AI that moves money, changes records and places orders on its own.
When it does the wrong thing, someone pays — today that's you.
WHAT IT IS
The true cover for first‒party AI loss.
Not an endorsement to a cyber policy. Not a clause bolted onto technology errors‒and‒omissions cover. An affirmative first‒party policy that pays your own costs when your AI does something it was not allowed to do.
If AI gives bad advice and a person acts on it, that is a professional liability question. When AI acts by itself, it can move money, change records, release code and place orders — faster than anyone can step in.
THE RISK
When AI acts, someone owns the loss.
When a business's own AI errs, there is no plaintiff, no defendant and no one to recover from. The loss belongs to the business from the moment it executes.
Orders placed wrong
An ordering workflow committed the wrong items to live orders, repeatedly, until the pilot was pulled.
Data destroyed
A coding workflow destroyed production data and its recovery path in seconds.
Payment misdirected
A payment workflow released funds to the wrong counterparty.
Spend runs away
A delegation loop between workflows billed six figures over a weekend.
Real failure modes, all observed in production. No attacker in any of them.
THE EVIDENCE
The market is already moving.
The exclusions are attaching.
Verisk's ISO generative-AI exclusions reached United States general liability forms in January 2026, and dozens of P&C groups have already filed to adopt them. The liability half is being answered by exclusion; the first-party half was never covered.
We have seen this before.
Exclusions created standalone cyber, moving from under two billion dollars of United States premium a decade ago to roughly nine billion in 2024.
The losses are real.
The failure modes above are drawn from publicly documented production incidents in which no attacker appears anywhere in the chain, which are compounding day by day as AI deployment speeds increase, leaving them mostly underreported.
THE GAP
Nothing you already buy responds.
Cyber
Built for a hacker getting in. Not for software you authorized that executed wrong.
Errors and omissions
Pays a claim made against you. Nobody is claiming.
Crime
Requires a dishonest person. There isn't one — the AI agent is not a person, and its credentials were valid.
Those policies were built for human‒led, break‒in‒based perils. This loss has no intruder, no claimant and no dishonest employee — which is why none of them was built to answer it. And the gap is widening: as carriers attach the AI exclusions at renewal, cover that was silent yesterday is excluded tomorrow.
WHAT IT COVERS
Five things it pays on.
What it pays
Money or records sent the wrong way. Spend that didn't stop. Data, code or records destroyed. The cost of putting it right. Lost profit while you're down.
One event, one cap
One root cause counts as one claim, however many AI workflows it runs through — one deductible, one limit.
What it doesn't cover
Not the model vendor. Not workflows or AI agents never registered. Not the insured's own misconfiguration. Stated before purchase, not at claim.
HOW IT WORKS
We diff the logs against the permissions.
What the workflow was allowed to do, recorded before it ran. What it actually did, recorded as it ran.
Where those two disagree, that is a deviation. Where the deviation causes financial loss, that is a Deviation Event — and that is what the policy pays. We do not adjudicate why the model did it, only whether the action exceeded permission. The record stays in your environment; our only connection to it is a read‒only hook.
WHERE YOU FIT
Three ways in.
Governance Platforms
You build the control layer AI runs on — your controls, our capital.