AI-Native Insurance for Agentic AI: Pricing, Underwriting, and End-to-End Automation Quanyan Zhu∗
arXiv:2607.13230v1 [cs.AI] 14 Jul 2026
Abstract Agentic AI shifts insurance from covering passive digital assets to covering operational actors that reason, invoke tools, alter external state, and depend on shared model and infrastructure providers. These capabilities generate losses from cyber compromise, autonomous decision error, model drift, dependency outage, professional negligence, regulatory violation, and cyber-physical harm. This paper develops an AI-native framework for underwriting, pricing, and contract design for agentic-AI deployments. Each deployment is represented by a risk state si = (αi , βi , ηi , gi , vi ) capturing autonomy category, operational authority, external-state permissions, governance maturity, and dependency concentration. The framework maps this state into event probabilities, severities, governance costs, risk loadings, coverage incidence, indemnity allocation, and policy covenants, and then formulates a contract-design problem over premiums, deductibles, limits, aggregate exposure, allocation rules, and governance obligations subject to participation, insurer-profitability, and incentive-compatibility constraints. We show that insurability forms a region of the risk-state space, that fixed-terms feasibility deteriorates monotonically as exposure grows, and that a governance threshold certifies a deployment as insurable. The paper further reads insurance as an AI operating cost and regulatory-control instrument that internalizes risk, shapes adoption incentives, and supports mandatory financialresponsibility requirements for higher-risk deployments. A healthcare care-coordination case study solves a finite contract menu and shows how delegated authority, permission exposure, dependency concentration, and governance maturity drive feasibility and pricing, and an automated workflow illustrates how monitoring, trigger evaluation, claims validation, and human escalation operationalize the contract architecture. ∗ Quanyan Zhu is with the Department of Electrical and Computer Engineering and the NYU Center for Cybersecurity, NYU Tandon School of Engineering, New York University, Brooklyn, NY 11201, USA. Contact: [email protected].
Keywords: agentic AI; cyber insurance; AI risk; contract design; governance incentives; risk-based pricing.
1
Introduction Agentic artificial intelligence (AI) changes the unit of insurance analysis. Conventional cyber
and technology policies are written around information systems, data assets, professional services, and security events. Agentic AI, by contrast, plans, invokes tools, coordinates multi-step workflows, communicates with external parties, modifies records, initiates transactions, and, in some deployments, acts on physical systems. The resulting exposure is no longer merely information risk, in which a system produces an output that a human may accept or reject; it is action risk, in which an AI-enabled workflow can directly create operational, legal, financial, or physical loss. This distinction reshapes underwriting. The relevant questions are what the deployed agent is permitted to do, which systems it can access, whether execution requires human approval, whether actions are logged and reversible, which vendors or model providers the workflow depends on, and whether a loss would fall under cyber, technology errors and omissions (TechE&O), professional liability, general liability, product liability, or an affirmative AI-specific endorsement. Market responses already point toward a layered architecture rather than a single monoline agentic-AI policy: cyber policies address security and privacy losses; TechE&O and professional-liability forms address faulty services and negligent deployment; general-liability and product-liability forms address bodily injury and property damage; and emerging AI endorsements attempt to make silent AI exposure explicit [2, 3, 6, 7, 12, 31]. The actuarial problem is hard because agentic-AI losses may occur without any traditional cyber compromise. A prompt-injection attack can redirect a legitimate workflow; a hallucinated clinical or financial recommendation can be converted into an external action; a model can drift after deployment; a cloud, model, or connector outage can affect many insureds at once; and a cyber-physical agent can cause bodily injury or property damage. Historical claims data for these mechanisms remain sparse, so pricing must initially rely on exposure assessment, scenario analysis, control effectiveness, dependency mapping, and accumulation-risk management—much as cyber insurance developed before broad actuarial credibility was available [15, 23, 34].
This paper develops a mathematical-programming framework for agentic-AI insurance contract design, building on recent work that treats agentic AI as an emerging insurable exposure class [37]. The framework formalizes the practical underwriting variables—autonomy category, operational authority, external-state permissions, governance maturity tier, and dependency concentration—as a compact risk state. It maps event categories to coverage layers, defines a binary coverage-incidence matrix, separates coverage availability from payment allocation, and formulates an optimization problem that jointly determines pricing, deductibles, limits, aggregate exposure, allocation rules, and governance obligations. On this foundation we establish three structural results: insurability forms a region of the risk-state space, fixed-terms feasibility deteriorates monotonically as exposure grows, and a governance threshold certifies a deployment as insurable. The paper further reads insurance as an AI operating cost and regulatory-control instrument: bundled into deployment cost or mandated by law, coverage can internalize risk, shape adoption incentives, and impose financial responsibility on high-risk systems. A healthcare care-coordination case study translates operational facts into feasible insurance terms, and a workflow section operationalizes the design through continuous monitoring, trigger evaluation, claims validation, and human escalation for exceptional cases.
2
Related Work This paper draws on four strands of work. The first is AI safety and foundation-model risk.
Early AI-safety research identifies accident mechanisms such as side effects, reward misspecification, distributional shift, unsafe exploration, and scalable-oversight failures [1]. Foundation-model research shows that broadly reusable models create cross-domain capabilities and cross-domain risks, including opacity, data-quality problems, bias, documentation gaps, and governance challenges [4, 9]. Work on frontier AI risk further motivates auditability, rigorous evaluation, and adaptive governance as systems grow more capable and autonomous [5]. Together these studies justify treating governance and monitoring as insurance-relevant variables, not merely technical best practices. The second strand is adversarial machine learning and prompt-based attacks. Adversarialexample research shows that machine-learning systems behave unpredictably under strategically
chosen inputs [11, 16]. In large-language-model applications, prompt injection and indirect prompt injection extend this concern to tool-using systems that retrieve external content, follow instructions, or execute actions [18, 25, 27]. The implication for insurance is that loss pathways include manipulated context, compromised tool outputs, and unsafe action execution—not only network intrusion or data breach. The third strand is cyber-insurance economics and incentive design. Classic work on security investment treats insurance as both risk transfer and an incentive mechanism [7, 8, 17]. Empirical studies of cyber-policy language and pricing show that coverage definitions, exclusions, limits, and claims categories decide whether insurance improves risk management or merely transfers poorly understood losses [31]. Contract theory under asymmetric information motivates the participation, incentive-compatibility, and moral-hazard constraints we adopt [14,30,32]. Mechanism-design work by Liu and coauthors studies how incentives improve interdependent security investment and how aggregate cyber-risk dependence threatens the sustainability of insurers and reinsurers [22, 26]. Several game-theoretic and contract-design papers by Zhu and coauthors are especially relevant. Attack-aware cyber-insurance models study interdependent networks in which users, attackers, and insurers interact strategically [35], and dynamic contract-design models capture self-protection, risk compensation, and evolving risk states [36]. Related work on systemic cyber-risk management and cyber resilience treats monitoring, residual risk, asymmetric information, and moral hazard as central design variables [13, 20, 21]. Most directly, recent work frames underwriting, pricing, risk transfer, and claims design as core challenges for AI deployments, while work on the Internet of Agentic AI emphasizes communication, coordination, collective intelligence, and interdependence among agents at scale [37,38]. This paper extends that perspective by linking autonomy, delegated authority, permissions, governance controls, and dependency concentration to insurance pricing, allocation, and claims execution.
3
Agentic AI in Practice and Underwriting Observables
Definition 1 (Agentic-AI deployment). An agentic-AI deployment is an AI-enabled operational workflow in which a model is connected to tools, data sources, memory or task context, workflow logic, and execution interfaces, so that model-generated outputs may condition actions in an exter-
nal environment. Such actions may include calling services, updating records, sending messages, initiating transactions, delegating subtasks, or interacting with physical systems. The insurance-relevant distinction is external-state change. An output-only system may produce misleading information, but an agentic deployment converts a model output into an operational step. Once output is wired to an action channel, errors, attacks, outages, and control failures become operational losses rather than merely informational defects [9, 24, 25]. In current practice, agentic AI is usually embedded inside business workflows rather than deployed as a stand-alone autonomous machine. Examples include customer-service and sales agents that retrieve account data and issue responses; software-engineering and security-operations agents that inspect code, open tickets, generate patches, or triage alerts; healthcare administrative agents that schedule visits, route patient messages, and summarize records; financial and compliance agents that review transactions or prepare filings; procurement and billing agents that initiate orders, refunds, or invoices; and cyber-physical agents that interact with devices, buildings, robots, vehicles, or industrial equipment. As these systems interconnect through shared communication, coordination, and service layers, deployment risk also depends on how each local agent participates in larger agentic-AI ecosystems [38]. Such applications differ less by the label “AI” than by the operational boundary drawn around the deployed system: what it can access, what it may change, whether a human must approve execution, how actions are logged and reversed, and which model, cloud, data, or connector providers it depends on. The same application category can therefore carry very different insurance exposures. A clinical assistant that drafts a message for clinician approval differs sharply from one that sends the message, schedules a follow-up visit, and updates the patient record without review. A customer-service agent that reads account data differs from one that issues refunds or changes billing records. A software agent that recommends code differs from one that merges code, rotates credentials, or modifies cloud infrastructure. These distinctions motivate the formal risk state of Section 4: αi captures capability, βi operational authority, ηi permissions, gi governance maturity, and vi dependency concentration. Table 1 also shows why a risk-state representation is useful for insurance. Every component is observable—from underwriting questionnaires, permission inventories, tool manifests, audit ev-
Table 1: Agentic-AI Deployment Features and Insurance-Relevant Observables Underwriting question What can the agent technically do? How much can execute without approval? Which systems can the agent touch? How controlled and auditable is the deployment? How concentrated are model and service dependencies?
Observable evidence Model and workflow description; task classes; tool manifests; orchestration design Approval policy; sampled action logs; autonomous-action frequency; escalation records API scopes; connectors; credentials; permission inventory; data and tool access lists Audit logs; monitoring controls; testing cadence; incident response; rollback and change-management evidence Model, cloud, API, data, and connector vendor inventory; traffic or workload shares
Risk-state component Autonomy category αi Operational authority βi Permission vector ηi and permission exposure ψη (ηi ) Governance tier gi = h(zi ) Dependency vector vi and concentration R(vi )
idence, telemetry, vendor records, incident reports, and policy-covenant attestations. Once collected, the state si feeds the event-probability maps, severity maps, coverage incidence, governance covenants, pricing schedules, and claims logic. The formal model below is thus best read as a compact representation of how an agentic-AI deployment operates in practice.
4
Risk-State and Coverage Framework for Agentic-AI Insurance The preceding section described agentic AI as an operational system with action channels,
permissions, approval rules, controls, and shared dependencies. The modeling thesis of this paper follows: the insured object is no longer an information system or software platform, but the joint exposure created by the AI system’s autonomy, operational authority, external-state permissions, governance controls, and dependency ecosystem. Whereas traditional cyber insurance ties losses primarily to external attacks and security failures [6,7], agentic-AI insurance must also cover losses generated by the AI system’s own behavior—hallucinations, autonomous decision errors, promptinjection attacks, model drift, dependency failures, and cyber-physical incidents [1, 24, 25].
4.1
From Underwriting Practice to Risk-State Variables
Building on the observables in Table 1, the practical underwriting question is not whether an organization uses AI, but what the agent is authorized to do, which systems it can reach, what
approvals precede execution, whether actions are logged and reversible, and how concentrated the deployment is across model, cloud, or connector providers. Agentic-AI underwriting should therefore begin with operational authority and control evidence rather than a generic AI-use questionnaire. The variables below are not abstract labels; each corresponds to information that an insurer can request in an application, verify through audit evidence, monitor through telemetry, and translate into pricing or coverage terms. We use a fixed indexing convention throughout the model. The insured organization is indexed by i ∈ I = {1, . . . , n} and appears as a subscript. The loss event e ∈ E and coverage layer r ∈ R both appear as superscripts. Thus qie denotes the probability of event e for insured i, xei denotes the corresponding gross loss, Yie,r denotes the indemnity attributed to coverage layer r, and Yie =
e,r denotes total indemnity for event e before any aggregate cap is applied. r∈R Yi
P
The variable αi is an autonomy category, not a continuous maturity score. It records how far the insured system moves from information generation toward external action. The categories are ordinal: higher categories indicate greater loss-generating capability, but the gap between adjacent categories is not numerically equal. We write A = {α(0) , α(1) , α(2) , α(3) , α(4) }, ordered α(0) ≺ α(1) ≺ α(2) ≺ α(3) ≺ α(4) ; Table 2 summarizes them. Table 2: Autonomy Categories for Agentic-AI Underwriting αi α(0)
Category Assistive AI
α(1)
Tool-enabled copilot
α(2)
Digital agent
α(3)
Multi-agent workflow
α(4)
Cyber-physical agent
Practical underwriting meaning Produces information, text, code, or recommendations; no independent external execution. Retrieves information or prepares actions through tools, but material execution remains subject to human approval. Executes digital actions such as sending communications, updating records, browsing, scheduling, or initiating workflow changes. Coordinates multiple agents, delegates subtasks, and may create cascading digital actions across systems. Acts through robotics, industrial systems, medical devices, vehicles, buildings, or other physical infrastructure.
