GET A QUOTE ONLINE 020 3883 7976

AI Is Changing Small Businesses.
Has Your Insurance Kept Up?

Artificial intelligence is no longer limited to technology companies or experimental projects.

Small businesses are using it to write emails, review documents, produce marketing materials, analyse information, take meeting notes and generate ideas.

Some are going further, using AI to develop products, improve services and change how work is delivered to customers.

FSB’s new report, The Confidence Code, found that 55% of small businesses now use AI, up from 20%.

The opportunity is clear. Small businesses that adopted AI during the previous 12 months saw an average 3% increase in revenue. FSB estimates that an extra £42 billion could be added to the UK economy each year if half of small businesses not currently using AI adopted it and existing users increased their use by 50%.

“Small businesses that adopted AI in the last 12 months saw an average resulting increase in revenue of 3%.”

But there is another side to the story.

The report also found that 92% of small businesses have concerns about AI, up from 73% in 2023. Those concerns include security, data privacy, intellectual property, inaccurate output and legal liability.

“Companies increasingly see AI not only as a powerful strategic opportunity, but also as a complex source of operational, legal, and reputational risk.”

AI may help a business work faster and grow. But it can also change the risks that business faces. The question is whether its insurance has kept pace.

The Risk May Change Before the Business Notices

A business does not need to build its own AI system for its risk profile to change.

Consider a consultancy that starts using AI to help prepare client reports.

  • A marketing agency might use it to create images, copy or campaign ideas.
  • A retailer could upload customer information to an AI tool to help analyse buying patterns.
  • An employer might use software to filter job applications or assess employee performance.
  • A software developer could add AI features to a product used by customers.

In each example, the business may still look broadly the same from the outside.

It may have the same employees, premises and clients. But the way it works has changed.

That could introduce new questions around confidentiality, data protection, professional responsibility, intellectual property, fraud and reliance on technology providers.

Looking ahead, the Association of British Insurers believes AI could reshape the wider risk landscape:

“AI-bolstered cyber threats will have radically changed the nature of the risks faced by households, communities and businesses.”

What Is Your Business Trusting AI to Do?

Zurich makes the point in relation to directors’ and officers’ insurance that:

“Whether AI risks are covered under a policy will depend on the wording.”

Not every use of AI creates the same level of risk.

Using AI to suggest ideas for a social media post is different from relying on it to produce technical advice, assess a customer or make a recommendation.

The more important the task, the greater the potential consequences if the output is wrong.

FSB’s report found that small businesses use AI for a wide range of activities, including:

  • Drafting and editing written content
  • Reviewing and summarising documents
  • Creating marketing materials
  • Generating images and videos
  • Analysing trends
  • Developing products and services
  • Supporting recruitment
  • Choosing suppliers

Many AI tools can produce confident, convincing answers even when the information is incomplete or wrong.

That does not always cause a problem. A person may notice the mistake and correct it.

However, the consequences could be more serious when inaccurate output is sent to a client, published online, used in a decision or built into a product.

The important question is not simply, “Does the business use AI?”

It is: What is the business trusting AI to do, and what could happen if it gets it wrong?

Five Insurance Questions for Businesses Using AI

1. Is Confidential Information Being Entered Into AI Tools?

Employees may use AI to summarise contracts, improve emails or review documents.

But those documents could contain customer details, employee information, commercial secrets or confidential client material. Businesses should understand what information is being entered, where it may be stored and whether the provider may use it to improve its models.

FSB found that businesses were concerned about where information shared with AI tools is stored, which legal jurisdiction applies and whether their data could be retrieved or reused. A data leak or privacy breach could lead to investigation costs, customer notification expenses, legal support and regulatory concerns.

Depending on the circumstances and policy wording, cyber insurance may help with some of the operational consequences of a data incident.

It should not, however, be treated as a replacement for sensible data controls.

2. Is AI Contributing to Professional Work?

Accountants, consultants, designers, advisers, technology firms and other professional businesses may use AI to support work delivered to clients.

AI could help research a subject, prepare a first draft or review a large amount of information. The risk comes when an unchecked answer becomes part of the final service.

If a client alleges that incorrect work, advice or designs caused them a loss, the fact that an AI tool produced the original content may not remove the business from the dispute.

Professional indemnity insurance is designed to respond to certain allegations involving professional errors, omissions or negligence.

Whether an AI-related claim would be covered would depend on the circumstances, the business activities declared to the insurer and the wording of the policy.

Businesses should be clear about where AI is used and maintain meaningful human review.

3. Is AI Creating Material That Will Be Published?

AI can produce articles, images, presentations, music, video and advertising materials in seconds. However, questions remain around how models are trained and whether generated material could resemble protected work.

FSB found that intellectual property was one of the main concerns small businesses had about AI. A business publishing AI-generated material could potentially face allegations involving copyright, trade marks, misleading content or damage to another organisation’s reputation.

