.

EU AI Act — the 2026 timetable, corrected

The EU AI Act still reaches UK SaaS & AI businesses — but the deadlines have moved

The EU AI Act applies to UK businesses whose AI systems or outputs touch the EU market, in the same way GDPR does — no EU entity, servers or staff required. In July 2026 the EU adopted the Digital Omnibus on AI, which pushed the heaviest obligations back by more than a year. Some duties moved; others didn't. Here's where it stands.

High-risk obligations: now December 2027

Obligations for standalone high-risk systems under Annex III were deferred from 2 August 2026 to 2 December 2027. AI embedded in regulated products (Annex I) moved to 2 August 2028. Preparation time, not a reprieve.

Transparency duties: unchanged

Article 50 transparency obligations — telling people they're interacting with AI, labelling synthetic content — were not deferred and applied from 2 August 2026.

AI literacy: already in force

The duty to ensure staff working with AI have appropriate AI literacy has applied since February 2025. Documented training is the expectation. Relevant to any consultancy using AI in client work.

What "high-risk" covers

Annex III includes recruitment and employment decisions, credit scoring, biometric identification, education assessment, essential services access, and risk assessment and pricing in life and health insurance.

What high-risk status brings

Risk management systems, technical documentation, conformity assessment, CE marking, automatic logging, human oversight and post-market monitoring — plus reporting serious incidents to national authorities.

Penalties

Up to €35m or 7% of worldwide turnover for prohibited practices; up to €15m or 3% for most other breaches. Where regulatory defence costs are insurable at all, sub-limits are common — worth checking specifically.

Where AI & SaaS claims actually come from

Tech E&O — the six exposures we check the wording for

AI and SaaS businesses face exposures that general Professional Indemnity wordings weren't drafted around. Technology Errors & Omissions is the specialist line normally looked to, but the scope varies a lot between insurers. These are the six areas we read the wording for before recommending anything.

Model

Foundation model dependency

You build on a third-party model and a customer sues over behaviour that originated upstream. Your supplier's indemnity is usually capped — check what your own policy says about third-party model failure.

Output

Hallucination & bias

A model produces confidently wrong or discriminatory output and a client suffers loss. Particularly live where AI touches HR, credit, healthcare or legal work.

IP

Training data & copyright

Claims that a model was trained on protected material, or that outputs infringe. An active area of UK and US litigation, and one where IP defence scope varies widely between wordings.

SaaS

SLA breach & downtime

You miss a contractual uptime or response commitment and a customer claims business interruption losses. Service credits and damages are treated differently — the wording matters.

Data

Data breach & regulatory

Customer data compromised through your platform, with ICO involvement and third-party claims following. Usually needs Cyber and Tech E&O working together rather than either alone.

Code

Open-source & dependencies

A library you ship carries a vulnerability or a licensing problem. Same principle as the model above — the claim lands on you, whatever the upstream terms say.

What AI & tech business insurance usually includes

Tech E&O, Cyber and Media Liability are the three pillars for most software businesses. D&O, IP and contractual liability scope become more important as contracts and funding get bigger.

⚙️

Technology Errors & Omissions

The core line for software businesses. Designed to respond to claims of negligent technology services, defective software, integration failures and, where the wording allows, AI model errors and SLA breaches.

🔒

Cyber Liability

Data breach, ransomware, business interruption from cyber events, ICO investigation defence, and breach response support such as forensics, notification and PR.

📰

Media Liability

Defamation, copyright and trade mark claims, and content licensing disputes. Increasingly relevant where AI generates published content or user content sits on your platform.

🤖

AI scope within the wording

Not a separate product in most cases — it's whether hallucination, bias, model drift and third-party model failure are addressed in your Tech E&O wording, or left silent. We check this specifically.

📋

Contractual liability scope

Liability you've taken on under contract — the data protection, IP and breach indemnities in your customer agreements. Many standard wordings restrict this, which is worth knowing before you sign.

🏛️

Regulatory defence

Defence costs for ICO investigations and, for regulated clients, sector regulator action. Fines are only insurable where the law permits, and sub-limits are common.

💼

Directors & Officers

Protects directors personally against claims arising from management decisions. Usually a priority once there are outside investors or a board.

🛡️

Employers' & Public Liability

Employers' Liability is compulsory once you have employees — £5m is the legal minimum, £10m the market standard. Public Liability matters if you visit client sites or have visitors.

