Financial services

AI agents in a broking business: the risks you’re actually taking on

When AI stops drafting and starts acting, a regulated broker takes on exposure a marketing team never will. Here are the five risks that matter — and how to adopt anyway.

FidwenJuly 20266 min read

Most AI a broker has met so far is polite and harmless. It drafts a renewal summary, suggests a reply, pulls the key facts out of a schedule. A person still reads the output and decides what to do with it. The risk stays low because the AI only ever hands you a piece of paper.

Agentic AI takes the piece of paper away. An agent doesn’t just answer a question — it pursues a goal across several steps and reaches into your systems to get things done: it reads the inbox, checks the record, drafts the quote, updates the management system and emails the client, escalating to a human only when it decides it needs to. That shift, from software that advises to software that acts, is where the appetite sits right now. It is also where the risk lives — and in a regulated broking firm, that risk is a different animal than it is almost anywhere else.

The warning is already on the table. Gartner expects more than 40% of agentic AI projects to be scrapped by the end of 2027 — not because the models fail, but because of escalating cost, unclear value and inadequate risk controls. For most businesses a cancelled project is wasted money. For a broker, weak controls around something that can act on a client’s cover aren’t just a budget problem; they’re a conduct problem.

In a broking firm the danger isn’t that the AI gets something wrong. It’s that it can act on being wrong before anyone has looked.
Five risks a regulated broker takes on
Accountability
A named person still owns every outcome. “The model decided” is not a defence.
Advice & liability
Confident, fluent, wrong answers — and PI cover that may not respond.
Data protection
Client data leaking into unvetted tools, still your problem under UK GDPR.
Fair outcomes
Bias and pricing that quietly fail Consumer Duty and vulnerable customers.
Autonomy at speed
One wrong rule, repeated a thousand times before anyone looks.
The gap between AI that assists and AI that acts — and why a regulated firm feels it hardest.

None of this is a reason to sit it out. The firms that name these risks tend to adopt faster and more safely than the ones that either ban the tools or quietly wing it. Here are the five worth naming.

1. The buck still stops with a person

The FCA has been clear that it will not write a separate rulebook for AI. Instead it applies the tools it already has — chiefly the Consumer Duty and the Senior Managers and Certification Regime. In practice that means AI sits inside your existing accountability, not outside it: a named senior manager is personally responsible for what an automated system does to a customer, and “the model decided” is not a defence anyone at the regulator will accept.

That cuts against the whole appeal of an agent, which is precisely that it acts without asking. The way to reconcile the two is to decide, deliberately and in writing, what an agent may do on its own and where it must stop and hand back to a human — and to make sure a real person owns that boundary.

No new AI law — the rules that already bite
Consumer Duty
Fair outcomes — including for vulnerable customers — whatever tool produced them.
SM&CR
A named senior manager is personally accountable for the AI’s conduct.
UK GDPR
Client data inside an AI tool is still your firm’s responsibility to protect.
ICOBS & conduct rules
Suitability and disclosure duties don’t change because a machine helped.
Source: FCA — AI is managed through existing frameworks rather than a dedicated AI rulebook.

2. Bad advice, and who pays for it

Generative systems have a failure mode that matters more in advice than almost anywhere else: when they don’t know, they can produce a confident, fluent, wrong answer rather than admit the gap. Put that in front of a client relying on you for suitability and the broker’s duty of care doesn’t move an inch — it is still your firm’s advice, however it was produced.

The uncomfortable open question is insurance. The market’s own view is that professional indemnity policies were not written with AI-generated error in mind, and there are real gaps between what a PI or cyber policy covers and how an AI failure actually plays out. It will probably take live claims before the position settles. The practical step is unglamorous and important: talk to your PI insurer before you deploy, not after a complaint.

3. Client data in the wrong places

The fastest way to turn an AI pilot into a data-protection incident is to let staff paste client details into a public chatbot to “save a bit of time”. Under UK GDPR that is your firm’s problem, and the ICO has been explicit that agentic systems — which move data between tools on their own — widen the surface for exactly this kind of leak. The rule that costs nothing and prevents most of the damage: no client data goes into any tool you haven’t vetted and put under contract.

4. Fairness, pricing and the vulnerable customer

The FCA’s own concern about AI in insurance isn’t science fiction — it has warned that data-hungry personalisation could push some customers towards being uninsurable, or bake historic bias into decisions that look neutral on the surface. For a broker that lands squarely on the Consumer Duty and on the duty to identify and support vulnerable customers. Any AI that touches segmentation, how a price is presented, or who gets offered what needs to be checked for fair outcomes, not just efficient ones.

5. Speed is the multiplier

The thing that makes an agent valuable — it works fast and without waiting for you — is the same thing that makes a mistake expensive. A wrong human email goes to one client; a wrong rule inside an agent can reach a thousand before anyone notices. It’s also a crowded, noisy market, with plenty of ordinary chatbots relabelled as “agents” — “agent washing” — which is part of why so many projects stall between a promising demo and something you can actually run in production.

Not sure where AI would actually pay in your firm? The free AI Opportunity Analysis shows where it fits — and where the risk isn’t worth it — in about three minutes.
Start the analysis →

How to adopt anyway

The guardrails are not complicated, and most of them are things a well-run broker already does elsewhere. Keep a human firmly in the loop on anything client-facing, anything that looks like advice, and anything that binds or changes cover. Put AI on the risk register with a named senior owner. Ban client data from unvetted tools. Have the PI conversation early. Start narrow — one contained task, heavily supervised — and let the agent earn a longer leash as it proves itself, with a log you can inspect when you need to explain what it did and why.

Do that and the risks above become manageable rather than disqualifying. The brokers who get real value from agents over the next two years won’t be the ones who moved fastest. They’ll be the ones who could move quickly because they had already decided, in advance, where the machine has to stop.

This article is general information, not legal or compliance advice. References to the Consumer Duty, SM&CR and the regulator are for context only; check your own obligations with a suitably qualified adviser before relying on anything here.

Share

Putting an agent into your brokerage?

We help independent brokers decide where AI can act, where it can only assist, and how to keep the whole thing inside Consumer Duty and SM&CR — without a grand programme. Start with the free analysis, or talk it through.

Start the AI Opportunity Analysis

Sources: FCA, “AI and the FCA: our approach” and public remarks on AI risks in insurance; Aviva Broker, “AI: a view from the FCA and ground rules” (2026); DAC Beachcroft, “FCA warns of AI risks”; Insurance Business UK, “When AI gives bad insurance advice, who actually pays?”; ICO guidance on AI and agentic systems; Gartner, “Over 40% of agentic AI projects will be cancelled by end of 2027” (June 2025). Figures verified July 2026; re-confirm before relying, as the position is moving quickly.