RiskMandate v1.19.0
The insurability layer for agentic AI

Make your agents insurable.

You cannot insure what nobody can describe. So we start with one agent: everything it can actually reach, what you authorised it to do, and the gap between them, written down as a policy you correct and keep. The Insurability Index is what those policies add up to — it is where this goes, and we say so rather than implying a number we do not yet compute.

Measured against the standards underwriters are adopting ISO/IEC 42001OWASP Agentic Top 10NIST AI RMFISO/IEC 27001
The problem

Cover is being withdrawn. Evidence buys it back.

Exclusions are attaching at renewal faster than teams can respond. Affirmative cover exists, but every carrier writing it asks the same question — and most teams cannot answer it in writing.

Filings Many

P&C groups have filed to exclude AI

Standardised AI exclusion endorsements are now in circulation, and some exclusions on D&O and E&O lines are absolute rather than partial.

Approvals Most

of those filings have cleared review

Whether AI is covered is decided policy by policy, jurisdiction by jurisdiction, at each renewal date — not once, centrally.

The gate 1

question decides the outcome

Can you show what your agents can reach, and evidence that the controls hold? Everything else follows from that answer.

Figures on this page describe a market in motion and are stated qualitatively on purpose; we cite specific filings and form numbers in the assessment itself, dated, rather than on a page that ages.

The state you are already in

Nothing is coming. You already connected it.

There is no deadline here, and we are not going to invent one. The exposure was created the moment somebody clicked authorise — last month, probably, on a mailbox or a drive — and it has never been enumerated. Below are three sentences from three vendors' own documentation, with the dates we read them. We have attached no adjective to any of them.

Mail
The only scope that lets anything read a message reads every message in the mailbox. There is no scope that filters by sender, by label or by date.
Derived from the publisher's own scope definitions at developers.google.com, read 12 September 2026. Quoted in full, with the scope names, in Lab 01.
Files
The default file-search corpus is defined by its own publisher as files owned by or shared to the user.
The corpora default at developers.google.com, read 12 September 2026. So everything a colleague, client or counterparty ever shared with that person is inside the default search on day one, without anybody choosing it.
The corporate file estate
Site-specific permissioning is not supported because the underlying search is tenant-wide.
A vendor's own connector security guide, read 12 September 2026 — a published statement that the intended narrowing mechanism is unavailable, leaving revocation as the only remaining lever.

The grant is user-shaped, not data-shaped.

The unit of restriction is the application, never the material. There is no supported way to say this assistant may read my files except the folder the legal team shared with me, or my inbox except messages from outside the company. Which means the only honest question is not whether to allow it. It is what, exactly, was allowed — and nobody has written that down.

Why this year rather than last

Two things changed, and neither of them was us.

If the state has always been like this, the fair question is what is different now. There are two dated answers and we did not write either of them.

1 January 2026 A standard exclusion took effect

The standard liability forms much of one large market runs on acquired a generative-AI exclusion, announced 21 October 2025 and effective on that date, and several carriers have filed their own — one of them absolute. The market replacing that cover prices on a description of what the agent is permitted to do. Something a business thought it had is being withdrawn on a date, and the thing replacing it asks a question most cannot currently answer.

9 March 2026 Responsibility was assigned

A national consumer regulator published that if an agent a business uses does something illegal, the business is responsible — and that businesses should be clear about what tasks an agent is allowed to perform, what data it can access, and what constraints apply. That is a regulator describing this document without naming it. It is current, and it is domestic.

Both are cited by date rather than characterised, and both are somebody else's publication. If your agent does something you did not authorise, the question you will be asked is what you did authorise — and that is the document this site exists to produce.

What we sell

One agent, written down.

An Agent Behaviour Policy is a description of one agent in one deployment: four objects, and the verb attached to each says how it is established. Three of them a person can write down out of what they understand today. The fourth is computed, and it is the one nobody has looked at.

