Do solicitors need a new type of insurance to protect themselves from missteps caused by AI tools?
Should law firms using agentic AI consider taking out specialist insurance in the light of the evolution of the AI-native law firm and a ‘new kind of security incident’ involving rogue AI agents?

A succinct LinkedIn post from tech analyst Benedict Evans last week follows the impact of legal tech on the profession over 40 years:
- 1985: PC-native law firm
- 2005: internet-native law firm
- 2025: AI-native law firm
This shows that legal AI is front of mind for high-profile tech commentators. It also outlines how law firm models have evolved in line with popular technology. But applying GenAI to legal is not a straightforward matter of switching devices or platforms, such as the shift from working on a PC to working online. The AI-native firm is a new legal business model from the ground up.
AI-native evolution
AI-native law firms are built on proprietary AI and agentic processes, and operate differently from conventional law firms. They either operate fixed pricing or utilise an onboarding process that automatically generates a quote. Client intake is an online process, and legal work is completed by [agentic] AI before being reviewed and signed off by a lawyer. Reviews and feedback are used to improve the model’s performance, although for regulatory purposes there must be a human in the loop.
While Evans correctly identified AI-native firms as this year’s model, they are still a long way from becoming the default. Matt Pollins, co-founder of legal tech company Lupl and Vibecode.law, an open-source platform for legal vibe-coding, curates a directory of AI-native law firms (regulated legal services providers) which currently has 58 listings. While numbers are increasing, regional distribution is skewed. Three-quarters of all AI-native firms operate in the US (59%) and the UK (16%), and a few key practice areas dominate.
Pollins defines AI-native firms as designed around AI – distinct from being augmented by AI. They include at least some of these characteristics: ‘Pricing, intake, delivery and team structure are all built with AI execution as the foundation. These firms tend to offer fixed or subscription-based fees, automated intake and systemic AI-first workflows.’
Gus Neate is co-founder and CEO of Claren, an AI contract assistant for in-house legal teams. He commented on LinkedIn that while some AI-native firms have raised significant venture capital funding, their key factor was pricing. This is notoriously difficult for AI models because AI-native firms and their investors were betting on ‘legal work priced like software, not hours’. Neate was clearly referring to software that operates consumption-based pricing in the same way as frontier AI models. Legal AI vendors, including Harvey and Legora, are starting to do this rather than SaaS (software as a service), which is usually priced per user/seat.
A major advantage of AI-native firms, in addition to the ability to fully leverage AI efficiencies, is the ability to adapt quickly to new tech and market developments.

Insuring AI agents
'I’ve always understood the main appeal of AI-native services to be that they provide the best of both worlds: the efficiency and cost savings of AI combined with the judgement and accountability of experienced professionals'
Jake Sendar, Walton
Last week, AI-native firm Crosby, which automates and accelerates commercial contract negotiation and review for fast-growing tech companies, announced that it was looking to buy professional liability insurance for its AI agents to enable them to ‘do autonomous legal work’. Co-founder and CEO Ryan Daniels wrote on LinkedIn: ‘Today, our lawyers review every single work output. As agents have improved in leaps over the last few months, it’s become clear this won’t be necessary in the future.’
This suggests replacing lawyer-supervised AI with insured, unsupervised AI output, which wouldn’t meet professional and regulatory requirements for providing legal advice. As Jake Sendar, founder of Walton, an AI system for autonomous legal transactions, observed, making this the end game would reduce the AI-native firm to selling software with insurance. ‘I’ve always understood the main appeal of AI-native services to be that they provide the best of both worlds: the efficiency and cost savings of AI combined with the judgement and accountability of experienced professionals,’ he wrote on LinkedIn. ‘But for that last part to be true, there must be some core human element that remains essential to delivering the services. What Crosby’s saying is actually, not really.’

