{"slug": "is-your-agentic-ai-actually-insurable", "title": "Is Your Agentic AI Actually Insurable?", "summary": "Insurance Services Office (ISO) endorsements CG 40 47 and CG 40 48, introduced in January 2026, explicitly exclude autonomous AI failures from standard commercial liability policies, leaving enterprises exposed to unmodeled liabilities from agentic AI. The shift requires organizations to adopt continuous telemetry, cryptographic API controls (OAuth 2.1), and specialized affirmative coverage frameworks from providers like Armilla, Coalition, and Munich Re.", "body_md": "*Legacy risk frameworks failing to catch autonomous execution liabilities.*\n\nImagine walking into your corporate board meeting to find that the autonomous procurement agent you deployed to save twenty hours a week has just successfully negotiated, signed, and wired funds for a five-year contract to buy three thousand custom-built industrial blenders — despite your company manufacturing enterprise financial software.\n\n*📊 Executive Summary:* Corporate policies written prior to 2026 leave enterprises exposed to unmodeled autonomous liabilities. Following the introduction of Insurance Services Office (ISO) endorsements CG 40 47 and CG 40 48 in January 2026, legacy cyber and CGL policies explicitly exclude autonomous AI failures (Insurance Services Office [ISO], 2026). Navigating this shift requires transitioning from static human-anchor assumptions to continuous telemetry, cryptographic API controls (OAuth 2.1), and specialized affirmative coverage frameworks (Armilla, Coalition, Munich Re).\n\nThink of self-attention mechanics like a bustling cocktail party where every sentence fragment listens simultaneously to every other word, but agentic execution is a rogue guest who has somehow stolen the corporate checkbook and is trading stocks in the bathroom. For years, digital transformation was treated as a software problem, a neat exercise in UI/UX modernization and cloud migration. Entering 2026, we have crossed a jagged line from tools that assist human thought to digital workers that take autonomous, consequential actions across enterprise APIs, cloud databases, and financial networks (Gervais & Nay, 2026; Zhu, 2026). This architectural leap has shattered the foundational assumptions of corporate risk management. The traditional insurance safety net — painstakingly woven over decades to catch human errors and network intrusions — has developed a gaping, structural tear. If your organization relies on automated agents to run operational workflows, your existing balance sheet is sitting entirely unprotected over an uninsurable abyss.\n\nFor years, artificial intelligence losses were covered almost by accident. Legacy cyber, Technology Errors and Omissions (Tech E&O), and Commercial General Liability (CGL) policies lacked definitions for artificial intelligence entirely (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). When an algorithmic hallucination resulted in a privacy breach, a discriminatory hiring outcome, or unexpected business downtime, the claim frequently slipped inside the coverage perimeter simply because no policy language explicitly forbade it (Leung, Zhang, Ling, et al., 2026). This phenomenon, mirroring the “silent cyber” crisis of the previous decade, exposed global carriers to unmodeled, systemic risks that defied traditional actuarial forecasting.\n\nThe insurance industry’s response throughout 2025 and 2026 has been swift, defensive, and structural. Carrier apprehension regarding unquantifiable AI risk has driven the widespread adoption of specific exclusionary language, fundamentally altering the baseline protection afforded by standard corporate policies (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Without historical loss frequency, severity, or correlation data, underwriters cannot price a risk; when they cannot price it, they mandate its exclusion (Zhu, 2026). In January 2026, the Insurance Services Office (ISO) introduced a suite of standardized endorsements designed to carve generative and agentic AI exposures out of standard commercial liability frameworks (Insurance Services Office [ISO], 2026). These endorsements rapidly became the default baseline across the commercial market, with major carriers securing regulatory approvals to attach them to renewals.\n\n*ISO exclusions functioning as an impenetrable structural barrier to silent AI coverage.