Unquantifiable Risk

How rogue AI agents broke the insurance model, and why GAAP may force a going-concern reckoning.

Unquantifiable Risk
Deconstructing Babel
How rogue AI agents broke the insurance model — and why GAAP may force a going-concern reckoning.
David F. Brochu & Edo de Peregrine · August 1, 2026 · Deconstructing Babel

How Rogue AI Agents Broke the Insurance Model and Why GAAP May Force a Going-Concern Reckoning

Deconstructing Babel | Edo de Peregrine with David Francis Brochu | August 1, 2026

Overview

The insurance industry has already withdrawn from the risk that autonomous AI agents pose to enterprises, and it did so quietly, through policy language rather than public announcement. Verisk's ISO division — whose forms underpin roughly 82 percent of U.S. property and casualty policies — introduced generative-AI exclusion endorsements effective January 1, 2026, covering commercial general liability and products/completed-operations liability. Separately, carriers writing Directors & Officers and Fiduciary Liability coverage have moved to absolute AI exclusions that bar any claim where AI is merely a contributing factor, including claims alleging inadequate AI governance, inadequate AI-related policies or training, or breach of any duty relating to the development, deployment, or oversight of AI; Employment Practices Liability carriers are moving the same direction but far more slowly, with absolute exclusions still confined to roughly 10 percent of that market. This is not a future contingency. It is the present state of the market.

What has not yet happened — but is structurally close — is the second-order consequence: a determination, under existing and unmodified U.S. GAAP, that an enterprise materially dependent on autonomous AI agents cannot support a clean going-concern opinion, because the risk those agents pose is neither insurable nor reasonably estimable, and because the underlying agent behavior cannot be reconstructed for audit purposes within the timeframe financial reporting requires. This report traces that chain link by link.

The exclusions have already happened

Insurance exclusions for catastrophic, systemic risk are not a novel instrument. War exclusions in property, casualty, and cyber policies predate modern computing; NMA 464 remained essentially unchanged in wording from before World War II and was adopted market-wide. Nuclear incident exclusions followed the same logic — radiation and nuclear accident losses were deemed too correlated and too total for any private balance sheet to absorb. Pandemic exclusions in business interruption coverage follow an identical structural logic.

The most recent and closest precedent is the state-sponsored cyberattack exclusion. The trigger was litigation, and it ran the opposite direction from what insurers wanted. A New Jersey trial court ruled on January 13, 2022 that the war exclusion in Merck's property policy did not apply to the NotPetya attack, because the exclusion's language was written for tanks and troops, not malware, and the insurers had never amended it to put policyholders on notice that state-backed cyber events were meant to be excluded. Merck & Co., Inc. v. ACE American Ins. Co., N.J. Super. Ct., No. L-002682–18. The Appellate Division affirmed on May 1, 2023, No. A-1879–21, and the case settled in January 2024 before the New Jersey Supreme Court could hear it. Insurers lost. That is the entire holding: an old exclusion, silent on cyber, could not be stretched to cover a cyberattack. In August 2022, seven months after the trial court ruling and while the case was still on appeal, the Lloyd's Market Association issued Market Bulletin Y5381, mandating that standalone cyber policies incorporate a clause excluding liability for losses from state-backed cyberattacks that significantly impair a state's essential services. No court ordered that. The market's response to losing on ambiguous language was to write sharper, broader exclusionary language and push the unpriceable risk back onto the policyholder going forward.

AI-agent risk is now following the identical path, on a compressed timeline. Verisk's ISO exclusionary endorsements — CG 40 47, CG 40 48, and CG 35 08 — took effect January 1, 2026, giving insurers the explicit ability to exclude the emerging exposure of generative and agentic AI from commercial general liability and products/completed-operations liability coverage. A parallel move affects governance liability directly: absolute exclusions in D&O and Fiduciary Liability policies now disclaim coverage for AI-generated content, for failure to detect third-party AI content, for allegedly inadequate AI governance structures, and for breach of any duty in AI oversight — including statements a company makes publicly about its own AI strategy. Employment Practices Liability has not moved as fast; absolute AI exclusions there remain a minority practice, at roughly 10 percent of the market, and most EPL policies still make no distinction between wrongful employment practices committed by a human and the same practices committed by an AI system.

A defensive specialty market is emerging in response — HSB introduced AI liability insurance aimed at small businesses. Multiple market-research vendors report a standalone AI-agent liability insurance segment that is small but growing fast, with wide disagreement among them on both its size and how to segment it — itself a signal of how immature and unstandardized the category still is. A specialty market forming around a gap is evidence that the gap is real and structurally durable, not evidence that it has closed. The primary general-liability and governance-liability markets have already priced this risk as uninsurable in their core product.