Grant

Everything it can reach

Not what somebody decided to give it. What it can actually reach in this deployment, including everything nobody thought about.

measured
Mandate

What you authorised it to do

The job, written down. The one object only you can supply, and it takes minutes because you already know it.

elicited
Delta

The gap between the two

Excess where it can and you did not ask; shortfall where you asked and it cannot. Never written by hand, recomputed whenever either input moves.

derived
Barrier

What stands in the way

Per capability, one of four kinds — and only the fourth bounds anything. A prohibition shown without its barrier is a claim we cannot support.

recorded

A policy is a draft and it is meant to be argued with. It goes to the people who built the agent, the people who own what it touches and the people accountable for it, and each corrects the part they know. It is delivered as a vault rather than a document, because the operator needs instructions, leadership needs a decision and security needs evidence out of the same record — with a named owner, a review trigger and every version kept.

AGENTS.mdMANDATE.mdGRANT.mdDELTA.mdLICENCE-TO-OPERATE.md
Where this goes

Three rungs. We are on the first.

Insurability is the destination and the behaviour policy is the doorway. Each rung needs the one below it, which is why we are selling the bottom one rather than the top.

01

The label — the behaviour policy

What the agent can do, what you authorised, the gap, and what is in the way. Context-free, so it is the same document wherever the agent runs. No score: it describes and it does not judge.

What we sell
02

The patient record — the twin

A read-only model of the environment the agent is actually in: the assets, the tools, the data, what is connected to what. This is where the grant stops being a deployment shape and becomes yours, and it is the point at which the exposure means anything.

Design, part built
03

The prescription — the Index and the acceptance

The two combined, dated, with a named owner and an expiry, so the decision comes back. This is the only rung with a score on it, and the only one somebody signs.

Design

Stated this way on purpose. The rungs below the score are the ones that make it mean something, and a number composed from rows nobody can check is the thing this whole model exists to avoid. The six levels and the five dimensions further down are the published design for rung three — the shape it will take, not a number we compute today.

The difference

Questionnaires describe. Evidence prices.

Underwriting agentic risk today runs on self-reported answers. The same three questions produce very different outcomes depending on where the answer comes from.

QuestionnaireRiskMandate
Where the answer comes from Someone's recollection. A security lead fills in a form once a year, from memory and a spreadsheet that was last accurate in March. The deployment, one capability at a time. Which agent, running where, with which class of credentials — and from that shape, every capability it can reach, each with what actually stands in the way of it. Recomputed when the shape moves.
What the underwriter gets A yes or no. No severity, no aggregation, no way to tell a contained agent from one holding standing production access. A priced exposure. Loss bands per agent, aggregate across the fleet, and concentration in shared models and vendors.
What happens at claim The answers get tested. Application warranties are examined after the loss. This is where cover is most often lost. The record holds. Timestamped control state, containment tests and an immutable action log, assembled before anything went wrong.
The Insurability Index · rung three

Six levels. One number, eventually.

This is the design for the top rung: where an agent estate sits, what an underwriter will offer at each level, and the gap to the next one as a work order. Select a level to see what it buys. It is published before it is built on purpose, so the commitment stays checkable afterwards.

The Index is a composite of five dimensions, weighted by how much each one moves a price. It is composed from behaviour policies rather than from a form: each one states capabilities and the barrier against each, so the number is an aggregate of rows that can be checked individually. Weights are set by underwriting judgement today and re-fit as loss experience accumulates — we say so rather than implying an actuarial precision that does not yet exist.

What gets measured · the design

Five dimensions, weighted by price impact.

What the Index is composed from, and how much each part moves a price. The weights below are underwriting judgement rather than fitted loss experience, and they are the design rather than a running calculation.

30%

Exposure containment

How bad one agent can get. Reachable actions, systems touched, the value of the authority it holds, and whether the damage is reversible.

Drives severity
20%

Authority definition

Whether every agent has a written mandate: purpose, permitted actions, data scope, and the points where a human must intervene.

