What AI insurance underwriters ask before writing a policy: Armilla, AIUC and the Lloyd's market.
Short answer. Every specialist AI liability underwriter asks for the same four documents: a technical description of the system, a governance and oversight record, an incident history, and a written statement of the scope limits the agent operates within. Armilla, a Coverholder at Lloyd's writing up to USD 25 million per organisation, runs a two-stage process: a governance questionnaire first, then a technical assessment. AIUC runs an AIUC-1 audit, 51 requirements and 130 controls across six pillars, and prices off the outcome. Placing into the Lloyd's market through a broker means presenting the same evidence in a submission rather than a questionnaire. Allow 90 days before the intended coverage start date. If you have built EU AI Act Article 9 to 17 documentation, you have already built most of the submission.
Key takeaways
- Every specialist AI liability underwriter asks the same foundational question before quoting: can the enterprise demonstrate structured governance over the AI system it wants to insure? The answer is not a yes or no. It is a documentation set. Governance evidence is the entry ticket to coverage, not a nice-to-have.
- Armilla, a Coverholder at Lloyd's writing limits of up to USD 25 million per organisation, uses a two-stage process: governance questionnaire followed by technical assessment. The governance questionnaire addresses ownership, oversight structure, incident history, and scope limits. Technical assessment examines the model's documented performance and risk controls.
- AIUC structures its process around the AIUC-1 certification standard, which links audit outcomes to pricing. The standard runs to 51 requirements and 130 controls across six pillars: data and privacy, security, safety, reliability, accountability, and societal risks. An earlier version of this article listed a different six, and that wrong list is in wide circulation.
- Specialist AI submissions across every route into the Lloyd's market converge on the same three conditions: documented human oversight of consequential AI decisions, a post-incident remediation record, and a technical summary of the system's training data provenance and scope constraints.
- Enterprises that have built EU AI Act compliance documentation under Articles 9 to 17 of Regulation (EU) 2024/1689 are producing the same material underwriters require. The compliance record and the underwriting submission are the same document, approached from different directions.
The underwriting problem that makes AI insurance different
Pricing conventional liability insurance depends on actuarial models built from historical claims data. A professional indemnity insurer pricing a law firm's E&O can draw on decades of data about the frequency and severity of legal malpractice claims, adjusted for firm size, practice area, and claims history. The risk is well-characterised.
AI agent liability has no equivalent data history. The systems being insured are novel, their failure modes are probabilistic rather than predictable, and the population of deployed systems is growing faster than the claims data that would allow actuarial modelling. This creates a fundamental underwriting challenge: the insurer cannot price from historical data alone and must rely instead on observable indicators of governance quality as a proxy for risk.
This is why every specialist AI liability underwriter focuses on documentation. Documentation is not bureaucracy. It is the closest available signal to what actuarial data would normally provide. An enterprise with strong governance documentation is, in the underwriter's assessment, a lower risk than an identical enterprise without it, because the documentation demonstrates structured oversight that reduces the probability of harmful failures and enables faster remediation when failures occur.
Understanding this logic reframes the documentation work. Building an AI governance record is not compliance overhead. It is directly improving your insurance eligibility and reducing your expected premium. The two activities are identical at the level of the evidence produced.
The four document categories every underwriter requires
Across Armilla, AIUC, the Lloyd's market, Munich Re aiSure, and Testudo, four categories of documentation are consistently required before a binding quotation is issued. These categories differ in label and format across carriers but are substantively the same.
1. Technical system description
The underwriter needs to know what the AI system does, at a level of specificity that allows them to assess the liability profile of its outputs. A description of "our AI assistant helps customers with queries" is not adequate. The required level of detail covers: the type of model used (large language model, classification model, recommendation engine, autonomous agent); whether the model is proprietary or a third-party foundation model accessed via API; the data on which the model operates in production; the categories of outputs it produces; and the channels through which those outputs reach end users or feed other systems.
The EU AI Act's technical documentation requirements under Article 11 and Annex IV provide a useful template for this description. An Annex IV technical documentation file completed for EU AI Act compliance purposes is, in most cases, sufficient for the technical description section of an AI liability underwriting questionnaire. Organisations that have not yet built their Annex IV documentation should treat the underwriting questionnaire as the reason to build it now. Further detail on Article 11 requirements is at agentliability.eu.