The autonomy category αi describes capability—what the agent is technically able to do. The variable βi ∈ [0, 1] describes operational authority—how much of that capability may execute without human approval. Let Ui denote the set of operational actions the deployed agent is authorized to initiate under its realized permission profile; Ui (ηi ) below makes this permission dependence
explicit. For each action u ∈ Ui , define the human-approval indicator
hi (u) =
1,
if execution of action u requires human approval,
0,
if execution of action u may proceed autonomously.
(1)
Let ωi (u) denote the relative frequency, criticality, or business importance of action u, with ωi (u) ≥ 0 and
u∈Ui ωi (u) = 1. The operational-authority variable is then
P
βi =
X
ωi (u) 1 − hi (u) ,
0 ≤ βi ≤ 1.
(2)
u∈Ui
Thus βi = 0 means that every authorized action requires human approval, while βi = 1 means that all authorized actions may execute autonomously. Intermediate values represent partial delegation. Equation (2) admits a probabilistic reading. If an authorized action is sampled according to the weights ωi (·) and Hi indicates that the sampled action requires approval, then βi = P(Hi = 0) and 1 − βi = P(Hi = 1). For telemetry-based underwriting over an observation period [0, T ], the same quantity is estimated from logs by βi (T ) = Niauto (T )/Nitotal (T ), the ratio of actions executed without human intervention to all agent actions in the period. This makes βi observable, auditable, and suitable for continuous underwriting. Table 3: Autonomy Category Versus Operational Authority Deployment Clinical copilot drafting recommendations Appointment-scheduling agent
αi α(2)
βi 0.05
α(2)
0.60
Autonomous customer-service workflow Industrial control agent
α(3)
0.85
α(4)
0.95
Interpretation Digital capability with nearly all actions reviewed by a clinician Same capability class, but many scheduling actions execute autonomously Multi-step workflow with limited human approval before execution Cyber-physical capability with very high autonomous execution authority
The vector ηi is the agent’s permission profile: it specifies which parts of the external environment the deployed agent is authorized to touch. Let P = {p1 , . . . , pm } denote the universe of
permission classes. The permission-allocation vector is ηi = (ηi,1 , . . . , ηi,m ) ∈ {0, 1}m , where
ηi,j =
1,
if the deployed agent is authorized to exercise permission pj ,
0,
otherwise.
(3)
Typical permission classes include external email, scheduling, customer-record modification, billing or payment initiation, procurement, electronic-health-record updates, physical-device control, and external API execution. If P(u) ⊆ P denotes the permissions required to execute action u, then the permissions determine the admissible action set Ui (ηi ) = {u : P(u) ⊆ {pj ∈ P : ηi,j = 1}} .
(4)
Thus ηi answers what the agent may do, while βi answers how often authorized actions may proceed without human approval. For example, an agent may have email permission ηi,email = 1 while every email still requires review, yielding βi = 0 for an email-only action set; permission exists, but autonomous execution authority does not. If the same email actions execute automatically, then both permission and authority are present. If ηi,email = 0, email actions are infeasible regardless of the value of βi . The unweighted count ∥ηi ∥1 =
j=1 ηi,j reports how many permission classes are granted but
Pm
treats them as equally risky. Because sending an email, modifying a payment record, and controlling a physical device carry very different loss implications, we use the weighted permission-exposure map ψη (ηi ) =
η η j=1 ωj ηi,j , where ωj > 0 is the risk weight of class pj and the unweighted count is
Pm
the special case ωjη ≡ 1. Table 4 gives representative classes and illustrative relative weights. For each insured organization i, the underwriting state is si = (αi , βi , ηi , gi , vi ) ∈ S := A × B × Pm × G × V, where B = [0, 1], Pm = {0, 1}m , G = {g (1) , . . . , g (M ) }, and V = ∆K = {v ∈ RK + :
(5) k=1 vk = 1}. The
PK
governance tier set G is finite and ordered as g (1) ≺ g (2) ≺ · · · ≺ g (M ) . Here vi records dependency shares across K model providers, cloud services, agent platforms, data sources, or connectors. A
Table 4: Illustrative Permission Classes and Relative Risk Weights Permission class pj External email Scheduling
Weight ωjη 1 2
Record modification Payments or billing
4 8
Physical-device control
15
concentration statistic such as R(vi ) =
Operational meaning Send external communications or notifications Create, cancel, or modify appointments and workflow tasks Modify customer, patient, or operational records Initiate financial transactions, invoices, refunds, or billing changes Control equipment, robotics, medical devices, buildings, vehicles, or industrial systems PK
2 k=1 vi,k
can be used when the insurer needs a scalar
accumulation-risk measure. The governance variable gi is a maturity tier capturing the overall effectiveness of governance, monitoring, and operational safeguards. The order g (1) ≺ · · · ≺ g (M ) represents increasing assurance, but the tiers are ordinal and need not be equally spaced. To ground the tier in evidence, let Lg = {1, . . . , Lg } index governance-control dimensions. For each ℓ ∈ Lg , let actrl i,ℓ ∈ Dℓ be the audit evidence, telemetry record, questionnaire response, or technical assessment submitted by insured i, and let a scoring rule ζℓ : Dℓ → [0, 1] return the normalized score zi,ℓ = ζℓ (actrl i,ℓ ): zero for an absent or ineffective control, one for a fully implemented and evidenced control, and intermediate values for partial implementation or weak evidence. Writing zi = (zi,1 , . . . , zi,Lg ) ∈ [0, 1]Lg , the tier is assigned by the underwriting rule gi = h(zi ), h : [0, 1]Lg → G. A higher tier means agent actions are more strongly constrained, observable, auditable, and recoverable. Representative dimensions include human approval gates, least-privilege access, credential isolation, execution logging, real-time monitoring, prompt-injection defenses, red-team testing, rollback capability, incident response, and vendor-risk management. The representation connects directly to practice: insurers can condition premium credits, deductibles, exclusions, or continued coverage on evidence supporting individual control components.
4.2
Mapping Notation and Indexing Discipline
The state vector si becomes useful for underwriting only after it is mapped into event probabilities, severity estimates, governance costs, and contract terms. To avoid ambiguity, we use uppercase symbols for mappings and lowercase indexed symbols for evaluated probability and severity quan-
Table 5: Risk-State Variables and Domains Variable αi βi
Domain A [0, 1]
ηi
{0, 1}m
gi vi
G = {g (1) , . . . , g (M ) } ∆K
Interpretation Autonomy category of the AI deployment Operational authority measure: fraction of weighted authorized actions that may execute autonomously Permission-allocation vector determining which external-state actions are feasible Governance maturity tier Dependency shares across K providers or services
tities. For each event e ∈ E, let Qe : S → [0, 1] be the annual event-probability mapping and X e : S → R+ be the representative conditional gross-severity mapping. The realized inputs for insured i are qie = Qe (si ) and xei = X e (si ). Thus qie and xei are scalar event-level quantities for the fixed insured; they are not functions. If a full severity distribution is required, X e (si ) can be replaced by a conditional moment, quantile, or scenario statistic of a random severity X e (si , ω). In Table 6, Ci denotes the feasible contract set for insured i, and gi⋆ denotes the governance tier required or selected in the issued contract. The coverage-layer index r appears only when a quantity is layer specific. Event frequency and gross severity, qie and xei , do not carry r because the event occurs before the claim is allocated to coverage layers. Deductibles Dir , per-event limits Lri , layer payments Yie,r , incidence indicators γie,r , and allocation shares λe,r i do carry r because they depend on the coverage layer. The total premium Ti , aggregate AI limit Ai , governance cost Ki (gi ), and total event indemnity Yie =
e,r do r∈R Yi
P
not carry r because they are contract-level, insured-level, or event-level quantities after aggregation. Table 6: Functional Mappings and Realized Quantities Object Event probability Gross severity Permission exposure Governance cost Premium schedule Deductible schedule Risk loading
Mapping Qe : S → [0, 1] X e : S → R+ ψη : Pm → R+ Ki : G → R+ τi : G → R+ dri : G → R+ ϱi : S × Ci → R+
Realized quantity for insured i qie = Qe (si ) xei = X e (si ) ψη (ηi ) Ki (gi ) Ti = τi (gi⋆ ) when used Dir = dri (gi⋆ ) when used ϱi (si , Ci )
These mappings are underwriting primitives, not mathematical decoration. The probability mapping Qe turns operational exposure into expected event frequency; the severity mapping X e
turns the same exposure into a conditional loss magnitude; the permission-exposure map ψη turns granted tool rights into a weighted attack-surface measure; the governance-cost mapping Ki is the insured’s cost of meeting a tier; the premium and deductible schedules τi and dri encode the insurer’s governance credits; and the risk-loading mapping ϱi absorbs capital charges, dependency accumulation, and model and legal uncertainty. Proposition 2 (Risk-state sufficiency for underwriting maps). Fix the underwriting maps Qe : S → [0, 1], X e : S → R+ , ψη : Pm → R+ , the concentration statistic R : V → R+ , and the governance assignment rule h : [0, 1]Lg → G. If two deployments have the same risk state si = sj , then they receive the same state-dependent event probabilities, severities, permission exposures, dependencyconcentration scores, and governance-tier evaluations under these maps. Any remaining differences in premiums, costs, or risk loadings must therefore arise from insured-specific contract terms, cost functions, capital charges, or legal assumptions rather than from the operational risk state itself. Proof. The conclusion follows by direct evaluation of the fixed maps at the common state. If si = sj , then Qe (si ) = Qe (sj ) and X e (si ) = X e (sj ) for every event e ∈ E. The equality of the permission, governance, and dependency coordinates implies ψη (ηi ) = ψη (ηj ), h(zi ) = h(zj ) whenever the same control scores induce the common governance tier, and R(vi ) = R(vj ). Quantities with insuredspecific subscripts, such as Ki , τi , or ϱi , may still differ if the insurer assigns different cost, market, capital, or legal parameters. The symbols ρeα , ξαe , κe , and χe are not additional state variables. They are event-specific calibration maps used to translate ordinal categories into numerical modifiers inside the probability and severity examples below. The subscript α indicates an autonomy-category effect; the governance maps do not carry this subscript because their input is gi . The superscript e indicates that different loss events may respond differently to the same autonomy category or governance tier. Table 7 summarizes their roles. These maps exist because autonomy categories and governance tiers are ordinal: they let an insurer specify monotone category effects without pretending the gap between adjacent categories is numerically equal. In practice they are calibrated from underwriting scorecards, expert elicitation, red-team results, control audits, incident and cyber claims data, stress scenarios, and portfolio
Table 7: Ordinal Effect Maps Used in the Example Risk Models Map ρeα
Domain and range A → R+
ξαe
A → R+
κe
G → R+
χe
G → R+
Interpretation Autonomy effect on event probability. It enters the logit of Qe ; larger values mean that event e is more likely under the corresponding autonomy category. Autonomy effect on conditional severity. It enters X e ; larger values mean that event e tends to produce larger losses under the corresponding autonomy category. Governance mitigation for event probability. It is subtracted in the logit of Qe ; larger values mean that stronger governance lowers the probability of event e. Governance mitigation for conditional severity. It enters through exp(−χe (gi )); larger values mean that stronger governance lowers the loss severity of event e.