Drives frequency
20%

Attestation integrity

Whether control state is evidenced continuously rather than asserted once a year, with logs and revocation tests that hold up under examination.

Drives warranty credibility
20%

Loss quantification

Expected loss per agent expressed as a range, not a point. A wide range is itself a finding — it means getting clarity is the next thing to fund.

Drives pricing
10%

Accountability

Who owns each accepted risk, for how long, and at what retention. Acceptance without a named owner and an expiry date is not acceptance.

Drives legal standing
Who it is for

One score. Both sides of the renewal.

For enterprises and mid-market

Mandate

Map every agent's blast radius, evidence the controls that contain it, and walk into your renewal with an evidence pack instead of a questionnaire.

  • A measured grant per agent, derived from the deployment shape rather than from a questionnaire
  • A written mandate per agent, generated from what the agent can actually reach
  • Continuous attestation mapped to ISO 42001 and the OWASP Agentic Top 10
  • A renewal report your broker can submit without rewriting

Sits on top of your existing identity and posture tools. We read; we are never in the request path.

For brokers, carriers and MGAs

Ledger

Price agentic risk from what is actually deployed in the insured's environment, and see where the same exposure repeats across your book.

  • Submission triage scored on evidence rather than self-reported answers
  • Exposure derived from the environment, with the derivation shown
  • Concentration view across shared models and vendors in a portfolio
  • An acceptance ledger that maps cleanly onto a policy period

Carrier-neutral by design. We score the risk; you set appetite and price.

The mechanic · rung three

Every risk gets an owner and an expiry.

A finding sitting in a backlog is not a decision, and an underwriter cannot price it. RiskMandate puts each risk through one of three doors, assigned to a named person for a stated interval. When the interval ends, the decision comes back.

Accept

Own it

A named executive holds this exposure for a set interval, with the amount written down.

Fund

Pay to reduce it

The exposure justifies budget. The number is what makes the case.

Fix

Remove it

Narrow the mandate or revoke the access, and the radius closes.

Revisit next quarter There is no fourth door. Silence is not a decision anyone can underwrite.

The acceptance workflow is a published approach rather than a running system: a risk is accepted by a named person for a stated period, and the interval is what brings the decision back. Implementation is not claimed. It belongs to the third rung, and it needs the first one underneath it — there is nothing to accept until somebody has written down what the agent can actually do.

Questions

What people ask first.

Is RiskMandate an insurance policy?

No. We are not a carrier, a broker or an MGA, and we do not sell or place cover. RiskMandate measures insurability and produces the evidence that underwriters price against. Your broker and carrier relationships stay exactly as they are.

Do you sit in the runtime path?

Never. All connectors are read-only and out of band. A governance layer that can take your agents down is a new source of the risk it was bought to measure.

Does this replace our agent security tooling?

No, and it is not meant to. We connect to what you already run — identity providers, cloud IAM, agent posture and access-governance tools — and translate their output into exposure an underwriter can read. If you have no controls at all, we will tell you that before you buy anything.

How is the Index calculated, and can we see the working?

It is a weighted composite of five dimensions, each derived from environment telemetry rather than a questionnaire. Every score decomposes to the evidence behind it, and the methodology is published. Weights are set by underwriting judgement today and re-fit as loss experience accumulates.

How long does a first assessment take?

Connector setup is typically under a day. A first Index and gap list land inside two weeks, which is deliberately shorter than most renewal windows.

Where does our data go?

Metadata about agent scope and permissions, not the contents of what your agents process. Self-hosted and sovereign deployments are available where the data cannot leave your boundary.

Before your carrier asks

View a policy. Then buy the one for your agent.

Fifteen example Agent Behaviour Policies are on this site, free, read live from their vaults with published keys. Pick the application closest to yours and read it. When you want the one that describes your deployment — the mandate corrected, a name on the licence, no public key — it is four levels at the store, from £5 for the pack to £1,500 with a professional's signature on it.