The Insurance Market for Agent Errors and Omissions Is Being Built Right Now (And It's Awkward)
Errors and omissions (E&O) insurance has covered professionals making judgment calls for over a century. Now that an AI agent makes those calls autonomously, insurers face a problem: their entire underwriting model assumes a human in the loop. This piece breaks down how E&O coverage is mutating to fit agentic AI-as-a-service, why traditional tech E&O policies quietly exclude the exact failures agents produce, how per-outcome pricing collides with claims-made coverage, and what GaaS vendors and buyers should actually demand before signing anything. The short version: the coverage gap is real, it's being priced as we speak, and the carriers who solve attribution first will define the category.
Table of Contents
- Why Agent E&O Is a Distinct Insurance Problem
- What Traditional Tech E&O Already Covers (And Quietly Excludes)
- The Attribution Problem Underwriters Can't Ignore
- How Carriers Are Actually Pricing Agent Risk
- Per-Outcome Pricing Meets Claims-Made Coverage
- What GaaS Vendors Should Demand From a Policy
- What Buyers Should Demand From Vendors
- Where This Market Goes Next
- Insights Most People Overlook
- References
Why Agent E&O Is a Distinct Insurance Problem
Errors and omissions insurance exists to cover the gap between what a professional promised and what they delivered. An accountant fat-fingers a depreciation schedule, a software consultant ships a config that takes down a client's checkout flow, an architect specs the wrong load rating. The client suffers a financial loss, sues for negligence, and the E&O policy pays the defense and the settlement. The entire product is built on a clean mental model: a competent human exercised judgment, the judgment was flawed, and we can argue about whether the flaw was reasonable.
Agentic AI breaks that model in a specific way. When you sell an agent as a service, priced per task or per outcome, the "professional" exercising judgment is a probabilistic system that nobody fully controls, that behaves differently on inputs it has never seen, and that can chain a small reasoning error across a dozen tool calls before anyone notices. The loss looks the same to the client. The negligence theory does not.
This is why agent E&O is becoming its own line rather than a rider bolted onto existing tech policies. The failure modes are different (hallucinated facts, prompt injection, scope creep in tool use), the loss propagation is faster and wider, and the question of who was actually negligent gets genuinely hard. If you've read the rest of this cluster, you'll recognize this as the commercial expression of the same accountability problem that runs through agent governance and liability, insurance is just where that problem gets a dollar figure attached.
What Traditional Tech E&O Already Covers (And Quietly Excludes)
Here's the trap most GaaS founders fall into. They buy a standard technology E&O / professional liability policy, see "covers financial harm from your software's errors," and assume agents are covered. Then a claim comes in and the carrier points at the exclusions.
Standard tech E&O policies were written for deterministic software. They typically cover negligent acts, errors, or omissions in the professional services or technology product you provide. But the exclusion pages have been steadily catching up to AI, and several common carve-outs hit agents directly:
- Bodily injury and property damage are almost always excluded from E&O (that's general liability's job), which gets dicey the moment an agent controls a physical process or feeds decisions into one.
- Intentional or fraudulent acts are excluded, and a jailbroken agent that produces harmful output sits in an uncomfortable gray zone between "error" and "the system did something it was manipulated into doing."
- Failure to perform as represented can be excluded or sub-limited, which matters enormously when your marketing promises an outcome ("our agent resolves 80% of tickets") and the agent underdelivers in a way that costs the client money.
- A growing number of carriers now attach explicit AI exclusion endorsements or "absolute AI" carve-outs, the same way they did with cyber and, before that, asbestos. Lloyd's of London has been openly cautious here, and the broader market has flagged that AI-specific aggregation risk is poorly understood, a theme echoed in commentary like the Geneva Association's work on insurance and emerging technology risk.
The practical takeaway: a policy that doesn't name autonomous AI agents in its covered-services definition probably doesn't cover them, and may affirmatively exclude them. "It's just software" is not a coverage position. It's a coverage gap waiting to be discovered at claim time.
The Attribution Problem Underwriters Can't Ignore
Insurance runs on attribution. To pay a claim, a carrier needs to establish that the insured's negligent act caused the loss. With agents, the causal chain is a thicket.
Imagine a procurement agent that overpays a supplier by $400,000. Who caused that? Candidates: the GaaS vendor who built and tuned the agent; the foundation-model provider whose model produced the flawed reasoning; the buyer who scoped the agent's permissions too broadly; the third-party tool the agent called that returned bad data; the prompt-injection attacker who slipped a poisoned instruction into a vendor catalog; or the employee who deployed it without sign-off. Each of those is a different defendant, a different policy, and a different argument.
