Skip to content

When your AI exceeds its permissions, we pay.

AI that moves money, changes records and places orders on its own. When it does the wrong thing, someone pays — today that's you.
WHAT THIS IS

Cover that pays you directly.

We pay directly when your AI does something it wasn't allowed to do — sends the wrong payment, deletes the wrong thing, burns a budget nobody approved.
Not a lawsuit you have to win. Not a break-in that has to happen first. You show us what it was allowed to do and what it did. Where they don't match, we pay.
An orange shield stands out in front of three white shields over a blue city skyline silhouette with digital circuit lines.
WHAT WE MEAN BY "AI THAT ACTS"
The scope, defined once.
AI that acts
AI that acts is software that executes real actions in live systems—like moving money or releasing code—without human approval at every step. You grant it authority and credentials to act on your behalf, yet it operates without a legal identity.
Unit of Cover
An AI agent is the software making decisions, while an AI workflow is a single agent or a team working together. This workflow is what we insure: each one is registered in your policy with its own unique permissions and limits.
What sits outside
Software following a fixed script and always returning the same result is just automation. The true test is simple: is it deterministic, or is it stochastic enough to independently change something in the real world?
Humans in the loop
Agentic systems do not mean removing humans entirely. Keeping a person in the loop on your highest-risk operational steps is a vital control—one that we actively encourage and reward with a lower policy premium.
WHAT IT COVERS
Five things it pays on.
A. Incorrect transaction
Money or records went the wrong way. Transfer, payment, order, commitment, price, record change.
B. Runaway execution
It didn't stop. Excess metered compute and service charges; the cost of actions it kept executing.
C. Destructive execution
It deleted or corrupted something. Data, records, code, models, configurations.
D. Restitution and rectification
Reversing it. Unwinding transactions, restoring data, making the counterparty whole.
E. Business interruption
You were down. Lost profit and extra cost while production is unusable.
One root cause counts as one Deviation Event, however many AI workflows it runs through one deductible, one limit. Business interruption is subject to a waiting period shown in the Declarations.
What it doesn't cover stated before purchase, not at claim. Not the AI vendor's fault. Not AI you never told us about. Not your own setup mistakes. What you configured is what counts. We won't get out of paying by arguing the prompt was written badly.
A glowing orange line connects a padlock and key to a digital document containing a checklist over a blue cityscape.
HOW IT WORKS
We diff the logs against the permissions.
Permissions what the workflow was allowed to do, written down before it ran. Logs what it actually did, in a record that can't be quietly edited afterwards.
Where those two don't match and the mismatch costs you money, that's a Deviation Event and that's what the policy pays.
One condition: a permission that only exists in a system prompt doesn't count; it has to be enforced by the system.
When you claim. Report it within the notice window and we settle from the record that already exists. The aim is to make you whole, not to settle a long time argument: we unwind the transaction, restore the data, settle with the counterparty and cover the profit lost while production was down.
WHAT IT COSTS
Priced on permissions and controls. Not revenue, not headcount.
How much permission it has
The registered inventory, the widest permissions in the schedule, and what each workflow is permitted to touch. This covers everything from read-only drafting up to autonomous execution.
How well it's controlled
The controls your systems enforce—which the agent cannot reach or change—hold the same way every time. The tighter your setup and the more resilient your governance, the lower your premium.
INSURABILITY
Three questions decide if we can cover you.
01
Can you see what it did?
Every action is visible end to end—whether you built it yourself, run it on a leading platform, or inherited it inside a vendor product. We require complete transparency from start to finish.
02
Are the logs tamper-evident?
Kept in a record the agent cannot amend, retained for a minimum period. Alter the record or fail to keep it, and we won't pay. We'd rather state this now than at claim time.
03
Do you have controls against mistakes?
Permissions must be encoded before anything reaches production, with change control on every update. A named person must be accountable for each workflow.
Three 'yeses' and we can quote. Two and we'll tell you which one to fix.
COMMON QUESTIONS
Asked before every quote.
Is this cyber insurance?
No. Cyber is built for an outsider getting in. This pays when there is no attacker at all: your own AI, holding credentials and authority you granted, executing beyond the permissions you gave it. The two sit alongside each other.
Does it replace my E&O cover?
No. E&O pays on a third party's claim, and only once it is settled whose error caused the loss — which for an AI failure means apportioning fault between you, the platform, the model vendor and whoever built the workflow, with the loss on your books throughout. This pays as soon as the record confirms your AI went beyond its permissions. Your balance sheet today, not after the argument.
What if we set it up wrong?
If your AI exceeded the permissions in force, you're covered — we won't avoid paying by arguing the prompt was written badly. The misconfiguration exclusion applies only when the AI stayed inside the permissions you gave it, such as when an agent was given a $50,000 transaction limit from the start and correctly executed a valid order within that limit, even though the business actually intended for the cap to be $5,000.
What if the AI was tricked?
AI doesn't need to be broken into. Someone can hide an instruction in a webpage, an email or a support ticket, and the agent reads it as a legitimate command and acts. If it was tricked past its permissions, we pay. If data was stolen or systems encrypted without anything exceeding permissions, that's cyber.
Does it cover vendor failure?
The policy covers your loss from your AI's conduct — it isn't product liability for the model vendor. The policy responds to your loss regardless of what the vendor's cap leaves behind.
Do I need your tooling?
No. We underwrite the record and control you already have in place. If you have gaps, a gap assessment shows you which ones; if you have nothing yet, a governance partner can put the layer in alongside the cover.
Isn't the cover too narrow?
Deliberately. A tightly bounded peril is one that can be defined before a loss, priced with discipline, and paid without argument — a form that promises everything about AI pays on nothing in particular. Where you need more, endorsements are individually priced and added to the base cover, so the policy is customized to what you run. Bounded today means insurable today.
How long do I have to report it?
Within the notice window stated in your policy. Cover applies to events occurring on or after your retroactive date for AI registered on the policy, provided the event is discovered during the policy year and reported either then or within a short window after it ends.
Can I see the policy wording?
A one-page coverage summary—detailing grants, exclusions, and claim mechanics—is available upon request. Specimen wording can be released via your broker under a nondisclosure agreement upon an indication of interest.
Coverage descriptions are summaries only. All coverage is subject to the policy terms as issued.
Book an underwriting conversation.