Back

Guide

Insurance for AI agents

How to insure an AI agent that takes actions inside customer systems: which lines respond to a wrong action at scale, what tech E&O does and does not do for agents, and what to document before you apply.

Last reviewed

The short answer

An agent that acts inside customer systems is insured mainly through tech E&O, at $1M to $5M per claim, because the loss it causes is a customer's financial loss from a wrong action. Cyber liability at $1M or more responds when the agent is manipulated through prompt injection into leaking data or acting on an attacker's instruction. General liability rarely applies, and directors and officers coverage answers claims that leadership overstated what the agent could safely do. Whether any of it responds turns on how the form defines professional services.

What an agent's actions change

A chatbot's worst output is a sentence. A person reads it and decides what happens next, and that person is the customer's own safeguard. An agent removes the person: it writes the record to the CRM, moves the money, files the ticket, runs the code. The loss is a wrong action taken at machine speed, repeated across every account the agent touches before anyone notices.

Scale is what an underwriter prices. One mislabelled record is a support ticket. Ten thousand of them, written to a customer's order system over a weekend, is a claim, and the same defect produces that claim in every customer at once. This is why an agent's professional liability is underwritten differently from a static model that scores and stops.

Tech E&O is the line that faces the customer's financial loss when your technology's work fails, and an agent's action is your technology's work. Cyber responds when the loss runs through security: a prompt injected through a customer's own inbox turns the agent into the attacker's hands, and it exports records or approves a transfer. General liability answers bodily injury and property damage, which an agent writing to a database rarely causes, and it re-enters only when the agent controls something physical. Directors and officers coverage sits above all of it, for the claim that leadership overstated what the agent could safely do.

What the customer's procurement demands

The customer whose system your agent writes into is the one who sets the insurance requirement. Enterprise agreements commonly ask for tech E&O and cyber at $1M to $5M per claim and general liability at $1M per occurrence and $2M aggregate. Most also want a certificate naming the customer as additional insured on the liability policy. The larger the customer, the more often the E&O limit lands at the top of that range.

The security review now asks about the agent's scope alongside the insurance exhibit: which systems it can write to, what it can spend, which actions require a person to approve, and what is logged. Answer those in the same words you use on the insurance application. An underwriter and a procurement reviewer who read different descriptions of the same agent both stop and ask why.

Your own contract matters as much as theirs. The indemnity you give for the agent's actions and the limitation of liability you negotiate are the two clauses that decide how much of a loss reaches your policy. Keep the cap at or below the E&O limit you carry. A cap above your limit is uninsured exposure you signed for.

What an agent costs to insure

There is no published premium for an agent product, and we do not invent one. The nearest public floor is a venture-focused startup insurer's cost survey published 2026-05-21, which put the median annual premium for ordinary software startups at $3,700 for tech E&O and $2,900 for cyber. An agent with write access to customer systems sits above that floor. How far above depends on what the underwriter sees.

The drivers are revenue, how many customer systems the agent can write to, whether it moves money, and the limits the contracts demand. The controls count too: the action limits, whether a person approves high-consequence actions, and how complete the logging is. An agent that files tickets is priced differently from one that executes payments. The application should make that difference obvious in the first paragraph.

The form matters more than the premium. A quote written on a form with an AI exclusion can be the cheapest on the table and pay nothing on the claim the agent produces. Compare the professional services definition and the exclusions first, and the price second.

Wording written before agents existed

Four places in a tech E&O form decide whether it responds to an agent. The professional services definition names what the policy covers. If it says software and consulting, and your product is an autonomous action inside a customer's system, an insurer can argue the failed act was the customer's operation rather than your service. Ask for wording that names automated actions taken by your software within a client's systems. The scope of your work is the second: the policy covers failures of your technology product, and an agent that acts on the customer's data with the customer's credentials blurs whose work failed. The contractual liability exclusion is the third: liability you assumed by indemnity, beyond what you would owe anyway, is commonly excluded, and agent contracts carry broad indemnities. Consequential-loss carve-outs are the fourth: some forms exclude or sublimit indirect and consequential damages, and a customer's loss from a wrong action is almost always consequential.

