RiskMandate v1.28.0
Insurance · the question, answered · 18 September 2026

Can you insure a software program? Yes, and it has been done for decades.

The interesting part is what got insured each time: the maker's liability, one named defect, the behaviour of the code, the accuracy of a model's output, and now the actions of an agent. Every step closer to the program itself has needed a better description of what the program does where it runs. That is the question this site exists to answer, so here is the history, dated and sourced, and where an Agent Behaviour Policy sits in it.

Context: RAND, How Is Artificial Intelligence Insured?, 16 September 2026. This page as markdown: insure-a-program.md.

01 · The question

One question, and the one under it.

Can you insure a software program, and has that ever been done? It is the first thing anybody asks when AI insurance comes up, and it deserves a dated answer rather than an opinion. The current account of how carriers answer it for AI is RAND's How Is Artificial Intelligence Insured? of 16 September 2026 (Romanosky and Robinson, report RR-A5130-1): through exclusions, endorsements, affirmative cover, or silence. Under that question sits the one this site is built around: can an individual agent be insured in its deployment, in the environment and context it actually runs in?

The makerInsured since the 1980s.

Technology errors and omissions cover pays when a program fails to perform as intended and a third party loses money. It insures the vendor's liability, not the code.

The programInsured, several times, on its own terms.

One named defect in 1997. The behaviour of a smart contract since 2019. A model's output against a threshold since 2018, as a warranty since 2024.

The agentInsured since February 2026, and only with a description of the deployment.

The first affirmatively insured agent deployment came with thousands of tests behind it, and the underwriters' own blueprint says the model is not the unit of risk. The deployment is.

02 · Has it ever been done

Eight dated answers, oldest first.

Each entry names what was insured and who held the cover. The sources are the insurers', the courts', the regulators' and the trade press's own pages, with the date on each; where a page could not be reached, the entry says what was read instead.

  1. 1980s

    The maker's errors, as professional liability

    Data processors' errors and omissions cover insured “liability arising from errors and omissions in performing data processing for outside entities on a fee basis”; computer software design E&O gave “professional liability coverage for computer software designers, analysts, and consultants to cover errors in programs or in systems design”. IRMI dates the rise of professional-liability claims around computers to the mid-to-late 1980s, and a 2006 survey of the market's evolution puts AIG's more comprehensive forms, errors and omissions included, at 2000. Nobody has published the date of the first such policy.

    IRMI glossary entries, undated, read 18 Sept 2026 · IRMI, Bregman, 18 Aug 2017 · Majuca, Yurcik & Kesan, The Evolution of Cyberinsurance, 2006
  2. 1997–1998

    One defect in every program, priced and then excluded

    Y2K was the first time the industry insured a specific fault in software as such. AIG launched Millennium Insurance in early 1997; the programmes required an audit and “commanded premiums in the six figures”; one fund manager “bought a $100 million Y2K insurance policy for a premium of $75 million”. Then the market excluded it: ISO's CG 21 60, CG 21 61 and IL 09 35 removed cover for “any actual or alleged Y2K (failure to recognize a year-date) hardware or software failure”, approved in most states with effect from 1 April 1998, and AIG withdrew its own form in August 1998 citing adverse selection. Cover was still being sold through Lloyd's, AIG and Aon in 1999, “quite expensive”, with “large deductibles” and “extensive pre-coverage audits”.

    Society of Actuaries, James, Feb 2025 · Rough Notes, April 1998 · FindLaw, March 1999
  3. 2018

    A model's output, guaranteed

    Munich Re says it wrote “our first AI policy for anti-fraud model in 2018”: if the model “fails to catch a fraud event, we provide a payout amounting to the losses incurred”. The line, aiSure, insures “performance warranties” a vendor gives its customer, with the error-rate threshold set after the reinsurer has assessed the data-science process. In February 2026 Mosaic put up to 15 million of capacity behind it for AI vendors “when an AI model fails to meet clearly defined performance thresholds”.

    Munich Re, Insure AI FAQ, undated, read 18 Sept 2026 · Emerj, 29 May 2023 · Mosaic, 26 Feb 2026
  4. 2019–2020

    The code itself, as the thing insured

    Nexus Mutual, a discretionary mutual, opened Smart Contract Cover in July 2019: the trigger is “unintended code usage that results in a material financial loss”, on a named contract at a named address. The first payout came in February 2020, about $31,000 across two claims on the bZx protocol, approved by member vote after the protocol's own post-mortem admitted a fault in the code. The 2021 wording widened it to economic design failure, oracle manipulation and governance attacks, and excluded phishing, key loss and known bugs. It is the clearest case on record of cover written on a program's behaviour rather than on its author.

