There is a quiet conflict of interest sitting at the center of the AI insurance market, and almost nobody is naming it.
The leading specialists all bundle three things: a standard, an audit against that standard, and a policy priced on the audit result. One company writes the test, marks the test, and then insures the outcome. When the same firm decides both whether your agent is safe and whether it will pay if your agent is not, the incentives bend in a direction that should make any risk manager uncomfortable. A soft audit wins the premium. A hard claim erases the margin. Those two pressures do not point the same way.
We think the market got here for an understandable reason. In 2024 and 2025 there was no loss data for AI agents, no actuarial table, and no accepted definition of “well built.” So the first movers had to invent a standard just to have something to underwrite against. Building the standard and selling the policy in one motion was the only way to get a product out the door. It was pragmatic. It was also temporary.
“your accountant does not audit their own books. a building inspector does not also sell you the fire policy.”
The rest of insurance settled this question a century ago. A credit rating agency that underwrites the bonds it rates is a scandal, not a business model. Independence between the party that assesses risk and the party that carries it is not a nicety. It is the thing that makes an assessment worth anything.
goodfault is built on that separation. We are a carrier, and only a carrier. We do not run audits, we do not sell certifications, and we do not have a house standard we are quietly steering you toward. Instead we recognize credible third-party audits from across the market: AIUC-1, ISO/IEC 42001, SOC 2 with an AI addendum, NIST AI RMF attestations, and independent red-team reports. Bring a recognized audit and you are in scope. Do not have one and we point you to auditors we do not own, then pick up once you are certified.
This costs us something. It is slower than auditing you ourselves, and it means we cannot capture the audit fee. We think that is the correct trade. A certificate is only valuable to your enterprise buyers and your regulators if the party accepting it has no stake in the grade. By staying out of the audit business, we make everyone's certificate mean more, including the ones our competitors issue.
The market will mature toward this. As loss data accumulates and standards consolidate, the bundling that made sense in the cold-start years will start to look like what it is. We would rather be early to the structure the industry ends up with than defend the one it is trying to grow out of.
“your auditor should not be your insurer. we are the insurer that agrees.”
draft content for company-building. case studies and figures are illustrative and are not an offer of insurance or legal advice. cited events and frameworks are drawn from public 2026 sources.