recurring flagship · reading time: 8 minutes

the ai damage report:issue 01

every month we catalog the agent failures that actually cost someone money, with an estimated loss and the control that would have contained it. this is the record the industry does not keep.

Nobody owns the incident layer for AI agents. Insurers price AI risk from questionnaires and gut feel because there is no shared registry of what has actually gone wrong and what it cost. The AI Damage Report is our attempt to build that record in public. Each issue ranks the month's notable agent failures by estimated loss, names the failure mode, and, because we are an insurer and cannot help ourselves, notes the control that would have capped it.

a note on method: dollar figures are estimates built from public reporting, disclosures, and comparable losses. this is a directional signal, not an audited ledger. the point is pattern, not precision.

unauthorized transactions remain the number one loss driver

The recurring shape is an agent with financial authority and a gap in its controls: refunds without a per-transaction cap, discounts without an approval threshold, purchases without a spending limit. The Ravelin 2026 report put a number on the exposure surface, with 44 percent of merchants already running agentic protocols while liability for a bad transaction stays unassigned. The containing control is boring and effective: a cap enforced in code rather than in a prompt, plus a daily circuit breaker.

hallucinated commitments keep converting into legal events

The Air Canada pattern is not a one-off. Any agent that can state a policy, a price, or a promise can invent one, and courts increasingly hold the deploying company to it. The containing control is a bounded response surface for anything that looks like a commitment, plus human review above a defined stakes threshold.

destructive actions are the tail risk that scares underwriters most

Public discussion this quarter kept returning to agents that can delete records, wipe configurations, or damage production systems. These are low-frequency, high-severity events, exactly the shape that ruins a loss ratio. The containing control is reversibility: rollback and a kill-switch turn a catastrophe into an interruption.

aggregation is the quiet story

When many companies run the same agent or the same model, one failure becomes many claims. The Mobley v. Workday litigation is the clearest live example. For an insurer, this is the single most important variable to watch, because it determines whether a book of AI risk is diversified or secretly correlated.

severity tracks authority, not model quality. the companies that can reconstruct what their agent did are the ones that can defend, insure, and settle quickly.

Three early lessons from the data. First, severity tracks authority, not model quality. A capable model with narrow permissions is a smaller risk than a mediocre one wired to move money. Second, the presence or absence of a handful of controls, cap, circuit breaker, logging, rollback, explains most of the gap between a contained incident and an uncontained one. Third, the companies that cannot reconstruct what their agent did are not uninsured. They are undefended.

If you have an agent incident you are willing to share, on or off the record, it makes this report better and the whole market smarter. Send it to us. The registry only works if it is fed.

draft content for company-building. case studies and figures are illustrative and are not an offer of insurance or legal advice. cited events and frameworks are drawn from public 2026 sources.

← previous writing

your gl renewal just excluded ai: cg 40 47 in plain english

next writing →

what makes an ai agent insurable: the audits we accept