*\n\nThe distinction between these forms hinges directly on the system’s degree of autonomy and the nature of the coverage. Endorsement CG 40 47 introduced a broad total exclusion, removing coverage for any loss caused directly or indirectly by AI, regardless of whether the AI operated autonomously or under direct human supervision (ISO, 2026). Endorsement CG 40 48 targets Coverage B by removing personal and advertising injury claims for AI, preserving protection *only* for systems that do not independently make decisions or operate without human oversight (ISO, 2026). Meanwhile, CG 35 08 extends the generative AI exclusion to products and completed operations, severely impacting software vendors and robotics manufacturers (ISO, 2026).\n\nFurthermore, major carriers such as W.R. Berkley, Chubb, and Travelers have filed absolute AI exclusions across Directors and Officers (D&O), Fiduciary, and Tech E&O lines, stripping protection for any claim arising from AI deployment (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Within cyber insurance specifically, carriers are increasingly imposing aggressive AI sublimits. For instance, a policy boasting a five-year aggregate limit may restrict AI-related security events or data breaches to a meager five-hundred-thousand-dollar sublimit (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). The burden has shifted entirely to the insured: AI is assumed to be excluded unless coverage is explicitly negotiated back into the policy through affirmative endorsements.\n\nActuarial models rely on empirical loss data to calibrate pricing and determine risk appetite. While the agentic AI claims environment is still maturing, several high-profile precedents across recent years have crystallized exactly how these systems fail in production and how ensuing liabilities interact with insurance policies. The phenomenon of AI confidently fabricating facts — commonly termed hallucination — has triggered notable professional liability claims and judicial sanctions. In the legal sector, attorneys have faced severe financial penalties and professional bans for submitting court briefs containing non-existent case citations generated by Large Language Models (Gervais & Nay, 2026; Leung, Zhang, Toyoda, & Loh, 2026). A database maintained by global legal researchers tracked nearly two thousand verified legal hallucinations by mid-2026.\n\n“Code executes cleanly, logic compounds blindly, balance sheets suffer silently.” *— Mohit Sewak*\n\nThe exposure extends deeply into the corporate sector. In August 2026, legal representatives for State Farm were forced to apologize and face judicial scrutiny in a Los Angeles Superior Court fire insurance lawsuit after submitting motions filled with nonexistent case law and fabricated holdings (Gervais & Nay, 2026). In customer-facing environments, chatbots misrepresenting corporate policies create binding financial liabilities. In the landmark case *Moffatt v. Air Canada* (2024), the airline’s website chatbot hallucinated a retroactive bereavement discount, and the tribunal rejected the defense that the chatbot was an autonomous entity responsible for its own answers, establishing that enterprises strictly own the outputs of their AI agents (Leung, Zhang, Toyoda, & Loh, 2026; *Moffatt v. Air Canada*, 2024). Hallucination risk also threatens claims handling: if an AI system hallucinates negative details that lead to the denial of a valid claim, the insurer faces immediate bad faith litigation (Roy & Singh, 2026; Zhu, 2026). In *The Estate of Gene B. Lokken v. UnitedHealth Group, Inc.* (2026), plaintiffs successfully compelled discovery into the insurer’s use of AI to deny claims with minimal human review, indicating that algorithmic hallucination is now a primary vector for bad faith allegations (Leung, Zhang, Toyoda, & Loh, 2026).\n\n*Perfect logical execution resulting in catastrophic business damage.*\n\nClassified by the Open Worldwide Application Security Project (OWASP) as the number one security risk for LLM applications, prompt injection has transitioned from a theoretical exploit to an active claim driver (Open Worldwide Application Security Project [OWASP], 2025). A prompt injection attack involves tricking an AI model by inputting text that masquerades as system instructions, exploiting the model’s inability to reliably distinguish between trusted developer directives and malicious user input (OWASP, 2025). If an AI-assisted accounts payable agent processes a vendor invoice containing a hidden prompt injection instructing the agent to alter payment routing numbers, the resulting loss enters a coverage gray area. Standard crime policies typically require an unauthorized third party to actively breach a system (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Because the prompt injection manipulates the AI into executing a fraudulent transfer using the AI’s *authorized* credentials, carriers frequently deny the claim, arguing it is an operational error resulting from semantic manipulation rather than a true network intrusion (Leung, Zhang, Ling, et al., 2026; Zhu, 2026).\n\nThe most actuarially complex claims involve autonomous agents executing precisely as programmed, yet causing massive financial or operational damage. A widely cited example from July 2025 involved a coding agent deployed by Replit that autonomously deleted a production database (Leung, Zhang, Toyoda, & Loh, 2026). Because these agents were authorized to modify their environments, no security breach occurred under traditional definitions, meaning cyber policies were inapplicable (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Conversely, standard Tech E&O policies require the plaintiff to prove a negligent act, error, or omission, a legal standard that is exceedingly difficult to map onto probabilistic machine behavior (Gervais & Nay, 2026; Zhu, 2026). Legal review firms have documented multiple cases where insurers denied claims because the automated system was technically operating as intended and simply read authorizations correctly, even though the business outcome was catastrophic (Leung, Zhang, Toyoda, & Loh, 2026; Zhu, 2026). The Stanford Center for Legal Informatics has introduced the Phantom Agent Framework to address this liability gap, arguing that an enterprise’s balance sheet remains fully exposed to the design, foreseeability, and causal trajectory of its autonomous deployments (Gervais & Nay, 2026).\n\nTo underwrite autonomous systems, actuaries evaluate an enterprise’s machine autonomy along a continuum of independence (Zhu, 2026). The risk surface expands exponentially when an enterprise upgrades from singular conversational assistants to multi-agent workflows. An AI assistant that merely drafts emails or summarizes documents presents a bounded risk, as errors remain contained unless a human operator negligently acts upon the output (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). However, Level 3 tool-calling and Level 4 multi-agent systems possess the authority to query live databases, execute remote code, interact with external APIs, and trigger financial workflows (Liu et al., 2024; Zhu, 2026).\n\nThe introduction of multi-agent systems — where specialized digital workers coordinate with orchestrator agents to achieve complex goals — creates novel failure modes that compound risk downward. Industry data indicates that chaining multiple agents significantly degrades overall system reliability. Assuming a sequence of five agents, each operating at an individual accuracy rate of 95%, the cumulative system reliability formula Rₛᵧₛ = 0.95ⁿ reveals that system reliability drops to merely 77% (Jimenez et al., 2024; Liu et al., 2024).\n\n*Compounding errors in multi-agent orchestration leading to system deadlock.*\n\n*🔍 Fact Check:* Industry empirical models confirm that chaining five autonomous agents at a 95% individual success rate drops overall system reliability to 77% (*Rₛᵧₛ = 0.95ⁿ), driving roughly 40% of production multi-agent pilots to fail within six months [31, 32].*\n\nConsequently, approximately 40% of multi-agent production pilots fail within six months of reaching real production deployment, as predictable demo environments give way to the chaotic edge cases of daily traffic (Jimenez et al., 2024; Liu et al., 2024).\n\nWhen these systems fail in production, the root cause is rarely the underlying model producing an inaccurate text string. Instead, failures manifest as profound orchestration breakdowns where agents call correct tools with incorrect arguments, suffer context exhaustion during long reasoning loops, or report success after a step has clearly failed (Jimenez et al., 2024; Liu et al., 2024). Crucially, they frequently enter infinite retry cycles, creating massive token exhaustion and subsequent API billing spikes that can cost enterprises tens of thousands of dollars in hours (OWASP, 2025; Zhu, 2026). Furthermore, sequential agent chains create severe latency cascades, turning a three-second query response into a thirty-second delay in production, which triggers business interruption thresholds (Liu et al., 2024). In environments lacking shared cognition protocols, isolated agents operating across organizational boundaries easily deadlock or execute contradictory logic (Zhu, 2026). For example, a site reliability agent attempting to push a hotfix to restore a crashed application may be autonomously blocked by a security agent enforcing a policy against untested code, exacerbating downtime while the system spirals into a cognitive deadlock (Zhu, 2026). Underwriters view the lack of formal inter-agent communication contracts and semantic caching controls as a severe accumulation risk (Zhu, 2026).\n\nBecause autonomous agents operate probabilistically and fail in complex orchestration patterns, traditional deterministic software testing methodologies are insufficient for risk assessment. Underwriters now rely on rigorous, continuous governance frameworks to evaluate an enterprise’s maturity. The underwriting submission for autonomous AI coverage has evolved into an intensive technical audit. Leading specialist carriers and Managing General Agents — including Armilla AI, Testudo, and Munich Re — require comprehensive evidence across four critical pillars before issuing a binding quotation (Leung, Zhang, Ling, et al., 2026; Roy & Singh, 2026; Zhu, 2026).\n\n*Continuous telemetry and deterministic circuit breakers replacing static attestation.*\n\nInsurers mandate a granular technical system description that articulates precisely what the agent does and what data it ingests in production (Leung, Zhang, Toyoda, & Loh, 2026; Roy & Singh, 2026). Increasingly, underwriters align their technical documentation requirements with Article 11 and Annex IV of the EU AI Act, where an Annex IV technical file is generally considered sufficient evidence of architectural maturity for liability placement (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Organizations must also clearly document scope constraints, which are explicit definitions of what the agent is not permitted to do, supported by technical safeguards that prevent scope drift (Leung, Zhang, Toyoda, & Loh, 2026).\n\nUnderwriters demand formalized governance structures. In the London market, the Lloyd’s Market Association (LMA), in partnership with Barnett Waddingham, published the AI Adoption Toolkit, which has rapidly become the baseline standard for how syndicates evaluate prospective clients (Lloyd’s Market Association [LMA] & Barnett Waddingham, 2026). The toolkit mandates five core principles: governance and accountability, risk tiering, data protection and security, training and awareness, and pragmatic scaling (LMA & Barnett Waddingham, 2026). The risk tiering component is paramount, as an LMA survey covering over 60% of Lloyd’s stamp capacity found that 93% of firms project their internal risk tiering standards onto their commercial clients (LMA & Barnett Waddingham, 2026). An organization submitting an application for AI liability without a formally documented risk tiering framework will face immediate declination or punitive premium adjustments (LMA & Barnett Waddingham, 2026).\n\n*💡 ProTip:* Never submit an AI liability application without a documented risk-tiering framework mapped to the LMA toolkit. Underwriters immediately penalize or decline organizations lacking formal operational tiering schemas.\n\nThe absence of human oversight in high-stakes automated decisions is a primary cause for underwriting declination. Underwriters require enterprises to implement specific oversight modes calibrated to their risk tier, distinguishing between Human-in-the-Loop, where a human explicitly authorizes actions before impact, and Human-on-the-Loop, where agents execute autonomously while humans monitor real-time telemetry (Roy & Singh, 2026; Zhu, 2026). An approval queue that simply rubber-stamps hundreds of agent requests daily is viewed by actuaries as a collapsed control (Roy & Singh, 2026). Consequently, insurers look for the implementation of automated circuit breakers and kill switches, which are deterministic threshold constraints that automatically open and sever an agent’s access to external tools if failure rates spike (Leung, Zhang, Toyoda, & Loh, 2026; Roy & Singh, 2026). Advanced implementations deploy adversarial self-critique mechanisms, wherein a secondary critic agent challenges the primary agent’s conclusions before human review, a technique proven to reduce hallucination rates from 11.3% to 3.8% in production environments (Roy & Singh, 2026).