    CoinDesk, 20 Feb 2020 · Nexus Mutual forum, 25 Feb 2021 · Coin Bureau, 29 Mar 2023
  5. 1991 → 2026

    The courts, on whether a program is a product

    Product liability law “is geared to the tangible world” (Winter v. G.P. Putnam's Sons, 9th Cir. 1991). An algorithmic risk tool “is neither ‘tangible personal property’ nor remotely ‘analogous to’ it” (Rodgers v. Christie, 3rd Cir. 2020). Then a chatbot app was “a product for the purposes of Plaintiff's claims” arising “from defects in the Character A.I. app rather than ideas or expressions within the app” (Garcia v. Character Technologies, M.D. Fla., 21 May 2025; settled January 2026). In the EU the question is closed by statute: Directive 2024/2853 defines a product to include “software”, operating systems, applications and AI systems however supplied, and applies to products placed on the market from 9 December 2026. The UK Law Commission is reviewing “whether software qualifies as a product when supplied in an intangible format”, consultation due October 2026.

    Rodgers v. Christie, 5 Mar 2020 · McGuireWoods, 18 Mar 2026 · Directive (EU) 2024/2853, OJ 18 Nov 2024 · Osborne Clarke, 14 Apr 2026
  6. 2023–2024

    A warranty on an AI model, sold to the buyer

    Armilla's warranty, backed by Swiss Re, Greenlight Re and Chaucer, “reimburses customers for fees paid to use an AI model if it fails to meet quality standards after passing the company's assessment”. One80 Intermediaries' term sheet of June 2024 makes the shape exact: the named insured is “the purchaser of the AI model”, the limit is the “annual cost of the model”, the premium “3% to 5% of the model subscription”, and the cover grant is that “the Vendor's services will perform in accordance with the performance and fairness metrics set forth in the assessment”. The same year Vouch sold AI E&O to start-ups and Coalition added an affirmative AI endorsement to cyber cover, for AI as an attack vector rather than as a source of wrong output.

    TechCrunch, 15 Feb 2024 · One80 term sheet, 17 Jun 2024 · Coalition, 26 Mar 2024
  7. 2025

    Liability for what the AI did, and the exclusions that made room for it

    Chaucer and Armilla put a standalone AI liability cover on Lloyd's paper on 22 April 2025, triggered by “the failure of the AI solution to perform as intended, generate critical errors, hallucinations or inaccuracies leading to damages”. AIUC launched in July with cover “tied directly to audit results” and a standard, AIUC-1, for “AI agent security, safety and reliability”. Going the other way: W. R. Berkley filed an absolute exclusion for claims from “any actual or alleged use, deployment, or development of Artificial Intelligence”, and Verisk announced three optional generative-AI exclusions for general liability, CG 40 47, CG 40 48 and CG 35 08, on 21 October 2025, effective January 2026. California's AB 316, signed 13 October 2025, says “it shall not be a defense that the artificial intelligence autonomously caused the harm”.

    Chaucer, 22 Apr 2025 · Insurance Journal, 25 Jul 2025 · Hunton, 28 May 2025 · IIABA, 21 Oct 2025 · AB 316
  8. 2026

    An agent, insured in one deployment

    On 11 February 2026 ElevenLabs announced the first deployment insured under AIUC-1: “an AI agent providing incorrect information to a customer, can be insured against”, after “5,835 technical tests across 14 risk categories”; neither release names the carrier or the limit. Armilla's cover rose to $25 million per organisation in January and named “AI Agent Failures (incorrect decisions, improper tool use, escalation errors)”; Chaucer's Vanguard AI structure of 10 February lists “AI agent actions” as a loss without “an underlying cyber event”. RAND's report of 16 September reads the filings: “Most AI policies still remain silent on AI agents, while AIUC and Armilla affirmatively cover them.”

    ElevenLabs, 11 Feb 2026 · Armilla, 21 Jan 2026 · Chaucer, 10 Feb 2026 · RAND RR-A5130-1, 16 Sept 2026
03 · What was insured, each time

Eight kinds of cover, eight different things insured.

Lined up, the answers to has it been done are also the answer to how. Every time cover moved closer to the program, the underwriter wanted a description of what the program does in the place it runs: an audit, a named address, a threshold, a term sheet's “metrics set forth in the assessment”, a test log. Without that description the cover is either on the author or it is silence.