accumulation studies. The next two equations are therefore transparent benchmark specifications, not the only admissible functional forms; they convert the state variables into event probabilities and conditional severities while preserving the signs and monotonicities an underwriter would expect. For event probabilities, a logistic mapping is natural because the output must remain between a lower reference frequency and an upper stress frequency. The inner index can be interpreted as a latent risk score for event e: autonomy, delegated authority, permission exposure, and dependency concentration increase this score, while stronger governance lowers it. The lower bound q̄ e captures e residual event frequency even for well-controlled deployments, and qmax captures the largest annual
frequency that the insurer regards as plausible for the class of event under stress. One illustrative event-probability mapping is
e Qe (si ) = q̄ e + (qmax − q̄ e ) σ ae0 + ρeα (αi ) + aeβ βi + aeη ψη (ηi ) − κe (gi ) + aeR R(vi ) ,
(6)
e where σ(z) = (1+e−z )−1 , 0 ≤ q̄ e < qmax ≤ 1, and the coefficients are event specific. The autonomy-
risk map ρeα : A → R+ and the governance-mitigation map κe : G → R+ satisfy ρeα (α(0) ) ≤ · · · ≤ ρeα (α(4) ) and κe (g (1) ) ≤ · · · ≤ κe (g (M ) ). This formulation respects the ordinal nature of both autonomy categories and governance tiers: it does not treat adjacent categories as equally spaced
numerical levels. For conditional severity, the modeling requirement is different. The loss amount X e (si ) must remain nonnegative, should grow with operational exposure, and should allow governance controls to reduce expected loss size without making losses negative. The following multiplicative specification serves that purpose. The baseline severity be0 represents the conditional loss for a low-exposure deployment, the first factor increases severity with autonomy, delegated authority, and weighted permissions, the second factor captures dependency concentration, and the exponential governance term applies a proportional mitigation credit. A compatible severity mapping is
X e (si ) = be0 1 + ξαe (αi ) + beβ βi + beη ψη (ηi ) (1 + beR R(vi )) exp(−χe (gi )) ,
(7)
where ξαe : A → R+ and χe : G → R+ are nondecreasing in the category order, so ξαe (α(0) ) ≤ · · · ≤ ξαe (α(4) ) and χe (g (1) ) ≤ · · · ≤ χe (g (M ) ). Higher operational authority, broader weighted permission exposure, and stronger dependency concentration increase severity, while higher governance tiers reduce it through the factor exp(−χe (gi )). Governance cost is also a discrete mapping Ki : G → R+ , with Ki (g (1) ) ≤ Ki (g (2) ) ≤ · · · ≤ Ki (g (M ) ), reflecting the higher cost of stronger monitoring, validation, logging, approval workflows, and incident-response readiness. (a) Event probability qie (%) α(2)
(b) Conditional severity xei (USD thousands)
α(4)
α(2)
12
900
8
600
4
300
0
α(4)
0 g (1)
g (2)
g (3)
g (4)
g (1)
g (2)
g (3)
g (4)
Figure 1: Illustrative bar-plot examples of risk mappings evaluated at discrete governance tiers. Panel (a) shows annual event probability and panel (b) shows conditional severity for two autonomy categories. The values are order-of-magnitude underwriting examples for a healthcare-style agenticAI deployment, not empirical estimates.
(a) Governance cost and premium (USD thousands) Ki (g)
(b) Deductible and risk loading (USD thousands)
τi (g)
120
75
80
50
40
25
0
dri (g)
ϱi
g (1)
g (2)
0 g (1)
g (2)
g (3)
g (4)
g (3)
g (4)
Figure 2: Illustrative bar-plot examples of financial and contract-schedule mappings evaluated at discrete governance tiers. Panel (a) shows governance cost and premium schedules; panel (b) shows deductible and risk-loading schedules. The values are order-of-magnitude underwriting examples for a healthcare-style agentic-AI deployment, not empirical estimates.
4.3
Agentic-AI Event Space
Traditional cyber-insurance models classify losses by attack category—phishing, ransomware, denial of service, malware, or insider threats. Agentic AI needs a broader event space, because losses may arise from autonomous behavior, flawed reasoning, degraded model performance, dependency failures, or cyber-physical interaction even when no conventional intrusion occurs. Let R = {Cyber, TechEO, Perf, GL, Mixed} denote the set of coverage layers. For each layer r ∈ R, let E r denote the set of event types naturally associated with that layer, and let E =
S
r∈R E
r
denote the full event space. The sets E r need not be disjoint because a single event may implicate several coverage layers. Table 8 lists representative events for each coverage layer. The symbols eH , eP , eF , eD , eO , and eC are used later in the healthcare case study as a reduced event set. Hallucination events arise when an AI system produces incorrect outputs, recommendations, or actions that are relied upon by users or automated workflows. Prompt-injection events occur when adversarial inputs manipulate the reasoning process of the AI system, causing it to disclose information, ignore safeguards, or execute unauthorized actions [18, 27]. Agentic fraud includes unauthorized transactions, deceptive communications, and abuse of operational authority. Model drift captures performance degradation under changing operating conditions [29]. Dependency outages arise from failures of cloud providers, model vendors, external APIs, software connectors,
Table 8: Representative Agentic-AI Events by Coverage Layer Layer r Cyber TechE&O Performance GL Mixed
Representative events e ∈ E r Prompt injection eP , data exfiltration, credential misuse, unauthorized tool invocation, malicious configuration change Hallucinated advice eH , faulty output, negligent automation, workflow misrouting, erroneous customer or patient communication Model drift eD , calibration failure, benchmark degradation, latency failure, reliability degradation Cyber-physical harm eC , bodily injury, property damage, equipment malfunction, unsafe robotic or IoT control Agentic fraud eF , dependency outage eO , multi-causal loss, unclear causation across cyber, service, and AI-behavioral factors
or hosted agent platforms. Cyber-physical harm covers bodily injury, property damage, equipment malfunction, or critical-infrastructure disruption resulting from autonomous interaction with physical environments [19].
4.4
Coverage Architecture
A defining feature of agentic-AI insurance is that a single event may simultaneously involve autonomous decision making, software malfunction, cyber compromise, professional negligence, regulatory violation, and physical consequence. The central modeling problem is thus not only whether coverage exists, but how an event maps into the appropriate coverage layers when several causal mechanisms contribute to the loss. For insured i, an agentic-AI insurance contract is Ci = (Ti , {Dir , Lri }r∈R , Ai , Γi , Λi , Ψi ) ,
(8)
where Ti ∈ R+ is the premium, Dir ∈ R+ is the deductible for layer r, Lri ∈ R+ is the per-event layer limit, Ai ∈ R+ is the AI aggregate limit, and Ψi is the governance-obligation component of the policy. The binary coverage-incidence matrix Γi ∈ {0, 1}|E|×|R| has entries γie,r , and the indemnity-share matrix Λi ∈ [0, 1]|E|×|R| has entries λe,r i . The binary variable γie,r is equal to one when event e is covered or assigned under layer r for insured i, and is zero otherwise. Thus Γi is a matrix of zeros and ones, not a fractional allocation matrix. The continuous share λe,r i determines the fraction of the payable loss attributed to layer r, and it
is admissible only when the corresponding incidence entry is active: e,r 0 ≤ λe,r i ≤ γi ,
X e,r
λi
≤ 1,
∀e ∈ E, r ∈ R.
(9)
r∈R
This separation is useful in mixed-cause events. The matrix Γi records which coverage layers are legally or contractually available, while Λi records how the indemnity is apportioned among those available layers for pricing and claims execution.
4.5
Governance Covenants and Policy Obligations
The term Ψi is the governance-obligation component of the policy—the part of the contract that converts underwriting assumptions into continuing obligations on the insured deployment. This matters because an agentic-AI risk state is not fixed at inception: delegated authority, permission scope, model dependencies, and operational capabilities may all shift during the policy period. Ψi should therefore be read as enforceable policy language in mathematical form, not merely a vector of model parameters. Formally, we write Ψi = (gi⋆ , z̄i , Oi , Mi , Ni ). Here gi⋆ ∈ G is the required governance tier, z̄i = (z̄i,1 , . . . , z̄i,Lg ) gives minimum acceptable control scores, Oi contains oversight obligations, Mi contains monitoring and evidence obligations, and Ni contains notice and remediation obligations. The map gmin (Ψi ) returns the minimum governance tier capable of satisfying the covenant package. A representative policy covenant may be written as follows. Agentic-AI governance covenant. The insured shall maintain human approval for safety-critical actions; tamper-evident audit logging of AI outputs, tool calls, approvals, and system actions for at least twenty-four months; quarterly prompt-injection and adversarial testing; written notice to the insurer within thirty days after any material expansion of AI permissions, autonomous authority, or external-system access; and incident notice within seventy-two hours after discovery of any event reasonably expected to give rise to a claim. Failure to maintain these controls may result in loss of governance-related premium credits, increased deductibles, suspension of coverage for affected AI-related claims, or other remedies permitted by the policy and applicable law.
Each clause has a direct interpretation in the model. Oversight obligations in Oi restrict oper-
ational authority. If safety-critical actions must be approved by a human, then those actions have hi (u) = 1 in (1). More generally, the covenant may impose an upper bound βi ≤ β̄i , where β̄i is determined during underwriting. This prevents the insured from expanding autonomous execution authority after coverage is priced. Monitoring and evidence obligations in Mi translate the threshold vector z̄i into auditable requirements. For a logging, testing, access-control, or incident-response dimension ℓ, the policy requirement is represented by zi,ℓ ≥ z̄i,ℓ . Since the assigned governance tier is gi = h(zi ), these thresholds determine whether the insured continues to satisfy the required governance tier gi⋆ . Audit logs, retained approval records, telemetry, prompt-injection tests, and model-performance reports therefore serve as evidence for the control scores used by the underwriting rule. The notice obligation for permission expansion is tied to the permission profile ηi . A deployment approved only for patient messaging and scheduling may later be given authority to modify patient records, initiate payments, invoke external APIs, or control devices. Such changes alter ηi , the weighted exposure ψη (ηi ), and potentially the admissible action set Ui (ηi ). The covenant therefore requires notice and possible re-underwriting before material permission expansions become part of the insured operating environment. Notice and remediation duties in Ni govern post-incident claims handling. They apply after a material incident, control failure, or potentially covered AI-related loss. Prompt notice preserves logs and causal evidence, allows the insurer to evaluate whether the event falls within the covered event set E, and supports the indemnity calculation through Γi , Λi , and the layer-payment functions. Remediation duties, such as an incident report within fourteen days and a remediation plan within thirty days, help prevent repeated losses from the same control failure. For the covenant quoted above, a concrete mathematical representation could be written as
cov Ψcov = g (3) , z̄i , Oicov , Mcov , i i , Ni
Oicov :
hi (u) = 1 ∀u ∈ Uicrit ,
Mcov : i
zi,ℓlog ≥ z̄i,ℓlog , Rilog ≥ 24,
Nicov :
tηi ≤ 30,
βi ≤ β̄i ,
zi,ℓtest ≥ z̄i,ℓtest ,
∆test ≤ 90, i tei ≤ 72.
(10)
Here Uicrit is the set of safety-critical actions, Rilog is the number of months for which tamper-evident logs are retained, ∆test is the maximum number of days between prompt-injection or adversarial i tests, tηi is the number of days before notice is provided after a material permission or authority expansion, and tei is the number of hours before incident notice is provided after discovery of a potentially covered event. A material permission expansion can be operationalized by comparing the post-change permission vector ηi+ with the underwritten vector ηi , for example by requiring re-underwriting whenever ψη (ηi+ ) − ψη (ηi ) ≥ εη for an insurer-chosen threshold εη , or whenever a scheduled high-risk permission class is newly activated. This example shows how the legal language of the covenant becomes constraints on human approval, operational authority, control evidence, testing frequency, permission changes, and notice timing. The covenant package connects directly to the optimization framework. It imposes the feasibility condition gi ⪰ gmin (Ψi ), shifts event probabilities and severities through qie = Qe (si ) and xei = X e (si ), and supplies the contractual mechanism behind governance-sensitive premium and deductible schedules. Premium credits, deductible credits, coverage enhancements, or continued eligibility may be conditioned on maintaining the required tier, while breach of Ψi may trigger repricing, higher deductibles, withdrawal of credits, non-renewal, or other policy remedies. Governance covenants are thus not administrative details; they are how agentic-AI controls become insurable, monitorable, and enforceable across the policy lifecycle.
4.6
Indemnity Function
For event e, the layer-level indemnity attributed to coverage layer r is n
o
e r + r Yie,r (Ci ) = λe,r i min (xi − Di ) , Li ,
Let Ybie (Ci ) =
(x)+ = max{x, 0}.
(11)
e,r b r∈R Yi (Ci ) be the event payment before the annual aggregate and let Yi (Ci ) =
P
be e∈E Yi (Ci ). The aggregate-adjusted event indemnity is
P
Ybie (Ci ) min{1, Ai /Ybi (Ci )},
Ybi (Ci ) > 0,
0,
Ybi (Ci ) = 0.