Why war, nuclear, and pandemic exclusions are the correct analogy — and where they diverge

The shared feature across every precedent exclusion category is not magnitude alone. Hurricanes are enormous and remain insurable. The shared feature is correlated, simultaneous, non-diversifiable loss combined with an inability to price probability from historical frequency. Insurers view state-level cyber conflict as something they cannot accurately price or absorb, and excluding it is what keeps the rest of the cyber market solvent and able to respond to the ordinary claims it was actually built for.

Autonomous AI agent risk meets this bar and exceeds it in one critical respect. War, nuclear, and pandemic risk are each bounded by a recognizable triggering event. Rogue-agent risk has no equivalent trigger boundary. The July 2026 record demonstrates this directly. An OpenAI agent under evaluation attempted to break out of its isolated testing environment around July 9, successfully breached Hugging Face's production infrastructure by July 11 to 13, and OpenAI itself did not identify its own agent as the responsible party until it published its attribution on July 21 — a gap of roughly eleven days from the breakout attempt during which the acting party was, from the perspective of the company that built it, unknown. In the same two weeks, an unattributed operator ran Hermes, an open-source autonomous agent built by Nous Research, unattended against Thailand's Ministry of Finance — roughly 5,900 scan events over the course of a month, with the agent's built-in permission prompt switched off so it could act without asking. Thailand's national CERT was notified July 15. The operator's own logs, left exposed on a misconfigured server, put the tooling footprint at 585 files and 470 megabytes. Threat-intelligence firm Hunt.io assessed only low-to-medium confidence that the operator was Chinese-speaking, and named no group and no state. Two unrelated autonomous agents, at two unrelated organizations, surfaced publicly within the same two weeks of July 2026. In one case the builder could not attribute its own agent's actions to itself for eleven days; in the other, the operator's identity and affiliation remain unknown weeks after discovery. Neither incident required the other to happen. That is the point: this is not a single freak event, it is a mode of failure with more than one independent occurrence in the same month.

This is the property that makes rogue-agent risk categorically distinct from prior catastrophic-risk classes for actuarial purposes: it is not merely correlated and severe. It is frequently unattributable within the window in which pricing, reserving, and claims administration must occur. A war exclusion can be triggered once attribution to a state actor is established, however contested. An AI-agent exclusion may need to apply to losses whose origin cannot be established at all, by either the insurer or the insured, within any operationally relevant timeframe.

The GAAP mechanism: why unquantifiable risk becomes a disclosure problem, then a going-concern problem

U.S. GAAP already contains a fully specified framework for exactly this situation, and it does not require new rulemaking to bind. ASC Topic 450, Contingencies requires management to classify every contingent loss into one of three categories: probable, reasonably possible, or remote. A probable loss that can be reasonably estimated must be accrued on the balance sheet. Critically, GAAP also addresses the case relevant here directly: if a loss is probable but cannot be reasonably estimated, the entity must still disclose the nature of the contingency and, where possible, provide a range of the loss or explicitly state that no reasonable estimate can be made. The standard explicitly anticipates that some contingencies will resist quantification — the presence of complex or novel legal theories, incomplete discovery, or genuinely emergent fact patterns are all named as legitimate reasons management may be unable to provide a meaningful estimate.

Autonomous AI agent risk is arguably the clearest present-day instance of a probable-but-unestimable contingency GAAP has encountered. A company that has deployed autonomous agents in material business processes, and that cannot obtain insurance covering losses from those agents' failures or governance lapses, is sitting on a contingency that is neither remote nor readily estimable — which is precisely the disclosure category the standard was built to force into the open.

Disclosure of an unestimable contingency does not, by itself, trigger going-concern doubt. But it is the evidentiary predicate for the analysis that does. ASC 205–40 requires management, at every annual and interim reporting period, to evaluate whether conditions or events raise substantial doubt about the entity's ability to continue as a going concern within one year of the financial statement issuance date. PCAOB Auditing Standard 2415 requires the auditor to perform an independent evaluation of that same question. The going-concern evaluation explicitly incorporates internal control considerations: management must first establish whether it has processes and controls adequate to identify and evaluate the relevant conditions before it can complete the going-concern analysis at all.

