Automated decisions in a broker inbox: what changed for UK brokerages in February 2026
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
Your brokerage runs AI-assisted replies. What MIPRU 3.2 obliges you to hold, and what the Insurance Act 2015 duty of fair presentation means at renewal.
Every brokerage in the UK and Ireland buys professional indemnity cover, and plenty of them place it for other professions as well. That gives you an advantage on this question: you already know what a proposal form is for, what a duty of disclosure does, and how badly a claim goes when the risk that materialised was never presented. Which makes it odd that so many firms have switched AI-assisted replies on in their client inbox without ever mentioning it to their own PI insurer.
This is not an argument about whether brokers should use AI. They already do. It is about the day a client says the message they received about their cover was wrong, and about whether the firm that sent it can point to a policy that responds and a file that defends.
The FCA has been unusually direct. On its AI and the FCA: our approach page the regulator states that it does not plan to introduce extra regulations for AI, and points instead at frameworks that already bind you: the Consumer Duty for outcomes, the Senior Managers and Certification Regime for accountability, and the Handbook's governance and record-keeping requirements for the rest.
Read that as a liability statement rather than a policy announcement and it stops being reassuring. There is no AI carve-out, no softened standard of care for a sentence a model produced, and no regime in which "the tool got it wrong" is an answer. An inaccurate statement about cover is an inaccurate statement about cover: it lands in negligence, in the Duty and in your PI tower, in that order. The governance side of this we have already covered in the Consumer Duty checklist for AI-assisted replies. What follows is the insurance sitting behind it.
MIPRU 3.2 requires an authorised intermediary to take out and maintain professional indemnity insurance covering the conduct of the firm, its employees and its appointed representatives. The minimum limits are expressed in euros — and a detail that catches out groups running a UK firm alongside an Irish, Dutch or German entity is that the UK and EU floors have not moved together since 2024.
| Minimum limit of indemnity | UK — MIPRU 3.2.7R | EU — IDD as amended by Regulation (EU) 2024/896 |
|---|---|---|
| Each claim | EUR 1,300,380 | EUR 1,564,610 |
| Aggregate per year | The higher of EUR 1,924,560 or 10% of annual income, capped at GBP 30 million | EUR 2,315,610 |
| Current figures apply from | Uplifted by the FCA in 2021, unchanged since | 9 October 2024 |
The excess is constrained too: a firm that does not hold client money may not carry an excess above the higher of GBP 2,500 or 1.5% of annual income, and a firm that does hold client money is capped at the higher of GBP 5,000 or 3%, unless it holds additional capital. More importantly, these are regulatory floors rather than a view on your exposure. Nothing in MIPRU knows how many clients you message each month, what you tell them, or who — or what — wrote the first draft.
When you buy your PI you are the insured, not the intermediary, and the Insurance Act 2015 duty of fair presentation applies to you exactly as it applies to the commercial clients you advise. The Act requires disclosure of every material circumstance you know or ought to know, or enough to put a prudent insurer on notice that it should ask more. The "ought to know" limb imports a reasonable search of information available to you, which includes what your own operations team switched on last quarter. Remedies are proportionate rather than all-or-nothing, but avoidance stays on the table for a deliberate or reckless breach.
So ask the question honestly: has the way your firm produces client communications changed since the last renewal? If a model now drafts replies, classifies inbound messages by sentiment or urgency, or answers anything without a person reading it first, the answer is yes. That is a change in process, supervision and error profile, not a change of stationery. We have written about walking a commercial client through fair presentation over WhatsApp; this is the same duty pointed back at your own firm. Put it in the presentation rather than waiting for a question on a shortened proposal form, because the absence of a question is not the absence of materiality.
None of these has a universal answer — intermediary PI wordings differ far more than the market usually admits. The point is to get the answers in writing before a claim rather than after one.
Wordings matter on the day. Records matter on every day before it. Defending a negligence allegation about a message calls for the same evidence as an FCA file review or a Financial Ombudsman case: what was sent, when, to whom, and by whom. With a model in the chain there is one addition — the difference between what it proposed and what the firm actually sent, plus the identity of the person who approved that. If your inbox cannot show it, your defence is a recollection.
Which is why the architecture matters more than the model. In ORIS a drafted reply is held for a named human unless a rule explicitly permits an automatic answer, negative sentiment always escalates to a person instead of being answered, and the audit log records the sequence: what was suggested, who approved it, what went out, and when a client opted out. The archiving expectations under SYSC 9 and ICOBS do not soften because a model is involved — they simply become impossible to meet when conversations live on personal handsets. To see what that evidence trail looks like against your own book, book a demo.
No rule names AI, but the Insurance Act 2015 duty of fair presentation covers every material circumstance you know or ought to know. A change in how client communications are produced and supervised is the kind of thing a prudent underwriter of a broker PI risk would want to weigh, so the safe course is to disclose it and let the insurer decide whether it is material rather than making that call yourself.
MIPRU 3.2.7R sets a floor, not an adequate limit. A firm sending large volumes of servicing messages is exposed to the same error repeating across many clients, which is a different shape of claim from a single misplaced risk. Discuss aggregation wording and reinstatement with your broker instead of renewing at the regulatory minimum by default.
Your contract with a supplier is a separate matter from your liability to your client, and recovery from a supplier is rarely quick or complete. The claim is against the authorised firm whose name was on the message. Treat vendor terms as a possible recovery, never as a substitute for cover.
The floors differ: the UK figures in MIPRU 3.2.7R were last uplifted in 2021, while the IDD amounts rose with effect from 9 October 2024. One tower can satisfy both, but only if the limits meet the higher requirement and the policy responds in the territory where each regulated entity operates. Ask for that confirmation in writing before renewal.
It changes the evidence, and the evidence is what determines how a claim runs. A file showing the draft, the reviewer and the version that was sent supports an argument that the firm exercised reasonable skill and care. An outbound message with no identifiable author supports nothing at all.
Shared WhatsApp inbox, client records, follow-ups and opportunities for the whole brokerage. 15-minute demo.
On 5 February 2026 the UK replaced Article 22 with Articles 22A to 22D. What a brokerage running AI replies, risk scores and lifecycle triggers must now show.
EIOPA's opinion on AI governance covers intermediaries, not only insurers. What its six areas ask of a brokerage running AI in a shared WhatsApp inbox.
Article 35 does not care that your AI only drafts replies. The screening test a brokerage should run before switching it on, and what to write down after.