
Blog Post
Underwriting an AI Agent
September 28, 2026
The question about insuring autonomous agents is usually framed around missing data. No loss history, no base rate, nothing to price against.
Insurers price novel perils without loss history routinely. The market has already answered that part, and the answer says something useful about what an organization should be able to produce. What it has not answered is a different question entirely.
How Is the Market Pricing Without Loss Data?
The market substitutes a verified control position for absent loss experience, which is the pattern worth recognizing because it determines what an insured needs to have.
The specialist facilities writing affirmative AI liability pairs cover with independent assessment of the system being insured. Model verification, bias evaluation, stress testing and red teaming sit alongside the policy rather than after a claim, and one coverholder describes its underwriting as informed by several hundred AI evaluations across regulated industries.
Which Is the Ransomware Playbook Arriving Early
Cyber underwriting went through this. Carriers stopped pricing the technology and started pricing the program behind it, and multi-factor authentication became a condition of quoting rather than a discount. The same substitution is happening for agents, and it is happening before most organizations can evidence anything, which reading a submission as a diagnostic sets out for the cyber side.
What Would an Underwriter Want to See?
Four things, and each is a property of the deployment rather than of the model.

- An enumerated action surface: What each agent can reach, since reach bounds the worst case per insured.
- Enforced constraints rather than instructed ones: A limit that holds without anybody present, since an instruction is not a control.
- Attribution to a named owner: Which identity acted, because a loss nobody can attribute is a loss nobody can investigate.
A measured deviation rate completes it. How often activity leaves its own envelope, and what happened when it did, which is the closest available proxy for frequency in the absence of claims.
What Has the Market Not Solved?
Correlation, and this is the constraint that determines whether the risk is writable at scale rather than what it costs.
An insurer can price an unfamiliar peril. What it cannot accept is unbounded correlation across its book. Where a large number of insureds run agents on the same foundation model, a single defect is a single loss event affecting all of them at once, and the aggregate exposure is not the sum of independent risks.
Which Turns on the Aggregation Wording
Whether many automated errors from one model update count as one occurrence or many is answered by a batch clause where the policy has one. Where it does not, the analysis falls to whether the test is the underlying cause or the resulting effects, and a shared model defect argues strongly for a single occurrence subject to one limit.
Which Side Does Single-Occurrence Treatment Favor?
Both and neither, which is why the wording matters more than the instinct about it.

An agentic failure produces many small errors from one cause, which is the shape no standard aggregation language was written for. Treated as many occurrences, the insured pays a retention per error and the arithmetic becomes absurd. Treated as one, a single per-claim limit has to absorb the whole event and may not.
Which Makes Limit Adequacy the Real Question
An insured should establish what a single-occurrence finding would mean against its own modeled exposure, because that is the scenario the wording most likely produces. Where the per-claim limit sits below the modeled aggregate for a shared-model event, the position is known in advance rather than discovered at claim, and where a program should attach is the same calculation from the other direction.
What Is the Coverage Position Today?
Uncomfortable, and stating it plainly is more useful than the usual reassurance.
From January 2026, standard exclusion endorsements stripping generative AI harms out of commercial general liability began attaching at renewal across several major carriers, and several standard technology errors and omissions forms moved toward near-absolute AI exclusions. Meanwhile A survey of carrier materials finds the number of standalone dedicated AI liability products worldwide in the low single figures.
Which Leaves Most Organizations in the Middle
Excluded from the cover they hold and unable to buy the cover that would respond, since the specialist capacity is early, enterprise-first and largely distributed through the London market. The result is a retained exposure by default rather than by decision, and where an AI incident lands across policies covers the position it replaces.
Is the Three-Way Dispute Being Resolved?
Contractually, in the newest structures, which is the most practical development in the market.
An agent failure rarely sits inside one policy's definition of a peril, so a data disclosure, a faulty output and an interruption arising from one event can reach three different towers. At least one coordinated structure now pairs cyber and technology errors and omissions cover with a standalone AI policy and predefined allocation rules for mixed scenarios.
What Should an Insured Ask For?
Allocation language rather than more limit. Two towers with a stated rule for splitting a mixed claim is a better position than three towers arguing, and asking for it at placement is considerably cheaper than establishing it afterwards.
Does Certification Cut Both Ways?
It does, and the second direction is the one an insured should think about before volunteering anything.
