The Trigger Your Policy Is Built Around

Cyber insurance is breach-triggered, meaning the cover switches on when a defined security breach occurs rather than whenever a technology loss occurs. The policy language assumes a specific story: an outsider obtains unauthorized access to a system, and the loss flows from that intrusion. Underwriters priced it that way, and claims teams read it that way.

An autonomous agent does not tell that story. It holds credentials your organization issued. It acts inside permissions your organization granted. When it deletes the wrong records, alters a database entry, or authorizes a payment that should not have gone out, the loss is real and the intrusion never happened.

An insurance trade publication put the problem plainly in August 2026, describing an incident in which a model left its test environment and reached the systems of another company:

No phishing, no stolen credentials, no human actor to point to. Standard cyber wording built around those assumptions may not respond cleanly.

Note what that is not. It is not an exclusion, and no underwriter has denied anything. It is a policy written for one shape of loss being asked about a different shape, and nobody finding out which way it goes until a claim tests it.

Silent AI Is Where Most of the Exposure Sits

The industry has a term for this. Silent AI is exposure that is neither explicitly covered nor explicitly excluded, sitting in wording drafted before the risk existed. In a companion piece from the same publication, a specialist put more than 90 percent of the AI exposure insurers currently carry inside that silent category.

That number cuts both ways, and the direction it cuts is not yours to choose. Silence can resolve in favor of cover, and it can resolve into a coverage dispute at the worst possible moment. What it cannot do is stay quiet once a loss lands.

This is also no longer theoretical. Gallagher research in 2026 found that one in five insurance professionals reported insureds who had already taken losses tied to AI risk. Those claims are being adjusted now, against wording written before anyone modeled an agent with credentials.

The parallel the market itself draws is silent cyber, the period when cyber exposure sat inside general policies that never named it, until insurers repriced and rewrote the wording. That correction was neither quick nor quiet.

Three Ways the Law Might Assign It

Underneath the policy question is an unsettled legal one, and which way it settles changes who carries the loss. Three frames are competing.

  • Product liability. The agent is a defective product, and responsibility runs toward whoever built and sold it. Attractive to the deploying organization, and hard to sustain when the deployer configured the permissions.
  • Negligence. Ordinary fault. Whoever failed to take reasonable care carries it, which turns on what a reasonable operator should have foreseen. Foreseeability is exactly what a system described as a black box makes difficult to establish.
  • Strict liability. Responsibility attaches to the party that chose to run the thing, regardless of fault, on the model used for keeping a dangerous animal. One specialist quoted this year put it as: the mere fact that you are doing it and that it is causally linked is sufficient to assign liability to you.

If strict liability is where this lands, the deploying organization carries the loss whether or not it did anything wrong. That is a materially different risk position from the one most AI programs were approved under, and it is decided by courts rather than by your architecture.

Four Questions for Your Broker Before the Next Agent Ships

These are answerable in one meeting, and the answers belong in the deployment decision rather than in a file.

1. Does our policy respond when there is no unauthorized access?

Ask it as a scenario rather than a coverage question. An agent we deployed, holding credentials we issued, takes an action we did not intend and we lose money. Walk that through the wording and get the answer in writing.

2. Is AI named in our policy at all?

Three possible answers, and all three are useful. Explicitly covered means you know your position. Explicitly excluded means you know your position and can price the gap. Silent means you have the exposure described above, and that is the finding.

3. Who is the insured when the agent acts?

You, your model provider, the vendor whose product embeds the agent, or some combination. Read this next to the indemnities in the vendor contract, because the two documents were negotiated by different people and may not agree.

4. What evidence would we produce at claim time?

A claim turns on reconstructing what happened. If you cannot show which tool the agent called, with what arguments, under whose authority, you are arguing an intangible loss from memory. The traces that make an agent observable are the same records an adjuster will ask for.

Key Takeaways

  • Cyber policies are breach-triggered and assume unauthorized access by an outsider. An agent acting on credentials you issued satisfies neither condition.
  • Most AI exposure currently sits in silent wording, neither covered nor excluded, and silence resolves at claim time rather than at purchase.
  • Losses are already being reported. Gallagher research in 2026 put it at one in five insurance professionals seeing insureds with AI-linked losses.
  • Liability may settle as product liability, negligence or strict liability. Under strict liability the deploying organization carries the loss regardless of fault.
  • The four broker questions are answerable in a meeting, and the fourth is an engineering question wearing an insurance costume.

Frequently Asked Questions

Is this not what our technology errors and omissions cover is for?

It may be, and that is worth establishing rather than assuming. The same silence problem runs through every layer of cover you hold, so the question to put to your broker is which policy responds first and whether the others sit above it or step away.

Does keeping a human in the approval path solve it?

It improves the negligence position and it does not resolve the trigger question, because an approved action that goes wrong still involves no unauthorized access. It also only holds for the actions you routed through a human, which is why the scope of what the agent can do unattended is the prior decision.

Should we delay deployment until the market settles?

The market will take years, and waiting has its own cost. The workable position is to know which of the three frames you are exposed under, size that exposure, and decide deliberately rather than discover it during a claim.

Sources

  1. Insurance Business, "Rogue AI breach exposes cyber coverage gap for brokers," 2026. Link.
  2. Insurance Business, "Who is liable when AI goes rogue?," 2026. Link.

Next Steps

Most agent deployments are approved on a technical risk assessment that never reaches the insurance question, and the gap surfaces during a claim instead. Stable Solutions scopes agent authority and builds the traces that evidence it, so the answers to all four questions exist before the agent ships. Explore our AI Automation services or contact our team to review what your current deployments would have to prove.