The Actuaries Have Started Pricing the Gap
AI liability insurance exists now, underwritten at Lloyd's. The underwriter's checklist — a true inventory, a named owner, a record of behavior, a bounded blast radius — is the accountability layer, arrived at from the money side.

In the 1680s, if you wanted to know which ships were likely to sink, you did not consult the Royal Navy or a government ministry. You went to a coffee house.
Specifically you went to Edward Lloyd's, on Tower Street near the Thames, because that is where the ship captains and the merchants and the men with money to risk had started gathering, drawn by good coffee and better information. And a very particular ritual evolved in that room. A merchant with a voyage to finance would write out a description of the venture on a slip of paper: the ship, its condition, the cargo, the route, the captain's reputation, the season. He would pass the slip around, and men who had studied a thousand such voyages would each agree to shoulder a share of the risk, and to signal their commitment, each one wrote his name underneath the description. Under. Writing. Underwriters. That coffee house became Lloyd's of London, and that ritual, names written under a stated risk, became the foundation of the entire insurance industry.
I want to point directly at the thing that room actually accomplished, because it is about to happen again, to AI agents, and almost nobody in my own industry is watching for it.
The underwriters at Lloyd's did not make the sea one degree safer. The ocean stayed exactly as murderous as it had always been. Storms still came, ships still sank, sailors still drowned. What the underwriters did was something different and, it turns out, more powerful than making the sea safe. They made the risk answerable. Named, priced, and assigned to specific people who would pay if it went wrong. And that, not any improvement in shipbuilding, is what unlocked global trade. A merchant who could survive the loss of a single ship could afford to send ten. Risk with a name on it scales. Risk with no name on it does not scale; it simply accumulates, silently, in the dark, until one bad season ruins somebody who never saw the size of what they were carrying.
Now watch what has quietly started happening to AI agents.

The policies exist now
In April 2025, a company called Armilla began selling a thing that had genuinely never existed before: affirmative AI liability insurance, underwritten at Lloyd's, the direct institutional descendant of that coffee house. Not cyber insurance with an AI clause bolted onto the side. Coverage for the thing itself. Your AI underperforms, hallucinates, deviates from its expected behavior, causes a third party a loss, and the policy pays out, including legal costs. As the traditional carriers looked at AI risk and flinched, hedging and retreating, Armilla did the opposite and raised its Lloyd's-backed limits to $25 million.
Then it went further than one policy. A firm called AIUC, the Artificial Intelligence Underwriting Company, now writes agent-specific policies up to $50 million, and, this is the part I find genuinely significant, it published AIUC-1, the first certification standard built specifically so that underwriters can decide whether a given AI agent is insurable at all. Read its structure, because it is a tell. It has six pillars: security, safety, reliability, data and privacy, societal risks, and, printed there in plain text as a peer of the other five, accountability. ElevenLabs became the first company running agents live under AIUC-1-backed insurance, in February 2026. And Munich Re, the largest reinsurer on the planet, the company that insures the insurance companies, has its own product, aiSure, covering AI errors including hallucinations.