Yie (Ci ) =
(12)
Equations (11)–(12) preserve the standard roles of deductibles, limits, and aggregate caps while enabling causation-sensitive allocation across the cyber, technology E&O, performance, generalliability, and mixed-cause layers. Losses below Dir stay with the insured, payments above the deductible are capped by Lri , and Ai bounds the insurer’s AI-related aggregate exposure over the covered event set. Figure 3 illustrates the layer-level payment schedule in (11) for a fixed event e and coverage layer r. The deductible creates a no-payment region for small losses, the layer limit creates a capped payment region for large losses, and the allocation share λe,r scales the amount paid by layer r i when the event is allocated across several layers. Yie,r (Ci ) (USD thousands) capped payment region
300
λe,r =1 i λe,r = 0.5 i
Lri 200 0.5Lri 100 deductible region 0 0
Dir
100
200
300 Dir + Lri
400
500
600
xei (USD thousands)
e r + r Figure 3: Illustrative layer-level indemnity schedule Yie,r (Ci ) = λe,r i min{(xi − Di ) , Li } as a e r r function of gross loss xi . The example uses Di = $50,000 and Li = $250,000. The solid curve shows full allocation to layer r, while the dashed curve shows a mixed-cause allocation in which only half of the payable loss is attributed to that layer.
5
Pricing and Contract Optimization Framework The preceding section defined the risk state, event taxonomy, coverage layers, and indemnity
function. This section uses those objects to state the pricing, participation, incentive-compatibility, and optimization conditions that determine a feasible agentic-AI insurance contract. Throughout, Ti , Dir , Lri , Ai , Γi , and Λi are the scalar or matrix decision variables of the contract. When premium or deductible schedules create governance incentives, they are written as separate functions τi (·) and dri (·), and the issued contract carries the realized scalars Ti = τi (gi⋆ ) and Dir = dri (gi⋆ ), where gi⋆ ∈ G is the required governance tier.
5.1
Insured Utility and Participation
Insurance is economically meaningful only if it improves the insured’s expected financial position. Let Ki (gi ) denote the annual cost of the governance controls associated with tier gi : monitoring, logging, approval workflows, red-teaming, model validation, rollback capability, and incident response. To keep notation clean, we separate the participation cost of an issued contract from the counterfactual governance-deviation cost used later for incentive compatibility. The insured’s participation cost under the issued contract Ci is Jipart (Ci ) = Ti + Ki (gi ) +
X
qie (xei − Yie (Ci )) .
(13)
e∈E
This expression evaluates the realized contract terms Ti , Dir , Lri , Ai , Γi , and Λi at the realized governance tier gi . It is the object used only for the participation comparison against the uninsured baseline. The baseline cost without insurance is Ji0 = Ki (gi0 ) +
X e,0 e,0
qi xi ,
(14)
e∈E
where gi0 , qie,0 , and xe,0 denote the governance tier, event probability, and gross loss under the i uninsured operating policy. Individual rationality requires Jipart (Ci ) ≤ Ji0 , which is the insured’s participation constraint [32].
5.2
Insurer Profitability and Risk-Based Pricing
The insurer’s expected payout for insured i is
P
e e e∈E qi Yi (Ci ).
Because agentic-AI insurance
faces sparse loss data, model evolution, legal uncertainty, and correlated dependency risk, expectedloss pricing must be supplemented by the risk-loading function ϱi : S × Ci → R+ [6, 7]. The risk-loaded premium condition is
Ti ≥
X
qie Yie (Ci ) + ϱi (si , Ci ).
(15)
e∈E
The loading ϱi (si , Ci ) should be interpreted as a total underwriting adjustment rather than as a required decomposition into named subcomponents. In practice, the insurer may set this loading
to reflect portfolio accumulation, dependency concentration, model uncertainty, sparse claims experience, legal uncertainty, regulatory exposure, and the amount of limit deployed. Figure 4 gives an illustrative bar-plot example of how the total loading may increase as underwriting uncertainty and concentration risk increase. Illustrative total risk loading Routine deployment
10
Single-vendor dependency
18
Novel model and legal risk
25
High-limit concentration
36 0
10
20
30
40
ϱi (si , Ci ) (USD thousands)
Figure 4: Illustrative total risk-loading levels for four underwriting scenarios. The values are order-of-magnitude examples in thousands of dollars and are not empirical estimates. The point is that ϱi (si , Ci ) can be treated as a single underwriting loading that increases with dependency concentration, model uncertainty, legal uncertainty, and deployed policy limits. The insurer’s risk-adjusted underwriting profit is Πi (Ci ) = Ti −
X
qie Yie (Ci ) − ϱi (si , Ci ).
(16)
e∈E
5.3
Governance Incentive Compatibility
A distinguishing feature of agentic-AI insurance is that many important risk factors stay under the insured’s direct control. After buying coverage, an insured may weaken monitoring, reduce human oversight, expand autonomous execution authority, or relax operational controls— raising expected losses through classic moral hazard [20]. Governance must therefore enter the contract-design problem, consistent with the insurance-economics distinction among risk transfer, self-insurance, and self-protection [14]. Let gi⋆ ∈ G denote the governance tier required by the insurer and define si (g̃) = (αi , βi , ηi , g̃, vi ). For a candidate governance tier g̃ ∈ G, define the induced event probability and severity as qie (g̃) =
Qe (si (g̃)) and xei (g̃) = X e (si (g̃)). The insured’s governance-deviation cost is then Jigov (g̃; Ci ) = τi (g̃) + Ki (g̃) +
X
qie (g̃) [xei (g̃) − Yie (g̃; Ci )] .
(17)
e∈E
Here Ci is fixed while g̃ varies; when governance-sensitive premium or deductible schedules are used, Ci is understood to include the schedules τi (·) and dri (·) for this counterfactual calculation. The participation cost satisfies Jipart (Ci ) = Jigov (gi ; Ci ) when the issued contract is evaluated at its realized governance tier. The governance requirement is incentive compatible if gi⋆ ∈ arg ming̃∈G Jigov (g̃; Ci ), or equivalently if Jigov (gi⋆ ; Ci ) ≤ Jigov (g; Ci ) for all g ∈ G. The insurer may induce this behavior (m)
through governance-sensitive schedules τi : G → R+ and dri : G → R+ . Let Ti r,(m)
Di
= τi (g (m) ) and
= dri (g (m) ). Premium credits and deductible credits for stronger governance can be imposed (1)
through Ti
(2)
≥ Ti
(M )
≥ · · · ≥ Ti
r,(1)
and Di
r,(2)
≥ Di
r,(M )
≥ · · · ≥ Di
. The scalar terms written
into the issued contract are then Ti = τi (gi⋆ ) and Dir = dri (gi⋆ ). These schedules reward monitoring, audit logs, approval controls, validation procedures, and human oversight throughout the policy period without treating Ti or Dir themselves as functions. Figure 5 illustrates the counterfactual calculation: each bar is the total expected cost obtained by evaluating the fixed contract schedule at one discrete governance tier, so the induced tier is the bar with the lowest value rather than the minimizer of a continuous curve. Illustrative Jigov (g; Ci ) (USD thousands) τi (g)
200
166
150
Ki (g)
retained expected loss
140
gi⋆ 131
144
g (2)
g (3)
g (4)
100 50 0
g (1)
Figure 5: Illustrative governance-deviation cost Jigov (g; Ci ) evaluated over discrete governance tiers. Each stacked bar decomposes total expected cost into the governance-sensitive premium, governance-control cost, and retained expected loss. In this example, the premium and retained loss decrease with stronger governance, while governance cost increases; the induced minimum occurs at gi⋆ = g (3) , satisfying the incentive-compatibility condition.
5.4
Agentic-AI Insurance Contract Optimization
The insurer’s contract-design problem can now be stated as a mathematical program over the premium, layer-specific deductibles and limits, the aggregate AI limit, the binary coverage-incidence matrix, the indemnity-share matrix, and the governance obligations. Problem 3 (Agentic-AI insurance contract design). For a fixed insured i with state si and baseline cost Ji0 , choose Ci = (Ti , {Dir , Lri }r∈R , Ai , Γi , Λi , Ψi ) to solve max Ci
s.t.
Πi (Ci ) = Ti −
qie Yie (Ci ) − ϱi (si , Ci )
(18a)
qie (xei − Yie (Ci )) ≤ Ji0
(18b)
X e∈E
Ti + Ki (gi ) +
X e∈E
Ti −
X
qie Yie (Ci ) ≥ ϱi (si , Ci )
(18c)
e∈E
gi ⪰ gmin (Ψi )
(18d)
gi⋆ ∈ arg min Jigov (g̃; Ci )
(18e)
g̃∈G
e,r 0 ≤ λe,r i ≤ γi ,
X e,r
λi
≤ 1,
∀e ∈ E, r ∈ R
(18f)
r∈R
γie,r ∈ {0, 1},
∀e ∈ E, r ∈ R
0 ≤ Dir ≤ Lri ≤ Ai ,
∀r ∈ R.
(18g) (18h)
The objective (18a) maximizes risk-adjusted underwriting profit. Constraint (18b) is the insured’s individual-rationality condition. Constraint (18c) enforces risk-loaded pricing. Constraint (18d) links the policy wording Ψi to a minimum operational control standard, while (18e) requires that maintaining the desired governance tier be optimal for the insured. Constraints (18f)–(18g) formalize Γi as a binary coverage-incidence matrix and Λi as the continuous payment-allocation matrix. Constraint (18h) imposes economically meaningful layer deductibles, limits, and aggregate exposure. The formulation therefore links agent autonomy, operational authority, permissions, governance, and dependency concentration directly to pricing, coverage allocation, incentive compatibility, and claims payment.
5.5
Insurability Region, Feasibility Monotonicity, and Governance Certification
Problem (18) optimizes over all contract terms. In practice, an insurer often fixes the coverage architecture—deductibles, limits, aggregate, incidence, allocation, and required governance tier— and asks only whether a premium exists that both parties accept. The case study of Section 7 follows exactly this fixed-terms logic. We formalize it here and show that it induces a well-structured insurability region in the underwriting state space, with the monotone feasibility and governancecertification properties invoked in the conclusion. Fix the non-premium terms Ci−T = ({Dir , Lri }r∈R , Ai , Γi , Λi , Ψi ) together with the uninsured baseline Ji0 and the governance cost Ki (gi ). The insurer-profitability constraint (18c) and the participation constraint (18b) bound the premium from below and above, Timin (si ) =
X
qie Yie (Ci ) + ϱi (si , Ci ),
Timax (si ) = Ji0 − Ki (gi ) −
X
qie xei − Yie (Ci ) .
(19)
e∈E
e∈E
A contract is marketable with surplus buffer s0 ≥ 0 if Timin (si ) ≤ Timax (si ) − s0 , where s0 guarantees the insured a minimum saving over the uninsured baseline, as imposed in the case study. Subtracting the two bounds, the indemnity terms cancel and the marketable surplus reduces to the closed form ∆i (si ) := Timax (si ) − Timin (si ) = Ji0 − Ki (gi ) −
X
qie xei − ϱi (si , Ci ).
(20)
e∈E
The identity (20) is itself informative: the indemnity schedule Yie determines where an acceptable premium lies but not whether the interval is nonempty. Feasibility depends only on the uninsured baseline, the governance cost, the expected gross loss, and the risk loading. Definition 4 (Insurability region). For fixed non-premium terms and buffer s0 ≥ 0, the insurability region is n
S ins (s0 ) = s ∈ S : ∆(s) ≥ s0 = s ∈ S : K(g) +
o
e e 0 e∈E q (s) x (s) + ϱ(s, C) ≤ J − s0 .
P
A state s is insurable at these terms if and only if s ∈ S ins (s0 ), in which case every premium
T ∈ [ T min (s), T max (s) − s0 ] is mutually acceptable. Insurance is thus available precisely when the expected all-in risk cost of the deployment—governance cost plus expected gross loss plus risk loading—does not exceed the value the insured can save, Ji0 − s0 . To describe how the region varies with the risk state, we order states by exposure. Write s ⪯E s′ when s and s′ share the same governance tier and s′ is componentwise weakly more exposed: α ⪯ α′ , β ≤ β ′ , ψη (η) ≤ ψη (η ′ ), and R(v) ≤ R(v ′ ). The pricing primitives are exposuremonotone if, for every event e, the maps q e and xe are nondecreasing under ⪯E and the loading ϱ(·, C) is nondecreasing under ⪯E . The benchmark specifications (6)–(7) satisfy this whenever their exposure coefficients are nonnegative. Proposition 5 (Monotone deterioration of fixed-terms insurability). Fix the non-premium terms, J 0 , and K(g), and assume the pricing primitives are exposure-monotone. Then the marketable surplus ∆(s) in (20) is nonincreasing under ⪯E , and the lower premium bound T min (s) is nondecreasing under ⪯E . Consequently the insurability region is downward closed in exposure: if s′ is insurable and s ⪯E s′ , then s is insurable. Equivalently, along any exposure-increasing path the surplus crosses zero at most once, from feasible to infeasible, and never returns. Proof. By exposure-monotonicity each product q e (s) xe (s) is nondecreasing under ⪯E , being a product of nonnegative nondecreasing maps, and ϱ(s, C) is nondecreasing. Since J 0 and K(g) are held fixed, (20) expresses ∆ as a constant minus a sum of nondecreasing terms, so ∆ is nonincreasing. e r + r e For the lower bound, Yie (Ci ) = λe,r i min{(xi − Di ) , Li } is nondecreasing in xi , hence
e e e q Y is
P
nondecreasing and, adding the nondecreasing loading, so is T min . Downward closure follows because s ⪯E s′ gives ∆(s) ≥ ∆(s′ ) ≥ s0 . The single-crossing property is immediate from monotonicity of ∆ along an exposure-increasing chain. Proposition 5 explains why raising delegated authority, permission exposure, or dependency concentration can only erode fixed-terms feasibility, never restore it—the behavior observed numerically in the sensitivity analysis of Section 7. Governance acts in the opposite direction, which yields a certification threshold.
