Nobody owns the incident layer for AI agents. Insurers price AI risk from questionnaires and gut feel because there is no shared registry of what has actually gone wrong and what it cost. The AI Damage Report is our attempt to build that record in public. Each issue ranks the month's notable agent failures by estimated loss, names the failure mode, and, because we are an insurer and cannot help ourselves, notes the control that would have capped it.
a note on method: dollar figures are estimates built from public reporting, disclosures, and comparable losses. this is a directional signal, not an audited ledger. the point is pattern, not precision.
unauthorized transactions remain the number one loss driver
The recurring shape is an agent with financial authority and a gap in its controls: refunds without a per-transaction cap, discounts without an approval threshold, purchases without a spending limit. The Ravelin 2026 report put a number on the exposure surface, with 44 percent of merchants already running agentic protocols while liability for a bad transaction stays unassigned. The containing control is boring and effective: a cap enforced in code rather than in a prompt, plus a daily circuit breaker.
hallucinated commitments keep converting into legal events
The Air Canada pattern is not a one-off. Any agent that can state a policy, a price, or a promise can invent one, and courts increasingly hold the deploying company to it. The containing control is a bounded response surface for anything that looks like a commitment, plus human review above a defined stakes threshold.
destructive actions are the tail risk that scares underwriters most
Public discussion this quarter kept returning to agents that can delete records, wipe configurations, or damage production systems. These are low-frequency, high-severity events, exactly the shape that ruins a loss ratio. The containing control is reversibility: rollback and a kill-switch turn a catastrophe into an interruption.
aggregation is the quiet story
When many companies run the same agent or the same model, one failure becomes many claims. The Mobley v. Workday litigation is the clearest live example. For an insurer, this is the single most important variable to watch, because it determines whether a book of AI risk is diversified or secretly correlated.
“severity tracks authority, not model quality. the companies that can reconstruct what their agent did are the ones that can defend, insure, and settle quickly.”
Three early lessons from the data. First, severity tracks authority, not model quality. A capable model with narrow permissions is a smaller risk than a mediocre one wired to move money. Second, the presence or absence of a handful of controls, cap, circuit breaker, logging, rollback, explains most of the gap between a contained incident and an uncontained one. Third, the companies that cannot reconstruct what their agent did are not uninsured. They are undefended.
If you have an agent incident you are willing to share, on or off the record, it makes this report better and the whole market smarter. Send it to us. The registry only works if it is fed.
draft content for company-building. case studies and figures are illustrative and are not an offer of insurance or legal advice. cited events and frameworks are drawn from public 2026 sources.