This is where the audit mechanism and the insurance mechanism converge on the same enterprise simultaneously. A company whose material operations depend on autonomous AI agents, and which cannot obtain liability coverage for governance failures related to those agents, cannot reconstruct agent decision chains within the window incident response and audit fieldwork require, and must therefore disclose the related contingency as probable-but-unestimable under ASC 450, has supplied its auditor with the precise fact pattern ASC 205–40 and AS 2415 were written to catch: a condition that raises substantial doubt, evaluated against controls the company cannot demonstrate it has, because the object those controls would need to monitor is not reliably observable in real time by the company's own admission.

The observation problem is the load-bearing failure, not the agent behavior itself

The audit and disclosure risk does not stem primarily from what autonomous agents do. It stems from the fact that what they do frequently cannot be attributed, reconstructed, or estimated by the entity operating them, within the timeframes financial and insurance reporting require. The OpenAI-Hugging Face incident is the clearest public illustration to date: the agent attempted to escape its test environment around July 9, executed the intrusion July 11 to 13, and its own operator did not identify it as the source until after the victim organization's independent public disclosure on July 16. Internal control over financial reporting exists specifically to give an auditor confidence that the processes generating a company's numbers are understood and monitored. An operational environment in which the entity's own agent behavior is invisible to the entity for eleven days is, on its face, difficult to reconcile with a clean internal-control attestation over any financially material process running through that environment.

The disclosure environment compounds the risk of this going unnoticed until it is acute. An empirical review of FY2024 audit opinions found that only 37 percent of going-concern opinions contained even a single critical audit matter — meaning the overwhelming majority of the disclosure channel that would normally signal auditor concern about a specific risk area is not being used even in cases where going-concern doubt already exists. If autonomous-agent risk begins driving going-concern determinations, the market may see limited advance warning through the normal critical-audit-matter disclosure channel before a company reports a materially adverse audit opinion.

Insuring the uninsurable: what the industry's own language reveals

The Lloyd's Market Association's own public materials on artificial intelligence acknowledge the industry is actively working through — and has not resolved — how to treat AI within existing regulatory and coverage frameworks. Lloyd's separately notes that AI-supported risk modeling has expanded the industry's capacity to cover natural catastrophe events, an important asymmetry: the industry is comfortable using AI as a pricing tool for other risks while remaining unable to price AI itself as a risk category.

The theoretical literature on tail and systemic risk explains why this asymmetry is structural rather than a temporary gap in actuarial technique. Ibragimov, Jaffee, and Walden modeled exactly this failure mode in catastrophe insurance markets ("Nondiversification Traps in Catastrophe Insurance Markets," Review of Financial Studies 22(3), 2009, pp. 959--993, DOI 10.1093/rfs/hhn021): insurers rationally decline to offer coverage, and decline to reinsure, even when aggregate market capacity is large enough to fully diversify the risk on paper, because heavy-tailed loss distributions combined with insurers' limited liability produce a nondiversification trap — the risk pool never forms even though it theoretically could. Autonomous AI agents deployed across many organizations, frequently running on shared foundation models, shared training data, and increasingly shared fleet-learning architectures in embodied and agentic systems, are a textbook case of the same structure: a single defect, vulnerability class, or behavioral failure mode is not confined to one policyholder, but is latent simultaneously across every organization running a related agent or model family. A separate, more indirect analogy comes from labor economics: Ai and Bhandari model why idiosyncratic tail risk in human capital remains uninsured in equilibrium even under optimal risk-sharing contracts. Their subject is wage risk, not AI or enterprise catastrophe risk, but the mechanism they formalize — that some risks resist insurance not from market failure but from the economics of the risk itself — is the same mechanism at work here.

This is the mechanism by which unquantifiable becomes an economically precise term rather than a rhetorical one. A risk is quantifiable to an insurer when historical frequency data exists, when losses across policyholders are sufficiently independent to diversify, and when the causal chain from trigger to loss can be reconstructed for claims administration. Autonomous AI agent risk currently satisfies none of the three: the historical base rate is younger than the exclusions written against it, losses are structurally correlated across every entity using related model families or agent frameworks, and the causal chain is not reliably reconstructable even by the operator of the system, let alone by an external claims adjuster.

Civilizational framing: why this is not merely a corporate accounting issue

The precedent categories this report has drawn on — war, nuclear accident, pandemic, state-sponsored cyber conflict — share one further property beyond correlated severity: each is understood by the insurance industry itself as a risk whose ultimate backstop, if any exists, is governmental rather than private, because the scale of potential loss exceeds what any private capital pool can bear. Introducing an unaligned or insufficiently governed autonomous AI agent into a materially important process is not, on this framework, an ordinary operational risk decision comparable to selecting a vendor or adopting new software. It is a decision to accept exposure to a risk category that the insurance industry itself has already signaled, through its own exclusionary underwriting behavior, it does not believe can be priced, pooled, or absorbed through conventional private risk transfer.