🔬

IP infringement defence

Defence costs and, depending on the wording, damages for intellectual property claims — a growing concern for AI businesses given current litigation over training data and outputs.

What cover typically comes up for your type of business?

Select your business profile to see what we'd usually discuss at quotation stage

AI startup / foundation model wrapper

  • Usually first Tech E&O with AI scope addressed in the wording
  • Usually first Third-party model failure — check how the wording treats it
  • Usually first IP infringement defence, given training-data litigation
  • Often included Cyber Liability
  • Often included Media Liability where AI output is published
  • Often included D&O once there are outside investors
  • Required by law Employers' Liability if you have employees

A guide to what we'd normally discuss — not a recommendation. What you actually need depends on your contracts, clients and how AI sits in your product.

B2B SaaS vendor

  • Usually first Tech E&O with limits set against your largest customer liability cap
  • Usually first SLA breach and contractual liability scope
  • Usually first Cyber Liability covering customer data held on your platform
  • Often included ICO investigation defence
  • Often included D&O for funded structures
  • Consider Media Liability if you host user-generated content
  • Required by law Employers' Liability if you have employees

A guide to what we'd normally discuss — not a recommendation. Your customer contracts are usually what drives the limits.

FinTech / HealthTech / LegalTech

  • Usually first Tech E&O at higher limits — these sectors attract closer underwriting scrutiny
  • Usually first Cyber Liability sized to the data you hold
  • Usually first Regulatory defence scope for your sector regulator
  • Often included Contractual liability scope
  • Often included D&O
  • Consider Crime / fraud cover where you handle client money
  • Required by law Employers' Liability if you have employees

A guide to what we'd normally discuss — not a recommendation. If your AI touches EU credit, employment or health decisions, EU AI Act classification is worth establishing early.

AI / tech consultancy

  • Usually first Tech E&O and PI matched to your client contracts
  • Usually first Advisory scope — model selection, deployment and governance advice
  • Often included Cyber Liability
  • Often included Public Liability if you attend client sites
  • Often included Contract review before accepting uncapped liability
  • Consider Media Liability if you publish or deliver training content
  • Required by law Employers' Liability if you have employees

A guide to what we'd normally discuss — not a recommendation. Client contract terms usually set the limit you need.

DevOps / managed services

  • Usually first Tech E&O covering configuration and deployment error
  • Usually first Cyber Liability, including customer data you administer
  • Usually first SLA breach and contractual liability scope
  • Often included Public Liability
  • Consider Equipment cover if you hold hardware or have a datacentre presence
  • Required by law Employers' Liability if you have employees

A guide to what we'd normally discuss — not a recommendation. Access to customer environments is usually the biggest driver here.

Marketplace / platform

  • Usually first Tech E&O — check whether platform liability is included or excluded
  • Usually first Media Liability for user-generated content
  • Usually first Cyber Liability including account compromise
  • Often included Contractual liability scope
  • Often included Online Safety Act obligations reflected in your risk information
  • Consider Payment fraud and chargeback cover for transactional platforms
  • Required by law Employers' Liability if you have employees

A guide to what we'd normally discuss — not a recommendation. Many general Tech E&O wordings exclude liability arising between platform users, so this one needs checking closely.

Why choose Miller & Partner for AI, SaaS & tech insurance?

General PI and off-the-shelf cyber cover weren't drafted around third-party model dependency, SaaS contractual indemnities or AI-specific wording gaps. Reading the wording properly is the difference.

📋

On the FCA Register

Miller & Partner Ltd, FRN 1029698 — an Appointed Representative of Gauntlet Risk Management Ltd (FRN 308081), which is authorised and regulated by the FCA.

🌐

Specialist markets

We place technology, cyber and Tech E&O risks with specialist insurers who understand software and AI businesses.

🧠

We follow the detail

EU AI Act timetable, the DUAA 2025 changes, and how insurers are starting to treat AI in wordings — we keep on top of it so you don't have to.

Claims support

If a customer claim, an ICO notification or a contractual indemnity is triggered, we help you notify properly and deal with insurers.

What drives the price of AI & tech insurance

Premiums for software businesses vary far too widely to publish a meaningful figure — two companies with the same turnover can be quoted very differently depending on their contracts and controls. These are the factors that move it.

The factors underwriters actually price on

If you want a number, the quickest route is a quote — but knowing what moves it means fewer surprises when it lands.

