Treadstone Associates
Ask an Expert · 3 min read

Do professional insurers ask about AI use?

AI use isn’t invisible to a liability policy — it just isn’t a separate question yet.

Treadstone Associates · Updated 2026

Short answer

No Canadian source located for this page states that professional-liability insurers specifically ask about AI use on an application. That doesn’t make AI invisible to a policy: it’s underwritten the same way any technology or vendor risk already is, through your existing duty to disclose material changes in how you handle client information and files.

Where AI risk actually shows up in coverage

Cyber liability insurance exists precisely for the costs that follow when client data goes somewhere it shouldn’t — the cost of investigating a breach, legally required notification, legal costs, and sometimes business interruption, as one existing-law explainer on the topic puts it, describing the coverage in general terms that predate generative AI entirely. An AI tool that mishandles or leaks a client’s information triggers the same claim a misconfigured server or a phished inbox would.

Canada’s Cyber Centre frames the everyday version of this risk plainly: people using generative AI tools can “unknowingly provide sensitive corporate data or personally identifiable information (PII) in their AI queries and prompts” without realising it — and once that information is out, the underlying incident is a data-handling failure, not an “AI failure” as such.

The disclosure question, reasoned by analogy

Canada has no stated rule requiring a professional to tell an insurer about routine AI use. The closest reasoned framework in the record was built for a different audience — the Law Society of Ontario’s four-factor test on whether to disclose Gen AI use to a client, discussed here — and it applies to an insurer only by the same kind of reasoning: does the use create a risk the other party would reasonably want to know about.

What would actually cause a problem

Not the tool. A breach traced to a client file being fed carelessly into an ungoverned AI service is indistinguishable, from the insurer’s point of view, from any other failure to safeguard information under PIPEDA — the accountability question discussed in the accountant question above applies here identically.

Where this goes next

Whether a firm’s AI use creates exposure worth disclosing is precisely what a diligence review is built to surface.