Your AI agent just cost someone money – and your policy may not care
You deploy an AI agent that quotes the wrong price, emails private data, or commits the company to terms it shouldn’t. The customer sues or demands a make-good. You file a claim. Then you discover the policy is silent, excluded, or written for human-written bugs and hackers – not autonomous actions. That’s the hole AI insurance is built to fill.
Companies ship agents fast. Carriers either carve AI out of standard lines or leave the wording untested. RAND’s September 2026 report is blunt: most insurers stay silent, some file broad exclusions, a handful sell affirmative cover. 84% of public generative-AI incidents in that work involve misinformation or deepfakes; U.S. litigation skews heavily IP and training-data fights. Meanwhile the financial hit from a bad agent decision still lands on you.
Why cyber, E&O and general liability fall short
Cyber usually needs a breach or unauthorized access. An agent that decides on its own to share a customer file? Different event. Tech E&O is built for bugs in code a human wrote. Autonomous choices sit outside that box – broker and carrier statements keep repeating the same gap.
GL is getting tighter paper, not looser. ISO/Verisk dropped optional generative-AI exclusion endorsements effective 1 January 2026: CG 40 47 (broad bodily injury/property damage plus advertising injury), CG 40 48 (narrower advertising), CG 35 08 (products/completed ops). Industry tracking put filings from more than 60 P&C carrier groups; absolute AI exclusions are also showing up in D&O, E&O and fiduciary forms. Silent wording is the trap – you only learn the answer after the loss and the legal bill.
One agent failure can touch professional liability, cyber, D&O and property in the same incident. That scatter is exactly why a named AI product showed up.
Who actually sells this in 2026
Affirmative AI liability policies name the failure modes out loud: model errors and hallucinations, harmful outputs (defamation, confidentiality, trade secrets), agent mistakes (wrong calls, skipped escalation, unauthorized actions), non-breach privacy leaks, and sometimes regulatory defense or contractual performance shortfalls.
| Provider | Focus | Key features (as of late 2026) | Limits/capacity notes |
|---|---|---|---|
| Armilla AI | Developers & deployers of GenAI/agents | Lloyd’s Coverholder; independent model evaluation + affirmative liability; performance warranties | Up to US$25M aggregate (US$5M per model) |
| Munich Re aiSure + Mosaic | Vendors and corporate users | Performance errors; contractual, financial and legal liabilities; parametric-like triggers on measurable thresholds | Up to ~$15M initial capacity in the Mosaic partnership |
| Klaimee | AI agents specifically | Risk score + certification + cover for hallucinations, prompt injection, unauthorized actions, data exposure | Illustrative from ~$22k/yr for $1M limit on early-stage products |
| AIUC | Frontier agents | AIUC-1 standard + 5,000+ adversarial audits + insurance | Reported up to $50M; ElevenLabs first live policy |
Turns out pricing is not a simple revenue slider. Armilla (Lloyd’s coverholder since its April 2025 launch) raised standalone limits to $25M aggregate by early 2026 and leans on independent evals – hundreds of models already reviewed. Munich Re’s aiSure docs describe contractual and financial loss from performance errors; the February 2026 Mosaic partnership adds parametric-style payouts when pre-agreed metrics break, with roughly $15M starting capacity. Klaimee’s public tables put early-stage (<$1M AI revenue) agents around $22,200/year for a $1M aggregate, climbing toward multi-thousand-per-month once revenue and risk score jump. AIUC pairs a hard audit bar (5,000+ adversarial tests) with reported limits up to $50M.
Better controls and a clean eval report move the quote more than headcount. Big limits still go through brokers; a few agent-focused shops offer faster paths for smaller deployments.
Pro tip: Before any carrier call, list every system that can take action or produce output a third party relies on. Write access, data classes touched, human-in-the-loop rules. That one inventory shortens underwriting and shows the real holes.
The catch is parametric speed. Products in the aiSure/Mosaic lane can pay on a threshold breach without a full negligence fight – but only if you already have measurable metrics. Most early agent rollouts don’t. No metrics, no fast trigger.
A practical path to getting covered
- Pull cyber, tech E&O, GL, D&O and professional liability. Search “artificial intelligence,” “generative,” “algorithm,” “model.” Ask the broker in writing: agent actions affirmatively covered, excluded, or silent?
- Map exposure. Which agents can cause third-party financial loss, privacy complaints, defamation, or contract breaches? Rank high-write-access and customer-facing first.
- Match product type. Performance warranty (Munich Re-style) fits vendors who guarantee accuracy to buyers. Broader liability fits teams that run agents in-house. Agent cert + insurance (Klaimee or AIUC style) helps when procurement wants proof on paper.
- Submit for evaluation – questionnaires, behavioral tests, model review. Broker for large limits; smaller agent covers can move quicker.
- Bind with named affirmative language, clear triggers, and sub-limits. Confirm defense costs and how allocation works if the same loss also hits cyber.
Vendors sometimes stick a performance warranty in the deal so buyers stop stalling. Armilla-style warranties on decision models and AIUC-backed live policies (ElevenLabs was first) turn the policy into a sales tool, not only a backstop. Remember the silent-coverage problem from RAND? This is the fix that actually names the risk.
What still feels unsettled
Claims history is thin. One ugly accumulation event – dozens of insureds on the same foundation model – could reprice the whole class overnight. Reinsurers already watch that concentration. Physical or safety-critical uses still sit outside most appetite.
Is every AI failure going to be insurable next year? Probably not. For the bounded B2B agents and GenAI tools most companies actually run, though, affirmative options exist today and the limit ladder is climbing.
FAQ
Does my existing business insurance cover AI agents?
Usually no clear yes. Get the wording and a written broker answer. Silence is not cover.
How much does AI insurance cost?
Klaimee’s illustrative band (as of late 2026) starts near $22,200/year for a $1M limit on early-stage products under $1M AI revenue, then climbs with revenue, workflow criticality, and risk score – sometimes toward ~$7k/month once you pass $20M revenue. Armilla-style standalone programs are quote-only and can reach multi-million limits. The eval result often moves the number more than company size.
Should developers or just deployers buy it?
Both, for different reasons. If your contracts already force you to indemnify customers for model errors, you need the policy whether you built the model or only call an API. Vendors buy it to clear enterprise procurement and to back performance promises. Deployers buy it for third-party claims when an internal agent causes harm. Some wordings cover both seats; others specialize. Skipping it because “we’re only the deployer” is the misconception that shows up after the demand letter.
Next action: open the policies today, search AI language, and email the broker three questions – affirmative cover for agent actions? Any new ISO exclusions on renewal? Appetite for a standalone AI liability quote? Do that before the next agent goes live.