Pushes the price up

  • Uncapped or high liability caps in your customer contracts
  • US customers or US-facing services, because of defence costs
  • AI used in decisions about people — hiring, credit, health, legal
  • Large volumes of personal or special category data
  • Previous claims, incidents or notifications
  • No documented security or AI governance to show

Helps your case

  • Cyber Essentials, Cyber Essentials Plus, ISO 27001 or SOC 2
  • Written AI governance — how models are chosen, tested and overseen
  • Documented human review of AI output before it reaches clients
  • Sensible liability caps negotiated into customer contracts
  • A tested incident response plan
  • A clear, complete proposal form — underwriters price uncertainty

Frequently asked questions

Most software businesses start with three lines. Technology Errors & Omissions is the core — it's designed to respond to claims that your technology or advice caused a client loss, covering things like software defects, integration failures and, where the wording addresses it, AI model errors. Cyber Liability deals with data breach, ransomware and ICO investigation defence. Media Liability covers defamation, copyright and content claims. Beyond that, Directors & Officers matters once you have investors, and Employers' Liability is compulsory once you have employees. The single biggest driver of the limits you need is the liability cap in your largest customer contract.

Historically most wordings said nothing about AI either way — it was covered by silence rather than by grant, which means the argument only happens at claim time. That's changing. Through 2026, some insurers have started attaching AI exclusions at renewal, while a small specialist market has begun offering cover that names AI explicitly. Neither is universal yet, so the honest answer for any individual business is: it depends entirely on your wording. If you build with AI or use it in client-facing work, ask your broker to show you what your policy says about it in writing. If nothing turns up, that's the answer — and it's worth knowing before a claim rather than after.

It can. The Act reaches beyond the EU in much the same way GDPR does — a UK business is potentially in scope if it places an AI system on the EU market or if the outputs of its AI system are used in the EU. No EU entity, servers or staff are needed. The timetable changed in July 2026: the Digital Omnibus on AI deferred obligations for standalone high-risk systems from 2 August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 2028. What did not move: the Article 50 transparency duties applied from 2 August 2026, and the AI literacy duty has applied since February 2025. Penalties run up to €35m or 7% of worldwide turnover for prohibited practices, and up to €15m or 3% for most other breaches. This is a summary, not legal advice — if you think you're in scope, take proper advice on classification.

If you build your product on someone else's model and a customer sues over the result, the claim still lands on you — your customer's contract is with you, not with the model provider. Model providers' own terms typically cap what they'll indemnify, and that cap is often well below the exposure. A properly structured Tech E&O policy is normally what you'd look to in that situation, but whether it responds depends on how the wording treats third-party technology and AI specifically. This is one of the first things we check on an AI risk, alongside what your supplier terms actually promise and whether your customer contract caps line up with your cover.

Hallucination claims arise where a model states something confidently wrong and a client relies on it — incorrect analysis, fabricated references, bad guidance. Bias claims arise where an AI system produces discriminatory outcomes, which is most acute where AI touches decisions about people. In the UK, the Equality Act 2010 applies, and the Data (Use and Access) Act 2025 reformed the UK GDPR rules on automated decision-making. Some specialist Tech E&O wordings address these exposures; many don't, and it has to be looked for rather than assumed. Practically: expect to be asked at proposal stage about your AI use cases, what testing you do, and where a human reviews output. Firms who can answer those questions clearly tend to get better terms.

We don't publish premium figures for this sector, because they'd be misleading. Two businesses with identical turnover can be priced very differently depending on their customer contracts, their data, their claims history and whether AI sits anywhere near decisions about people. What we can tell you is what moves the number: contract liability caps, US exposure, the limits you need, the sensitivity of the data you hold, your claims record, and how much documented governance you can show an underwriter. The section above sets those out. For an actual figure, a quote takes a few minutes and costs nothing.

Sometimes, and it depends on the wording. SaaS contracts routinely commit to uptime and response times, with service credits as the contractual remedy. Service credits and damages for a customer's actual losses are treated differently by insurers, and many wordings restrict cover for liability assumed purely by contract. Where downtime is caused by a cyber event, Cyber Liability is usually the more relevant line, and you may also want business interruption cover for your own lost revenue. The practical step is to check your SLA commitments against your policy before you sign the next big customer contract, not after an outage.

This is an active area of litigation in the UK and US, with cases brought by publishers, authors, image rights holders and music rights holders over both training data and model outputs. Some specialist Tech E&O wordings include intellectual property defence; others exclude it or sub-limit it heavily, so it's worth confirming rather than assuming. On the risk management side, insurers respond well to documented training data provenance, licences for material you rely on, and a clear record of what your supplier terms indemnify you for. For related cover, see our cyber insurance page.

