coverage · the named perils

we write the perilseveryone else justexcluded.

standard cyber and errors-and-omissions policies now exclude ai outright. the iso cg 40 47 wave that hit every renewal on january 1, 2026. goodfault writes these perils affirmatively, by name. if it isn't named here, ask us; if it is, it's covered.

Napoleon Crossing the Alps. Jacques-Louis David, 1803

division a · bits

software agents: the named perils

a1 · financial

unauthorized transactions

rogue refunds, mistaken discounts, wrongful payments, and unauthorized purchases the agent makes without a human.

a2 · legal

hallucinated commitments

the air canada peril: the agent invents a policy, price, or promise, and a court makes you honor it.

a3 · data

data leakage by agent

pii exfiltration, cross-tenant exposure, and ip disclosure caused by the agent's own actions.

a4 · operational

destructive actions

deleted records, wiped configs, broken pipelines, and production systems the agent damages.

a5 · security

injection-induced behavior

third parties manipulating your agent through prompt injection into any of the above.

a6 · people

bias & discrimination

adverse automated decisions in hiring, lending, or pricing, and the aggregation exposure they carry.

a7 · regulatory

regulatory defense

investigation and defense cost for eu ai act, revised product liability directive, and sector regulators.

a8 · operational

business interruption

your own downtime when a failing agent has to be pulled, paused, or rolled back.

division b · atoms

physical ai:same engine, higher stakes

when ai is embodied, errors become bodily injury and property damage, not just financial loss. the same insurers excluding digital ai are excluding embodied ai. while liability migrates from the robot's owner toward its manufacturer and software provider as autonomy increases. we underwrite both on one engine.

b1 · embodied

humanoid & general-purpose robots

liability cover for humanoid fleets in industrial, logistics, hospitality, and domestic settings. bodily injury, third-party property damage, and the operational perils of machines designed to work near people. no standalone humanoid policy exists in the market today; we intend to write the first one.

b2 · industrial

autonomous mobile robots & industrial fleets

amrs, warehouse and delivery robots, agriculture, construction, and mining autonomy. general liability plus errors & omissions for developers, operators, and service providers, priced from fleet telemetry.

b3 · aerial

drones & uas

commercial drone liability and hull, written the way the mature drone market taught everyone it works: usage-based, on-demand where operations justify it, priced per mission profile. drones prove that physical ai risk becomes an insurable, falling-price commodity once loss data accumulates.

b4 · consumer

physical ai products

product liability for ai-embedded devices: companion robots, ai appliances, autonomous tools, and consumer robotics. covers manufacturer and deployer for failures of the ai behavior layer. the exposure classical product wordings never contemplated.

b5 · mobility

av & robotaxi programs

participation in autonomous-vehicle fleet programs alongside established capacity, focused on the agentic software layer: the decision system, not the sheet metal. entered gradually as our physical book and capacity relationships mature.

what we donot cover

we insure ai we can trust the record of, in either division. six gates, applied identically to a support bot and a humanoid fleet. fail one and the answer is not a higher price. it is not yet.

gate 1

no kill-switch or rollback

irreversible actions with no way to stop or undo them.

gate 2

no logging or trace

if what the ai did cannot be reconstructed, the claim cannot be adjusted.

gate 3

never adversarially tested

prompt injection for agents; hazard and intrusion testing for machines.

gate 4

uncapped unattended authority

unlimited spend for agents; unsupervised force or speed envelopes for machines.

gate 5

cbrn, weapons & critical infrastructure

outside appetite entirely, at any price.

gate 6

no recognized audit

not declined, deferred. certified systems come back and bind.

no recognized audit means not yet insurable. that's the front door, not a wall.

built like a product,not paperwork

01

quote in minutes, not weeks

a telemetry feed replaces the questionnaire. terms come back while your renewal is still warm.

02

priced on authority

premium keyed to what the agent is authorized to do unattended. drop its authority, watch the price drop live.

03

control credits up to 20%

pass a recognized certification and the discount is structural, not negotiated.

04

parametric fast-pay

a refund-anomaly spike pays in days, not quarters. some triggers don't need an adjuster.

05

live risk dashboard

your blast-radius score and drift, visible all policy long. not just at renewal.

06

conditions that are best practice

caps enforced in code, rollback, circuit breakers. our policy conditions read like your sre runbook.

like what you see?
get covered.

tell us what your agent does, what tools it can reach, and what a bad day looks like. we return a premium in plain english. no actuarial latin, no 40-page pdf. most policies bind in under a week.

get a quote

consult the oracle

not ready for a quote? describe your agent to the oracle and get an honest read of your riskiest failure mode. the one your roadmap is politely ignoring. free, anonymous, occasionally prophetic.

summon the oracleknow thy agent.