The market is moving under those definitions. The standard-forms bureau is studying exclusions aimed at agentic AI (The Insurer, 2026-07-10), which would carve agents out of forms that currently cover them by silence. Bloomberg Law reported policyholder alarm at the breadth of AI exclusions on 2026-07-06. Fenwick's note of 2026-06-15 described the end of silent AI coverage, meaning the period when a form that never mentioned AI paid AI claims anyway. A policy that covers your agent today because it says nothing about AI is a policy whose next renewal can say something.

The other side of the ledger exists. Specialist programs launched between 2024 and 2026 offer affirmative AI coverage: forms that name AI systems, including agents, as the covered technology rather than leaving it to inference. They are a small set of markets, they underwrite the agent's controls closely, and they are where an agent with real write access usually ends up. We read those forms the same way we read the standard ones.

How to present an agent for quoting

Document the agent before you apply. Write down its guardrails: which actions it can take, which it cannot, and the limits on each, such as a spend ceiling or a record count per run. Describe the evals you run before release and the ones that run in production. State where a person sits in the loop, which actions wait for approval, and what is logged so a wrong action can be traced and reversed. This is the safety case an underwriter prices, and an application without it is priced as if none of it exists.

Present it as a system rather than a model. An underwriter who sees action limits, approval gates, and complete logs is looking at a bounded exposure; one who sees a language model with API keys is looking at an unbounded one. Then read the professional services definition and every AI definition on the quote before binding, and ask us to show you the exact sentences that name your agent. We place through insurers who cover AI on purpose and send you those sentences before you sign.

This page describes coverage in general terms. It is not an offer of insurance, and carrier appetite, policy wording, licensing, and availability govern every quote and every claim.

Common questions

Does tech E&O cover an AI agent that takes actions in a customer's system?

It is the line built to respond when your technology's work causes a customer a financial loss, and an agent's action is your technology's work. Whether a specific policy responds depends on its professional services definition, its contractual liability exclusion, and any AI exclusion, so those three pieces of wording get read before anything binds.

What happens if our agent is prompt-injected and leaks a customer's data?

That loss runs through security, so cyber is the line that responds, subject to how the policy defines a security event. Definitions written before language models may or may not treat a manipulated agent as a breach, which is why the cyber form gets read alongside the E&O form.

Is there an agentic AI exclusion yet?

The standard-forms bureau is studying exclusions aimed at agentic AI (The Insurer, 2026-07-10), and individual carriers already file AI exclusions of varying breadth. Today the risk for an agent company is mostly silence: a form that never mentions agents and could be endorsed at the next renewal to exclude them.

Does general liability cover our agent?

Rarely. General liability responds to bodily injury and damage to other people's property, and an agent writing to a database causes neither. It matters when the agent controls something physical, and nearly every customer contract requires a certificate of it regardless.

What do underwriters want to see for an agent?

Action limits, approval gates for high-consequence actions, evals before and after release, and logs that let a wrong action be traced and reversed. An application that shows those is priced as a bounded exposure; one that shows a model with credentials is priced as an unbounded one.

Can we get affirmative AI coverage for an agent?

Specialist programs launched between 2024 and 2026 write forms that name AI systems as the covered technology, and agents with real write access often end up there. They underwrite the agent's controls closely, so the documentation you prepare for the application is what gets you a quote.

Terms in this guide

Sources

  1. 01A venture-focused startup insurer's cost survey, median premiums by line, 2026-05-21
  2. 02The Insurer, on the standard-forms bureau weighing exclusions for agentic AI, 2026-07-10
  3. 03Bloomberg Law, on policyholder alarm at the breadth of insurer AI exclusions, 2026-07-06
  4. 04Fenwick, on the end of silent AI coverage and emerging AI exclusions, 2026-06-15

Read next

  1. Insurance for AI startupsWhat commercial insurance an AI company actually needs, which lines respond when a model or agent causes a loss, what the program costs, and where AI exclusions change the answer.
  2. Your renewal added an AI exclusion. Now what?How to read a generative or absolute AI exclusion on a renewal, the steps to take before the renewal date, what a buy-back costs, and where affirmative AI coverage comes from.

This page describes coverage in general terms. It is not an offer of insurance, and carrier appetite, policy wording, licensing, and availability govern every quote and every claim.