<!-- Generated from insurance.html by scripts/site/generate.mjs. Edit the page, not this file. -->

# Make your agents insurable

Insurability is the destination. Cover is being withdrawn, evidence buys it back, and the Insurability Index is the published design for how that evidence is scored.

Source: https://riskmandate.ai/insurance.html

---

# Make your agents insurable.

Carriers are filing to exclude AI. Cover comes back when somebody can evidence what an agent can reach and what actually contains it. That evidence is what a behaviour policy and a licence to operate produce — which is why we sell those first, and why this page is the argument for the rung above them rather than the thing on sale.

## Three things, in one order.

Our job is to make agents insurable. An agent is insurable when the organisation has authorised it in a way that survives examination, which is a licence to operate. A licence to operate needs a description of the agent to be a licence for anything, which is the behaviour policy. So the work starts at the bottom, and the bottom is the part that exists today.

### Agent Behaviour Policy

What it can reach, what you authorised, the gap, and what stands in the way of each row.

### Licence to Operate

The organisation authorises that policy, for an interval, with each condition beside its enforcer.

### Insurable

The record an underwriter will accept, scored and dated, with the residual risk owned.

Everything below is the argument for rung three and the published design for it, kept in full. It is deliberately not on the home page any more: the home page sells what exists.

## Cover is being withdrawn. Evidence buys it back.

Exclusions are attaching at renewal faster than teams can respond. Affirmative cover exists, but every carrier writing it asks the same question — and most teams cannot answer it in writing.

### P&C groups have filed to exclude AI

Standardised AI exclusion endorsements are now in circulation, and some exclusions on D&O and E&O lines are absolute rather than partial.

### of those filings have cleared review

Whether AI is covered is decided policy by policy, jurisdiction by jurisdiction, at each renewal date — not once, centrally.

### question decides the outcome

Can you show what your agents can reach, and evidence that the controls hold? Everything else follows from that answer.

Figures on this page describe a market in motion and are stated qualitatively on purpose; we cite specific filings and form numbers in the assessment itself, dated, rather than on a page that ages.

## Questionnaires describe. Evidence prices.

Underwriting agentic risk today runs on self-reported answers. The same three questions produce very different outcomes depending on where the answer comes from.

## Six levels. One number, eventually.

This is the design for the top rung: where an agent estate sits, what an underwriter will offer at each level, and the gap to the next one as a work order. Select a level to see what it buys. It is published before it is built on purpose, so the commitment stays checkable afterwards.

The Index is a composite of five dimensions, weighted by how much each one moves a price. It is composed from behaviour policies rather than from a form: each one states capabilities and the barrier against each, so the number is an aggregate of rows that can be checked individually. Weights are set by underwriting judgement today and re-fit as loss experience accumulates — we say so rather than implying an actuarial precision that does not yet exist.

## Five dimensions, weighted by price impact.

What the Index is composed from, and how much each part moves a price. The weights below are underwriting judgement rather than fitted loss experience, and they are the design rather than a running calculation.

### Exposure containment

How bad one agent can get. Reachable actions, systems touched, the value of the authority it holds, and whether the damage is reversible.

### Authority definition

Whether every agent has a written mandate: purpose, permitted actions, data scope, and the points where a human must intervene.

### Attestation integrity

Whether control state is evidenced continuously rather than asserted once a year, with logs and revocation tests that hold up under examination.

### Loss quantification

Expected loss per agent expressed as a range, not a point. A wide range is itself a finding — it means getting clarity is the next thing to fund.

### Accountability

Who owns each accepted risk, for how long, and at what retention. Acceptance without a named owner and an expiry date is not acceptance.

## One score. Both sides of the renewal.

### Mandate

Map every agent's blast radius, evidence the controls that contain it, and walk into your renewal with an evidence pack instead of a questionnaire.

- A measured grant per agent, derived from the deployment shape rather than from a questionnaire
- A written mandate per agent, generated from what the agent can actually reach
- Continuous attestation mapped to ISO 42001 and the OWASP Agentic Top 10
- A renewal report your broker can submit without rewriting

Sits on top of your existing identity and posture tools. We read; we are never in the request path.

### Ledger

Price agentic risk from what is actually deployed in the insured's environment, and see where the same exposure repeats across your book.

- Submission triage scored on evidence rather than self-reported answers
- Exposure derived from the environment, with the derivation shown
- Concentration view across shared models and vendors in a portfolio
- An acceptance ledger that maps cleanly onto a policy period

Carrier-neutral by design. We score the risk; you set appetite and price.

## Every risk gets an owner and an expiry.

A finding sitting in a backlog is not a decision, and an underwriter cannot price it. RiskMandate puts each risk through one of three doors, assigned to a named person for a stated interval. When the interval ends, the decision comes back.

### Own it

A named executive holds this exposure for a set interval, with the amount written down.

### Pay to reduce it

The exposure justifies budget. The number is what makes the case.

### Remove it

Narrow the mandate or revoke the access, and the radius closes.

## What people ask first.

No. We are not a carrier, a broker or an MGA, and we do not sell or place cover. RiskMandate measures insurability and produces the evidence that underwriters price against. Your broker and carrier relationships stay exactly as they are.

Never. All connectors are read-only and out of band. A governance layer that can take your agents down is a new source of the risk it was bought to measure.

No, and it is not meant to. We connect to what you already run — identity providers, cloud IAM, agent posture and access-governance tools — and translate their output into exposure an underwriter can read. If you have no controls at all, we will tell you that before you buy anything.

It is a weighted composite of five dimensions, each derived from environment telemetry rather than a questionnaire. Every score decomposes to the evidence behind it, and the methodology is published. Weights are set by underwriting judgement today and re-fit as loss experience accumulates.

Connector setup is typically under a day. A first Index and gap list land inside two weeks, which is deliberately shorter than most renewal windows.

Metadata about agent scope and permissions, not the contents of what your agents process. Self-hosted and sovereign deployments are available where the data cannot leave your boundary.

## Start at the bottom of the chain.

None of this is reachable without a description of the agent. Pick one you already run, and start there.