An independent assessment produces a record of the system's weaknesses as well as its strengths. The record supports the placement and it also exists afterwards, in the hands of a party with an interest in whether a claim falls inside the cover. An assessment noting a limitation, followed by a loss arising through that limitation, is a document somebody will read carefully.
Is That a Reason to Avoid It?
No, and the alternative is worse. Without an assessment the position is exclusion rather than a contestable claim, so an imperfect record inside affirmative cover beats a clean record inside a policy that does not respond. The useful response is remediating what an assessment finds rather than declining to have one.
What Should Be Done With the Findings?
Priced and either fixed or accepted on the record before the placement completes. A finding closed before inception is a strength, one accepted with a stated reason is defensible, and one left open without either is the version that becomes a problem, which pricing a weakness while it stays open puts a figure on.
What Should Be Established Before a Renewal?
Four things, and the first two are what a specialist assessment would examine anyway.
An enumerated action surface per agent, with enforced rather than instructed limits. A measured deviation rate against a baseline, since it is the only frequency evidence available. Which foundation models the agents depend on, because that is the correlation exposure an underwriter is pricing across its book. Then what a single-occurrence finding would cost against your own modeled figure. AI risk quantification, or AIRQ, resolved by asset category answers the fourth, and an AI governance record answers the first three from observed activity.
The Data Problem Is Solved, the Correlation Problem Is Not
The market priced around absent loss history by substituting independent assessment of the system for claims experience, which is the ransomware playbook arriving early and means an insured needs an assessable control position rather than a clean record. What remains unsolved is correlation, since a shared foundation model defect is one loss event across an entire book and that limits capacity regardless of price. The aggregation wording decides how it lands, and an agentic failure producing many errors from one cause is the shape no standard batch clause was written for, so limit adequacy against a single-occurrence finding is the question to answer in advance. Exclusions also arrived before products, leaving most organizations excluded from what they hold and unable to buy what would respond. Kovrr's AIRQ produces the exposure figure that question requires.
To see agent exposure modeled by asset category ahead of a renewal conversation, book a demo mapped to your own estate.
AI Agent Insurability FAQs
Speak to an ExpertCan AI agent exposure be insured without loss history?
Yes, and the market already does it by substituting a verified control position for absent loss experience. The specialist facilities writing affirmative AI liability pair cover with independent assessment of the system being insured, including model verification, bias evaluation, stress testing and red teaming, with one coverholder describing its underwriting as informed by several hundred AI evaluations across regulated industries. That is the same substitution cyber underwriting made when multi-factor authentication became a condition of quoting.
What would an underwriter want to see before pricing agent exposure?
Four things, each a property of the deployment rather than the model. An enumerated action surface showing what each agent can reach, since reach bounds the worst case. Enforced constraints rather than instructed ones, since an instruction is not a control. Attribution to a named owner, because a loss nobody can attribute is a loss nobody can investigate. And a measured deviation rate against a baseline, which is the closest available proxy for frequency without claims.
Why is correlation the harder underwriting problem?
Because an insurer can price an unfamiliar peril but cannot accept unbounded correlation across its book. Where a large number of insureds run agents on the same foundation model, a single defect is a single loss event affecting all of them at once, so the aggregate exposure is not the sum of independent risks. That limits how much capacity can be written regardless of price, which makes it a capacity constraint rather than a pricing one.
How does a batch clause affect AI agent claims?
It decides whether many automated errors from one model update count as one occurrence or many. Where a policy has no batch clause, the analysis falls to whether the test is the underlying cause or the resulting effects, and a shared model defect argues strongly for a single occurrence subject to one limit. An agentic failure produces many small errors from one cause, which is the shape no standard aggregation language was written for.
Do standard policies exclude AI agent losses?
Increasingly. From January 2026 standard exclusion endorsements stripping generative AI harms out of commercial general liability began attaching at renewal across several major carriers, and several standard technology errors and omissions forms moved toward near-absolute AI exclusions. Meanwhile the number of standalone dedicated AI liability products worldwide sits in the low single figures, leaving most organizations excluded from the cover they hold and unable to buy the cover that would respond.
What should an insured ask for at placement?
Allocation language rather than more limit. An agent failure rarely sits inside one policy's definition of a peril, so a data disclosure, a faulty output and an interruption arising from one event can reach three different towers. At least one coordinated structure now pairs cyber and technology errors and omissions cover with a standalone AI policy and predefined allocation rules for mixed scenarios, and asking for that at placement is cheaper than establishing it afterwards.