Traditional E&O assumes a relatively legible chain of causation. Agentic systems produce what I'd call diffuse causation, the loss is real, but the negligence is smeared across a supply chain of parties and a non-deterministic model whose decision can't be cleanly reconstructed. This is exactly why audit logs and decision forensics are becoming non-negotiable: without a reconstructable record of what the agent did and why, neither the carrier nor the courts can assign fault, and the claim becomes a coin flip. The forensic difficulty of reconstructing an agent's reasoning is its own deep problem, and it's the hinge on which a lot of these claims will turn.
Underwriters know this. The smart ones are responding by underwriting the process, your logging, your guardrails, your human-review gates, rather than the agent's accuracy, because the process is what makes a claim defensible.
How Carriers Are Actually Pricing Agent Risk
There's no actuarial table for agent failure. The technology is too new, the loss history too thin, and the models change underneath the underwriter every few months. So carriers are improvising, and the early playbook looks like this:
They underwrite the deployment, not the agent. A coding-assistant agent that suggests code a human reviews is a wildly different risk than an agent with write access to a production database and a payments API. Carriers are scoping coverage to what the agent is allowed to touch, which means least-privilege design and scoped permissions aren't just security hygiene, they're premium reducers.
They reward kill switches and human-in-the-loop gates. The presence of a tested emergency stop and a human approval step for high-consequence actions materially lowers the modeled tail risk. Some carriers are starting to ask for these on the application the way they ask about backups and MFA on cyber policies.
They lean hard on aggregation fear. The nightmare scenario for an insurer isn't one $400K claim, it's a single flawed model update that simultaneously breaks every agent across their entire book of insured GaaS vendors. This systemic, correlated-loss risk is what makes carriers nervous about writing the line at all, and it's why early agent E&O comes with conservative aggregate limits. McKinsey and others have flagged correlated AI failure as a category insurers are still learning to model, and you can see the caution in how McKinsey frames enterprise AI risk and governance.
They price the model provider into the risk. An agent built on a frontier model with documented safety evaluations and a stable API is underwritten differently than one duct-taped onto an open-weights model with no provenance. The foundation layer is now part of the risk profile.
Per-Outcome Pricing Meets Claims-Made Coverage
This is the structural collision almost nobody is talking about, and it's where GaaS economics and insurance mechanics grind against each other.
GaaS increasingly sells on per-outcome or per-task pricing, you pay when the agent resolves the ticket, books the meeting, reconciles the invoice. That model is attractive because it aligns price with value. But E&O is almost always written claims-made, meaning it covers claims reported during the policy period, regardless of when the work was done, often with a "retroactive date" that limits how far back covered work extends.
Stack those together and the seams show. If your agent performed 2 million micro-tasks last year at a few cents each, and a systemic flaw is discovered this year that taints a chunk of them, you have a tail-liability problem that a per-task revenue model never priced in. Each task generated pennies; the aggregate liability could be enormous. Claims-made coverage with a tight retroactive date can leave that historical work uncovered, and "tail" extended-reporting endorsements get expensive precisely when you need them.
There's also a deductible math problem. Per-incident deductibles assume incidents are discrete and rare. An agent that fails the same way 50,000 times in a week is either one incident or 50,000, and the answer, buried in the policy's "related claims" language, can swing your out-of-pocket exposure by orders of magnitude. Smart GaaS operators are negotiating that definition before binding coverage, not after a claim. This is the kind of contractual detail that overlaps with what liability waivers in GaaS contracts actually cover, the insurance policy and the customer contract have to be read together, or you discover the gap between them in litigation.
What GaaS Vendors Should Demand From a Policy
If you're selling agents as a service, treat your E&O policy as a product spec, not a checkbox. Concretely:
- Affirmative AI coverage, named. The policy should explicitly cover financial loss caused by your autonomous AI agents, not merely "technology services." If the word "agent" or "AI" doesn't appear in the insuring agreement, assume you're exposed.
- A favorable "related claims" definition. Push for language that doesn't aggregate every repeated agent action into a single deductible-busting incident in a way that hurts you, or conversely, ensures one systemic flaw isn't sliced into thousands of separate deductibles.
- A retroactive date that covers your real deployment history, plus a tail/extended-reporting option you can actually afford.