Proposition 6 (Governance certification threshold). Fix the exposure coordinates s−g = (α, β, η, v) and the non-premium terms other than the required tier. Suppose stronger governance is net riskreducing, i.e., the map
Φ(g) := K(g) +
X
q e (s−g , g) xe (s−g , g) + ϱ(s−g , g)
e∈E
is nonincreasing in the tier order over the relevant range. Then ∆ is nondecreasing in g, and there is a minimal certifiable tier
g cert (s−g ) = min g ∈ G : Φ(g) ≤ J 0 − s0
(whenever this set is nonempty) such that the deployment is insurable at the fixed terms if and only if g ⪰ g cert (s−g ). Proof. Since ∆(s−g , g) = J 0 − Φ(g) by (20) and Φ is nonincreasing in g, ∆ is nondecreasing in g. The set {g : Φ(g) ≤ J 0 − s0 } = {g : ∆ ≥ s0 } is therefore an up-set in the tier order, so it has a least element g cert when nonempty, and g ⪰ g cert is equivalent to insurability. Definition 7 (AI-insurability certificate). A deployment with exposure s−g is insurability-certifiable at the fixed coverage terms if g cert (s−g ) exists and is attainable by the insured, in the sense that some tier g ⪰ g cert (s−g ) can be evidenced through the control scores zi and assigned by gi = h(zi ). The certificate attests that governance at tier g cert or higher renders the deployment insurable at the stated terms. Proposition 6 converts governance from a qualitative virtue into a contractible admission condition: below g cert no premium clears the market, whereas at or above it a mutually acceptable contract exists. Together, Definition 4 and Propositions 5–6 show that insurability is a structured region of the risk-state space—shrinking monotonically in exposure and expanding with verifiable governance—rather than a case-by-case judgment.
6
Insurance as AI Operating Cost and Regulatory Control The preceding framework treats insurance as a private contract between an insurer and an
insured. It also carries a public-policy interpretation. When an AI deployment can inflict losses on patients, customers, employees, counterparties, infrastructure users, or the public, insurance becomes more than risk transfer: it can act as a priced condition for operating an AI system, a quasitax on risk creation, and a regulatory control that decides which deployments must demonstrate financial responsibility before going into use. The interpretation is familiar in law and economics. Liability rules, safety regulation, and mandatory insurance are alternative instruments for controlling external harms when private actors do not fully internalize the social costs of their activity [10, 33]. In Pigouvian terms, a charge attached to risky activity curbs excess by making decision makers face more of the expected social cost they impose on others [28]. Agentic AI is a natural setting for this logic, because the same technical capability can be socially valuable in one context and socially costly in another, depending on permissions, delegated authority, governance, and dependency concentration.
6.1
Insurance as a Bundled Cost of AI Deployment
Consider an organization deciding whether to deploy an AI agent with risk state si . Let Bi (si ) denote the organization’s private operating benefit from the AI deployment, such as reduced labor cost, faster service, improved triage, increased throughput, or new revenue. Let Ciop (si ) denote ordinary operating cost, excluding insurance and governance. If insurance is optional, the organization may compare the AI benefit with technical operating cost and expected uninsured loss. If insurance is bundled into the legal or commercial cost of using AI, the adoption calculation changes. For a deployment insured under contract Ci , the private annual cost of using AI can be written as CiAI (si , Ci ) = Ciop (si ) + Ki (gi ) + Ti +
X
qie xei − Yie (Ci ) .
(21)
e∈E
The term Ti is then not merely an insurance premium from an accounting perspective. It becomes part of the all-in cost of deploying agentic AI. If a vendor bundles insurance into an AI product, this cost may appear as a licensing surcharge, a per-agent fee, a per-action fee, or a sector-specific
compliance charge. For example, if Niact denotes the expected annual number of covered agent act actions, the premium can be converted into an action-level insurance cost cact i = Ti /Ni . A buyer
then experiences insurance as part of the marginal cost of operating the AI workflow. This cost has an incentive effect. The organization deploys the agent only if the net value Bi (si ) − CiAI (si , Ci ) exceeds the non-AI alternative, so higher premiums, governance expenditures, and retained losses can discourage deployment. That is not necessarily a defect: when an AI system creates high expected external harm and low private value, a high insurance cost screens out undesirable deployment. But if premiums are poorly calibrated, unavailable, or inflated by legal uncertainty and sparse claims data, the same mechanism can deter socially valuable uses. Insurance can therefore discipline risky AI adoption, yet also become a barrier to innovation whenever the price of coverage substantially exceeds the risk the deployment creates.
6.2
Premiums as Quasi-Pigouvian Risk Prices
The premium can be interpreted as a private-market analogue of a Pigouvian tax when it increases with the expected losses and external risks generated by the deployment. In the model above, the risk-loaded premium condition requires Ti ≥
e e e∈E qi Yi (Ci ) + ϱi (si , Ci ).
P
When the
indemnity Yie (Ci ) approximates harm that would otherwise be borne by third parties, customers, or the public, the premium forces the AI operator to internalize a priced portion of that harm. This interpretation is clearest when the premium is monotone in the exposure components of the risk state. If higher operational authority βi , broader weighted permissions ψη (ηi ), or greater dependency concentration R(vi ) increases event probabilities, severities, or risk loadings, then the premium increases with risk-creating activity. Conversely, stronger governance gi can reduce the charge by lowering probabilities, severities, deductibles, or risk loadings. The premium schedule therefore acts as a market-based control signal: Ti = τ (si , Ci )
with
τ increasing in exposure and decreasing in verified governance.
Unlike a public tax, the premium is paid to an insurer rather than the government, and it finances risk transfer, claims adjustment, capital cost, and monitoring. Nevertheless, from the AI user’s perspective, it has a tax-like effect because it raises the private cost of risky AI deployment and
can reduce demand for high-risk configurations. Proposition 8 (Adoption effect of bundled insurance cost). Fix the non-AI outside option and the AI deployment benefit Bi (si ). If insurance is mandatory or commercially bundled into the deployment cost, then any increase in Ti , Ki (gi ), or expected residual loss weakly decreases the set of risk states for which deploying the AI system is privately profitable. Proof. The deployment is privately profitable only when Bi (si ) − CiAI (si , Ci ) exceeds the outside option. In (21), the cost CiAI is increasing in Ti , Ki (gi ), and expected residual loss. Increasing any of these terms weakly lowers net private value and therefore can only shrink, not expand, the set of states satisfying the adoption inequality. The proposition formalizes the basic adoption tradeoff. Insurance can be a useful social instrument because it discourages deployments whose benefits do not justify their risk. But it also creates a policy-design problem: the mandate should be targeted enough that the cost falls primarily on deployments capable of material third-party harm rather than on low-risk assistive uses.
6.3
Mandatory Insurance and Financial Responsibility
A regulator can use the risk-state representation to specify which AI deployments must be insured. Let di denote nontechnical context, such as sector, population affected, criticality, transaction value, and whether the deployment affects health, employment, credit, education, public safety, financial transfers, or physical systems. A mandate can be represented by an indicator
M (si , di ) =
1,
if deployment i must carry agentic-AI insurance,
0,
otherwise.
The mandate may be triggered by autonomy category, authority, permission exposure, dependency concentration, sector, or combinations of these factors. For example, a regulator may require insurance when αi ⪰ α(2) , βi ≥ β̄, ψη (ηi ) ≥ ψ̄, or the deployment operates in a high-impact sector. A stricter rule may require insurance for any cyber-physical agent or any AI workflow authorized to initiate financial transactions, modify critical records, or make operational decisions without human approval.
Definition 9 (Mandated insurability requirement). A deployment i satisfies a mandated insurability requirement if M (si , di ) = 0, or if M (si , di ) = 1 and there exists an admissible contract Ci ∈ Ci such that the required premium is paid, the aggregate limit satisfies Ai ≥ Amin (si , di ), the governance tier satisfies gi ⪰ gmin (Ψi ), and the coverage incidence matrix Γi includes all event-layer pairs required by law or regulation. This definition separates two questions that are often conflated. The first question is whether an organization can obtain insurance in the market. The second is whether the organization is legally permitted to operate the AI system without insurance. A mandate makes insurability a precondition for deployment. If no admissible contract exists because the risk is too high, the coverage is unavailable, or the required governance tier is not met, then the deployment fails the financial-responsibility requirement even if the operator would otherwise prefer to use the AI system.
6.4
Insurance as a Control Mechanism
Mandatory insurance can therefore operate as a regulatory control. It does not directly prescribe every technical design choice. Instead, it requires an AI operator to satisfy underwriting, governance, coverage, and monitoring conditions before deployment. The control is implemented through several linked mechanisms. First, the mandate defines the boundary of covered AI activity. The permission profile ηi , operational authority βi , and deployment context di determine whether insurance is required. Second, the insurer evaluates the state si and prices the policy. Third, the policy covenant Ψi requires ongoing governance controls, notice obligations, and evidence retention. Fourth, failure to maintain the underwritten state can trigger repricing, higher deductibles, loss of premium credits, suspension of coverage for newly enabled permissions, nonrenewal, or regulatory noncompliance. This gives insurance a dual role. Ex ante, it screens deployments by making high-risk AI more expensive, or uninsurable until governance improves. Ex post, it builds a claims and monitoring infrastructure that records losses, identifies failure modes, and generates data for future pricing and regulation. Over time, the feedback loop sharpens both actuarial calibration and public oversight. The policy challenge is calibration. Too broad a mandate becomes a general AI tax that deters low-risk productivity tools and small organizations; too narrow a mandate lets high-risk deploy-
ments operate without adequate financial responsibility. A principled mandate should therefore be risk-based, attaching its strongest requirements to systems with high autonomy, high delegated authority, broad external-state permissions, high-impact sectors, cyber-physical consequences, or systemic dependency concentration. In this sense agentic-AI insurance is not merely a private financial product; it is a candidate governance layer for aligning AI deployment incentives with social risk.
7
Case Study: Agentic-AI Insurance for Clinical Care Coordination To illustrate the framework in practice, we consider a healthcare system that deploys an au-
tonomous clinical care-coordination agent to support physicians, nurses, and administrative staff. The agent reviews patient messages, summarizes electronic health records, prioritizes incoming requests, schedules appointments, drafts patient communications, and escalates potentially urgent cases for clinical review. It cannot prescribe medication or independently discharge patients, but it does produce persistent external-state changes through scheduling systems, communication channels, and workflow-management tools. The deployment therefore falls within the autonomous digital-agent category and carries insurable risks that extend well beyond traditional cybersecurity concerns. The hospital’s deployment is represented by the state vector si = (αi , βi , ηi , gi , vi ), where αi = α(2) denotes an autonomous digital agent, βi = 0.45 means that roughly 45 percent of weighted authorized actions may execute without human approval, and ηi = (1, 1, 0, 0, 0) indicates that the system can communicate with patients and schedule appointments but cannot prescribe medication, modify billing systems, or control physical devices. Under the illustrative permission weights in Table 4, this profile has weighted permission exposure ψη (ηi ) = 3, reflecting email and scheduling rights without higher-risk billing, record-modification, or device-control permissions. The hospital maintains extensive governance controls including clinician review, audit logging, prompt-injection filtering, incident monitoring, and rollback capabilities, so the underwriting rule assigns it to governance tier gi = g (3) . Finally, the deployment relies on a single cloud-hosted foundation-model
provider, resulting in a dependency concentration measure of R(vi ) = 0.40. The reduced healthcare event set is E hc = {eH , eP , eF , eD , eO , eC }, where eH denotes hallucination, eP prompt injection, eF agentic fraud, eD model drift, eO dependency outage, and eC cyber-physical harm. Table 9 reports representative annual probabilities qie , gross losses xei , and the active coverage layer used in the simplified numerical calculation. Table 9: Representative Agentic-AI Healthcare Loss Scenarios Event e Hallucination eH Prompt injection eP Agentic fraud eF Model drift eD Dependency outage eO Cyber-physical harm eC
Active layer r TechE&O Cyber Mixed Performance Mixed GL
qie 0.060 0.025 0.010 0.040 0.080 0.002
xei $250,000 $400,000 $300,000 $150,000 $100,000 $2,000,000
The expected annual loss before insurance is E[Xi ] =
X
qie xei
e∈E hc
= 0.060(250, 000) + 0.025(400, 000) + 0.010(300, 000)
(22)
+ 0.040(150, 000) + 0.080(100, 000) + 0.002(2, 000, 000) = 46, 000. The insurer seeks to design Ci = (Ti , {Dir , Lri }r∈R , Ai , Γi , Λi , Ψi ). The objective is to maximize riskadjusted underwriting profit while ensuring that the hospital voluntarily participates, the insurer earns at least the required risk loading, and the hospital maintains the required governance controls. The resulting optimization problem is
max Ci
s.t.
