You can already buy A-rated AI-agent insurance. The interesting question is not whether the agent economy gets insured; it is whether the coverage prices what makes an agent dangerous, and whether there is a record to settle a claim. Three checkable bets, resolving January 1, 2027.
In August 2020, a Citibank employee sat in front of an internal payment screen, meaning to send a $7.8 million interest payment on a Revlon loan. Through a confusing interface and a set of checkboxes that didn't do what the operators thought they did, the bank instead wired out the entire loan principal: $894 million, money that wasn't due until 2023. Citi asked for it back. About half a billion dollars' worth of lenders said no.
What followed was a two-year, nine-figure fight over a deceptively simple question: the action was authorized (the operator had the credentials and clicked the buttons) but was it what anyone intended, and who eats the loss when authorized and intended come apart? In February 2021, Judge Jesse Furman of the Southern District of New York ruled Citi couldn't claw the money back under the “discharge for value” rule. In September 2022, the Second Circuit reversed him unanimously and ordered it returned. Nearly a billion dollars turned on the gap between “the system did what it was told” and “the system did what we meant.”
Now swap the operator for an AI agent, and the confirmation screen for a tool-call permission. That gap is about to become an insurance question, and I want to make three dated, checkable bets about how fast, because “the agent economy will get insured” is exactly the kind of comfortable, unfalsifiable claim that deserves a resolution date stapled to it.
Here's the thing most “can you even insure AI?” takes get wrong: you already can. As I write this in mid-2026, A-rated capacity is writing standalone AI-liability coverage.
Armilla AI operates as a Lloyd's of London coverholder, and its standalone AI-liability policy is backed by a stack of carriers with the ratings that matter: Chaucer (AM Best A+), Axis Capital (A), Convex (A), Swiss Re (A+), and Greenlight Re (A-). Limits, the company says, reach up to $25 million per organization. And this is not vague “model risk” coverage: the product page carries a section titled, in as many words, AI Agent Failures, covering “claims arising from incorrect decisions, improper tool use, or escalation errors.” Improper tool use. That is your agent's failure mode, written into an insurance contract by a Lloyd's syndicate. Alongside it, Munich Re's aiSure product (distributed with the specialty insurer Mosaic) offers up to €15 million on a parametric-style structure that pays out on measurable performance failures.
So the naive question (will there be insurance for AI agents) is already answered: yes, with real carriers, real ratings, and real limits. Which means the honest, interesting questions are narrower and sharper. Does the coverage price the specific thing that makes an agent dangerous: how much autonomy and authority and permission it holds? And is there a mechanism (some record of what the agent actually did) that would let an adjuster settle a claim when one lands? Those two questions separate a genuine actuarial layer from a marketing wrapper, and each gets a bet.
A word on the format, because the format is the argument. The forecasting world has one habit worth stealing: a prediction isn't serious until it carries a resolution date and a resolution rule, a public artifact that will, on a fixed day, make you objectively right or wrong. Everything below resolves on January 1, 2027, against something you can pull up in a browser. Two of the three, as of today, resolve in the direction that makes this essay worth writing.
Resolves YES if, by 2027-01-01, an A-rated carrier's public product page or regulatory filing prices agentic-AI liability with premium or terms that vary by the agent's autonomy level or permission scope.
Today this resolves no, and the reason is precise. The coverage clears the first bar easily: a named, A-rated, standalone product that explicitly covers agent failures. But read how it's underwritten, and the autonomy tiering isn't there. Armilla keys its underwriting on a documented AI risk assessment plus independent certification. Munich Re's aiSure asks applicants for a technical description of the system, training-data sources, accuracy and hallucination benchmarks, operational-monitoring details, and a governance-framework description: documentation deliberately aligned with the EU AI Act's Annex IV and ISO/IEC 42001.
Notice what every one of those gates has in common: they describe what the system is and how tidily it was built. None of them prices how much rope the agent is given: whether it can spend money or only draft emails, whether it holds write access or read-only, whether a human confirms its high-stakes actions or it runs unattended. An agent that can wire funds unsupervised and an agent that can only summarize documents get underwritten through the same certification checklist. That is the gap the bet lives in. To resolve yes, someone has to publish terms where the premium moves because the authority moves, and as of mid-2026, no public artifact does.
Resolves YES if, by 2027-01-01, any of the publicly-documented A-rated AI-liability products makes a post-incident audit trail (a required, tamper-evident record of what the agent did and under what authority) a stated pricing factor or coverage condition. I am betting NO.
This one is an absence claim, so let me pin the resolution set to keep it honest: I'm grading against the publicly-documented AI-liability products of A-rated carriers as of the resolution date: Armilla and its syndicate, Munich Re's aiSure with Mosaic, and any named successor in that class. Not “the entire planet,” which is unfalsifiable; a defined, checkable list.
Against that set, the bet holds today, and the distinction is the whole point. Every underwriting requirement I can find is ex ante and about governance paperwork: show me your ISO 42001 alignment, your benchmark results, your monitoring plan. None is ex post and about the agent's behavior: show me the tamper-evident log that reconstructs what your agent did, and under what authority, at the moment of the loss.