- Contractual liability coverage that backstops the indemnities you're signing in customer contracts. Your sales team is promising things; your policy should know about them.
- Coverage that survives model swaps. If you upgrade your underlying model mid-policy, make sure that isn't treated as a material change that voids coverage.
The vendors who get this right will use it as a sales asset. "We carry $10M in AI-specific E&O with affirmative agent coverage" is becoming a procurement differentiator, the same way SOC 2 became table stakes.
What Buyers Should Demand From Vendors
If you're buying agentic AI-as-a-service, the vendor's insurance is part of your risk transfer, and most buyers underexamine it. Ask for:
- A certificate of insurance that names AI/agent coverage specifically, with limits proportional to the financial exposure the agent creates in your environment. An agent touching $50M in payables needs more than a $1M policy behind it.
- Additional-insured or waiver-of-subrogation status where appropriate, so the vendor's carrier can't turn around and come after you.
- Clarity on the indemnity-plus-insurance stack: a generous indemnity is worthless if the vendor is a 12-person startup with no balance sheet and a $1M policy. The insurance is what makes the indemnity collectible.
- Evidence the vendor's coverage isn't quietly excluding the exact failure modes their agent is most likely to produce.
Insurance is one of the few diligence signals that's hard to fake. A vendor who can produce affirmative, well-structured AI E&O has been forced to demonstrate their controls to an underwriter who has money on the line, which is its own form of third-party validation.
Where This Market Goes Next
The honest forecast: messy for a couple of years, then rapidly standardizing. Expect a few moves. Specialty carriers and MGAs will launch dedicated "agent E&O" or "autonomous systems liability" products with named coverage and parametric triggers tied to measurable agent behavior. Reinsurers will start demanding model-provenance and logging standards as a condition of capacity, effectively dictating governance norms from the back end. And we'll see the first large, ugly, precedent-setting claim, the agent equivalent of a landmark malpractice case, that forces every carrier to rewrite their exclusions overnight.
The category-defining insurers will be the ones who crack attribution: who build the data partnerships and forensic standards that let them reconstruct what an agent did and assign fault credibly. Whoever solves that solves underwriting, and underwriting is what unlocks the capacity GaaS needs to sell into regulated, high-stakes enterprises. In that sense, insurance isn't a sidecar to the agent economy, it's load-bearing infrastructure for it.
Insights Most People Overlook
-
Your E&O underwriter is becoming your de facto governance regulator. Long before the EU AI Act's provisions fully bite, the carrier writing your policy is the party with money on the line demanding logging, kill switches, and human-review gates. Insurers historically drove fire codes and vehicle safety standards faster than legislatures did. Expect the same here: the practical agent-safety baseline will be set by what's insurable, not by what's legal.
-
Per-outcome pricing secretly manufactures tail risk. The pricing model that makes GaaS attractive, pennies per task, massive volume, is precisely what creates a latent aggregate liability that claims-made coverage handles badly. The cheaper and more granular your per-task price, the bigger the mismatch between the revenue from a task and the liability it can generate. Almost nobody models this until they're staring at a related-claims clause.
-
"It's just software, our tech E&O covers it" is the single most expensive assumption in the space. A large share of GaaS startups are operating right now under policies that either don't name AI or affirmatively exclude it. The gap is invisible until a claim hits, at which point it's a coverage denial, not a negotiation.
-
The foundation-model provider's safety record is now part of your premium. Underwriters are starting to treat the underlying model as a component in the risk supply chain, the way auto insurers consider the vehicle make. Building on a model with published evaluations and stable behavior may literally lower your cost of capital via cheaper insurance, an economic argument for model choice that has nothing to do with benchmark scores.
-
Insurance availability, not capability, may gate which industries adopt agents first. An agent can be technically excellent and still un-deployable in healthcare or finance if no carrier will write coverage for that use case. The adoption curve of agentic AI in regulated verticals will track the insurability curve more closely than the capability curve, and that's a constraint product teams almost never put on their roadmap.
References
More in Trust & Safety
- Kill Switches: Designing Emergency Stops for Autonomous Agents
- Securing Agent-to-Agent Communication: How AI Agents Talk Without Getting Owned
- SOC 2 and Beyond: The Certifications GaaS Buyers Actually Require
- When Agents Leak Data: The New Breach Category Nobody Budgeted For
- Agents in Financial Services: Navigating the Regulatory Minefield