It's worth understanding, though it's a tax question rather than an insurance one. IR35 determines whether someone working through their own limited company is treated as employed for tax purposes. Since April 2021, medium and large private sector clients have been responsible for making that determination and issuing a Status Determination Statement. It doesn't change your insurance cover directly, but it does indicate how you work — and consultancy advisory work and deliverable-based project work aren't always covered by the same wording, so it's worth being clear about which you're doing. For more, see our tech contractors page.

Generally yes for the traditional exposures — a data breach is a data breach whether or not AI was involved, and ransomware affecting your systems is covered on normal terms. Where it gets less certain is AI-specific attacks: model poisoning, adversarial attacks, prompt injection, model theft. Some insurers now address these explicitly; others have started adding AI-related exclusions. Cyber underwriters are also asking more detailed questions about how AI systems are secured and who has access to them. As with everything else on this page, the answer for your business is in your wording — and if you can't find AI mentioned at all, that itself is worth raising at renewal.

Platforms carry exposures that ordinary SaaS wordings often exclude — in particular, liability arising from what your users do to each other. Add user-generated content risk (defamation, IP, harmful content), Online Safety Act obligations, and account compromise, and a general Tech E&O policy can leave real gaps. Media Liability usually becomes essential rather than optional, and platform liability needs to be looked for specifically in the Tech E&O wording. If you handle payments between users, fraud and chargeback exposure is worth a separate conversation.

The things that consistently help: a security certification an underwriter recognises, such as Cyber Essentials Plus, ISO 27001 or SOC 2; written AI governance showing how models are selected, tested and overseen and where humans review output; negotiating sensible liability caps into customer contracts rather than accepting uncapped exposure; a documented and tested incident response plan; and a complete, well-presented proposal form, because underwriters price uncertainty. None of these are quick wins on their own, but together they change the conversation — and the governance documentation is increasingly what separates a quote from a decline on AI risks.

General information, not advice. This page describes the types of cover we arrange. It is not personalised advice, a personal recommendation or an offer of cover, and it does not take account of your own circumstances. Cover is subject to insurer acceptance, underwriting criteria and the full terms, conditions, limits and exclusions of the policy issued. Any figures shown are illustrative and are not quotations. Our full regulatory status and complaints information are set out in the footer of every page.

Ready to protect your business?
Get expert advice and a tailored commercial insurance quote today.

✔ Independent broker
✔ Access to leading UK insurers
✔ Fast turnaround

[[email protected]]
[Call 01792 001350]

Exclusive Offer

Free Insurance Review
& Zero Broker Fee

Let us review your current insurance and see if we can improve your cover while reducing the cost.

Free no-obligation insurance review tailored to your business
£
Zero broker fee on all new policies
Fast response from a real insurance specialist

You're in 🎉

Thanks for requesting your free review. We'll be in touch shortly.

🔒 No spam, ever. Your details are safe with us.

Check out our AI and Tech Article Hub

Check out our latest AI and Tech Articles

Game Development Business Insurance Guide 2026

Insurance For Experimental Technology Companies UK: 2026 Guide

We're an Appointed Representative of Gauntlet Risk Management Ltd, which is authorised and regulated by the FCA. You can check our entry on the FCA Register.

MEET THE Director

Hey, I'm John!

I started Miller & Partner with the aim to bring back personable, approachable broking to UK businesses who were tired of large corporate brokers and feeling like they were just another number.

I have built this brokerage up with no pushy sales techniques or big business tactics, just honest, approachable and professional relationships with my clients.

Over 13 years experience in business insurance

Client first approach

5* rated broker on Google

Office: Vivian House, Roman Bridge Close, Mumbles, Swansea, SA3 5BG

Miller & Partner Ltd is an Appointed Representative of Gauntlet Risk Management Ltd, which is authorised and regulated by the Financial Conduct Authority (FRN 308081). Miller & Partner Ltd is entered on the Financial Services Register under firm reference number 1029698. You may check this on the Financial Services Register by visiting the FCA website at https://www.fca.org.uk/firms/financial-services-register or by contacting the FCA on 0800 111 6768. Miller & Partner Ltd is registered in England & Wales, company number 16206282. Registered office: 20 Vivian House, Roman Bridge Close, Swansea, SA3 5BG.