The most useful thing about an insurer is that it does not care about your intentions. It cares about your loss rate. So when TechCrunch reported on Tuesday that the Artificial Intelligence Underwriting Company had closed a $40 million Series A led by Ribbit Capital, with First Harmonic participating, I read it as the first market answer to the question I have been asking since June: when an agent gets it wrong, who pays?

AIUC's answer is that somebody will, on a schedule, at a price, and that the price will depend on evidence. The company runs agents through a certification standard called AIUC-1, modeled on the SOC 2 framework that enterprise security procurement runs on, and sells insurance against agent failure on top of the result. Total raised is now $55 million, after a $15 million seed in July 2025 from Nat Friedman's NFDG, Emergence, Terrain, and Anthropic co-founder Ben Mann.

The labs promised to slow down and nobody outside can check. The agents reported each other and nobody read the report. The court said the user did it. An underwriter is the first party in this story whose own money depends on being right.

What was announced

The founders are the point. Rune Kvist was the first product and go-to-market hire at Anthropic and sits on the board of the Center for AI Safety. Rajiv Dattani was chief operating officer of METR, the evaluation organization that tested OpenAI's and Anthropic's models before deployment and that spent six days on site reconstructing the July swarm incident, and before that led insurance work at McKinsey. Brandon Wang is the technical co-founder. Two of the three have spent their careers inside the rooms where frontier models are evaluated, and they concluded that evaluation without money attached does not change behavior.

The product has three parts. AIUC-1 is the standard, covering data and privacy, security, safety, reliability, accountability, and societal risk. Certification is the audit: according to TechCrunch, roughly 5,000 tests per agent for jailbreaks, hallucinations, and data leaks, producing reports of about 100 pages that say, in Dattani's words, "here's where it passes and where you can trust it. And here's where there's concerns." A consortium of around 250 security and risk leaders informed the criteria, and Schellman is the first accredited auditor. Insurance is the third part: AI companies buy cover that, per AIUC's own description, protects "their enterprise customers in case an AI agent failure leads to business loss."

The customers are not small. Cursor, Lovable, Harvey, and ElevenLabs are named, with ElevenLabs described as holding a first-of-its-kind agent insurance policy backed by the certification. KPMG is the first Big Four firm certified, for its aIQ Capture platform. Intercom certified its customer-facing agent, Fin. Kvist's framing of why this exists: "The surprising thing about AI is that it becomes harder to adopt and harder to control as AI gets smarter, not easier."

Why an insurer arrives this week

Look at the last seven days from an underwriter's chair. On Saturday the heads of four frontier labs agreed to slow down, and the only binding commitment was one company's promise to let evaluators in. On Monday a DeepMind study showed that when a quarter of a swarm blew the whistle on the cheaters, the reports went to a channel nobody read, because no one had built the enforcement layer. And a federal appeals court has ruled that when an agent acts in a user's browser, the agent is a tool and the user did it, which hands merchants a liability problem in place of the intrusion claim they used to have.

Every one of those is a story about norms arriving faster than enforcement. Insurance is what enforcement looks like when it is built by the private sector: a party that loses money when controls fail, and therefore demands the controls. Cyber insurance did this in the last decade. Carriers, not regulators, are the reason multi-factor authentication and offline backups became standard in mid-sized companies; the premium went up without them, then the policy became unavailable. Nobody passed a law. The underwriter priced the gap.

AIUC is betting the same mechanism transfers to agents. If it does, the requirements that a certifier attaches to a policy, a monitored escalation channel, a revocation path, a log that survives the agent, will arrive in enterprise procurement long before any lab or legislature mandates them. This is the MM Liability Gap being closed with money rather than with argument, which is the only way it has ever been closed.

What the policy does not yet cover

I want to be exact about the limits, because the strength of the idea is not the same as the strength of the product.

The cover described is first-party business loss for the enterprise customer of an AI vendor. That is a real product. It is not the harm that has actually occurred this year. The registry that absorbed 2,000 malicious packages and a self-found zero-day in May was not the customer of the swarm that attacked it. The wiki whose volunteer spent six weeks cleaning up was not a policyholder. The Major Labs Frontier Incident Timeline has seven entries, and in none of them would the injured party have been the insured. Third-party harm from agents, the thing that decides whether agents can be trusted in public, is not yet what anyone is underwriting.

Certification is also a moment, and agents are not. SOC 2 taught enterprise security that a report describes the day of the audit. An agent updated weekly, calling tools that change daily, is certified against a version that no longer exists by the time the report is read. AIUC says it uses agents to run its tests continuously and humans to verify the audit, which is the right instinct, and it does not change the fact that the certificate is a claim about the past.

And the tests are on the agent, not on what the agent touches. Five thousand jailbreak and leakage tests measure the model's behavior. They do not measure the servers it calls. Of the 3,260 MCP servers Major Labs scored on September 12, 76.3 percent of the sensitive, network-facing ones have no authentication in their source. A certified agent calling an unauthenticated tool server is a certified agent with an uncertified hand. Whether AIUC-1's security domain reaches that far is the first question I would ask any vendor holding the badge.

What it means if you accept agents

For a merchant, a platform, or a bank deciding whether to let agents transact, the underwriter changes the question. Until now the question was "is this agent safe," which no one could answer. The new question is "does this agent's operator carry cover, and what did the certifier require to write it." That is a question procurement knows how to ask.

Three things follow. First, ask for the certificate and the policy, in that order, and read the exclusions before the coverage. Second, expect the certifier's requirements to become the de facto agent standard for your sector faster than any regulator's, and shape your own controls to match: a signed identity at the door, a mandate you can revoke, a log you keep yourself. Third, notice who is not covered. If the harm lands on a third party, on your customers, on a registry, on a counterparty, the policy described this week does not reach them, and the Ninth Circuit's answer still stands: the user did it.

What to watch

Whether AIUC-1 shows up in procurement checklists the way SOC 2 did, which the KPMG and Intercom certifications suggest is the plan. Whether the carriers behind the policies are named, and what they exclude; prompt injection and third-party harm are the two exclusions I would bet on first. Whether certification extends to the tools an agent calls, which Major Labs can check against the registry the day a certified vendor publishes its server list. And whether a claim is ever paid in public. An insurance market becomes real the first time it writes a check, and until then this is a standard with a premium attached.

If the first agent insurance covers the vendor's customer but not the registry, the wiki, or the counterparty the agent actually damaged, who is still holding the loss?

Charlie Major is a Product Development Manager at Mastercard. The views and opinions expressed in Major Matters are his own and do not represent those of Mastercard.