On 14 July 2026, the Artificial Intelligence Underwriting Company published a report with a striking finding: more than 90 per cent of insurers’ exposure to AI-related loss sits in what the industry calls silent cover. It is not written as AI cover. It is bundled, unpriced and often unnoticed, inside conventional cyber, directors-and-officers, general liability, and technology errors-and-omissions policies.
The report follows the International Organization for Standardization’s January 2026 generative-AI exclusion for commercial general liability policies. The direction of travel is clear enough. Exposure that was absorbed silently gets identified, then excluded, then priced.
Agents widen the liability surface
The accelerant the report identifies is agentic deployment. While an AI system only produces text for a human to act on, the failure mode is bounded and familiar: bad advice, given and then acted upon by a person who remains in the loop and in the record.
Once systems can move funds, reach into internal applications, and execute multi-step workflows with limited supervision, the exposure changes shape. The question is no longer whether the model’s answer was wrong. It is whether an unauthorised action occurred, who authorised the chain that led to it, and what the system understood itself to be doing at each step. That gap, between what insurers currently cover and what deployed systems actually do, is widening faster than underwriting can reprice it.
Evidence becomes the commercial variable
For anyone operating these systems in a regulated Swiss context, the practical consequence is worth stating plainly. When a claim arrives, the institution that can produce a complete, tamper-evident record of every agent action, from the prompt through each tool invocation to the outcome, is in a materially different negotiating position from one that cannot.
The second institution is not necessarily at fault. It simply cannot demonstrate that it was not. Its records live in a third party’s platform, retained under that provider’s schedule, disclosed under another jurisdiction’s rules, and reconstructed after the fact from whatever the API happened to log.
This reframes something that has often been presented as a compliance cost. Governance infrastructure, the ability to trace and evidence what a system did, has usually been justified by pointing at the regulator: FINMA expectations, EU AI Act obligations, internal audit. Those arguments hold. But the insurance angle adds a second and more immediate one, because it attaches a price.
What this looks like in practice
Institutions that already run their inference on infrastructure they control tend to get this property almost incidentally. The logs are theirs, retained on their schedule, inside a perimeter their own auditors already examine. Tracing tools such as the open-source LLM observability stacks now in wide use can be run entirely on that same infrastructure, so nothing has to leave the boundary to produce the record.
The recommendation for anyone reviewing an AI programme this year is therefore narrow and concrete. Establish, before the next renewal conversation, who holds the record of what your AI systems do, how long it is retained, and whether it can be produced in a form that an underwriter or an auditor would accept. Sovereign infrastructure was always a way to satisfy the regulator. It is now also a way to satisfy the insurer.