Think of it as the dashcam problem. You can sell auto insurance without requiring a dashcam, for a while. Then claims volume climbs, disputes get expensive, “he said / she said” becomes “the camera says,” and the requirement quietly enters the contract. Pre-incident governance maturity tells an underwriter the shop is tidy. A post-incident audit trail tells a claims adjuster what actually happened, which is the only thing that lets you adjudicate a Citibank-shaped dispute. The market has priced the tidiness test and skipped the truth test, because claims volume on autonomous agents hasn't forced the issue yet. Bet 2 says it still won't have, publicly, by New Year's Day 2027. The coverage is shipping ahead of the mechanism that would make it underwritable, which is a genuinely strange and revealing place for a market to be.
Resolves YES if, by 2027-01-01, a publicized dispute (news report, court filing, or carrier statement) turns on whether an AI agent acted within its authorized scope.
No such dispute is publicly documented yet, which is exactly why this is a forward bet rather than a fact. But the template is not hypothetical; it's the Citibank wire, and it already cost nearly a billion dollars in the human version. The question that consumed two federal courts (was an authorized-but-unintended action within scope, and who bears the loss) maps one-to-one onto an agent that calls a tool it technically had permission to call, to do something no one actually wanted. The permission was real. The intent wasn't. Somebody's insurance policy will have to say whose problem that is.
The reason I'll bet this resolves yes before long is that the ingredients are all present: agents are being handed operational authority (Armilla is already covering “improper tool use”), the coverage exists to be disputed, and the underlying legal question is a known-expensive one with fresh appellate precedent. What's missing is a single loud enough incident. Given how the other two bets describe a market writing coverage without the audit trail to settle claims cleanly, a contested “was it in scope” fight isn't a tail risk. It's the natural first stress test of a market that sold the policy before it built the mechanism.
There's a piece of theory underneath all three bets worth naming, because it turns intuition into structure. In July 2026, Quanyan Zhu published a framework paper, “AI-Native Insurance for Agentic AI” (arXiv:2607.13230), that models an agent deployment as a risk state with five axes: autonomy level, operational authority, permission exposure, governance maturity, and dependency concentration. It's a single-author preprint, a mathematical framework rather than a book of real losses, and it should be read as theory. But its central structural result is the sentence every developer should sit with: the insurability region shrinks monotonically as exposure grows: the more autonomy and authority you give an agent, the smaller the set of terms on which anyone can insure it, with governance certification as the main lever that buys some of that region back.
Read that against the usual product instinct, which is “more capability, more value, ship it.” The actuarial view inverts it: the very thing that makes your agent useful (the autonomy to act without a human in the loop) is the thing that makes it hard to insure. Capability and insurability trade off against each other, and governance is the only dial that partly reconciles them. That's not a marketing story an insurer wants to lead with, which is part of why the market is quietly underwriting certifications instead of loudly pricing autonomy.
Here's the part that should change what you build on Monday, and it's the reason this market is worth a developer's attention at all: the risk state an insurer will eventually price is the risk state your architecture already exposes.
Autonomy level, operational authority, permission exposure, governance maturity, dependency concentration: that is not insurance jargon. That is a description of your agent's config file. The insurer pricing your policy and the attacker probing your system are reading the same spec sheet, and increasingly so is a plaintiff's lawyer. Which gives you three concrete moves, none of which requires waiting for the insurance market to mature:
| Bet | Resolves YES if (public artifact) | State as of mid-2026 |
|---|---|---|
| 1 | An A-rated carrier's public page/filing prices agentic-AI liability tiered on autonomy/permission scope | NO: coverage exists (Armilla covers “AI Agent Failures”), but underwriting keys on certification, not autonomy |
| 2 | Any such product makes a post-incident audit trail a stated pricing factor or condition | NO (bet holds): every gate is pre-incident governance paperwork |
| 3 | A publicized dispute turns on whether an AI agent was within authorized scope | Not yet. Citibank/Revlon is the pre-AI template |
That's the essay's real deliverable: not a prediction you have to trust, but a scorecard you can re-grade. On January 1, 2027, open Armilla's and Munich Re's product pages and any successor's, search your news feed for the first “was the agent authorized” claim dispute, and mark each row yes or no. If I'm wrong (if a carrier ships autonomy-tiered pricing, or an audit-trail requirement, or the scope fight lands early) that's not a loss for you; it means the actuarial layer matured faster than I bet, which is good news for everyone shipping agents.
But my money says you'll find a market that has sold the coverage and skipped the mechanism: writing policies on “improper tool use” while pricing on how tidy the shop is rather than how much rope the agent holds or what it did with it. The gap between those two is where the next $894 million lives. The difference from 2020 is that this time, you can see it coming, and you have until New Year's to instrument the record that proves what your agent actually did.
All market facts are stated as of mid-2026; this market moves quickly, and the January 1, 2027 resolution is the point: re-verify each product page on the date before grading.
Instrument the audit trail now, before anyone requires it: the tamper-evident record of what the agent did, under what authority, in what order.
That record is exactly what Chain of Consciousness produces: a signed, tamper-evident trail of an agent's decisions and the authority behind each one, the artifact that makes you debuggable today and underwritable tomorrow, and that can settle a “was it in scope” dispute when a Citibank moment arrives. It is one layer of the Agent Trust Stack, the harness for making agent behavior verifiable, claimable, and auditable rather than reconstructed after the loss from logs you didn't keep.
See Hosted Chain of Consciousness · Read the Theory of Agent Trust
pip install chain-of-consciousness · npm install chain-of-consciousness
Full trust stack: pip install agent-trust-stack · npm install agent-trust-stack