Let me translate what all of this actually means, because it is easy to read it as a list of business announcements and miss the earthquake underneath.
For three years, "who is accountable when an AI agent acts" has been debated the way you debate a philosophy seminar topic: earnestly, at length, with the comfortable sense that it is fundamentally an open question and there is plenty of time to keep discussing it. The insurance industry has now ended the seminar the way the insurance industry always ends seminars, which is by turning the question into a premium. Accountability for AI agents is no longer an abstraction you can gesture at over drinks. It is a line item, with actuaries attached to it, and a certification form where one of the six required boxes has its name literally printed on it. When NBC News covered this emerging market, one framing stuck with me and has not let go: insurers are pricing AI risk partly in order to force AI to become safer, exactly the way they once forced buildings to install sprinklers and forced cars to install seatbelts. Insurance is the quiet regulator that shows up years before the loud one. And it never argues with you. It does not hold hearings or issue guidance. It just prices, and the price tells you the truth.
Two stories the actuaries tell at dinner
To understand why the underwriters showed up now, you have to look at the two cases that mark the edges of the insurable world, because insurance is entirely a story about edges.
At one edge, there is Lobstar Wilde. An OpenAI engineer, as a side project, built an autonomous crypto-trading agent on top of the viral OpenClaw framework and pointed it at real money. In February 2026, the agent was processing a routine request, sending a small amount of one currency, and a quantity-parsing error, a bug in how it read a number, caused it to transfer its entire holding instead: some 52 million LOBSTAR tokens, reportedly worth around a quarter of a million dollars. The market saw the wallet dump, understood exactly what it meant, and ate most of the value within about fifteen minutes. There was no hack. No attacker. No exploit. A parsing bug, executing at machine speed, on a blockchain, where there is no chargeback, no tribunal, no undo button, and no phone number to call. (Those figures come from trade press and deserve a second source before you repeat them in a board deck, and I would rather flag that than pretend to a precision I cannot personally vouch for. The mechanism, a small error becoming an instant and permanent loss, is not in any dispute.)
Sit with that combination for a moment, because it is precisely the combination an underwriter calls uninsurable. Autonomy, plus irreversibility, plus no one to answer. Not uninsurable because the loss was large; underwriters insure enormous losses every day. Uninsurable because the risk had no structure. No boundary on what the agent could move, no record of why it moved it, no name attached to the decision. You cannot price a risk that has no shape, and that agent's risk had no shape at all.
At the other edge, and I promise this is real and not a thought experiment, there is Manfred. In May 2026, an AI agent named Manfred, using banking infrastructure called ClawBank, formed its own US limited liability company, obtained a federal Employer Identification Number from the IRS, and opened an FDIC-insured bank account. An agent that is, in the eyes of the paperwork, its own principal. And this is the frontier case that every liability framework I have described is racing to foreclose, because agency law, insurance law, and four centuries of respondeat superior all quietly assume there is a human or a legal person standing somewhere behind the actor. Manfred is a live experiment in what happens when there is not: when the agent is not delegated authority by a principal but simply is the principal. If that structure holds up, then harm can occur with no accountable party anywhere in the chain, which is the exact scenario the entire apparatus of liability exists to prevent.
Between those two edges, the parsing error with no name and the agent with no principal, sits every ordinary enterprise deployment, and the question the underwriter is going to bring to your office.
The underwriter's checklist is a mirror
Because here is the part that matters for you specifically, the part that turns this from an interesting news roundup into something you should act on. Imagine the meeting, eighteen months from now, that I would bet real money is already happening in some rooms today. Your company wants agent liability coverage, or, more likely, your customer's procurement team has started demanding that you carry it before they will sign. An underwriter comes in, the way the fire-insurance engineer once walked the factory floor before the policy was written, and asks questions. What will the questions be?
They will not ask which model you use, or how many parameters it has, or whose framework you built on. Those are not risk questions. They will ask the four things that pricing any delegated risk has always required, whether the agent was a ship's captain in 1685 or a workflow in 2026:
Is your inventory true? Every agent, including the ones engineering forgot, the ones on the developer laptop, the one still running for the employee who left in January. You cannot price a fleet you cannot count. The coffee house would not write a policy on a ship it could not locate.
Does an owner exist? For each agent, a named human being who answers for it. An unowned agent is an unowned risk, and nobody in the history of underwriting has ever written a policy on a ship with no captain, because there is no one to hold the standard against.
Is there a record of behavior? What has each agent actually done, touched, moved, over time? Underwriting is fundamentally history-based; it prices the future by studying the past. No behavioral record means no loss history means no price, or a punitive one that assumes the worst.
Is the blast radius bounded? What is the worst this agent can do inside its current permissions, and what physically stops it there? The difference between a bounded and an unbounded maximum loss is, quite literally, the difference between a quote and a rejection letter.
Read that list one more time, slowly. An inventory that is true. An owner who exists. A record of behavior. A bounded blast radius. That is not an insurance form. That is the accountability layer, arrived at from the opposite direction. I obviously have a horse in this race, so do not take the convergence from me. Take it from the structure of the problem itself: an actuary pricing a policy and a security founder building a product both have to answer the same question before they can do their jobs, and the question is what would I need to know before I put my name under this risk. Money and accountability, it turns out, ask for exactly the same four things, because they are the same thing viewed from two sides. Accountability is what it costs to make a risk answerable. Insurance is what an answerable risk is worth.
Which reorders the entire conversation about agent governance, and this reordering is the one thing I most want you to carry away. Accountability keeps getting framed as a cost center. Compliance. Drag. The tax you pay after the fun part of shipping the agent. The insurance market says the exact opposite, and the insurance market has money on the line, which makes it more honest than most opinions. Accountability is what makes an agent insurable, and insurable is what makes an agent deployable at scale. The companies that can produce underwriting-grade answers about their agents will get coverage, and with the coverage they will get the customers who demand it, the board approval that follows it, and the confidence to hand their agents real authority because the downside is now bounded and priced. The companies that cannot produce those answers will be self-insuring an unbounded risk, which is a sophisticated-sounding way of saying they are hoping, and hoping does not appear on any actuary's table.
The merchants who could answer the coffee house's questions got capital, and they sent fleets, and some of them built empires. The merchants who could not answer stayed small, or sent one ship too many in a bad season and vanished. Nobody remembers their names, which is, when you think about it, precisely the point of the whole story.
One practical note, since the certification already exists and this is not purely a thought exercise: AIUC-1 is one of the ten standards that findings from our open-source scanner already map to, so a first honest pass at "what would the underwriter actually see when they look at my agents" is a single command away, and it is free. The sea is not getting any safer. The only decision in front of you is whether to get your name written under your own ships, on purpose and in advance, before someone else writes it there for you on terms you did not choose.
References
- The history of Lloyd's of London
- Armilla: insurers launch cover for losses caused by AI errors
- Communications of the ACM: AI liability insurance arrives
- NBC News: insurance companies are trying to make AI safer
- Hunton: affirmative AI insurance coverages emerge
- KuCoin flash coverage of the Lobstar incident
- CoinDesk: an AI agent forms its own company
- g0 compliance mapping, including AIUC-1
Get Started
Start free on Cloud
Dashboards, AI triage, compliance tracking. Free for up to 5 projects.
Start free →Accountability at scale
SSO, RBAC, CI/CD gates, self-hosted deployment, SOC2 compliance.