Some professional indemnity, media liability or cyber policies may include relevant protection, but this varies significantly. Businesses should not assume that content is safe to use simply because an AI tool created it.

Human checks, source records and appropriate licences remain important.

4. Could AI Make Fraud More Convincing?

AI is not only being used by legitimate businesses. Criminals can use it to create convincing emails, imitate voices, alter images and produce fake videos.

“…fraudsters are increasingly using deepfake media to maintain the deception and build trust with their victims.”

  • A payment request may appear to come from a director.
  • A telephone call could sound like a trusted supplier.
  • A video meeting could feature an artificial version of a real person.

These attacks may bypass traditional checks because the message looks or sounds genuine.

Commercial crime insurance may protect certain forms of fraud. Cyber policies may also contain crime or funds-transfer extensions.

However, policies can include specific conditions relating to payment verification and internal controls. Businesses should use separate checks for payment requests, particularly when bank details change or an instruction is unusual. A familiar voice is no longer enough.

5. What Happens If an AI Provider Stops Working?

Many businesses are becoming dependent on third-party technology.

An AI platform could experience an outage, suffer a cyber incident, change its terms, restrict an account or remove an important feature.

A business may then lose access to a tool it now relies on for daily operations. Standard business interruption insurance is often linked to physical damage at insured premises. It may not automatically respond when an online platform becomes unavailable.

Some cyber and technology policies provide cover for certain interruptions involving IT systems or external service providers, but the scope and waiting periods vary. Businesses should understand which platforms are critical, keep copies of essential information and prepare a manual alternative where possible.

There Is No Single Policy Called AI Insurance

AI-related losses do not fit neatly into one category.

Depending on what happens, several types of insurance could become relevant:

  • Cyber insurance for certain data breaches, cyber incidents, system interruptions and response costs.
  • Professional indemnity insurance for certain allegations involving professional errors, omissions or negligent work.
  • Commercial crime insurance for certain fraud and funds-transfer losses.
  • Management liability insurance where directors or senior managers face certain claims arising from decisions or governance.
  • Media liability cover for certain claims involving published content, intellectual property or defamation.
  • Business interruption extensions where covered technology failures prevent the business from operating.

No policy covers every possible consequence of using AI.

The cause of the loss, how AI was being used, the information provided to the insurer and the policy’s terms, conditions and exclusions will all matter.

Good AI Governance May Also Be Good Risk Management

One of the clearest findings from The Confidence Code is that successful technology adoption depends on how it is introduced.

Businesses that involve employees, provide training and create a clear implementation plan may be better placed to gain value from technology.

Those steps may also help reduce risk.

A practical AI policy could cover:

  • Which tools employees may use
  • What information must never be entered
  • Which tasks need human approval
  • How output should be checked
  • How AI-assisted work should be recorded
  • Who is responsible when something goes wrong
  • How suspected data or security incidents should be reported

The policy does not need to be long or complicated.

Its purpose is to prevent employees from making important decisions about data, confidentiality and accuracy without guidance.

Training matters too. FSB members can also access AI Skills 4 SMBs, a free three-hour online course featuring Microsoft experts. It covers practical AI use, cybersecurity, ethics and accountability, with an official Microsoft credential available on completion.

Employees need to understand that AI output can be wrong, confidential information must be protected, and unusual payment requests should always be checked through another channel.

When Should a Business Speak to Its Broker?

Using AI to correct spelling in an internal email may not fundamentally change a business.

Using it to deliver client work, make automated decisions, process sensitive information or power a new product could be more significant.

A business should consider speaking to its broker when it:

  • Begins using AI in work delivered to clients
  • Automates an important business decision
  • Handles more personal or confidential data
  • Develops an AI-powered product or service
  • Becomes dependent on a particular technology provider
  • Changes its professional services or contractual responsibilities
  • Experiences rapid growth because of new technology

Whether a change needs to be reported immediately will depend on the policy and its terms.

However, waiting until a claim occurs is not the right time to discover that the insurer did not understand how the business operated.

Has Your Insurance Kept Pace?

AI can give a small business more time, more capability and more room to grow. It can also alter how work is produced, how information is handled and how decisions are made. Those changes may create exposures that were not considered when the business arranged its current insurance.

That does not mean businesses should avoid AI.

It means adoption should be planned, controlled and reviewed alongside the rest of the business. When technology changes how a business operates, its insurance may need to change too.

Need Help Reviewing Your Business Risks?

FSB members can speak to a UK-based adviser about their business activities and the insurance options available.

Call FSB Insurance Service on 020 3883 7976.

For a closer look at responsibility when AI-generated work causes a problem, read If AI Goes Wrong, Who’s Liable?

This content is for general information only and is not intended to provide advice or a personal recommendation. Insurance cover is subject to the terms, conditions and exclusions of the policy. Always consider your individual circumstances and seek professional advice before arranging insurance. External websites are not under our control, and we are not responsible for their content.

Related Posts