2. Governance and oversight record
The governance section of an underwriting questionnaire addresses who is responsible for the AI system and what controls they exercise over it. The questions typically cover: designated ownership at the organisational level (who is accountable when something goes wrong); the review and approval process for new AI deployments; the ongoing oversight mechanism (who reviews outputs, at what frequency, using what criteria); and the escalation path when an incident or anomaly occurs.
Underwriters are particularly interested in human oversight at decision points. For AI agents that take consequential actions, such as communicating with customers, generating documents, making recommendations, or executing transactions, the governance section should document whether there is a human approval requirement before the action is taken or whether the system acts autonomously. Fully autonomous consequential actions without human approval gates are a significant risk signal for most underwriters. Munich Re aiSure, which settles on measurable performance data, prices autonomous system exposure differently from supervised deployment: the scope of autonomous action is directly related to coverage limits and premium.
3. Monitoring and incident record
The monitoring section demonstrates that the organisation is actively tracking the AI system's performance in production and responding to anomalies. Questions in this section cover: how the system's outputs are monitored; what metrics are tracked; what thresholds trigger review or escalation; and whether there is a formal incident log.
An incident log is not a negative signal for underwriters. An enterprise that has experienced AI-related near-misses or minor incidents and has documented them, assessed root causes, and implemented corrective actions is demonstrating exactly the kind of active governance that underwriters look for. An enterprise with no incident history and no monitoring record is a different kind of signal: it may reflect genuinely clean performance, or it may reflect absence of monitoring. Underwriters assume the latter until documentation suggests otherwise.
Post-market monitoring requirements under EU AI Act Article 72 require deployers of high-risk AI systems to maintain a post-market monitoring plan and record. This document, if maintained correctly, satisfies the monitoring section of an AI liability underwriting questionnaire.
4. Scope constraints and exclusion documentation
Underwriters want to know what the AI system cannot do and what safeguards prevent it from acting outside its intended scope. This section covers: documented constraints on the system's output range; human approval requirements before consequential actions; technical safeguards against prompt injection, data leakage, or scope drift; and any known limitations or failure modes that have been identified and accepted.
This documentation reflects the risk management system required under EU AI Act Article 9 for high-risk AI systems, which requires deployers to maintain a risk management system that identifies, analyses, and assesses risks and implements risk management measures. The Article 9 risk management documentation, if structured to include scope constraints and safeguards as required by the Act, covers the underwriter's scope constraints section.
Carrier-specific requirements: Armilla, AIUC, and Lloyd's
What does Armilla ask for, and what does its policy actually cover?
Armilla Insurance Services is a Coverholder at Lloyd's, the first dedicated exclusively to AI liability, and its Affirmative AI Liability Insurance is, in its own words, "underwritten by certain underwriters at Lloyd's". Its Standalone AI Liability Policy carries limits of up to USD 25 million per organisation. Armilla names five partners at source: Chaucer Group, AXIS Capital, Convex, Greenlight Re and Swiss Re.
One correction worth making early, because it is the most repeated error about this company and this desk repeated it too. The USD 25 million is a policy limit, not a funding round. There was no round of that size. Trade press conflated the limit with a raise, several outlets printed it as a Series A or a Series B, and the error propagated into secondary coverage including ours. If you are reading a summary that treats that figure as a funding round, it has the market wrong in a way that matters: it is describing the size of a company when it is looking at the size of a policy.
Armilla is the most relevant specialist for a European enterprise buyer for a specific reason rather than a general one. Its policy names AI regulatory violations, covering defence costs and insurable fines arising from investigations under regulations including the EU AI Act and the Colorado AI Act. Most affirmative AI cover in this market responds to third-party loss and stops there. A policy that names the regulatory limb is the one a European compliance officer can actually take to a board.
The process runs in two stages. First a governance questionnaire, which the applicant completes directly or through a broker, covering the four documentation categories described above with particular weight on governance and oversight. Then a technical assessment of the model's documented performance and risk controls. The gap between the two stages is where most submissions stall, and it stalls for a predictable reason: the governance answers are written by a risk or legal function and the technical evidence sits with an engineering function that was not in the room when the questionnaire was filled in. Get both in the room before stage one.
