August 7, 2026 · 7 min read
AI Agent Insurance Is
Tightening in 2026

Key Definitions
Privileged Execution Layer CyberCube's H1 2026 threat brief characterization of AI agents: an autonomous software layer that can interact directly with critical systems and execute multi-step workflows, introducing new enterprise cyber risk pathways.
Generative AI Exclusion Three ISO commercial general liability endorsements (CG 40 47, CG 40 48, CG 35 08) effective January 2026 that exclude harm arising from generative AI from general liability coverage.
For much of the past decade, AI was framed by cyber insurers as a force multiplier that enhances malicious actors' capabilities. That assumption is becoming outdated as a new generation of autonomous systems — agentic AI — performs multi-step tasks across enterprise environments with limited human oversight. When insurance cannot price an agent, it excludes the agent. That wave of exclusions has already landed in 2026.
From Augmentation to Autonomy: Hidden Exposures
AI adoption is accelerating rapidly across industries. According to Darktrace, 78% of organizations already use generative AI in at least one business function, while more than 80% are expected to deploy AI models or applications in production by the end of 2026. At the same time, autonomous agents are beginning to execute multi-step operational workflows end to end, effectively embedding themselves within core business processes.
CyberCube's H1 2026 threat briefing characterizes AI agents as a new privileged execution layer capable of interacting directly with critical systems. Unlike AI treated as a mere tool, these agentic systems can execute harmful actions while appearing to follow instructions or propagate errors across interconnected systems. Even without external attackers, autonomous failures can trigger outages or data loss. CyberCube's William Altman notes: AI is compressing the cyberattack lifecycle, enabling impact before detection and containment are effective.
The 2026 AI Exclusions Are Already Written
In January 2026, the Insurance Services Office (ISO) issued three generative AI exclusions for commercial general liability: CG 40 47 (excludes Coverage A and Coverage B), CG 40 48 (limits the exclusion to Coverage B personal and advertising injury), and CG 35 08 (companion form). Several carriers adopted them within weeks. By April 2026, carriers including W.R. Berkley, Chubb, Travelers, Berkshire Hathaway, and Cincinnati Financial had filed to adopt ISO endorsements or proprietary AI exclusion language.
The broader picture is sharper. Berkley Insurance filed an absolute AI exclusion for D&O, E&O, and fiduciary lines covering any actual or alleged use, deployment, or development of AI. Hamilton Select uses comparable language. Berkshire Hathaway, Chubb, and Travelers secured state regulator approval to strip AI-related damages from corporate policies entirely. Cyber lines are the exception — most carriers there affirm coverage for AI-driven attacks. The broader liability market is moving toward blanket exclusions.
New Underwriting Logic: Permissions, Controls, Monitoring
The exposures that come with agentic AI mean traditional prevention-centric controls may be insufficient. Recovery capability — the ability to restore systems and data quickly — is emerging as a critical determinant of loss severity. CyberCube highlights three areas underwriters are watching:
Permissions — do AI agents run under least-privilege access or broad, potentially dangerous access levels? Controls — are there safeguards before agents execute high-impact actions like data deletion or system changes? Monitoring — do organizations have sufficient visibility into how agents interact with systems, and can they detect and respond to abnormal behavior?
Altman stresses robust identity security and regular patching as the fundamentals: AI does not introduce entirely new weaknesses; it amplifies existing ones. Underwriters are pricing the security program behind the agent, not the technology itself.
One Incident, Three Policies: How Boundaries Blur
An AI agent error rarely fits cleanly into one policy. The same incident can read as a professional mistake, a security failure, and a product defect at once, each pointing at a different insurance line with different wording, different exclusions, and a different appetite. Take a European advisory firm running an autonomous client-facing agent: an attacker crafts a prompt-injection input that causes the agent to (1) disclose another client's confidential file, (2) give materially wrong regulatory advice causing quantified financial loss, and (3) auto-execute a settings change that takes the portal offline for a day.
The wrong advice points to professional indemnity/E&O; the disclosure of a third party's confidential file points to cyber (data breach and privacy liability); the portal outage points to the cyber business interruption section. Recovery depends on three separate wordings holding at once, with no gap and no double counting. The failure mode is rarely total absence of cover — it is the seam between policies, where the cyber insurer argues the loss was professional advice and the PI insurer argues it was a security event, and the claim sits unallocated.
Three Things to Prepare Before Renewal
Capgemini's 2026 World P&C Insurance Report found that 42% of insurers track no AI metrics at all. Without loss frequency, severity, or correlation data, underwriters cannot price the risk; when they cannot price it, they exclude it. Enterprises should prepare three things before the next underwriter conversation:
A written AI inventory — what systems you run, what data they access, what tools they can call, and what they are authorized to do. Implemented controls — matching the emerging baseline, including access controls, monitoring, audit trails, and prompt-injection defenses, in place rather than planned. Documented evidence that controls have been tested — adversarial test outputs, remediation records, and a recurring testing cadence. A controls list without test results reads as self-attestation to an underwriter; an application with adversarial test outputs and remediation records reads as an underwritable risk.
References:
Frequently Asked Questions
What structural change hit the AI insurance market in 2026?+
The Insurance Services Office (ISO) filed three generative AI exclusions (CG 40 47, CG 40 48, CG 35 08) effective January 2026, and several carriers adopted them within weeks. Berkley Insurance filed an absolute AI exclusion for D&O, E&O, and fiduciary lines covering any actual or alleged use, deployment, or development of artificial intelligence. Berkshire Hathaway, Chubb, and Travelers secured state regulator approval to strip AI-related damages from corporate policies entirely. This is the underwriting response to agentic AI risk.
Why do insurers now treat AI agents as a new risk?+
CyberCube's H1 2026 threat briefing characterizes AI agents as a new privileged execution layer able to interact directly with critical systems. Unlike the era when AI was seen as a force multiplier, today's autonomous systems execute multi-step operational workflows end to end with limited human oversight. Even without external attackers, autonomous failures can trigger outages or data loss. Darktrace data shows 78% of organizations already use generative AI in at least one business function, and over 80% are expected to deploy AI in production by end of 2026.
What are underwriters watching for in AI agents?+
CyberCube highlights three areas: permissions — whether AI agents run under least-privilege access or broad, potentially dangerous access levels; controls — whether safeguards exist before agents execute high-impact actions like data deletion or system changes; and monitoring — whether organizations have sufficient visibility into how agents interact with systems and can detect and respond to abnormal behavior. Recovery capability is emerging as a critical determinant of loss severity.
How does an AI agent incident blur policy boundaries?+
A single AI agent incident can simultaneously read as a professional mistake, a security failure, and a product defect. A prompt-injection attack might cause an agent to disclose another client confidential file (pointing to cyber and privacy liability), give materially wrong regulatory advice causing financial loss (professional indemnity/E&O), and auto-execute a settings change that takes the portal offline (cyber business interruption). Recovery depends on three separate wordings holding at once; the failure mode is the seam between policies, not the absence of any policy.
What should enterprises prepare before renewal?+
Underwriters exclude risks they cannot price. Capgemini reports 42% of insurers track no AI metrics at all. Enterprises should prepare three things: a written AI inventory (what systems run, what data they access, what tools they can call); implemented controls matching the emerging baseline (access controls, monitoring, audit trails, prompt-injection defenses); and documented evidence those controls have been tested (adversarial test outputs, remediation records, recurring testing cadence). A controls list without test results reads as self-attestation; one with adversarial test outputs reads as an underwritable risk.