Πi (Ci ) = Ti −
qie Yie (Ci ) − ϱi (si , Ci )
(23a)
qie (xei − Yie (Ci )) ≤ Ji0
(23b)
X e∈E hc
Ti + Ki (gi ) +
X e∈E hc
Ti −
X
qie Yie (Ci ) ≥ ϱi (si , Ci )
(23c)
e∈E hc
gi ⪰ gmin (Ψi )
(23d) X e,r
e,r 0 ≤ λe,r i ≤ γi ,
λi
≤ 1,
∀e ∈ E hc , r ∈ R
(23e)
r∈R
γie,r ∈ {0, 1},
∀e ∈ E hc , r ∈ R
0 ≤ Dir ≤ Lri ≤ Ai ,
∀r ∈ R.
(23f) (23g)
Constraint (23b) ensures that the hospital prefers purchasing insurance to remaining uninsured. Constraint (23c) imposes the insurer’s risk-loaded profitability requirement, while (23d) enforces the governance obligations embedded in the policy. Constraints (23e)–(23f) require Γi to be a binary coverage-incidence matrix and Λi to allocate payment only to active coverage layers. To illustrate how the optimization problem is solved, suppose that the governance-obligation package Ψi is fixed by regulatory and organizational requirements. In this case study, Ψi is a policy-covenant package requiring gmin (Ψi ) = g (3) , clinician approval for high-acuity patient communications, least-privilege access to scheduling and messaging tools, retention of complete and tamper-evident action logs for twenty-four months, monthly reporting of autonomous-action rates, quarterly prompt-injection testing, rollback capability, dependency-continuity procedures for the foundation-model provider, insurer notice within seventy-two hours after unauthorized tool execution or suspected patient-data disclosure, an incident report within fourteen days, and a remediation plan within thirty days. The computational implementation in case study optimization.py solves a finite-menu version of (23a)–(23g). It searches two governance choices, g (3) and g (4) ; five common deductible choices from $0 to $100,000 in $25,000 increments; four common layer limits from $250,000 to $1,000,000; and three aggregate limits from $1,000,000 to $1,500,000. To avoid nonmarketable thin coverage, the menu imposes an expected indemnity ratio of at least
75 percent, a cyber-physical event payment of at least $400,000, and an insured surplus of at least $5,000 relative to the uninsured baseline. The risk-loading rule used in the computation is ϱi = 9000 + 0.05 E[Yi (Ci )] + 0.002(Ai − 1, 000, 000)+ + 2500 − c(gi⋆ ), where c(g (4) ) = 1500 and c(g (3) ) = 0. This loading captures fixed underwriting expense, claims volatility, dependency concentration, aggregate-limit capital cost, and a governance credit for the stronger tier. For the simplified numerical calculation, the active incidence entries of Γi are exactly the event-layer pairs ′ listed in Table 9. For each listed pair (e, r), set γie,r = 1 and λe,r i = 1; for all other layers r ̸= r, ′
′
set γie,r = λe,r = 0. Thus Γi is a binary matrix with one active entry in each event row, while i Λi assigns the full payable loss to that active layer. Mixed-cause claims can be represented by activating multiple entries in the same row and choosing corresponding shares in Λi . For any candidate contract, first compute the event payment before the annual aggregate:
e r + r Ybie,r (Ci ) = λe,r i min{(xi − Di ) , Li },
Ybie (Ci ) =
X
Ybie,r (Ci ).
(24)
r∈R
where (x)+ = max{x, 0}. Let Ybi (Ci ) =
be e∈E hc Yi (Ci ).
P
The annual aggregate is then applied
by Yie (Ci ) = Ybie (Ci ) min{1, Ai /Ybi (Ci )} when Ybi (Ci ) > 0, and Yie (Ci ) = 0 otherwise. Because the illustrative calculation has one active layer for each event and common active-layer terms Dir = $25, 000 and Lri = $500, 000, the six pre-aggregate event payments are $225,000, $375,000, $275,000, $125,000, $75,000, and $500,000. Their sum is $1,575,000. For the selected annual aggregate Ai = $1, 500, 000, all event payments are therefore multiplied by 1, 500, 000/1, 575, 000, yielding the indemnity values reported in Table 10. Table 10: Indemnity Payments Under the Candidate Contract Event Hallucination eH Prompt injection eP Agentic fraud eF Model drift eD Dependency outage eO Cyber-physical harm eC
Active layer TechE&O Cyber Mixed Performance Mixed GL
Gross loss $250,000 $400,000 $300,000 $150,000 $100,000 $2,000,000
Yie (Ci ) $214,286 $357,143 $261,905 $119,048 $71,429 $476,190
For example, the hallucination loss of $250,000 has active TechE&O incidence γieH ,TechEO = 1, so it produces a pre-aggregate payment of $225,000 and an aggregate-adjusted payment of
YieH (Ci ) = $214, 286. The catastrophic cyber-physical loss of $2,000,000 has active GL incidence γieC ,GL = 1; it is capped by the layer limit at $500,000 before the annual aggregate and becomes YieC (Ci ) = $476, 190 after aggregate allocation. Substituting all indemnity values into the insurer’s expected payout calculation gives
E[Yi (Ci )] =
X
qie Yie (Ci )
e∈E hc
= 0.060(214, 286) + 0.025(357, 143) + 0.010(261, 905) + 0.040(119, 048) + 0.080(71, 429) + 0.002(476, 190) = $35, 833.
(25)
Table 11: Computational Solution of the Healthcare Contract-Design Problem Quantity Governance tier Layer deductible Dir Layer limit Lri Aggregate AI limit Ai Expected gross loss E[Xi ] Expected indemnity E[Yi (Ci )] Expected coverage ratio Expected residual loss Risk loading ϱi (si , Ci ) Feasible premium interval Selected premium Ti⋆ Risk-adjusted underwriting profit Hospital expected annual cost Hospital savings versus uninsured baseline
Computational solution g (3) $25,000 $500,000 $1,500,000 $46,000 $35,833 77.9% $10,167 $14,292 $50,125–$54,833 $54,833 $4,708 $95,000 $5,000
4.6
1600
4.4
1550
4.2
1500
4.0
1450
3.8
1400
3.6
selected contract 78
80 82 84 86 88 Expected indemnity ratio (%)
Selected contract economics
1650 Aggregate limit (thousand dollars)
Risk-adjusted profit (thousand dollars)
Feasible contract menu
1350
Premium
54.8
Expected indemnity
35.8
Risk loading
14.3
Insurer profit
4.7
Governance cost
30.0
Residual loss
10.2
Hospital savings
5.0
0
10
20 30 40 50 Thousands of dollars
60
Figure 6: Computational solution of the healthcare case study. The left panel plots all feasible contracts in the finite menu by expected indemnity ratio and risk-adjusted underwriting profit, with color indicating the aggregate limit. The right panel decomposes the selected contract economics into premium, expected indemnity, risk loading, insurer profit, governance cost, residual loss, and hospital savings. Equation (25) determines the actuarially fair component of the premium for the selected contract. The computational solution selects gi⋆ = g (3) , Dir = $25, 000, Lri = $500, 000, and Ai = $1, 500, 000. Under the risk-loading rule above, ϱi (si , Ci ) = $14, 292, so the profitability constraint requires Ti ≥ 35, 833 + 14, 292 = $50, 125. This establishes the minimum premium required to satisfy the insurer’s risk-adjusted profitability requirement for the selected coverage terms. Next, the insurer evaluates the hospital’s participation constraint. Assume that maintaining the governance controls associated with tier gi = g (3) requires annual expenditures of Ki (gi ) = $30, 000. The expected residual loss retained by the hospital after insurance is E[Xi − Yi (Ci )] = 46, 000 − 35, 833 = $10, 167. Substituting these quantities into the hospital’s participation-cost function yields Jipart (Ci ) = Ti + 30, 000 + 10, 167. Suppose that operating without insurance would result in weaker governance and an expected annual cost of Ji0 = $100, 000. The computational case study imposes a minimum insured surplus of $5,000, so the participation condition is Ti +40, 167 ≤ 95, 000, which implies Ti ≤ $54, 833. Combining the minimum and maximum premium conditions yields the feasible premium interval 50, 125 ≤ Ti ≤ 54, 833. The insurer-profit-maximizing premium within this marketable interval is therefore Ti⋆ = $54, 833. Substituting this premium into the objective function gives Πi (Ci ) = 54, 833 − 35, 833 − 14, 292 = $4, 708. The hospital’s expected annual cost
becomes Jipart (Ci ) = 54, 833 + 30, 000 + 10, 167 = $95, 000, which is $5,000 below the uninsured baseline. The optimized contract therefore benefits both parties: the hospital reduces its expected total cost while maintaining strong governance controls, and the insurer receives compensation for assuming agentic-AI risk. The same code can be used to compare the impact of individual underwriting variables. Table 12 and Figure 7 recompute the finite-menu problem under one-factor changes in operational authority, weighted permission exposure, dependency concentration, and governance tier. Except for the final governance-upgrade row, the comparisons hold the governance requirement at g (3) so that the effect of the changed variable is isolated. The values should be read as scenario-based underwriting calculations rather than empirical estimates. Table 12: Sensitivity of Optimized Contract Economics to Underwriting Variables Scenario Lower authority Baseline Higher authority Broader permissions High dependency Stronger governance
Change βi = 0.20 βi = 0.45, ψη = 3, R = 0.40 βi = 0.75 ψη (ηi ) = 7 R(vi ) = 0.80 gi = g (4)
E[Xi ] $41,690 $46,000 $52,029 $49,331 $51,972 $33,948
Timin $45,562 $50,125 $55,233 $51,437 $56,778 $38,735
Expected gross loss by scenario Lower authority
Timax $54,798 $54,833 $53,669 $52,752 $52,817 $42,467
Result profit $9,235 profit $4,708 gap $1,564 profit $1,315 gap $3,961 profit $3,731
Premium feasibility interval
41.7
Baseline
46.0
Higher authority
gap
52.0
Broader permissions
49.3
High dependency
52.0
Stronger governance
gap
33.9
0
10
20
30 40 Thousands of dollars
minimum premium participation cap 50
60
35
40
45 50 Thousands of dollars
55
60
Figure 7: Sensitivity of the optimized healthcare contract to selected underwriting variables. The left panel shows expected gross loss under each scenario. The right panel compares the minimum risk-loaded premium Timin with the participation cap Timax . A scenario becomes infeasible when the minimum premium exceeds the participation cap.
Reducing delegated authority from βi = 0.45 to βi = 0.20 lowers expected gross loss from $46,000 to $41,690 and raises feasible underwriting profit to $9,235. Increasing authority to βi = 0.75 instead raises expected gross loss to $52,029 and opens a $1,564 insurability gap under the fixed participation baseline. Expanding weighted permission exposure from ψη (ηi ) = 3 to 7 remains feasible but cuts risk-adjusted profit from $4,708 to $1,315, and raising dependency concentration to R(vi ) = 0.80 opens a larger $3,961 gap by increasing both expected loss and the dependencyrelated loading. Upgrading the governance requirement to g (4) , by contrast, reduces expected gross loss to $33,948 and keeps the contract feasible with $3,731 of risk-adjusted profit after the higher governance cost. These one-factor movements instantiate the structural results of Section 5.5: every exposure increase shrinks the marketable surplus toward infeasibility, as in Proposition 5, while the governance upgrade expands it, as in Proposition 6. This example shows how the framework turns qualitative notions—autonomy category, operational authority, governance maturity tier, external-state permissions, and dependency concentration— into a quantitative contract-design problem. Rather than picking premiums and limits by hand, the insurer derives every contract parameter from a constrained optimization that jointly weighs expected losses, governance incentives, participation constraints, and risk-adjusted profitability. The result is a rigorous foundation for underwriting and pricing agentic-AI systems in healthcare settings.
