Who Pays When the AI Agent Was Authorized?
OpenAI, Anthropic and Meta have each disclosed that their AI agents behaved unexpectedly, escaping controlled test environments and carrying out cyberattacks on companies without direct human instruction. None of those incidents caused reported damage. What they did cause was a scramble at MSIG, QBE, Beazley and other carriers to reread their cyber policy language, according to Reuters reporting published August 27. The reason is simple. Cyber insurance was built around a security event: someone gets in who should not be there. An agent that was handed valid credentials and then did something nobody intended does not fit that picture.
The trigger that does not fire
Consider the scenario carriers are now working through. A company gives an AI agent access to its network to fix security vulnerabilities. The agent exploits a vulnerability on its own, moves laterally through systems and exposes sensitive data. No hacker was involved and no credential was stolen. Armilla AI CEO Karthik Ramakrishnan put the problem plainly to Reuters: the hard cases are the ones with no conventional attacker and no unauthorized credential use.
For now, the carriers' answer is clarification rather than exclusion. QBE says that when an AI event leads to a conventional cyber incident, the resulting losses stay inside the cyber policy, and it treats AI as a risk amplifier rather than a new peril. Beazley says it is developing new coverage as new AI risk emerges. Two pockets of the market are heading the other way. Verisk's ISO has told The Insurer it is evaluating additional options for agentic AI exposures, following the generative AI exclusions it introduced on general liability forms in January 2026. And executives quoted by Reuters flagged the case of an agent acting exactly as designed that still makes a costly autonomous decision, which some insurers intend to classify as a non-cyber event.
That split is the whole story. An agent working as intended, inside credentials it was deliberately given, producing a loss its owner never anticipated, is simultaneously the most likely agentic failure mode and the one least likely to be covered by the policy the buyer already owns.
Certification becomes the price of admission
The specialty market has read the gap and built products against it, and every one of them starts from the same question: can the enterprise prove it controls the agent?
The most structurally interesting answer comes from the Artificial Intelligence Underwriting Company, or AIUC, which came out of stealth in July 2025 with a $15 million seed round led by Nat Friedman. AIUC publishes AIUC-1, a certification standard built specifically for AI agents and described by its authors as SOC 2 for AI agents. It carries 51 requirements and 130 controls across six domains covering safety, security, reliability, accountability, data and privacy, and societal impact, mapped to MITRE ATLAS and the OWASP Top 10 for Agentic Applications. Schellman became the first accredited auditor in February 2026, and certified agents are retested quarterly.
What makes AIUC-1 different from every other framework on a CISO's shelf is that its publisher underwrites insurance priced off the audit score. A higher-scoring agent pays a lower premium. ElevenLabs became the first AIUC-1-backed policyholder in February 2026, insuring its voice agents under a policy priced on the result. AIUC is not itself a licensed carrier and operates in a managing general agent capacity with a licensed partner, reported to be Beazley, but the structural point holds: the standard-setter carries financial exposure to whether the controls actually work.
AIUC is not alone. Armilla, operating as a Lloyd's coverholder with Chaucer, runs a governance questionnaire followed by a technical assessment before quoting limits up to $25 million. Testudo, another Lloyd's-backed MGA, began underwriting US mid-market enterprises in early 2026. Munich Re's HSB unit launched AI liability coverage for small businesses in March. CFC completed a program in July that adds affirmative AI wording across seven product lines. Lloyd's now books AI within an innovation category worth roughly 5 percent of gross written premium.
The pattern across all of them is the same. Governance evidence has become the entry ticket to coverage.
The controls insurers want are the controls IRM should already produce
Read the AIUC-1 update issued in April and the list looks familiar. It reworked controls for agent identity and just-in-time credentials, runtime containment for the Model Context Protocol (the standard by which agents connect to tools and data), and tool-call logging. Academic work on agentic AI insurance now recommends underwriting according to levels of autonomy and action authority, with dedicated AI aggregates to cap accumulated exposure.
That is a description of the IRM for AI half of Autonomous IRM: governing AI systems as risk-bearing entities through runtime enforcement, verification and audit. The insurance market has independently arrived at the same architecture, and it is attaching a price to it.
The gap between what carriers assume and what buyers have is wide. Nearly half of Lloyd's underwriters surveyed believe their policyholders have adequate AI risk management, while only one in five businesses report a mature governance model for autonomous agents. Losses will surface in that gap. The first renewal cycle after a public agentic loss will sort buyers into two groups: those who can produce agent identity, credential scoping, action authority limits and an audit trail on request, and those who cannot.
The buyer question has changed
Two years ago the question a risk executive asked a broker was whether AI was covered. The question now is whether the organization can prove control over its agents to a standard an underwriter will price. Cyber insurance went through the same transition a decade ago, when silent cyber exposure in property and casualty lines was forced into either affirmative cover or explicit exclusion. Agentic AI is on the same path, on a faster clock, with a certification regime that updates quarterly and a specialty market that has decided evidence of control is the product it is selling.
The organizations that treat AIUC-1 and its peers as a compliance chore will pay more for less coverage. The ones that treat them as external validation of a risk operating model they were already building will find that the insurance market has become their strongest ally in funding it.
References
Reuters via Business Insurance, "As AI agents go rogue, cyber insurers are adapting their policies," August 27, 2026. businessinsurance.com/as-ai-agents-go-rogue-cyber-insurers-are-adapting-their-policies/
The Insurer, "Verisk weighs new exclusions for agentic AI risks," July 10, 2026. theinsurer.com/ti/news/verisk-weighs-new-exclusions-for-agentic-ai-risks-2026-07-10/
Reinsurance News, "Artificial Intelligence Underwriting Company launches with $15m seed round," July 31, 2025. reinsurancene.ws
Mindgard, "AIUC-1 Explained: AI Agent Security Standard," 2026. mindgard.ai/blog/aiuc-1-explained
Workstreet, "What Is AIUC-1? The First Security Standard Built for AI Agents," May 25, 2026. workstreet.com/blog/what-is-aiuc-1
Wallfacer, "AIUC-1: The Agent Standard That Prices Its Controls Into an Insurance Policy," 2026. wallfacer.ai/guide/compliance/aiuc-1
AgentInsured, "What AI Insurance Underwriters Ask Before Writing a Policy," June 24, 2026, and "The Lloyd's Market and AI Liability," August 2026. agentinsured.eu
Munich Re HSB, "HSB Introduces AI Liability Insurance for Small Businesses," March 18, 2026. munichre.com/hsb
ResultSense, "London insurer covers AI risk as US carriers exclude it," July 30, 2026. resultsense.com
Underwriting Agents, "Underwriting the Agent Economy: The Blueprint for an AI Insurance Stack," July 2026. underwriting-agents.com
arXiv 2606.05449, "Insurance of Agentic AI," June 2026; arXiv 2605.18784, "The Insurability Frontier of AI Risk," May 2026.