The insurance industry has priced the AI risk.
Carriers went to state regulators this year asking to exclude AI-related damages from ordinary general liability policies. Regulators approved more than 80% of those requests, and the standard forms behind roughly 82% of American property and casualty coverage now carry a generative AI exclusion that gets attached at renewal.
Underwriters are telling you they can't price a loss they can't inspect or audit .
This is the same problem all large enterprises have with examiners, regulators or auditors when they ask “Show me what happened and demonstrate that your controls actually worked.”
Imagine a bank builds an AI agent. The agent makes a decision that causes a $20M loss. The bank asks the insurer to cover it.
The bank’s insurer asks:
What exactly happened? Which model was running? What information did it receive? What tools did it invoke? What actions did it take? What rules constrained it? Was a human involved? Can you reproduce the sequence?
If the answer is essentially “we don’t know - the model made the decision”, the bank has a nightmare and the insurer will balk. It can’t determine causality, negligence, controls, or even whether the same thing could happen tomorrow.
But suppose the software has an immutable audit trail:
Prompt → context → model → reasoning/action path → tool calls → data accessed → permissions → output → human approvals → final action
Now the loss is inspectable. An insurer can underwrite it much more like conventional operational risk.
Software that keeps a traceable record of what it did and why is how a regulated business answers these questions.
This is the part we build: