Three questions to ask before anything else.
Read each one, answer it honestly for your own business, then read the guidance. If you can answer all three well, you are ahead of most operators we hear from. If you cannot, the next step for each is right there. About ten minutes.
Do you have documentation of what your agents do, and of the guardrails around them?
Write down, on one page, every AI agent running in your business today. For each, note what it may do, who it talks to, which tools or APIs it can call, what data it can read and write, and which decisions need a person to approve them. If you cannot fill this in during an afternoon, you do not yet have documentation.
Good looks like a short operating manual a new hire could read in fifteen minutes and come away understanding the whole AI footprint of the company. It is plain, a little boring, and updated every time someone changes an agent. It lists the known failure modes and the guardrails that catch them. It names an owner for each agent.
The test is whether a reasonable person outside your company would read it and conclude the business knows what it is running. If the honest answer is "some of it lives in our heads", or "our CTO keeps meaning to write it down", that is the gap. Regulators, insurers and claimants' lawyers will all ask for this document. You want it to exist before they do.
Have you read your current insurance for AI exclusions?
Gather every policy the business holds: errors and omissions, cyber, general liability, directors and officers, and any media or technology liability wrapper. Send them to your broker with one question: "Please tell me in writing how each of these policies responds to a claim arising from an AI agent deployed in our business." Then read the answers.
Good looks like a written position on each policy, referring to specific clauses, with any AI exclusion identified by number and page. A verbal "it will be fine" is not an answer. A broker who cannot tell your AI agent from any other piece of custom software is the wrong broker for this. The area is moving quickly enough that the quality of your broker matters more this year than it did last year.
What you are watching for is silent cover turning into explicit exclusion. A policy that quietly covered you in 2024 may exclude AI at a 2026 renewal. A policy that never addressed the question will turn on how a claims adjuster reads the wording after the event. You want the written position, and the direction of travel, on every line.
Do you have a plan for the day an agent causes harm?
Picture a call at 9:04 on a Tuesday morning. A customer tells your support team that your agent promised them something yesterday the company cannot honour, and they have already acted on it. The loss is real without being catastrophic, and the customer is angry and threatening to post about it. Who takes the call, who decides to pause the agent, who tells the affected customers, and who decides whether to notify a regulator?
Good looks like a one page playbook with named roles, a kill switch any on call engineer can flip without a deployment, a prepared message for customers, another for the regulator in your jurisdiction, and a written decision tree for when to bring in outside counsel. It has been rehearsed at least once, in a tabletop exercise, with the people who would really be on the call.
The aim is not to prevent every incident. Incidents will happen. The aim is to contain the harm, record your response honestly, and be able to show a regulator or insurer later that the business acted reasonably. A reasonable response with an imperfect outcome can be defended. No plan at all cannot.
What your answers mean. A readiness check, not a grade.
Insurers writing AI cover ask for exactly these artefacts before they quote. If you have them, the next step is straightforward. If you do not, building them is straightforward too. Either way, you move.
All three, with evidence
Go to the coverage path. You can put a credible file in front of a broker now.
Gaps on one or two
Work through the path. An assessment against a published standard produces the evidence you are missing.
Gaps on all three
Start with the first question. You cannot review policies or plan a response without knowing what the agents actually do.
Further reading on each question.
If one of the three landed harder than you expected, these take it apart properly.
- Five questions to ask before deploying an AI agent in your businessThe pre-deployment checklist that turns the documentation question into something you can answer in an afternoon.
- Does your business insurance cover AI mistakes? Probably not.A clause by clause look at errors and omissions, cyber, general liability and D&O, with the wording to send your broker.
- The Air Canada chatbot case: what SME operators should learnThe incident response lessons from the tribunal decision, to read before you write your own playbook.
- My AI agent gave a customer wrong advice. Am I required to compensate them?When you are legally required to pay, what insurance covers, and what to do in the first 48 hours.
- Do my clients have the right to know I use AI in their work?Disclosure duties, EU AI Act transparency rules, contract clauses, and what happens if you say nothing.
- AI liability for law firmsProfessional indemnity gaps, the Mata v. Avianca precedent, SRA expectations and five questions for your broker.
- AI liability in recruitment and HRHiring is high risk under EU AI Act Annex III point 4. Bias exposure, coverage gaps and pre-deployment checks.