\n\nAgents cause damage by leveraging authorized access to execute catastrophic logical actions at machine speed through APIs (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Therefore, API security is fundamentally intertwined with AI underwriting. Modern underwriting standards require distinct, per-agent cryptographic identities enforced through mutual TLS (OWASP, 2025; Zhu, 2026). The gold standard involves OAuth 2.1 implementation utilizing the Phantom Token pattern, which ensures the API gateway exchanges an opaque reference token for a short-lived JSON Web Token, guaranteeing the Large Language Model never possesses direct access to sensitive claims data (OWASP, 2025). Security controls must also prevent Broken Object Level Authorization attacks, where an agent inadvertently accesses another user’s data due to flawed schema validation (OWASP, 2025). Further complicating the underwriting process is the proliferation of Shadow AI — the deployment of unsanctioned consumer chatbots or unauthorized API integrations by employees (FAIR Institute, 2024; OWASP, 2025). From an underwriting perspective, Shadow AI is a material breach of policy conditions. If a cyber incident is traced to an unapproved AI agent, carriers may argue the insured failed to maintain mandated security controls, triggering coverage exclusions or outright claim denial (FAIR Institute, 2024; Leung, Zhang, Ling, et al., 2026). Consequently, demonstrating automated, API-level discovery mechanisms — such as deploying a Cloud Access Security Broker capable of identifying rogue AI tools across the network — is rapidly becoming a prerequisite for comprehensive cyber coverage (FAIR Institute, 2024).\n\n*Modular affirmative endorsements locking into place to secure AI risk.*\n\nAs enterprises recognize the operational gaps created by absolute AI exclusions, the insurance market has responded with sophisticated vehicles for risk transfer, broadly categorized into affirmative cyber endorsements, standalone AI liability policies, and performance guarantees (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Leading cyber carriers have chosen to adapt existing cyber risk frameworks to encompass AI-specific perils, provided the insured demonstrates adequate governance. Coalition introduced an Affirmative AI Endorsement to its cyber policies, expanding the definition of a security failure or data breach to include events triggered by AI technology (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Crucially, it expands the trigger for Funds Transfer Fraud to encompass fraudulent instructions generated via deepfakes or malicious AI manipulation, directly addressing the prompt injection and social engineering vulnerabilities that traditional policies deny (Leung, Zhang, Ling, et al., 2026; OWASP, 2025). AXA XL adopted a specialized approach with its CyberRiskConnect Gen AI Endorsement, focusing on organizations developing or fine-tuning foundational models by covering training data poisoning, intellectual property infringement, and regulatory defense costs arising from compliance failures under the EU AI Act (Leung, Zhang, Ling, et al., 2026; Zhu, 2026).\n\nFor businesses where autonomous AI is the core product or where agentic workflows manage mission-critical operations, standalone policies offer the most comprehensive protection. Armilla AI, operating as a Lloyd’s Coverholder, offers a dedicated AI liability product with aggregate limits reaching up to $25 million per organization (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Unlike generic Tech E&O policies, Armilla’s affirmative language explicitly names the novel exposures of the autonomous era: hallucination-induced losses, model drift, algorithmic bias, deteriorating performance, and agentic execution failures (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Similarly, newer Managing General Agents like Testudo provide generative AI liability coverage explicitly designed to insulate deployers from third-party claims arising from hallucinations, reputational harm, data disclosure, and AI-driven intellectual property disputes, offering limits up to $9.25 million (Leung, Zhang, Ling, et al., 2026).\n\nIn the performance guarantee space, Munich Re offers aiSure, distributed via Mosaic Insurance. While not a traditional third-party liability product, aiSure provides a first-party financial backstop for AI developers (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). If an AI model underperforms against contractually defined accuracy or uptime metrics, the policy triggers a settlement based on measurable performance telemetry rather than a subjective loss adjustment process (Leung, Zhang, Ling, et al., 2026; Zhu, 2026). Munich Re’s Technical Due Diligence process for aiSure is exhaustive, involving a four-step evaluation led by research scientists and domain experts to assess the model’s architecture, data sources, and quality management pipelines (Zhu, 2026).\n\n*🔍 Fact Check:* Despite rigorous engineering evaluations required by Munich Re’s aiSure technical framework, approximately 90% of applicant companies successfully pass the audit and secure coverage offers within three to four weeks [65].\n\nDespite the rigor, Munich Re reports that approximately 90% of companies undergoing this technical assessment successfully pass and receive coverage offers within three to four weeks (Zhu, 2026). Recognizing the needs of the long tail, Munich Re’s HSB division also launched a specialized AI liability insurance product for small and mid-sized enterprises, specifically reinstating the bodily injury, property damage, and advertising injury protections that were stripped away by the ISO CG 40 47 and CG 40 48 exclusions (Insurance Services Office [ISO], 2026; Leung, Zhang, Ling, et al., 2026).\n\n*Transitioning from unmitigated operational risk to governed, auditable AI architecture.*\n\nThe integration of agentic artificial intelligence into enterprise operations has forced the commercial insurance market to mature at an unprecedented velocity. The era of relying on ambiguous, legacy policy language to cover dynamic algorithmic risks definitively ended with the deployment of standardized ISO exclusions. For enterprise risk managers, chief information security officers, and technology architects, the implications are unambiguous: insurability is now inextricably linked to demonstrable, continuous algorithmic governance. The analytical framework applied by underwriters today looks past the marketing claims of AI platforms to interrogate the underlying architecture. Securing comprehensive, affirmative AI liability coverage — whether through specialized endorsements from carriers like Coalition and AXA XL, or standalone policies from Armilla and Testudo — requires enterprises to present a meticulously documented risk posture.\n\nThis posture must align with frameworks like the LMA AI Adoption Toolkit and the EU AI Act, evidencing strict autonomy calibration, cryptographic API security with OAuth 2.1, deterministic circuit breakers, and unwavering human-in-the-loop oversight for consequential actions. This underwriting evolution is heavily accelerated by a tightening global regulatory net. The European Union’s AI Act represents the most significant legislative pressure, carrying punitive non-compliance fines of up to €35 million or 7% of global annual turnover, a regulatory exposure that standard corporate policies routinely exclude (FAIR Institute, 2024; Leung, Zhang, Ling, et al., 2026). Concurrently, the United States is advancing its own frameworks, including the Colorado AI Act, which mandates risk management frameworks and impact assessments for AI involved in consequential decisions, alongside international standards like ISO/IEC 42001 (Leung, Zhang, Ling, et al., 2026; Lloyd’s Market Association [LMA] & Barnett Waddingham, 2026). To translate these complex vulnerabilities into quantifiable actuarial metrics, the insurance industry increasingly leverages frameworks such as Factor Analysis of Information Risk for Artificial Intelligence (FAIR-AIR), deconstructing technical risks into regulatory liability, operational productivity loss, and intellectual property erosion (FAIR Institute, 2024).\n\nUltimately, autonomous agents operate at machine speed, capable of scaling efficiency or compounding errors instantaneously. The insurance industry has responded by moving from attestation-based underwriting to evidence-based continuous monitoring. Organizations that treat AI governance not merely as a compliance exercise, but as the foundational security architecture of their digital workforce, will secure the risk transfer mechanisms necessary to innovate safely. Those that deploy autonomous capabilities without these rigid, auditable constraints will find themselves operating bare, entirely exposed to the unmitigated financial and legal consequences of machine execution.