Insure Your Agent

Three questions to ask before anything else.

Read each one, answer it honestly for your own business, then read the guidance. If you can answer all three well, you are ahead of most operators we hear from. If you cannot, the next step for each is right there. About ten minutes.

01

Do you have documentation of what your agents do, and of the guardrails around them?

Write down, on one page, every AI agent running in your business today. For each, note what it may do, who it talks to, which tools or APIs it can call, what data it can read and write, and which decisions need a person to approve them. If you cannot fill this in during an afternoon, you do not yet have documentation.

Good looks like a short operating manual a new hire could read in fifteen minutes and come away understanding the whole AI footprint of the company. It is plain, a little boring, and updated every time someone changes an agent. It lists the known failure modes and the guardrails that catch them. It names an owner for each agent.

The test is whether a reasonable person outside your company would read it and conclude the business knows what it is running. If the honest answer is "some of it lives in our heads", or "our CTO keeps meaning to write it down", that is the gap. Regulators, insurers and claimants' lawyers will all ask for this document. You want it to exist before they do.

Red flagsNo single list of agents. Guardrails set in prompts and never written down. No named owner per agent. No record of the last review. Production agents running on a developer's personal API key.

Next: assess against a published standard

02

Have you read your current insurance for AI exclusions?

Gather every policy the business holds: errors and omissions, cyber, general liability, directors and officers, and any media or technology liability wrapper. Send them to your broker with one question: "Please tell me in writing how each of these policies responds to a claim arising from an AI agent deployed in our business." Then read the answers.

Good looks like a written position on each policy, referring to specific clauses, with any AI exclusion identified by number and page. A verbal "it will be fine" is not an answer. A broker who cannot tell your AI agent from any other piece of custom software is the wrong broker for this. The area is moving quickly enough that the quality of your broker matters more this year than it did last year.

What you are watching for is silent cover turning into explicit exclusion. A policy that quietly covered you in 2024 may exclude AI at a 2026 renewal. A policy that never addressed the question will turn on how a claims adjuster reads the wording after the event. You want the written position, and the direction of travel, on every line.

Red flagsThe broker cannot produce a written response. An AI related exclusion with no alternative buy back. Policies renewing in the next ninety days that nobody has re-read. Anyone saying "we have always been covered for everything".

Next: six questions for your broker

03

Do you have a plan for the day an agent causes harm?

Picture a call at 9:04 on a Tuesday morning. A customer tells your support team that your agent promised them something yesterday the company cannot honour, and they have already acted on it. The loss is real without being catastrophic, and the customer is angry and threatening to post about it. Who takes the call, who decides to pause the agent, who tells the affected customers, and who decides whether to notify a regulator?

Good looks like a one page playbook with named roles, a kill switch any on call engineer can flip without a deployment, a prepared message for customers, another for the regulator in your jurisdiction, and a written decision tree for when to bring in outside counsel. It has been rehearsed at least once, in a tabletop exercise, with the people who would really be on the call.

The aim is not to prevent every incident. Incidents will happen. The aim is to contain the harm, record your response honestly, and be able to show a regulator or insurer later that the business acted reasonably. A reasonable response with an imperfect outcome can be defended. No plan at all cannot.

Red flagsNo written kill switch procedure. No named incident owner. No messages drafted in advance. Counsel not briefed on the AI footprint. "We would figure it out on the day."

Next: build the incident plan

What your answers mean. A readiness check, not a grade.

Insurers writing AI cover ask for exactly these artefacts before they quote. If you have them, the next step is straightforward. If you do not, building them is straightforward too. Either way, you move.

All three, with evidence

Go to the coverage path. You can put a credible file in front of a broker now.

Gaps on one or two

Work through the path. An assessment against a published standard produces the evidence you are missing.

Gaps on all three

Start with the first question. You cannot review policies or plan a response without knowing what the agents actually do.

The coverage path