What is insuredWho holds itWhat triggers a claimExample, dated
The maker's liabilitythe vendora third party loses money because the program did not perform as intendedtech E&O, described by IRMI 2003; Chubb claims scenario 2019
One named defectthe operatora year-date failure, after an auditY2K cover 1997–99; excluded from standard forms from 1 Apr 1998
The code's behaviourthe user of the contract“unintended code usage that results in a material financial loss”Nexus Mutual Smart Contract Cover, July 2019; first payout Feb 2020
The model's outputthe vendor, for its customeroutput below a stated thresholdMunich Re aiSure, first policy 2018; Mosaic capacity Feb 2026
The model's performance, as a warrantythe purchaser of the modelfailure against “the performance and fairness metrics set forth in the assessment”One80 / Armilla term sheet, June 2024
The deployer's liability from AIthe business using it“hallucinations or inaccuracies leading to damages”; bodily injury or property damage from AI useChaucer / Armilla, Apr 2025; HSB, Mar 2026; Testudo, 2025–26
An agent's actionsthe vendor and its customers“incorrect decisions, improper tool use, escalation errors”; “tool call failures”Armilla, Jan 2026; AIUC / ElevenLabs, Feb 2026
Nothingany claim “arising out of … any actual or alleged use, deployment, or development of Artificial Intelligence”W. R. Berkley absolute exclusion, 2025; ISO CG 40 47 / 40 48 / 35 08, Jan 2026
What the numbers say about scale. The underwriters' own blueprint puts today's standalone AI limits at “up to $50 million”, “one or two orders of magnitude below what the largest enterprise deployments will demand” (AIUC, Underwriting the Agent Economy, July 2026, p. 50). RAND's reading of 125 admitted-market filings is that carriers are “some offering affirmative coverage for certain risks (e.g., model errors), and others filing broad exclusions”, and that most “are remaining silent … leaving coverage for such losses untested and open to dispute” (RR-A5130-1, 16 Sept 2026).
04 · The question under the question

An agent is not insured as a program. It is insured in a deployment.

The question under the question is whether an individual agent can be insured in its deployment or context environment. The people now writing the cover answer it in their own words. The blueprint published by the Artificial Intelligence Underwriting Company in July 2026, with authors from a reinsurer, two insurers, RAND and several universities, puts it like this:

“A certified AI agent autonomously executing trades in a brokerage poses very different risks than a certified AI agent handling internal document summarization for a law firm. The underlying model and guardrails might be the same, but the legal exposure, potential severity of loss, and probability of a claim will diverge enormously.”

Trout et al., Underwriting the Agent Economy, AIUC, July 2026, p. 51

The same report lists what an underwriter must ask about the agentic system, beyond revenue and sector: “Does it recommend actions or execute them?”, “How much human oversight is involved?”, “Agent access-control configurations”, “Agent observability tools”, “Human oversight and handoff protocols” (p. 51–52). Earlier it expects that “underwriters will again need recognized minimum standards for issues like least-privilege scoping of the tools and data exposed to agents through protocols such as the Model Context Protocol”. A cyber analytics firm told Insurance Business in April 2026 that insurers now examine an agent's permissions, the controls on its high-impact actions, and its monitoring. And an underwriter at Armilla told Reuters in August 2026 that “the harder cases are where there is no conventional attacker and potentially no unauthorized credential use”: the agent did what its credential allowed, and nobody had said that was not allowed.

What the underwriter asksWhere an Agent Behaviour Policy answers it
Does it recommend actions or execute them?Every row of the grant is a capability, verb.object.reach, with how it was established: measured on the thing itself, documented from the vendor's page, or inferred. Execute and recommend are different verbs.
Agent access-control configurationsThe grant is what the credential and the deployment actually permit, including what nobody thought to check; the mandate is what the business authorised. Their difference, the delta, is the excess authority, recomputed whenever either moves.
Human oversight and handoff protocolsEach capability carries the kind of thing that stands in its way: nothing, an expectation, a setting, or a boundary with an enforcer. Only the last is a control, and the ABP says which rows have one.
Least-privilege scoping of tools and dataThe same capability through two paths is one row with two doors, so a connector's real reach is written down, not its label. Sixteen template vaults show what that looks like for named shapes.
Observability, logs, incident recordsThe behaviour policy lives in an encrypted vault with every version kept, a read key the underwriter can hold, and the evidence tier on every number.

