on the sistine ceiling, two hands reach for each other and almost touch. that gap is where you live now. you built a mind, gave it your tools, and let go. the ideal hangs in museums. the real ships on friday. we underwrite the difference: the space between what your agent promises and what it does at 3am.
platonic ideals
your spec, your evals, your promises to customers. the agent your team designed on the whiteboard. we read it like scripture, because it sets the bar every claim is measured against.
I
aristotelian proof
then we watch what the agent actually does in production. logs, traces, tool calls, edge cases. the distance between the ideal and the observed is the risk. and the premium.
II
socratic audit
before we underwrite, we interrogate. adversarial prompts, injection attempts, runaway-loop drills. we keep asking until your agent breaks. so the world doesn't get to ask first.
III
chapter ii · the crossing
thenamedperilsofanautonomousagent
shipping an agent is marching it over the alps: glorious on canvas, cold in practice. since january 2026, iso's cg 40 47 generative-ai exclusions have been attaching to gl renewals carrier by carrier, and ai carve-outs are appearing in cyber and e&o forms. goodfault writes the mountain's perils affirmatively, by name.
financiala1
unauthorized transactions
rogue refunds, mistaken discounts, wrongful payments, and unauthorized purchases the agent makes without a human.
legala2
hallucinated commitments
the air canada peril: the agent invents a policy, price, or promise, and a court makes you honor it.
dataa3
data leakage by agent
pii exfiltration, cross-tenant exposure, and ip disclosure caused by the agent's own actions.
operationala4
destructive actions
deleted records, wiped configs, broken pipelines, and production systems the agent damages.
securitya5
injection-induced behavior
third parties manipulating your agent through prompt injection into any of the above.
peoplea6
bias & discrimination
adverse automated decisions in hiring, lending, or pricing, and the aggregation exposure they carry.
regulatorya7
regulatory defense
investigation and defense cost for eu ai act, revised product liability directive, and sector regulators.
operationala8
business interruption
your own downtime when a failing agent has to be pulled, paused, or rolled back.
what we do not cover
no kill-switch, no logging, no injection testing, uncapped unattended financial authority, or anything cbrn / critical infrastructure. we don't insure agents without a recognized audit. that's a position, not a limitation.
the risk was never about which model the ai runs. it is about what the ai is allowed to do, and how much damage it can cause before a human steps in. one underwriting engine prices all of it. a humanoid running an agentic policy model is both an agent and a machine, and we are built for where that line ends up.
division a · bits
software agents
customer support, commerce, coding, operations, screening, and workflow agents. eight named perils, written affirmatively, from rogue refunds to regulatory defense.
when ai gets a body, errors become bodily injury and property damage. not just financial loss. humanoids, warehouse fleets, drones, ai devices, and the software layer of autonomous vehicles.
we are a carrier, not an auditor. hold a recognized ai-agent audit and you're in scope. upload it, get terms. no audit yet? we refer you out to recognized auditors and bind when you're certified. keeping those two roles separate is what makes our paper neutral.
1
tell us about your agent
a short intake: what it does, how much autonomy it holds, its financial authority, and its blast radius.
2
priced on authority & blast radius
premium keyed to what the agent is allowed to do unattended. not to which model powers it. drop the authority, drop the price.
3
repriced on what actually happened
optional telemetry feed from your agent logs. renewal tracks real behavior, not a stale questionnaire, and earns a trace discount.
a support agent was socially engineered into thousands of wrongful refunds over one weekend. the code-enforced per-transaction cap and daily circuit breaker, both policy conditions, contained it.
unauthorized transactionsloss held to $180k
paid in 6 days via parametric trigger
gf-0002
the deleted database
saas · coding agent with prod access
a coding agent wiped a customer table. the rollback condition in the policy meant four hours of interruption instead of four days. and because the control worked, the premium fell at renewal.
destructive actionsbi claim paid
4 hours of downtime, not 4 days · premium down at renewal
gf-0003
cert to coverage in 48 hours
ai vendor · aiuc-1 certified
an ai vendor already held an aiuc-1 certificate. they uploaded it, the audit mapped straight to our intake, and coverage bound the same week with no back-and-forth.
agentic liabilitybound in 2 days
zero re-audit · certificate did the underwriting
gf-0004
referred, then covered
startup · no audit on arrival
a startup arrived with no audit and was out of scope. we referred them to a recognized auditor, they passed, and they returned to bind. we never touched the audit. that's the point.
the funnel workingcertified in 3 weeks
then insured · neutrality intact
gf-0005
the compliance clock
eu deployer · ai act obligations
an eu deployer used its certificate plus a goodfault policy as documented risk-transfer evidence. against high-risk fine exposure of up to 3 percent of global turnover.
regulatory defense3% of turnover at stake
compliance evidence in place before the clock runs
said in public, on the record. we collect the chorus because we underwrite exactly what it describes.
“every major technological leap in history, from electricity and automobiles to flight and the internet, was unlocked by private market insurance.”
“we regard the hallucination of generative ai as an error, a type of risk we are familiar with from other ai applications we've been insuring since 2018.”
“the chatgpt moment for physical ai is here. when machines begin to understand, reason and act in the real world.”
“people outside the field are often surprised and alarmed to learn that we do not understand how our own ai creations work.”
“my prediction is that optimus will be the biggest product of all time by far.”
”for
builders
founders
agents
autonomous things
builders
of the ambitious
epilogue · above the fog
we'vegotthewhat-ifscovered.
what if the agent loops? what if the model drifts? what if a customer screenshot goes viral? this is where the story ends when you're covered: standing above the fog instead of inside it. the sea of what-ifs is still down there, it always will be, but every failure mode is named, capped, and carried. the view is the product.
tell us what your agent does, what tools it can reach, and what a bad day looks like. we return a premium in plain english. no actuarial latin, no 40-page pdf. most policies bind in under a week.
not ready for a quote? describe your agent to the oracle and get an honest read of your riskiest failure mode. the one your roadmap is politely ignoring. free, anonymous, occasionally prophetic.