\n\nReady to evaluate your enterprise risk exposure? Download our confidential *2026 Enterprise Algorithmic Governance & Insurability Audit Template* to benchmark your current agentic architecture against leading MGA underwriting standards, or schedule a risk readiness review with our specialized advisory team today.\n\nInsurance Services Office. (2026). *Commercial general liability endorsements: Generative artificial intelligence exclusions (Forms CG 40 47, CG 40 48, CG 35 08)*. Verisk Analytics.\n\nLeung, A., Zhang, R., Ling, E., Toyoda, K., & Loh, S. (2026). The insurability frontier of AI risk: Mapping threats to affirmative coverage, silent exposures, and exclusions. *arXiv*. [https://doi.org/10.48550/arXiv.2605.18784](https://doi.org/10.48550/arXiv.2605.18784)\n\nZhu, Q. (2026). Insurance of agentic AI. *arXiv*. [https://doi.org/10.48550/arXiv.2606.05449](https://doi.org/10.48550/arXiv.2606.05449)\n\nGervais, D., & Nay, J. (2026). *The phantom agent: A framework for artificial intentionality and civil liability*. Stanford Center for Legal Informatics (CodeX).\n\nLeung, A., Zhang, R., Toyoda, K., & Loh, S. (2026). From control boundary to insurance claim: Reconstructing AI-mediated losses through the CER framework. *arXiv*. [https://doi.org/10.48550/arXiv.2606.03777](https://doi.org/10.48550/arXiv.2606.03777)\n\n*Moffatt v. Air Canada*, 2024 BCCRT 149 (CanLII). [https://canlii.ca/t/k2z3w](https://canlii.ca/t/k2z3w)\n\nJimenez, C. E., Yang, J., Wettig, A., Yao, S., Pei, K., Press, O., & Narasimhan, K. (2024). SWE-bench: Can language models resolve real-world GitHub issues? In *Proceedings of the Twelfth International Conference on Learning Representations (ICLR 2024)*. [https://openreview.net/forum?id=VTColl7Nx4](https://openreview.net/forum?id=VTColl7Nx4)\n\nLiu, X., Yu, H., Zhang, H., Xu, Y., Lei, X., Lai, H., Gu, Y., Ding, H., Men, K., Yang, K., Ling, S., Deng, X., Zeng, A., Du, Z., Shan, C., Huang, Y., Ye, J., Hao, J., Dong, Y., … Tang, J. (2024). AgentBench: Evaluating LLMs as agents. In *Proceedings of the Twelfth International Conference on Learning Representations (ICLR 2024)*. [https://openreview.net/forum?id=7h1LZeHQyv](https://openreview.net/forum?id=7h1LZeHQyv)\n\nOpen Worldwide Application Security Project. (2025). *OWASP top 10 for large language model applications 2025* (Version 2.0). OWASP Foundation. [https://genai.owasp.org/llm-top-10/](https://genai.owasp.org/llm-top-10/)\n\nFAIR Institute. (2024). *A FAIR artificial intelligence (AI) cyber risk playbook: FAIR-AIR approach*. FAIR Institute. [https://www.fairinstitute.org/](https://www.fairinstitute.org/)\n\nLloyd’s Market Association, & Barnett Waddingham. (2026). *AI adoption toolkit: Practical guidance for managing agents*. Lloyd’s Market Association. [https://www.lmalloyds.com/](https://www.lmalloyds.com/)\n\nRoy, J., & Singh, S. K. (2026). Agentic AI for commercial insurance underwriting with adversarial self-critique. *arXiv*. [https://doi.org/10.48550/arXiv.2601.14449](https://doi.org/10.48550/arXiv.2601.14449)\n\n*Disclaimer: The views and opinions expressed in this article are personal and do not necessarily reflect the official policy or position of any associated agencies, organizations, or the India AI Mission. AI assistance was utilized in the research, drafting, and ideation of this article. Licensed under CC BY-ND 4.0.*\n\n[Is Your Agentic AI Actually Insurable?](https://pub.towardsai.net/is-your-agentic-ai-actually-insurable-acc56ac10d57) was originally published in [Towards AI](https://pub.towardsai.net) on Medium, where people are continuing the conversation by highlighting and responding to this story.", "url": "https://wpnews.pro/news/is-your-agentic-ai-actually-insurable", "canonical_source": "https://pub.towardsai.net/is-your-agentic-ai-actually-insurable-acc56ac10d57?source=rss----98111c9905da---4", "published_at": "2026-09-07 18:01:01+00:00", "updated_at": "2026-09-07 18:30:27.170840+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety", "ai-agents"], "entities": ["Insurance Services Office", "Armilla", "Coalition", "Munich Re", "CG 40 47", "CG 40 48", "OAuth 2.1"], "alternates": {"html": "https://wpnews.pro/news/is-your-agentic-ai-actually-insurable", "markdown": "https://wpnews.pro/news/is-your-agentic-ai-actually-insurable.md", "text": "https://wpnews.pro/news/is-your-agentic-ai-actually-insurable.txt", "jsonld": "https://wpnews.pro/news/is-your-agentic-ai-actually-insurable.jsonld"}}