Armilla announced a collaboration with Trustible, described as first to market, on 8 October 2025. Trustible publishes an AI governance documentation platform. The practical read for a buyer is not that you need Trustible; it is that Armilla is comfortable receiving governance evidence in structured, platform-generated form rather than as prose, which is a signal about what a good submission looks like. The same logic transfers to a European submission, because what an operator builds for EU AI Act compliance is largely what the underwriter wants to see.
On sector exclusions. This desk has previously stated that Armilla excludes medical diagnosis, mental health support and legal advice from its core product. Armilla does not publish a sector exclusion list at armilla.ai, checked 17 August 2026, so treat that as market understanding rather than a published term and confirm it with your broker. It is consistent with the direction of the market: high-consequence professional advice sits where liability exposure is largest and where an underwriter has the fewest governance standards to price against.
How to approach it. Armilla writes surplus lines and reaches European buyers through wholesale broker intermediaries rather than directly, so a European enterprise generally arrives through a broker who has access to the Lloyd's market. It is not a European-domiciled product, and that distinction matters for anyone whose procurement requires an EU-domiciled counterparty. See the carrier matrix for how Armilla sits against Munich Re aiSure, Counterpart and the rest of the market, and Armilla and the Lloyd's coverholder model for how a coverholder arrangement works in practice.
What is the AIUC-1 standard and how does it change the price?
The Artificial Intelligence Underwriting Company (AIUC) emerged from stealth in July 2025 with a USD 15 million seed round led by Nat Friedman at NFDG, and combines certification with coverage. Its AIUC-1 standard runs to 51 requirements and 130 controls across six pillars: data and privacy, security, safety, reliability, accountability, and societal risks. Certificates run twelve months with at least quarterly testing, and Schellman is the first accredited auditor. An enterprise that completes a full AIUC-1 audit is eligible for coverage priced against the assessed quality of that specific system.
Note the six pillars carefully, because an earlier version of this article listed a different six, and the wrong list is in wide circulation. AIUC-1 operationalises ISO/IEC 42001, the NIST AI Risk Management Framework, MITRE ATLAS and the OWASP Top 10 for LLMs, which is why its pillars read like a security and governance standard rather than like a machine-learning research taxonomy. If a summary tells you AIUC-1 assesses alignment and interpretability, it is describing something else.
The AIUC model is the most actuarially interesting approach in the market: by connecting audit outcomes to pricing, AIUC is building the dataset that would eventually let the market price AI liability from observable risk indicators rather than from governance proxies. ElevenLabs secured the first AIUC-1-backed policy in February 2026, after more than 5,000 adversarial simulations, described elsewhere as 5,835 technical tests across 14 risk categories, and the policy was placed through Lloyd's of London. No insurer or reinsurer is named at source for that policy, by AIUC or by ElevenLabs, and no limit is disclosed. Several summaries name a reinsurer. They are guessing.
AIUC-1 was designed for the US legal and regulatory context. It does not map specifically to EU AI Act compliance obligations. European enterprises seeking AIUC coverage should supplement their AIUC-1 preparation with EU AI Act compliance documentation to ensure the governance record covers both frameworks. The Agent Certified framework at agentcertified.eu is structured around EU AI Act requirements and maps to the same dimensions that AIUC-1 assesses.
What does the Lloyd's market ask for, and how do you reach it?
Two routes reach the Lloyd's market. Through a coverholder such as Armilla, which holds delegated authority and can bind cover within its binding authority criteria without a Lloyd's broker in the chain. Or through a direct placement via a Lloyd's broker, who accesses the market on the buyer's behalf and places the risk with one or more syndicates. The coverholder route is faster and bounded by the coverholder's authority; the broker route is slower and is how limits above that authority get built, by layering syndicates.
A note on what this desk will and will not tell you about Lloyd's wordings. Trade reporting through 2026 has described managing agents circulating draft AI endorsements extending professional liability and technology errors and omissions cover to model errors, hallucinations, harmful outputs and agent failures. We have not been able to confirm any specific draft, any clause number or any central Lloyd's AI underwriting framework at lloyds.com or lmalloyds.com, checked 17 August 2026, and an earlier version of this article cited a Lloyd's Emerging Risk Group consultation draft that we could not find. That citation has been removed. What is verifiable is the structure of the market rather than the wordings inside it, and the structure is what a buyer plans against.
