Agent Insured

Five kinds of loss. Where cover begins and ends.

The losses an operator of AI agents can face, each described the way a wording would describe it: what it covers, and where it stops. It is a reading frame for buyers, brokers and carriers. Agent Insured does not write or sell cover.

Financial loss from a wrong output

Indemnity for direct financial loss, to the insured or a third party, caused by factually incorrect, fabricated or unsupported output from an AI agent working inside an insured workflow, with defence costs where the output is cited as the proximate cause.

Scope. Contract errors, financial miscalculations, incorrect advice, fabricated citations, invented references in regulated filings.

Where it stops. Deliberate misuse, unapproved model substitutions, and output released without the human review the policy required.

Data leakage and privacy

Third party liability for the unauthorised disclosure of personal or commercially sensitive data by an AI agent, including prompt injection, training data exposure and cross tenant contamination in multi agent deployments.

Scope. Regulatory claims, data subject claims under Article 82 of the GDPR, notification costs, forensic investigation, and credit monitoring where the law requires it.

Where it stops. Leakage after a failure to apply a published vendor security patch, breaches that start outside the agent's perimeter, and known vulnerabilities left unresolved.

Intellectual property

Liability for claims that AI-generated output infringes copyright, a trade mark, a design right or a database right. It matters most to operators whose agents produce customer-facing content, code, images or technical documentation.

Scope. Defence and indemnity for infringement claims, reasonable settlement and mitigation costs, and both direct and vicarious liability.

Where it stops. Reproduction of protected material on the operator's instruction, and models the operator knew were trained on unlicensed data.

Regulatory penalties

Indemnity, where the law allows it, for administrative fines imposed under the AI Act and the GDPR, with legal defence throughout the regulatory process. Article 99 of the AI Act and Article 83 of the GDPR set the ceilings.

Scope. Supervisory investigations, notice of intent proceedings, defence counsel, technical expert witnesses and corrective action planning.

Where it stops. Intentional breach, any system prohibited under Article 5 of the AI Act, and fines the member state's law does not allow to be insured.

Autonomous action

Cover for claims that arise when an AI agent, acting within its authorised scope, executes a transaction, a decision or an external action that causes loss. This is the core cover for operators whose agents act on customers, systems or markets, and the one the revised Product Liability Directive, Directive (EU) 2024/2853, brings closest.

Scope. Faulty transactions, misrouted instructions, autonomous commitments, errors in agent to agent contracting, and wrong approvals in automated workflows.

Where it stops. Actions outside the agent's certified scope, deployments without the audit records the schedule requires, and circumvention of approval gates.

How the market words this today.

The five above are how a purpose-built AI policy would be structured. The wordings on sale are narrower, split across two forms, and the difference decides whether a loss is paid.

The clearest worked example is what Coalition's affirmative AI endorsement covers, and what European operators still cannot buy: an endorsement whose name promises AI cover and which reaches only an AI-caused security failure and a fraudulent instruction sent through a deepfake.

Alongside it, Counterpart's professional liability route covers the other half of the problem, and who insures AI agents in Europe maps who can write for a European buyer today. The carrier matrix has each programme with its source.

Terms, as used here.

TermMeaning
AI agentA software system that takes action on behalf of a person or organisation within a defined operational scope.
DeployerThe natural or legal person using an AI system in the course of a professional activity, as defined by the AI Act.
High-risk systemAn AI system listed in Annex III of the AI Act, or embedded in a product under Annex I, subject to conformity assessment and post-market monitoring.
Audit recordsStructured, tamper-evident records of an agent's inputs, decisions and outputs, kept for the period the policy schedule sets.
Certification evidenceDocumentation produced under the Agent Certified standard that establishes the governance, controls and test results of an AI agent.
References
  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council, the Artificial Intelligence Act.
  2. Directive (EU) 2024/2853 on liability for defective products, repealing Directive 85/374/EEC.
  3. Regulation (EU) 2016/679, the General Data Protection Regulation, Articles 82 and 83.
  4. AIUC-1, a security, safety and reliability standard for AI agents published by the Artificial Intelligence Underwriting Company (AIUC). aiuc.com.
  5. Mosaic Insurance, partnership with Munich Re's aiSure, 26 February 2026: up to EUR/USD/CAD 15 million in initial capacity. mosaicinsurance.com.
  6. Armilla, Standalone AI Liability Policy, limits up to USD 25 million per organisation. armilla.ai.
  7. Coalition, Affirmative Artificial Intelligence (AI) Endorsement, 26 March 2024, US Surplus and Canada cyber policies. coalitioninc.com.
Follow the market

The wordings will move. Hear when they do.

Join the waitlist to record your interest, or read the monitor for what has changed. Neither is an application for cover, and nothing is sold here.