IntelligenceThe agent has permission. Who owns the loss?
Map authorized-agent failure scenarios to controls, contracts, and insurance evidence. Leave with a broker-ready question pack, a responsibility matrix, and a leadership decision memo.
Name the exposure in business terms.
Describe one agent and the real action it can take. Use approved boundaries, not hoped-for behavior.
Replace “we have cyber” with written evidence.
For each plausible loss, record the policy expected to respond, the current answer, and the exact evidence. “We think” counts as unconfirmed.
| Authorized-agent loss scenario | Modeled exposure | Expected policy / contract | Current status | Evidence reference | Business owner |
|---|
Make the retained risk visible before release.
This is an evidence-status decision, not a legal coverage opinion. The release lane is based on what is documented today.
What must be resolved
Evidence work by owner
Your broker-ready evidence pack.
Copy or export the same facts for leadership, the broker, counsel, and the implementation team.
Questions for the broker and carrier
Owns the business outcome, acceptable loss ceiling, and release decision.
Owns access, limits, testing, logs, rollback, and change control.
Interpret wording and contracts, document answers, and surface exclusions or gaps.
Preserves evidence, contains impact, notifies required parties, and coordinates recovery.
Scenario ownership record
| Scenario | Owner | Status | Evidence |
|---|
Minimum incident evidence starter
Agent incident disclosure pack
Use system records, tool receipts, and downstream confirmations. The agent's own explanation is context, not proof of what committed.
What the report cannot yet prove
Incident facts and disclosure route
Research basis, operating assumptions, and citations
Emerging coverage question. Reuters reported on August 27, 2026 that cyber insurers are reviewing policy language for autonomous-agent losses, including cases in which an agent uses access a company intentionally granted. The article describes an evolving market, not a general exclusion or coverage rule. Reuters.
Risk spans policy lines. Aon says AI exposure can overlap cyber, professional liability, crime, employment, intellectual property, product liability, and directors and officers coverage. It recommends mapping AI use, reviewing whether existing programs remain fit for purpose, and documenting governance and testing. Aon is an insurance broker and its statements are market guidance, not a determination of coverage. Aon, 2026.
Performance failure can differ from attack. Munich Re describes AI performance failures without malicious attacks as a risk layer beyond traditional cyber threats and offers specialized AI performance products. Product availability and fit vary. Munich Re aiSure.
Incident reports need specific facts. On September 7, 2026, a European Commission spokesperson said an incident report should be precise and accurate about measures taken, not treated as a tick-box exercise. Reuters reported this after OpenAI submitted a report concerning the German wiki incident. The article does not establish a universal reporting template or legal duty for every organization. Reuters, September 7, 2026.
The disclosure standard is still developing. OpenAI said on September 5 that its misalignment disclosure practices need to expand and that the industry lacks a clear standard across training, evaluation, and deployment. This is OpenAI's statement about the reported wiki incident, not an independent finding about prevalence. Reuters, September 5, 2026.
A safety stop is not a rollback. OpenAI says monitoring for covered Astra conversations is asynchronous, so an external action may have completed before a stop. A stop does not undo earlier actions, stopped API conversations generally cannot resume, and blind automatic retries should be avoided. The coverage and behavior of this control are product-specific and can change. OpenAI API guidance.
Aule method. The evidence lane, scenario set, release blockers, responsibility map, incident checklist, reconstruction score, and disclosure draft are Aule Intelligence operating standards. They are not insurance, legal, regulatory, or claims advice. Policy wording, contracts, jurisdiction, facts, exclusions, limits, deductibles, notice duties, and carrier decisions control actual coverage.