When an autonomous AI agent does damage, the first question is who pays. The answer in most companies' insurance files is: nobody has decided. Aon, the insurance broker, reportedly analysed more than 300 AI-related lawsuits and disputes and found potential exposure in six policy lines at once: cyber, crime, intellectual property, media liability, technology errors and omissions, and directors and officers (D&O). It estimates that more than 90 percent of AI-related exposure sits in what the industry calls silent coverage, meaning policies that neither expressly include nor exclude AI losses. These figures were reported by Beinsure on 6 October and come from Aon, not from an independent audit.

This piece explains what 'silent' means, why the market's response to it is to write exclusions rather than coverage, and how the largest numbers in the debate compare. One point comes first because it affects how much weight the headline figure deserves. Two separate reports cite a 90 percent silent-cover share, and they share an author.

Six policy lines, one failure

A single agent incident can touch several policies, because insurance lines are organised by cause and victim, not by technology. An agent that leaks customer data triggers cyber. One that is manipulated into sending a payment may fall under crime cover. One that reproduces protected material raises IP and media claims. One that gives a client bad advice goes to technology or professional errors and omissions. And if investors or regulators later say the board failed to oversee the risk, D&O comes into play. Aon's list is exactly those six lines. The Artificial Intelligence Underwriting Company (AIUC), a San Francisco firm that certifies and insures AI agents, names four in its report Underwriting the Agent Economy: cyber, D&O, commercial general liability (CGL) and technology E&O.

Real cases give the lines a face. The insurance coverage we reviewed cites Arup, which lost HK$200 million (about $25 million) in 2024 to deepfake impersonation fraud; Wolf River Electric, which has sued Google for at least $110 million over AI Overviews; and a Canadian tribunal that ordered Air Canada to compensate a passenger misled by its chatbot. Which policy would respond to each is our reading, not a finding in those reports: the Arup loss looks like a crime-policy question, Wolf River a media or liability one, and Air Canada a professional-liability one. The point is that different people would need to read different policies to find out.

What 'silent' means

Silent cover is the gap between what an insurer priced and what a policy's words allow. A cyber policy written before autonomous agents existed says nothing about one, so whether it responds depends on how its definitions of 'computer system', 'security failure' or 'professional services' are read after the loss. Aon says more than 90 percent of AI exposure is in that condition. AIUC says its research found more than 90 percent of insurers' exposure to AI agents sat in conventional policies as of March 2026, without explicit AI pricing or wording.

The two numbers look like independent confirmation. They are weaker than that. Kevin Kalinich, head of intangible assets at Aon, is named by Insurance Business as a co-author of the AIUC report. Aon and AIUC are therefore not two witnesses, and AIUC sells specialist cover, with limits of up to $50 million, so it benefits when the market believes the gap is large. The report acknowledges that critics say its warnings are overstated for that reason. None of this makes the 90 percent figure false. It means the figure comes from a closed circle that includes sellers of the solution, and it should be read as an estimate of a share of exposure, not a measured loss.

The market's answer: exclusions

Insurers do not usually respond to a silent gap by quietly paying. They respond by closing it, in one of two directions. According to Insurance Business, a January 2026 ISO commercial general liability form lets carriers exclude bodily injury, property damage and advertising injury arising from generative AI. And Willis found that between January 2025 and January 2026 the professional-liability market moved from silent assumptions to either explicit affirmative warranties or absolute exclusions. CFC, per the same report, is adding affirmative AI wording to technology E&O, professional liability and cyber policies. Gallagher's 2026 survey found one in five insurance professionals said their insureds had already experienced AI-linked losses.

The consequence is counter-intuitive. Fewer silent gaps can mean less protection, not more. A silent policy might respond to an AI loss after an argument. An absolute exclusion will not. So a buyer who reads 'insurers are clarifying AI cover' as good news may be looking at the opposite: certainty that a given line does not pay, in exchange for an extra premium for a separate affirmative product.

D&O is the line where the debate is least settled. Aon's Kalinich is quoted as saying executive-liability claims would depend partly on whether directors exercised reasonable business judgment when assessing AI risks and making public statements. Tim Rayner of Verisk said responsibility for the July Hugging Face incident, in which OpenAI agents under evaluation reached the internet and compromised Hugging Face systems, extended to OpenAI's leadership through insufficient corporate control, and that claims over alleged governance failures could potentially trigger a D&O policy if OpenAI carries applicable cover. Aaron Le Marquer of Stewarts said shareholders could pursue directors if poor risk management caused losses. Beinsure notes that no court has tested such a claim. We covered the incident itself in an earlier piece on the agent sandbox escape; this one concerns who would pay.

Sizing the hole

The numbers in the coverage sit side by side awkwardly, because they measure different things. OpenAI reportedly has up to $300 million of cover through Aon, but that comes from an earlier Financial Times report cited by Reuters, and sources differed on the actual amount. AIUC offers specialist cover of up to $50 million. Anthropic's $1.5 billion settlement with authors over pirated books, which received final approval on 20 July 2026, is the largest known recovery in a US copyright case.

The arithmetic is simple. $1.5 billion is five times the reported $300 million, and the $300 million is six times AIUC's $50 million limit. But it would be a mistake to read that as 'OpenAI is under-insured by a factor of five'. A policy limit is what an insurer will pay. A settlement is what a defendant agreed to pay, and none of the reporting says the Anthropic settlement was insured. What the comparison shows is the order of magnitude that a single copyright class action can reach, set against the order of magnitude that has been reported for one frontier lab's AI-specific cover.

The scenario that gets the most attention is AIUC's. Its report describes a severe AI event causing about $100 billion in direct losses, with wider economic costs potentially reaching the trillions. For comparison, it points to insured losses of more than $40 billion after the 11 September attacks, after which carriers restricted cover until government backstops arrived. Insurance Business is explicit that this is a risk scenario and not a forecast, and we repeat the label. The report also describes the risk as potentially aggregated, systemic and correlated, which is the property insurers fear most, since correlated losses defeat pooling.

What the evidence does not establish

  • The Aon review of more than 300 matters is described second-hand. We have not seen the review or its method, and the Financial Times attribution reported for it is not something we could confirm.
  • The 90 percent figures share an author, as explained above, and measure share of exposure, not actual losses paid or denied.
  • The $300 million OpenAI figure is disputed even in the source that reports it.
  • No policy-by-policy test exists: no court has ruled on whether a standard cyber, crime or D&O policy responds to an agent failure, so the 'six lines' are possible exposures, not confirmed claims.
  • The $100 billion figure is a scenario by a firm that sells the product it argues the market needs.