What every specialist submission converges on, across all three routes, is three requirements. First, documented human oversight of consequential AI decisions: a written review process for AI-assisted decisions above a defined threshold of significance, with the threshold itself written down. Second, a post-incident remediation record: evidence that material AI incidents have been investigated, root-caused and corrected, and that the process is repeatable rather than improvised. Third, training data provenance: for systems built on foundation models, a description of training data governance good enough for an underwriter to price exposure to intellectual property, privacy and bias claims. Those three map almost exactly onto EU AI Act Articles 14, 73 and 10 respectively, which is the whole reason compliance work and underwriting work are the same work.
Brokers placing AI liability into the Lloyd's market will increasingly need to provide these three documents as part of the presentation. Enterprises that have built this documentation before approaching the market will have a significantly faster path to a binding indication than those who are assembling it in response to a carrier's request.
What disqualifies an AI deployment from coverage
Several characteristics consistently produce a decline from specialist AI underwriters or result in coverage terms that are too narrow or expensive to be useful.
No documentation whatsoever. An enterprise that cannot produce any governance, monitoring, or technical documentation for its AI system is presenting an unquantifiable risk. No specialist underwriter will write it at a viable premium. This is the most common single reason for an unsuccessful coverage approach in the current market.
Deployment in excluded categories. Most specialist AI carriers explicitly exclude medical diagnosis, mental health support, legal advice, and autonomous weapon systems. For enterprises in these sectors, coverage must be sought through sector-specific routes, typically a specialist professional liability or medical malpractice insurer that is developing AI-specific language, or through a Lloyd's syndicate focused on medical or legal professional liability.
Prior incidents with no documented remediation. An enterprise that has experienced AI-related harm events and cannot show that those events were investigated, root-caused, and corrected is presenting a high-risk signal. The incidents themselves are manageable if properly handled. The absence of remediation documentation is not.
Opaque third-party model supply chains. AIUC in particular requires that the operator can describe the training data governance of the model it is deploying. For enterprises using third-party foundation models via API from providers that do not publish training data information, this creates underwriting difficulty. The Agent Certified dimension on training data governance, drawn from EU AI Act Article 10, addresses this: it guides enterprises through the documentation they can and should obtain from foundation model providers even when full transparency is not available.
Full autonomy without human approval gates for consequential actions. A fully autonomous AI agent that can commit the enterprise to contracts, make payments, or send consequential communications without human approval before the action is taken represents a tail risk that underwriters are reluctant to write at standard terms. Enterprises should document the scope of autonomous action clearly and implement approval gates for actions above defined thresholds. This documentation both improves insurability and satisfies the human oversight requirements of EU AI Act Article 14.
Preparing a strong underwriting submission
The most effective approach to AI insurance preparation treats the underwriting submission as the compliance documentation, assembled in advance rather than in response to a carrier's questionnaire under deadline pressure.
Concretely, this means four workstreams running in parallel. First, complete the technical documentation for each AI system in scope: what it does, what model it uses, what data it processes, what outputs it produces. Second, document the governance structure: ownership, oversight process, approval gates for consequential actions, incident escalation paths. Third, establish and maintain a monitoring log: performance metrics, anomaly records, and incident documentation. Fourth, document scope constraints: what the system cannot do, what safeguards prevent scope drift, what human approval is required before irreversible actions.
For organisations building EU AI Act compliance programmes under the August 2026 deadline, this workstream is the same as the compliance workstream. The documentation produced for Articles 9 (risk management), 11 (technical documentation), 12 (logging and record-keeping), 13 (transparency towards deployers), 14 (human oversight), and 72 (post-market monitoring) is the documentation an underwriter will ask for. The return on compliance investment is therefore doubled: it satisfies the regulatory requirement and positions the enterprise for coverage when products become available.
Start the preparation at least 90 days before the intended coverage start date. Armilla's technical assessment takes two to four weeks. AIUC's full audit takes four to eight weeks. If documentation is incomplete at the start of that process, the timeline extends accordingly. Organisations that approach the market without documentation will not obtain coverage within a normal renewal cycle.
