The Regulator Gave You Until 2027. The Underwriter Wants Evidence Now.
There's a new questionnaire making the rounds in AI operations, and it didn't come from Brussels. It came from an underwriter. It's longer than the regulator's, it's due sooner, and unlike the regulator's, failing it has a price printed directly on it.
While everyone was watching the EU's Digital Omnibus push high-risk AI Act obligations toward 2027 and 2028, a quieter enforcement mechanism arrived: AI agent liability insurance became a real market. And insurance doesn't wait for enforcement dates. It prices your governance today.
The market showed up before the mandate did
Armilla, a Lloyd's of London coverholder, now writes AI liability coverage up to $25 million per organization, backed by names that don't gamble casually: Chaucer Group, AXIS Capital, Convex, Greenlight Re, Swiss Re. Getting a policy means passing a two-stage review — a governance questionnaire followed by a technical assessment.
Alongside the carriers, a certification layer has emerged. The AIUC-1 standard — from the AI Underwriting Company, founded in mid-2025 with $15 million in seed funding — defines 51 requirements and 130 controls across six pillars: data and privacy, security, safety, reliability, accountability, and societal risks. The audit takes four to eight weeks, and premium pricing correlates directly with your assessment score.
Read that again: there is now a number, denominated in dollars, that goes up when your agent governance is bad and down when it's good. Regulators publish frameworks. Underwriters publish invoices.
What the underwriter actually asks for
The academic literature and the carriers agree on the shape of the ask. Quanyan Zhu's recent NYU paper on insuring agentic AI spells out the telemetry insurers need from agent operators: "materially relevant prompts, tool traces, access logs, model/version records, approval records, and rollback history." Plus autonomy declarations — documented statements of what your scheduled agents are permitted to touch — and change notifications when that autonomy expands.
The Lloyd's market converges on three elements: documented human oversight, post-incident remediation records, and training data provenance. The disqualifiers are just as instructive. No governance documentation: declined. Prior incidents without remediation records: declined. Fully autonomous consequential actions with no approval gates: declined.
Notice what's not on the list. Nobody asks which model you use. Nobody asks how clever your system prompt is. The underwriter's entire worldview is: show me the evidence trail, show me the containment story, show me what happened last time something broke.
Why most operators would fail the questionnaire today
Here's where the market's new questionnaire collides with the industry's actual posture. Gravitee's State of AI Agent Security 2026 report, surveying over 900 executives and practitioners, found that 88% of organizations confirmed or suspected an agent security incident this year — while only 47.1% of an organization's agents are actively monitored or secured at all. More than half of deployed agents operate with no security oversight or logging. And 45.6% of teams still authenticate agent-to-agent traffic with shared API keys.
Assemble those numbers into an underwriter's view of the applicant pool: nearly nine in ten have had an incident (an underwriting question), more than half can't produce logs for more than half their agents (a disqualifier), and the incident remediation record — the thing that separates "insurable" from "declined" — mostly doesn't exist, because you can't document remediating what you never logged.
This is the same dynamic fire insurance ran on boilers and factories a century ago. The inspection standard didn't come from the legislature; it came from the carrier that had to pay when things exploded. Insurers are extremely good at locating the difference between claimed safety and evidenced safety, because they're the ones holding the bill for the gap.
Evidence is infrastructure, not paperwork
The mistake is treating the underwriter's list as a documentation exercise — something to assemble in a war room the week before the audit. Every item on that list is actually a runtime capability, and it maps directly onto what a trust layer does:
The evidence trail. "Tool traces, access logs, approval records" only count if they can't have been edited after the fact. A log your agent — or your intern — can rewrite is a story, not evidence. VeriSwarm's Vault writes every agent event into an immutable, hash-chained audit ledger with chain verification and exports. When the assessor asks how you know the record is complete, the answer is a cryptographic property, not a policy PDF.
The performance record. Underwriters want "independently measurable thresholds" for claims assessment. Gate scores every agent continuously against behavioral baselines — an actuarial history of how each agent actually behaves, accumulating from the day you enroll it. Free tier, always on.
The containment story. "Rollback history" and approval gates presume you can actually stop an agent. Guard provides the kill switch and policy rules that turn "we would intervene" into a timestamped record of interventions.
The autonomy declaration. Zhu's paper asks operators to document what each agent is permitted to do. Passport makes that declaration a signed, verifiable manifest rather than a wiki page — scoped delegations included, so the declaration survives the agent handing work to another agent.
The premium is the point
For three years, the honest objection to agent governance spend was that the enforcement was hypothetical. The EU moved its deadlines. The frameworks stayed voluntary. That objection just expired — not because a regulator acted, but because a market did. Governance now has a spot price, updated per audit, and the spread between evidenced operators and everyone else will only widen as claims data accumulates.
You don't need an insurance policy today. But the day you do — or the day a customer's procurement team asks whether you could get one — the audit trail either already exists or it never will. Evidence doesn't backfill.
Vault, Gate, Guard, and Passport turn the underwriter's questionnaire into a settled question. Start the evidence trail at veriswarm.ai — before someone prices its absence for you.
Sources: AgentInsured, "What AI Insurance Underwriters Ask Before Writing a Policy" (2026); Quanyan Zhu, "Insurance of Agentic AI," arXiv (2026); Gravitee, "State of AI Agent Security 2026" (2026).