Every insurance product has a threshold below which it will not write a risk. For AI agents, ours is simple and stated up front: bring a recognized third-party audit and you are in scope. Do not have one and we will point you to auditors, then quote once you are certified. We do not run the audit ourselves, because we do not think your insurer should also be the party grading your safety.
why a certificate is the gate
An audit does the underwriting work we would otherwise have to guess at. It tells us whether the agent was built with observability, guardrails, and a defined authority envelope, or duct-taped onto a model API with none of those things. A well-built agent and a fragile one are fundamentally different risks even when they run the same model, and only an independent assessment can tell them apart before a claim does.
what we recognize today
- i.aiuc-1: the emerging ai agent security standard, often described as soc 2 for ai agents. six pillars: data and privacy, security, safety, reliability, accountability, and societal risk. the fastest path to a quote.
- ii.iso/iec 42001: the international standard for ai management systems. governance, oversight, and lifecycle control; we read it alongside evidence of the specific deployment.
- iii.soc 2 with an ai addendum: your security and operational controls, paired with an ai-specific addendum covering the agent's authority, logging, and testing.
- iv.nist ai rmf attestation: a structured approach to identifying and mitigating ai risk, mapped to the nist framework.
- v.independent red-team or evaluation report: a current report covering prompt injection, jailbreak resistance, and blast-radius testing. it tells us what actually breaks, and how hard.
freshness matters
Agents change, models get swapped underneath them, and permissions drift. We treat a recognized audit as current for twelve months and ask for re-certification at renewal. An audit from two model generations ago describes an agent that no longer exists.
“the certificate is not just a ticket in. it is a lever on your rate.”
The gate is binary, but the result is not. A stronger audit, with wider evaluation coverage and cleaner control evidence, earns a larger control credit and a lower premium.
If you are not certified yet, you are not turned away. you are pointed forward. We maintain relationships with recognized auditors we do not own, make a warm introduction, and hold your file open. Most agents that arrive uncertified are back within a few weeks with a report in hand.
One rule, stated plainly, applied the same way to everyone: no recognized audit, no bind. It is the whole of our underwriting discipline in a sentence, and it is exactly what our capacity partners want to hear.
draft content for company-building. case studies and figures are illustrative and are not an offer of insurance or legal advice. cited events and frameworks are drawn from public 2026 sources.