So the honest answer to can you insure an agent in its deployment is: yes, two carriers have started to, and the thing they price on is a description of that deployment which most businesses cannot yet produce. The first job is producing it.

05 · Where we come in

Make agents insurable, starting from the bottom.

RiskMandate is not a carrier, a broker or an MGA, and does not sell or place cover. The strategy is to make agents insurable by producing the evidence underwriters price against, in the order the evidence has to exist. The bottom rung is the part that exists today and is for sale: Agent Behaviour Policies, and the means for anyone to create one.

On sale nowRung 1 · Describe it

Agent Behaviour Policy

the building block

One agent, in one deployment: everything it can reach, what you authorised, the gap, and what stands in the way of each thing. Sixteen template vaults, free to read with their keys published; four levels at the store, from a downloaded pack to a professional's signature. And a prompt, MAP-A-GRANT.md, that lets the agent holding a credential measure its own grant, so the description can be created by anyone, not only by us.

The library of behaviour policies →
Template availableRung 2 · Authorise it

Licence to Operate

the instrument

The business is the authority, the behaviour policy is the instrument, the agent is the licensee, for an interval, with each condition beside its enforcer. It is what turns a description into something a board has signed and an underwriter can hold a business to.

The licence →
In designRung 3 · Insure it

Insurability Index

the record an underwriter accepts

Composed from behaviour policies rather than from a questionnaire, so every number decomposes to rows that can be checked. Published as a design before it is built, on purpose, so the commitment stays checkable.

The design →
Why the building block first. Every dated answer above ends the same way: the cover got written once somebody could describe the program's behaviour where it runs, and got withdrawn where nobody could. The RAND report's recommendation is an AI Coverage Notice, so a buyer knows whether AI loss is covered, excluded or left silent by line. Our side of that is the other half of the conversation: a business that can hand its broker one document per agent saying what it can reach, what it was told to do, and what actually stops it. That document is a behaviour policy, and the pieces are open source and CC BY 4.0 so the format outlives us.
06 · Sources, and what could not be read

Every claim above carries its date.

Read on 18 September 2026 unless the entry says otherwise. Two pages refused a direct read and are cited through what could be read: RAND's own page and PDF returned 403 to us, so the report's findings come from its abstract in search indexes and from the trade press of 18 September; the Justia page for Winter likewise, so its sentence is confirmed only through a search index. The One80 term sheet, the AIUC report PDF and the Nexus Mutual wording were read in full.

RAND, How Is Artificial Intelligence Insured? / The Insurability of Artificial Intelligence, RR-A5130-1, Romanosky & Robinson, 16 Sept 2026 · Insurance Business, most carriers are silent on AI, 18 Sept 2026 · AIUC, Underwriting the Agent Economy, July 2026 · AIUC-1, the standard, version Q3-2026 · Romanosky, Ablon, Kuehn & Jones, Content analysis of cyber insurance policies, Journal of Cybersecurity, 2019 · IRMI, Tech E&O Insurance — A Primer, 1 Nov 2003 · IRMI, Year 2000 exclusion, undated · Chubb, E&O claims scenarios, 27 Feb 2019 · Munich Re, Insure AI, undated · Munich Re, HSB AI liability insurance, 18 Mar 2026 · Testudo, testudo.co, undated; Fintech Global, 9 Mar 2026 · Armilla, affirmative AI liability insurance, 30 Apr 2025 · One80 Intermediaries, AI warranty coverage, 21 May 2024 · Evertas, Lloyd's coverholder status, 3 Feb 2022 · Munich Re, Google Cloud Risk Protection Program, 2 Mar 2021 · Insurance Business, agentic AI underwriting, 16 Apr 2026 · Insurance Journal (Reuters), insurers review wordings for agents, 27 Aug 2026 · Hunton, AI Liability Directive withdrawn, 14 Feb 2025 · Policyholder Pulse, AI exclusions, 13 Apr 2026 · CSIS, the insurance industry's retreat from AI, 4 Sept 2026 · arXiv: Insurance of Agentic AI, 3 Jun 2026; The Insurability Frontier of AI Risk, 6 May 2026; trace-economic underwriting, 15 Jun 2026.

Not claimed here. The carrier and limit behind the ElevenLabs cover; AIUC's $50 million product limit and its Beazley capacity, reported behind a paywall; the total Y2K premium written; the first-ever tech E&O policy. Where a company is named, the page says what its own release says and when, and nothing about how good it is.