Insurability Is Decided by the Same Evidence as an Audit

State regulators have approved more than 80% of carrier filings that exclude AI from conventional coverage, and at the same time the Artificial Intelligence Underwriting Company (AIUC) launched in July 2025 with a $15M seed round, reported as the largest in insurance history, to sell affirmative cover priced off a certification audit. The insurance market for AI agents is splitting in two, and which side you land on is decided by the same evidence an auditor asks for: attribution and an audit trail. The attribution and audit trail properties the environment already produces are what an insurer underwrites. A team that produces that evidence as a byproduct of how its agents run is insurable. A team that cannot is the default case, and the default is deployer pays, out of pocket.

Traditional carriers are writing AI out

The exclusions arrived in 2025 and 2026, and they are broad. ISO filed three generative-AI exclusion endorsements for commercial general liability policies (CG 40 47, CG 40 48, CG 35 08), issued around January 2026, barring coverage for harms "arising out of generative artificial intelligence." Berkley filed an "absolute" AI exclusion for D&O, E&O, and fiduciary lines: no coverage for claims attributable to "any actual or alleged use, deployment, or development of Artificial Intelligence." Hamilton adopted similar wording, and Business Insurance reports that major carriers including Chubb, Travelers, and Berkshire Hathaway received regulatory approval for AI exclusions, with more than 80% of such filings approved by state regulators.

Even where no exclusion applies, an agent failure may simply not trigger the policy. The problem has a name: "silent AI." Most cyber policies trigger on a security breach. An agent that malfunctions with no attacker involved, the Replit-style failure, may fall outside the wording entirely, and neither insurer nor insured knows until a claim is litigated. Vendor contracts close the gap from the other direction: outside the well-developed copyright indemnities, AI coding vendors disclaim defect liability and cap exposure, so the gap lands on the deployer. The full picture is on who pays.

An insurer is writing AI in, priced off an audit

AIUC's model is a three-pillar loop: a standard (AIUC-1), an independent audit (Schellman was the first accredited auditor), and insurance priced off the audit result. Per Fortune's launch coverage, "insurance policies cover customers and vendors in the event an agent causes harm, with pricing that reflects how safe the system is," and the audits adversarially try to make agents fail, hallucinate, and leak data. The backers are telling: Nat Friedman led the round after watching enterprises hesitate on Copilot as GitHub's CEO, and the founding team came out of Anthropic, METR, and consumer underwriting.

Coding agents are explicitly in scope. AIUC's 2026 whitepaper with Lovable identifies 75 coding-agent-specific risks and frames the stakes plainly: "A hallucinated authentication pattern is no longer an inconvenience, it's a vulnerability shipping to production." Lovable is the first agentic-development platform pursuing certification, with a Schellman audit scheduled for summer 2026. AIUC is not alone on the affirmative side: Munich Re's aiSure has sold insurance-backed AI performance warranties since 2018, and AXA XL added generative-AI cyber endorsements in October 2025.

The insurer's claims question is the auditor's first question

The insurer's first claims question and the auditor's first question are the same: whose change was this, what did the agent have access to, and what was the approval chain? AIUC-1's Accountability category requires assigning accountability, logging AI system activity, and maintaining AI failure plans; the Q2-2026 update added agent identity and permissions explicitly. That is the attribution and audit trail properties restated as insurance prerequisites, and both fall out of the environment design rather than a separate compliance project.

Academic work reaches the same place. Zhu's Insurance of Agentic AI (arXiv, June 2026) argues no single product covers agentic risk and that pricing any of the layered coverages depends on "improved governance, transparency, telemetry." An environment without a queryable per-task event log is not just non-compliant, it is uninsurable at a fair price. The same session log the agent reads to resume after a crash, which is also the auditor's evidence as a byproduct, is the claims file an insurer underwrites.

Four moves close the gap before renewal

  • Check your own policies for AI exclusions. Berkley-style absolute exclusions and the ISO endorsements arrive at renewal and can silently remove coverage you assumed you had.
  • Turn the IP indemnities on, deliberately. The GitHub/Microsoft and Anthropic copyright indemnities are conditional: paid tier, filters enabled. An environment that doesn't enforce the conditions forfeits the one vendor promise that exists.
  • Retain the audit trail on a claims timeline. An insurer's or plaintiff's discovery window runs years, not an auditor's twelve-month lookback. Evidence as a byproduct only works if you keep the byproduct.
  • Expect insurability questions in procurement. Certification priced into premiums means "are you certified or insurable" will show up in enterprise questionnaires the way SOC 2 does. Lovable's summer-2026 audit is the first coding-agent test case.

Two gaps. As of June 2026 there is no public AIUC policy form, named carrier, disclosed limits, or paid claim; the model is documented, the loss experience is not. And no court anywhere has decided liability for a defect in agent-written code. The bifurcation is real and moving, but one half of it is still untested paper.