How AI liability is underwritten
Axiom SpecialtyAugust 16, 20263 min read
Underwriting AI liability starts with a question about roles, not companies. A vendor supplies a system. A deployer runs it, in agents, chatbots, or copilots, and puts its name on the output. When a third party is harmed, they sue the deployer, because the deployer owed them the duty. Vendor and deployer are roles, and one firm is often both at the same moment.

That is the exposure AI Liability is written for, and it is why the form is priced on the deployer's side of the picture.
What we actually price: authority, containment, compliance
We underwrite three things about how a business runs its AI, not a score of how good the model is.
- Authority. What is the system allowed to do, and how far can it reach on its own. An agent that can move money or commit the business carries a different exposure than a copilot that drafts text a person signs.
- Containment. What stops it when it goes wrong. A documented authorization scope enforced in configuration, timestamped logging, and a person who can halt the agent. These are the qualifying governance we require at deployment for any agent, and the free governance software puts them in place and evidences them for a claim.
- Compliance. Which duties and statutes attach to the use. Employment, lending, tenancy, and clinical uses carry named regulatory exposure, tracked on the statute schedule attached to each policy.
The single largest input to the premium is the proportion of AI output that reaches a third party without a person reviewing it first. That is a fact about how you operate, and it moves what you pay rather than whether you are covered.
How the underwriting is done
There is no audit, no penetration test, no model evaluation, and nothing installed in your environment to price the risk. Underwriting runs from an application and a public-record check.
- Declare, do not inventory. You select the categories of use you want covered, and schedule only the systems that can do real damage: agents, high-severity systems, and automated decision systems. A spreadsheet in the same columns is accepted.
- Four conditions precedent, and no others. Qualifying governance for agent matters, licensed sign-off for clinical use of head (d), the outside date for notice, and the recovery and record requirements for first-party losses. Failing one affects only the claim it relates to, never the whole policy.
- A fast, plain answer. An indication within five business days of a complete submission, and a hard decline within one business day, with the reason.
Accreditation, priced but never required
You can evidence qualifying governance from your own configuration and logs, from a written attestation by the supplier of the agent, or from Axiom Accreditation, an independent evaluation of a scheduled high-severity system. Accreditation is optional, and it may earn a rating credit. It is one way to show an underwriter the containment is real.
We insure the business that uses AI, not the business that supplies a system a third party deploys for itself. Everything above follows from that one line: we price the duty the deployer owes, and the authority, containment, and compliance around how the AI is actually run.
See how a scheduled system is evaluated.
Axiom Accreditation