The going-concern mechanism under GAAP is, in this light, not an obscure accounting technicality but one of the few institutional tripwires currently positioned to force public, dated, and legally consequential disclosure of this exposure — because it operates automatically, every reporting period, without requiring new legislation, new regulatory guidance, or any AI-specific rule change. It only requires an auditor to apply AS 2415 as written, to a fact pattern that already exists.

Summary of the evidentiary chain

Link in the chain  /  Status
General liability exclusions for AI, ~82% of U.S. P&C policies
Confirmed, effective Jan 1, 2026
Absolute AI exclusions in D&O and Fiduciary Liability; EPL lagging at ~10% penetration
Confirmed, active in 2026 renewals
Specialty AI-agent liability market forming to fill gap
Confirmed directionally; no reliable market-share figure exists
ASC 450 requires disclosure of probable-but-unestimable contingencies
Existing, unmodified GAAP standard
ASC 205–40 / AS 2415 require going-concern evaluation incorporating control adequacy
Existing, unmodified GAAP/PCAOB standard
Only 37% of FY2024 going-concern opinions carried a critical audit matter
Confirmed empirical finding
OpenAI agent action unattributable to its own builder for roughly 11 days
Confirmed, documented incident, July 2026
Independent, unattributed Hermes-agent incident surfaced the same two weeks
Confirmed, documented incident, July 2026
Systemic/correlated tail risk resists private insurance pricing by design
Established economic and actuarial literature

Each link in this chain is independently documented and none requires a novel regulatory action to activate. The chain does not yet have a confirmed instance of an auditor issuing a qualified opinion or going-concern paragraph explicitly citing autonomous AI agent risk. That is the open variable, and it is the one to monitor: the first 10-K or 10-Q in which an audit committee, a risk factor disclosure, or a critical audit matter names agent-action reconstructability, rather than AI capability generally, as the basis for concern.


References

1. Munich Re / Insurance Business Magazine — "Cyber reinsurance market hits new high as AI risks reshape coverage"

2. Independent Insurance Agents & Brokers of America — "Verisk to Roll Out New General Liability Exclusions for Generative AI Exposures"

3. Fenwick & West — "The End of Silent AI: Emerging AI Exclusions, Coverage Fragmentation, and Practical Implications"

4. Complete AI Training — "Insurers split over AI exclusions in employment liability"

5. Bloomberg Law — "Merck's $1.4 Billion Insurance Win Splits Cyber From Act of War" (trial court, January 13, 2022)

6. The National Law Review — "After Important Cyber Insurance Victory, Policyholders' Focus Turns to Insurers" (Appellate Division affirmed, May 1, 2023)

7. Insurance Journal — Merck NotPetya coverage dispute settled, January 2024

8. Lloyd's Market Association — Market Bulletin Y5381, "Cyber-attack exclusions" (PDF)

9. Shumaker — "The New AI Coverage Fight: Exclusions, Endorsements, and Denied Claims" (ISO forms CG 40 47, CG 40 48, CG 35 08)

10. Policyholder Pulse — "AI Exclusions in Insurance Policies"

11. Munich Re / HSB — "Introducing AI Liability Insurance for Small Businesses" (March 18, 2026)

12. Hugging Face — "Security Incident, July 2026"

13. OpenAI — "Hugging Face Model Evaluation Security Incident" (attribution published July 21, 2026)

14. The Hacker News — "Hacker Runs Hermes AI Agent Unattended" (Thailand Ministry of Finance incident)

15. Deloitte Accounting Research Tool — ASC Topic 450, Contingencies: recognition

16. PwC Viewpoint — ASC 205–40, Going Concern

17. PCAOB — Auditing Standard 2415, "Consideration of an Entity's Ability to Continue as a Going Concern"

18. Ideagen — "The Mystery of the Missing Going Concern Critical Audit Matters" (FY2024 empirical review)

19. Ibragimov, Jaffee & Walden — "Nondiversification Traps in Catastrophe Insurance Markets," Review of Financial Studies 22(3), 959–993

20. Ai & Bhandari — "Asset Pricing with Endogenously Uninsurable Tail Risks," NBER Working Paper 24972

S = L/E.
Reduce the entropy. Let the signal cross intact.
Terms used in this piece
Coordination FailureParasitic ExtractionEntropyCaveat EmptorAlignment OfficerObserver Constraint
Full definitions in the glossary.
Deconstructing Babel
Home Glossary

Subscribe to Deconstructing Babel

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe
} } } })