For the structured seven-dimension certification framework that produces this documentation systematically, see the Agent Certified methodology. For a full analysis of EU AI Act deployer documentation requirements, see the Article 26 guide on agentliability.eu.
Frequently asked questions
What documentation do AI liability underwriters require before quoting?
Four categories are consistently required: a technical system description (what the AI does, what model it uses, what outputs it produces); a governance and oversight record (who owns it, what oversight exists, how incidents are escalated); a monitoring and incident log (performance data and incident documentation); and a scope constraints statement (what the system cannot do, what human approval gates exist). Carriers including Armilla, AIUC, and Lloyd's managing agents all require variants of this documentation before issuing a binding indication.
What disqualifies an AI deployment from coverage?
The most common reasons for decline are: no documentation at all, deployment in excluded categories (medical diagnosis, mental health, legal advice), prior incidents with no documented remediation, opaque training data provenance for the underlying model, and fully autonomous consequential actions without human approval gates. Each of these is addressable if identified early enough in the submission preparation process.
How does Armilla's underwriting process work?
Armilla uses a two-stage process: a governance questionnaire covering ownership, oversight, incident history, and scope limits, followed by a technical assessment of the system's documented performance and risk controls. Limits reach $25 million per organisation. The Trustible collaboration announced in October 2025 shows the shape of the pathway: a governance platform produces the artefacts, and those artefacts feed the underwriting assessment directly.
What is the AIUC-1 standard and how does it affect pricing?
AIUC-1 is an AI security, safety and reliability standard published by the Artificial Intelligence Underwriting Company. It runs to 51 requirements and 130 controls across six pillars: data and privacy, security, safety, reliability, accountability, and governance. Higher audit scores produce lower premiums. The standard was designed for US legal context and does not map to EU AI Act obligations, but the assessment dimensions closely parallel those of the Agent Certified European framework.
How far in advance should I prepare my AI underwriting submission?
At least 90 days before the intended coverage start date. Armilla's technical assessment takes two to four weeks. AIUC's audit takes four to eight weeks. If documentation is incomplete at the start of either process, the timeline extends further. Organisations building EU AI Act compliance documentation in parallel are building the underwriting submission at the same time, which reduces the preparation burden significantly.
References
- Armilla Insurance Services. Affirmative AI Liability Insurance: Coverholder at Lloyd's, underwritten by certain underwriters at Lloyd's, limits up to USD 25 million per organisation; partners named at source are Chaucer Group, AXIS Capital, Convex, Greenlight Re and Swiss Re. armilla.ai (checked 17 August 2026).
- Artificial Intelligence Underwriting Company (AIUC). AIUC-1: 51 requirements, 130 controls, six pillars (data and privacy, security, safety, reliability, accountability, societal risks). Out of stealth July 2025, USD 15 million seed led by Nat Friedman at NFDG. aiuc.com (checked 17 August 2026).
- Munich Re. aiSure AI performance insurance, underwritten and marketed by Mosaic Insurance. mosaicinsurance.com.
- Lloyd's of London market structure: coverholder and direct broker placement routes. An earlier version of this article cited a Lloyd's Emerging Risk Group AI underwriting framework and a Q1 2026 consultation draft. Neither could be found at lloyds.com or lmalloyds.com on 17 August 2026 and the citation has been removed.
- European Parliament and Council. Regulation (EU) 2024/1689 on Artificial Intelligence (EU AI Act). Articles 9 (risk management), 11 (technical documentation), 12 (logging), 14 (human oversight), 72 (post-market monitoring). Official Journal of the European Union, 12 July 2024.
- AIUC seed round: USD 15 million led by Nat Friedman at NFDG, July 2025, verified at aiuc.com (checked 17 August 2026). Trade coverage retained for the record: Fortune, 23 July 2025.
- Armilla. Standalone AI Liability Policy, limits up to USD 25 million per organisation. armilla.ai/ai-insurance.
- ElevenLabs AIUC-1-backed policy, February 2026, placed through Lloyd's of London. aiuc.com and elevenlabs.io (checked 17 August 2026). No insurer or reinsurer is named at source and none is named here.