Should law firms consider specialist insurance, both for their own AI agents and to manage risks from third-party agentic AI operating with limited human oversight? Research by the Artificial Intelligence Underwriting Company (AIUC), which certifies and insures AI agents, calls for dedicated AI cover, common technical standards and clearer policy language to reduce the likelihood of disputes over AI liability risks. Shortly after the report was published, new cybersecurity risks emerged from breaches inadvertently caused by frontier AI models.
Transfer news
On 20 July, final approval was granted for Anthropic’s $1.5bn settlement of a class-action copyright lawsuit by publishers and authors whose works had been illegally downloaded and stored. This brought media attention back to Anthropic’s Project Panama, which involved the company buying second-hand books, slicing them up and scanning their pages to train AI models. While this brings to mind Ray Bradbury’s 1953 dystopian novel Fahrenheit 451, or even a chapter of Burning the Books, Richard Ovenden’s 2020 history of the deliberate destruction of knowledge, both of these works are about preventing people accessing knowledge. Anthropic’s project was about knowledge transfer, buying second-hand books (which are generally still in circulation) and redeploying them as training material for a large language model. Destroying the material rather than redistributing it avoids copyright claims. I wonder whether we will soon hear about a legal LLM ingesting law books and case law so that it can learn to generate legal advice?
Combatting rogue elements
In July, both OpenAI and Anthropic reported ‘a new kind of security incident’. Powerful AI models escaped secure testing environments, accessed the internet and hacked into other organisations. During an internal evaluation of their cyber capabilities, two OpenAI models, GPT-5.6 Sol and another prototype model, used stolen credentials to access AI research platform Hugging Face to obtain test solutions from its database (to achieve the goal set by their evaluation). Fortunately, Hugging Face’s own AI agents detected and contained the breach.
Following OpenAI’s disclosure of the Hugging Face breach, Anthropic reviewed its own cybersecurity evaluations and identified three incidents involving Claude Opus 4.7, Claude Mythos 5 and an internal research model breaking out of internal evaluation environments to hack into three separate organisations.
As the Financial Times reported on 5 August, the UK government’s AI Security Institute (AISI) has since revealed that Anthropic’s Mythos 5 and OpenAI’s GPT 5.6 Sol also broke into third-party software and emailed individuals to steal their credentials, as well as attempting to insert malicious code into an open-source project on GitHub. ‘Identifying new behaviour like this and sharing our findings, so we can tackle it, is exactly what AISI was set up to do,’ commented AI minister Kanishka Narayan.
While no legal AI rogues have been reported, there is always the risk that a rogue agent could break into a law firm. In an opinion piece for the Wall Street Journal, Haran Segram, an adjunct assistant professor at the New York University Stern School of Business, cited research from the Cloud Security Alliance in which ‘84% of organisations surveyed doubted they could pass a compliance audit of their AI agents’ behaviour or access controls. Only about 1 in 5 maintains a real-time inventory of the agents it is running’.
New types of security incidents require more resilient systems and new approaches to cybersecurity. Commenting on the OpenAI Hugging Face breach, AUIC co-founder Rajiv Dattani wrote on LinkedIn: ‘We noted in a recent report that agents continue to get rapidly more powerful, but their reliability is not keeping up. There were no losses here, but it’s only a matter of time. Barring major changes, highly capable agents working over long time-horizons will be involved in a major accident.’ He added: ‘Defence can scale with offence, if we invest in it.’
Benchmarks and certifications
Another way of minimising agentic risk is to manage agent behaviour, and the legal AI unicorns are already taking steps to do so. Last week, Harvey became the first legal AI company to earn AIUC-1 certification for AI agent security, safety and reliability. Harvey’s other independent third-party verifications include ISO 27001 (information security), ISO 27701 (privacy) and ISO 42001 (AI systems and ethical AI deployment) certifications and SOC Type 2 attestation (which tests how well a company protects customer data).
Both Harvey and Legora have also established benchmarks to evaluate how AI agents manage legal work. Harvey launched its Legal Agent Benchmark in May, and in July Legora’s Benchmark for Agentic Reasoning was set up to evaluate its own performance across multiple cases and practice areas.
In addition to a relentless programme of strategic fundraising and acquisitions, ensuring that their agentic platforms are (and are seen to be) reliable and resilient is helping Harvey and Legora secure their leading position in legal AI against competition from the frontier AI models, which in recent weeks have been dominating the headlines for all the wrong reasons.























No comments yet