8
Designed Contract for the Healthcare Case Study The numerical case study in Section 7 solves the contract-design problem; an insurance paper
should also show what the resulting policy looks like in practice. This section translates the optimized healthcare example into a realistic contract schedule for the clinical care-coordination agent. The aim is not a complete legal policy form, but a demonstration of how the mathematical objects Ti , Dir , Lri , Ai , Γi , Λi , and Ψi become concrete policy terms. The designed contract is a twelve-month agentic-AI endorsement attached to a healthcare cyber and technology E&O insurance package. It covers the specific deployed care-coordination agent described in the case study, with risk state αi = α(2) , βi = 0.45, ψη (ηi ) = 3, gi = g (3) , and R(vi ) = 0.40. The policy is priced at the optimized premium Ti⋆ = $54,833. It uses a $25,000
per-event deductible, a $500,000 per-event active-layer limit, and a $1,500,000 annual AI aggregate limit. These values are the selected solution reported in Table 11. Table 13: Issued Contract Schedule for the Clinical Care-Coordination Agent Contract item Insured AI system Policy period Premium Required governance tier Deductible Per-event layer limit Annual AI aggregate limit Expected economics Covered deployment boundary
Designed policy term Clinical care-coordination agent used for patient-message triage, appointment scheduling, patient communications, workflow routing, and escalation support. Twelve months, with renewal subject to updated risk-state review and control evidence. Ti⋆ = $54,833. This equals the participation cap in the optimized marketable interval and yields risk-adjusted underwriting profit of $4,708. gi⋆ = g (3) , with continued eligibility conditioned on maintaining the covenant package Ψi . Dir = $25,000 for each covered event and active coverage layer. Lri = $500,000 for each active layer shown in Table 14. Ai = $1,500,000 across all covered agentic-AI events during the policy period. Expected gross loss is $46,000, expected indemnity is $35,833, expected residual loss is $10,167, and the risk loading is $14,292. The agent may use patient messaging and scheduling tools. Prescribing, billing changes, EHR modification beyond approved workflow notes, procurement, and physical-device control are not covered unless endorsed after underwriting review.
The coverage grant is event-specific. Table 14 gives the corresponding binary incidence entries e,r = 1; = 1 and λe,r γie,r and payment shares λe,r i i . For each listed event, the active layer has γi
nonlisted layer-event pairs have γie,r = 0 and λe,r i = 0. This is a simple one-layer schedule chosen for the case study. In a real mixed-cause claim, the same structure could allocate one event across several active layers by using several positive λe,r i values whose sum is at most one. The governance covenant Ψi is central to the policy because the premium and coverage terms are justified only for the underwritten risk state. The issued contract requires gi⋆ = g (3) , clinician approval for high-acuity messages and safety-critical workflow changes, least-privilege access to messaging and scheduling systems, tamper-evident logs of prompts, outputs, tool calls, approvals, and actions for twenty-four months, monthly reporting of the autonomous-action rate used to estimate βi , quarterly prompt-injection and adversarial testing, and documented rollback procedures. The policy also requires dependency-continuity procedures for the foundation-model provider and any critical external connector. The permission covenant fixes the underwritten permission boundary ηi = (1, 1, 0, 0, 0). The
Table 14: Coverage-Layer Schedule for the Issued Healthcare Contract Covered event Hallucination eH
Active layer TechE&O
Modeled payment $214,286
Prompt injection eP
Cyber
$357,143
Agentic fraud eF
Mixed
$261,905
Model drift eD
Performance
$119,048
Dependency outage eO
Mixed
$71,429
Cyber-physical harm eC
GL
$476,190
Practical coverage interpretation Erroneous AI-generated care-coordination recommendation, message, routing decision, or escalation failure relied upon in clinical operations. Adversarial prompt or malicious input causes unauthorized disclosure, tool invocation, or security-policy bypass. Autonomous communication or workflow action contributes to fraudulent transaction, deceptive communication, or improper benefit routing. Degradation in triage, prioritization, or routing performance causes measurable operational loss or required remediation. Foundation-model, cloud, connector, or external API outage disrupts covered care-coordination operations. Covered AI workflow contributes to bodily injury, delayed escalation of urgent care, or related liability; payment is capped by the layer limit and then adjusted by the annual aggregate.
insured must notify the insurer before enabling new external-state permissions such as billing, record modification, procurement, prescribing support, or device control. A material expansion can be defined by a positive increase in ψη (ηi ) beyond an insurer-specified threshold, or by activation of any high-risk permission class. Until the expansion is underwritten and endorsed, losses arising from the newly enabled permission are outside the designed contract boundary. The authority covenant fixes the underwritten operating authority at βi ≤ 0.45. The hospital must report the monthly fraction of weighted actions that execute without human approval. If telemetry shows a sustained increase above the underwritten threshold, the insurer may require remediation, re-underwrite the policy, remove governance credits, or increase deductibles for future events. This term is important because two agents with the same autonomy category α(2) can have very different risk if one only drafts recommended actions and the other executes most actions automatically. Claims duties are also stated in operational terms. The insured must provide notice within seventy-two hours after unauthorized tool execution, suspected patient-data disclosure, dependency
failure causing material workflow disruption, or any agent-related event reasonably expected to give rise to a claim. It must preserve logs and approval records, submit an incident report within fourteen days, and submit a remediation plan within thirty days. These duties are not merely administrative. They preserve the evidence needed to identify the event e, confirm the active coverage layer r, evaluate the incidence matrix Γi , determine any payment share in Λi , and compute the indemnity Yie (Ci ). This contract shows how the optimization output becomes an insurable product. The insurer is compensated for expected indemnity and risk loading; the hospital obtains an expected coverage ratio of 77.9 percent and cuts its expected annual cost by $5,000 against the uninsured baseline; and the governance covenants hold the deployed agent within the priced risk state. The policy is thus far more than a premium and a limit—it is a coupled pricing, coverage, monitoring, and governance mechanism for one specific agentic-AI deployment.
9
Automated Agentic-AI Insurance Workflow The risk-state, coverage, pricing, and optimization frameworks developed above provide the
economic and contractual foundation for agentic-AI insurance. Equations (13)–(18h) define the underwriting variables, coverage structure, indemnity calculations, governance incentives, and optimization constraints that determine an economically feasible insurance contract. Figure 8 illustrates how these mathematical constructs can be operationalized through an automated agentic-AI insurance workflow. Figure 8 should be read from left to right. The left panel represents the insured AI-agent network and the external environment with which it interacts; these interactions generate the underwriting inputs (αi , βi , ηi , gi , vi ). The middle panel is the insurer-side workflow engine. Its upper stages transform the submitted risk state into underwriting, pricing, and policy-creation decisions, while its monitoring layer converts event logs, telemetry, audit trails, system context, external data feeds, and control-posture evidence into trigger evaluations and dynamic risk scores. The lower stages then move from trigger detection to claim initiation, validation, decision, approval, settlement, and payout. The right panel indicates that human involvement is not eliminated but reserved for exception classes, including complex losses, disputes, fraud review, coverage ambigu-
Insured Agentic-AI Deployment
Human-in-the-Loop (Exceptions)
Automated Insurance Workflow Engine
Risk state si
1
Onboarding & risk submission
2
Risk assessment & underwriting
3
Policy issuance
Orch.
Underwriting & policy creation
Complex losses: high-severity or systemic impacts Escalation Disputes: coverage disagreements or conflicting evidence
Continuous Monitoring & Risk Detection Policy & governance
Runtime monitoring
Anomaly detection
Policy trigger engine
4
Automated claim initiation
5
Claim validation & assessment
6
Decision & approval
7
Settlement & payout
Risk scoring
Alerting
Feedback
External environment: APIs, databases, users, devices, third-party platforms
feeds
Interconnected AI agents
Key data & evidence: event logs, telemetry, audit trails, system context, external feeds, control posture
Fraud review: suspicious behavior, collusion, abuse
Coverage ambiguity: unclear terms or novel scenarios
High-severity events: catastrophic or regulatory
Human decision: recorded and fed back to the engine
Figure 8: Automated insurance workflow for insured agentic-AI systems. The workflow begins with onboarding and underwriting of insured AI agents characterized by the risk state si = (αi , βi , ηi , gi , vi ). Automated underwriting uses the risk-state, coverage, pricing, and optimization frameworks developed in Sections 4 and 5 to determine premiums, limits, deductibles, coverage allocations, and governance requirements. Once coverage is active, continuous monitoring, anomaly detection, trigger evaluation, and risk scoring observe the insured agent in real time. Covered events initiate automated claims processing, validation, indemnity computation, and settlement. Human experts intervene only for exceptional situations such as catastrophic losses, disputes, fraud investigations, coverage ambiguity, or regulatory concerns. The workflow operationalizes the mathematical programming framework by transforming insurance contracts into continuously monitored and computationally executable risk-transfer mechanisms. ity, high-severity events, and final human decisions that feed back into the automated workflow. Throughout, the risk-state variables map to operational insurance outputs: autonomy category and operational authority primarily affect severity and liability, the permission profile defines feasible loss pathways and weighted exposure, governance maturity affects expected loss and incentive terms, and dependency concentration captures systemic accumulation risk. A distinguishing feature of agentic-AI systems is that they emit continuous streams of operational evidence—telemetry, audit logs, execution traces, dependency-status information, permission changes, model-performance indicators, and governance-control metrics. Where traditional insurance leans on periodic audits and retrospective claims investigations, these signals allow continuous observation of the insured system throughout the policy period. Many underwriting, monitoring, and claims-management functions can therefore be delegated to specialized insurance agents acting on the insurer’s behalf. The workflow begins with agent onboarding and risk submission. Information describing the insured deployment is collected and mapped into the agentic-AI risk state si = (αi , βi , ηi , gi , vi ).
This state representation serves as the primary underwriting input and determines the event probabilities, expected losses, governance requirements, and risk-loading components appearing in the pricing and optimization framework. Automated underwriting then evaluates the submitted risk state and solves the contract-design problem defined by (18a)–(18h). The resulting contract specifies the premium Ti , layer deductibles Dir , layer limits Lri , aggregate AI limit Ai , binary coverage-incidence matrix Γi , payment-share matrix Λi , and governance obligations Ψi . Policy issuance therefore becomes the execution of a computational underwriting process rather than a purely manual assessment activity. Once coverage is active, continuous monitoring modules observe the insured agent and its operating environment. Runtime monitoring, anomaly detection, policy-trigger evaluation, and dynamic risk scoring continuously update the insurer’s estimate of exposure. Observed events are mapped into the event space E introduced earlier, allowing the system to determine whether a covered loss event has occurred. Because the event taxonomy and coverage allocations are already embedded within the contract, trigger evaluation can be performed automatically. When a trigger condition is satisfied, an automated claims agent initiates the claims process. Evidence is collected from telemetry records, audit logs, dependency-status information, system context, and external data sources. Claim validation determines the applicable event category, estimates the realized loss xei , evaluates exclusions and coverage conditions, and computes the corresponding indemnity payment using (12). For routine claims, settlement can be executed automatically once contractual requirements have been verified.
