The insurability layer for agentic AI

Make your agents insurable.

Your carriers have filed to exclude AI. RiskMandate measures what your agents can actually do, proves the controls, prices the exposure, and produces the evidence an underwriter will accept.

Northgate Financial
47 agents in production · assessed 12 Aug
Renewal in 38d
0/ 100

Level L3 — Attested. Standalone AI liability available.

Exposure containment74
Authority definition81
Attestation integrity66
Loss quantification41
Accountability88
Accept
Fund
Fix

Measured against the standards underwriters are adopting

  • ISO/IEC 42001
  • OWASP Agentic Top 10
  • NIST AI RMF
  • ISO/IEC 27001
The Problem

Cover is being withdrawn. Evidence buys it back.

Exclusions are attaching at renewal faster than teams can respond. Affirmative cover exists, but every carrier writing it asks the same question — and most teams cannot answer it in writing.

Filings
60+

P&C groups filed to exclude AI

ISO forms CG 40 47, CG 40 48 and CG 35 08 took effect 1 January 2026. Some exclusions on D&O and E&O are absolute.

Approvals
80%

of those filings cleared review

Whether AI is covered is now decided policy by policy, jurisdiction by jurisdiction, at each renewal date.

The gate
1

question decides the outcome

Can you show what your agents can reach, and prove the controls hold? Everything else follows from that answer.

The Difference

Questionnaires describe. Evidence prices.

Underwriting agentic risk today runs on self-reported answers. The same three questions produce very different outcomes depending on where the answer comes from.

Questionnaire
RiskMandate
Where the answer comes from
Someone's recollection.

A security lead fills in a form once a year, from memory and a spreadsheet that was last accurate in March.

Your environment.

Read-only connectors derive what each agent can actually reach, refreshed as permissions and deployments change.

What the underwriter gets
A yes or no.

No severity, no aggregation, no way to tell a contained agent from one holding standing production access.

A priced exposure.

Loss bands per agent, aggregate across the fleet, and concentration in shared models and vendors.

What happens at claim
The answers get tested.

Application warranties are examined after the loss. This is where cover is most often lost.

The record holds.

Timestamped control state, containment tests and an immutable action log, assembled before anything went wrong.

The Insurability Index

Six levels. One number.

Every agent estate sits somewhere on this ladder. Your level determines what an underwriter will offer, and the gap to the next one is your work order. Select a level to see what it buys.

L3 · 56–72

Attested

What an underwriter offers

Evidence you need

The Index is a composite of five dimensions, weighted by how much each one moves a price. It is derived from your environment through read-only connectors, never from a self-assessment.

What Gets Measured

Five dimensions. Weighted by price impact.

30%

Exposure containment

How bad one agent can get. Reachable actions, systems touched, dollar value of authority, and whether the damage is reversible.

Drives severity
20%

Authority definition

Whether every agent has a written mandate: purpose, permitted actions, data scope, and the points where a human must intervene.

Drives frequency
20%

Attestation integrity

Whether control state is proven continuously rather than asserted once a year, with logs and revocation tests that hold up under examination.

Drives warranty credibility
20%

Loss quantification

Expected loss per agent expressed as a range, not a point. A wide range is itself a finding — it means getting clarity is the next thing to fund.

Drives pricing
10%

Accountability

Who owns each accepted risk, for how long, and at what retention. Acceptance without a named owner and an expiry date is not acceptance.

Drives legal standing
Who It's For

One score. Both sides of the renewal.

For enterprises and mid-market

Mandate

Map every agent's blast radius, prove the controls that contain it, and walk into your renewal with an evidence pack instead of a questionnaire.

  • Agent discovery and blast-radius measurement through read-only connectors
  • A written mandate per agent, generated from what the agent can actually reach
  • Continuous attestation mapped to ISO 42001 and the OWASP Agentic Top 10
  • A renewal report your broker can submit without rewriting
Sits on top of your existing identity and posture tools. We read; we never sit in the request path.
For brokers, carriers and MGAs

Ledger

Price agentic risk from what is actually deployed in the insured's environment, and see where the same exposure repeats across your book.

  • Submission triage scored on evidence rather than self-reported answers
  • Exposure derived from the environment, with the derivation shown
  • Concentration view across shared models and vendors in a portfolio
  • An acceptance ledger that maps cleanly onto a policy period
Carrier-neutral by design. We score the risk; you set appetite and price.
The Mechanic

Every risk gets an owner and an expiry.

A finding sitting in a backlog is not a decision, and an underwriter cannot price it. RiskMandate forces each risk through one of three doors, assigned to a named person for a stated interval. When the interval ends, the decision comes back.

Accept

Own it

A named executive holds this exposure for a set interval, with the amount written down.

Fund

Pay to reduce it

The exposure justifies budget. The number is what makes the case.

Fix

Remove it

Narrow the mandate or revoke the access, and the radius closes.

Revisit next quarter There is no fourth door. Silence is not a decision anyone can underwrite.
Questions

What people ask first.

Is RiskMandate an insurance policy?

No. We are not a carrier, a broker or an MGA, and we do not sell or place cover. RiskMandate measures insurability and produces the evidence that underwriters price against. Your broker and carrier relationships stay exactly as they are.

Does this replace our agent security tooling?

No, and it is not meant to. We connect to what you already run — identity providers, cloud IAM, agent posture and access-governance tools — and translate their output into exposure an underwriter can read. If you have no controls at all, we will tell you that before you buy anything.

Do you sit in the runtime path?

Never. All connectors are read-only and out of band. A governance layer that can take your agents down is a new source of the risk it was bought to measure.

How is the Index calculated, and can we see the working?

It is a weighted composite of five dimensions, each derived from environment telemetry rather than a questionnaire. Every score decomposes to the evidence behind it, and the methodology is published. Weights are set by underwriting judgement today and re-fit as loss experience accumulates — we say so openly rather than implying an actuarial precision that does not yet exist.

How long does a first assessment take?

Connector setup is typically under a day. A first Index and gap list land inside two weeks, which is deliberately shorter than most renewal windows.

Where does our data go?

Metadata about agent scope and permissions, not the contents of what your agents process. Self-hosted and sovereign deployments are available where the data cannot leave your boundary.

Know your number before your carrier does.

A first assessment returns your Insurability Index, the gap list to the next level, and a renewal report written for an underwriter rather than a security team.

© 2026 RiskMandate. Know the risk. Name the owner. Enforce the mandate.