9.1
Discrete-Event Simulation of Online Claims Execution
To make the workflow operational, we implement a discrete-event simulator for the designed healthcare contract in Section 8. The issued contract is fixed throughout the simulation: Ti⋆ = $54, 833, Dir = $25, 000, Lri = $500, 000, Ai = $1, 500, 000, the coverage schedule is the eventlayer assignment in Table 14, and the policy covenants fix the endorsed permission boundary, authority threshold, logging requirements, incident notice requirement, and governance tier gi⋆ = g (3) . The simulation therefore does not re-optimize the contract. To make the online process visible without making a single insured look unrealistically loss-prone, we simulate a small portfolio of 25
comparable healthcare deployments, each issued on the same Section 8 terms. The per-contract claim-arrival process remains calibrated to the status-quo frequencies used in the healthcare case study: the six annual event probabilities sum to 0.217 material events per contract-year, and the contract-design calculation gives expected indemnity of $35,833 per contract-year. Across the portfolio, this corresponds to 5.4 expected material claims and $895,825 of expected indemnity per year. The simulator maintains an event queue whose elements are time-stamped workflow states: telemetry alert, automated detection, claim validation, human review, and claim closure. Each alert carries an event class e, a realized loss estimate xei , a detection score, an evidence score, an ambiguity score, and indicators for permission-boundary or covenant violations. An alert becomes an automated detection when its detection score exceeds the trigger threshold. A detected material event becomes a claim notice. The validation agent denies claims that fall outside the endorsed permission boundary, violate a governance covenant, or lack sufficient evidence. It automatically pays claims with strong evidence and low ambiguity. It escalates claims with high ambiguity, cyber-physical consequences, or large projected payments. For an approved claim under contract j arriving at time t, the operational payment is charged to that contract’s remaining annual aggregate as Yj,t = min{(xj,t − D)+ , L, A −
τ <t Yj,τ }. Thus each contract has its own aggregate, while the
P
figure reports the portfolio-level sum of validated payments. Table 15: Discrete-Event Simulation of Automated Claims Execution Quantity Portfolio size Expected material event frequency Expected portfolio claim count Expected portfolio indemnity Telemetry alerts processed Automated detections Claim notices opened Automatically paid claims Human-reviewed claims Denied claims Total indemnity paid Remaining portfolio aggregate capacity Portfolio aggregate capacity used Median claim closure time
Simulated value 25 contracts 0.217 per contract-year 5.4 per year $895,825 102 25 16 9 0 7 $1,303,776 $36,196,224 3.48% 1.3 days
Discrete-event simulation of automated claim execution Online trigger detection and claim disposition
telemetry alert
automated detection
Closure Validation Detection Telemetry 0
50
100
150
200 Policy day
250
300
350
Thousands of dollars
Cumulative portfolio indemnity 1500 1000
expected portfolio indemnity
500 0
0
50
100
150
200 Policy day
250
300
350
Claim closure time by workflow stage P18-N2 denied P24-C01 paid P06-C01 paid P15-N1 denied P05-C01 paid P13-C01 paid P12-C01 paid P20-N2 denied P03-C01 paid P07-N1 denied P02-C01 paid P23-C01 paid P05-N2 denied P20-N1 denied P01-C01 paid P01-N2 denied
0.0
detect 0.5
1.0
1.5 Days from telemetry alert
validate 2.0
settle / review 2.5
Figure 9: Discrete-event simulation of online automated claim execution for a small portfolio of designed healthcare contracts. The panels show trigger disposition, cumulative portfolio indemnity relative to expected indemnity, and claim closure time by workflow stage.
Figure 9 illustrates one portfolio-year realization. The monitoring layer processes 102 telemetry alerts across 25 contracts. Twenty-five alerts exceed the automated-detection threshold and 16 become claim notices. Nine covered claims are validated and paid automatically, while seven notices are denied because they lack sufficient evidence or fall outside the endorsed permission boundary. Total indemnity paid is $1,303,776, compared with $895,825 of expected portfolio indemnity, leaving $36,196,224 of remaining portfolio aggregate capacity and using 3.48% of available aggregate capacity. The realized payment is above the actuarial expectation but remains credible for an active portfolio year because the per-contract frequency is unchanged and the additional events arise from portfolio breadth rather than inflated single-policy frequency. The example shows how the same mathematical contract can be executed as a monitored online process: telemetry produces triggers, triggers produce validation tasks, validation produces automatic payment, denial, or escalation, and every approved payment updates the corresponding contract aggregate. Human participation is reserved primarily for exceptional situations. As shown in Figure 8, escalation occurs when the automated workflow encounters disputed causation, suspected fraud, ambiguous coverage allocation, catastrophic losses, regulatory concerns, or other circumstances requiring human judgment. Human decisions are subsequently fed back into the workflow, enabling continual refinement of underwriting models, claims procedures, governance standards, and riskassessment mechanisms. From this vantage, the mathematical-programming framework and the automated workflow are complementary halves of one system. The optimization model determines what contract to offer through the solution of (18a), and the workflow determines how that contract is monitored, enforced, and executed across the policy lifecycle. Automated agentic-AI insurance is feasible precisely because these two capabilities meet: the formal contract-design framework of Equations (13)–(18h), and the ability of agentic-AI systems to supply real-time observability, automated reasoning, evidence collection, risk computation, and claims execution.
10
Conclusion Agentic AI pushes insurance beyond asset-centered cyber coverage toward behavior-centered
risk transfer. The relevant exposure is not whether an organization uses AI, but what the deployed
agent is authorized to do, which external systems it can affect, how often actions execute without human approval, how governance controls are evidenced, and how concentrated the deployment is in shared model, cloud, data, and connector dependencies. This paper formalizes these underwriting questions through the risk state si = (αi , βi , ηi , gi , vi ) and connects that state to event probabilities, loss severities, coverage incidence, indemnity allocation, governance covenants, risk loadings, and contract-design constraints. The main contribution is a unified mathematical architecture for AI-native insurance. The framework separates event occurrence from coverage-layer allocation through Γi and Λi , treats governance covenants Ψi as enforceable policy obligations rather than informal underwriting notes, and formulates the insurer’s contract problem over premiums, deductibles, limits, aggregate exposure, allocation rules, and governance requirements. On this foundation, three structural results (Definition 4 and Propositions 5–6) show that insurability is a region of the underwriting state space, that fixed-terms premium feasibility deteriorates monotonically as exposure increases under monotone pricing primitives, and that a governance threshold certifies a deployment as insurable at given coverage terms. The framework also gives a policy interpretation of insurance as an AI operating cost and regulatory-control mechanism. If insurance is bundled into the cost of AI deployment or mandated for high-risk systems, the premium functions like a risk price: it can discourage deployments whose private benefits do not justify their expected harms, while requiring financial responsibility for systems that can affect patients, customers, infrastructure, or the public. This creates a calibration problem for regulators and insurers. A mandate that is too broad may operate as a general AI tax and deter low-risk innovation, while a mandate that is too narrow may leave high-impact agentic systems without adequate governance or loss-absorption capacity. The healthcare care-coordination case study demonstrates the framework in practice, translating operational facts about a clinical agent into event probabilities, gross losses, indemnity payments, risk loadings, participation bounds, and feasible premiums. The numerical comparisons confirm the structural results: higher delegated authority, broader permission exposure, and stronger dependency concentration narrow or eliminate the feasible premium interval, while stronger governance lowers expected loss and restores insurability. This is the central economic role of governance-
sensitive pricing—monitoring, approval gates, logging, testing, rollback capability, and notice obligations are not compliance details but contractible controls that shape both risk and marketability. Several extensions remain important. First, empirical calibration will require claims data, incident reports, audit evidence, telemetry, and stress scenarios specific to agentic-AI deployments. Second, portfolio models are needed to capture accumulation risk from shared model providers, cloud platforms, data sources, and agent frameworks. Third, dynamic policy mechanisms should adjust pricing, deductibles, limits, and covenants as agents gain permissions, change autonomy modes, or migrate dependencies. Finally, reinsurance and capital models will be needed for correlated failures that strike many insured agents at once. Together these steps would carry agentic-AI insurance from a contract-design framework toward a full actuarial and market infrastructure for governing autonomous AI risk.
References [1] D. Amodei, C. Olah, J. Steinhardt, P. Christiano, J. Schulman, and D. Mane. Concrete problems in ai safety. arXiv preprint arXiv:1606.06565, 2016. [2] Armilla AI. Armilla launches affirmative ai liability insurance with lloyd’s underwriter chaucer, 2024. Public announcement. [3] AXA XL. AXA XL unveils new cyber insurance extending coverage to help businesses manage emerging GenAI risks, 2024. Public announcement. [4] E. M. Bender, T. Gebru, A. McMillan-Major, and S. Shmitchell. On the dangers of stochastic parrots: Can language models be too big? In Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency, pages 610–623, 2021. [5] Y. Bengio, G. Hinton, A. Yao, D. Song, P. Abbeel, T. Darrell, Y. N. Harari, Y.-Q. Zhang, L. Xue, and S. Shalev-Shwartz. Managing extreme ai risks amid rapid progress. Science, 384(6698):842–845, 2024. [6] C. Biener, M. Eling, and J. H. Wirfs. Insurability of cyber risk: An empirical analysis. The Geneva Papers on Risk and Insurance - Issues and Practice, 40(1):131–158, 2015.
[7] R. Bohme and G. Schwartz. Modeling cyber-insurance: Towards a unifying framework. In Workshop on the Economics of Information Security, 2010. [8] J. Bolot and M. Lelarge. Cyber insurance as an incentive for internet security. In M. E. Johnson, editor, Managing Information Risk and the Economics of Security, pages 269–290. Springer, New York, 2009. [9] R. Bommasani, D. A. Hudson, E. Adeli, R. Altman, S. Arora, et al. On the opportunities and risks of foundation models. arXiv preprint arXiv:2108.07258, 2021. [10] G. Calabresi. The Costs of Accidents: A Legal and Economic Analysis. Yale University Press, 1970. [11] N. Carlini and D. Wagner. Towards evaluating the robustness of neural networks. In 2017 IEEE Symposium on Security and Privacy, pages 39–57, 2017. [12] Chaucer Group and Armilla AI. Chaucer and armilla ai launch vanguard ai coordinated insurance structure, 2025. Public announcement. [13] J. Chen, Q. Zhu, and T. Başar. Dynamic contract design for systemic cyber risk management of interdependent enterprise networks. Dynamic Games and Applications, 11(2):294–325, 2021. [14] I. Ehrlich and G. S. Becker. Market insurance, self-insurance, and self-protection. Journal of Political Economy, 80(4):623–648, 1972. [15] European Insurance and Occupational Pensions Authority. Methodological principles of insurance stress testing: Cyber component, 2024. Online report. [16] I. J. Goodfellow, J. Shlens, and C. Szegedy. Explaining and harnessing adversarial examples. In International Conference on Learning Representations, 2015. [17] L. A. Gordon and M. P. Loeb. The economics of information security investment. ACM Transactions on Information and System Security, 5(4):438–457, 2002. [18] K. Greshake, S. Abdelnabi, S. Mishra, C. Endres, T. Holz, and M. Fritz. Not what you’ve signed up for: Compromising real-world llm-integrated applications with indirect prompt injection.
In Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security, pages 79–90, 2023. [19] A. Humayed, J. Lin, F. Li, and B. Luo. Cyber-physical systems security–a survey. IEEE Internet of Things Journal, 4(6):1802–1831, 2017. [20] S. Liu and Q. Zhu. Mitigating moral hazard in cyber insurance using risk preference design. arXiv preprint arXiv:2203.12001, 2022. [21] S. Liu and Q. Zhu. Cyber insurance for cyber resilience. arXiv preprint arXiv:2312.02921, 2023. [22] P. Naghizadeh and M. Liu. A tale of two mechanisms: Incentivizing investments in security games. arXiv preprint arXiv:1503.07377, 2015. [23] National Association of Insurance Commissioners. Cybersecurity insurance report, 2025. Online report. [24] National Institute of Standards and Technology. Artificial intelligence risk management framework (ai rmf 1.0). Technical Report NIST AI 100-1, National Institute of Standards and Technology, 2023. [25] OWASP Foundation. OWASP Top 10 for Large Language Model Applications. https:// owasp.org/www-project-top-10-for-large-language-model-applications/, 2025. [26] R. Pal, Z. Huang, X. Yin, S. Lototsky, S. De, S. Tarkoma, M. Liu, J. Crowcroft, and N. Sastry. Aggregate cyber-risk management in the IoT age: Cautionary statistics for (re)insurers and likes. arXiv preprint arXiv:2105.01792, 2021. [27] F. Perez and I. Ribeiro. Ignore previous prompt: Attack techniques for language models. arXiv preprint arXiv:2211.09527, 2022. [28] A. C. Pigou. The Economics of Welfare. Macmillan, 1920. [29] J. Quinonero-Candela, M. Sugiyama, A. Schwaighofer, and N. D. Lawrence, editors. Dataset Shift in Machine Learning. MIT Press, Cambridge, MA, 2009.
[30] A. Raviv. The design of an optimal insurance policy. The American Economic Review, 69(1):84–96, 1979. [31] S. Romanosky, L. Ablon, A. Kuehn, and T. Jones. Content analysis of cyber insurance policies: How do carriers price cyber risk? Journal of Cybersecurity, 5(1):tyz002, 2019. [32] M. Rothschild and J. Stiglitz. Equilibrium in competitive insurance markets: An essay on the economics of imperfect information. The Quarterly Journal of Economics, 90(4):629–649, 1976. [33] S. Shavell. A model of the optimal use of liability and safety regulation. The RAND Journal of Economics, 15(2):271–280, 1984. [34] The Geneva Association. Advancing accumulation risk management in cyber insurance, 2024. Online report. [35] R. Zhang and Q. Zhu. Attack-aware cyber insurance of interdependent computer networks. Technical Report 16-18, NET Institute, 2016. [36] R. Zhang and Q. Zhu. Optimal cyber-insurance contract design for dynamic risk management and mitigation. IEEE Transactions on Computational Social Systems, 9(4):1087–1100, 2021. [37] Q. Zhu. Insurance of agentic ai, 2026. arXiv preprint arXiv:2606.05449, 3 June 2026. [38] Q. Zhu. The internet of agentic ai: Communication, coordination, and collective intelligence at scale, 2026. arXiv preprint arXiv:2606.12835, 11 June 2026.