A single foundation-model defect can now propagate across thousands of unrelated insureds at once: over 80% of enterprise AI agent deployments run on just three foundation-model providers, according to a July 2026 report from the Artificial Intelligence Underwriting Company (AIUC, July 2026). That concentration converts agent liability from an independent per-policy loss into a correlated accumulation exposure closer in structure to a catastrophe peril than to ordinary casualty risk.
Key Takeaways
- Over 80% of enterprise agent deployments run on three foundation-model providers, so a training-data flaw or a defective model update is a single shared hazard sitting under a growing share of the commercial book.
- Roughly four months is the doubling period for the length of task an agent can complete autonomously, which means the unit of correlated exposure is not stationary across a treaty year.
- Nearly 50% of Lloyd's underwriters believe policyholders already have adequate AI risk management, against 1 in 5 businesses reporting a mature governance model for autonomous agents.
- No attacker is required. Cyber accumulation needs an exploit to activate a latent shared vulnerability; a routine model update starts a correlated loss event with no adversary in the loop.
- 117 pages from more than thirty contributors across Anthropic, OpenAI, RAND, QBE, Generali and Aon, placing accumulation modeling ahead of pricing in the proposed eight-component stack.
A Report Written by the People Who Would Have to Underwrite It
"Underwriting the Agent Economy: The Blueprint," published July 1 by the Artificial Intelligence Underwriting Company, is not a vendor deck. Corresponding author Cristian Trout leads more than thirty contributors drawn from Anthropic, OpenAI, Stanford, RAND and MIT alongside QBE, Generali and Aon, and the full report runs to 117 pages of underwriting mechanics. Its argument is that autonomous agents are already generating claims severe enough to matter and that the industry lacks the infrastructure to price or absorb them.
The provider-concentration figure should concern capital modelers more than any coverage-wording gap. More than 80% of agent deployments run on models from three providers, so a training-data flaw, a prompt-injection vulnerability or a defective model update is not confined to one insured, one industry, or one coverage line (AIUC, July 2026).
The peril is also not stationary. The length of task an agent can complete autonomously before human intervention is doubling roughly every four months, a pace the report flags as faster than actuarial reliability models can track, and incident severity has moved from hallucinated refund policies in 2022 to wrongful death cases in 2025.
Demand runs ahead of price: over 90% of businesses want frontier-AI-tailored coverage while 60% of business leaders say they are deliberately slowing AI implementation over error concerns.
Provider Concentration Is a Textbook Accumulation Exposure
Actuaries size accumulation risk by asking how many policies share a single loss-generating event. A hurricane accumulates across every policy in its footprint; a systemic cyber event accumulates across every insured running the same vulnerable software version. Foundation-model concentration has the identical structure with a different footprint: the shared hazard is one model version sitting inside claims, procurement, coding and customer-facing agents across thousands of unrelated policyholders at once.
The Lloyd's Market Association reaches a compatible conclusion from the underwriting side. Across 39 responses covering more than 60% of Lloyd's stamp capacity, the LMA found AI adoption more than doubling in twelve months, and its systemic-risk language is direct: models trained on similar architectures and datasets develop similar biases, raising correlated-failure risk for the whole sector.
One structural difference from cyber decides how the correlation load has to be built. Cyber accumulation typically requires an attacker, or at minimum a triggering exploit, to activate a shared vulnerability that is latent until something acts on it. A foundation-model concentration event requires no attacker: a provider ships a routine update, a subtle behavior shift propagates through every agent built on that model, and the loss begins.
| Stack component | What it does | Actuarial function it maps to |
|---|---|---|
| Incident data collection | Pooled incident databases across public and private policyholder data, standardized format | Loss data infrastructure / triangle inputs |
| Accumulation risk research & cat modeling | Models systemic failure from concentrated model providers and multi-agent interaction | Capital modeling / PML and correlation assumptions |
| Standard setting | Prescriptive, auditable insurability minimums, an Underwriters Laboratories precedent | Underwriting eligibility criteria |
| Contract design | Moves silent coverage toward affirmative definitions, exclusions, aggregation clauses | Policy wording / attachment definition |
| Risk selection & evaluation | Red-teaming and recurring technical assessment beyond annual questionnaires | Risk classification |
| Pricing | System-specific, forward-looking rate formulas with accumulation loading | Rate indication / correlation loading |
| Ongoing monitoring & loss control | Continuous risk guidance tracking rapid model evolution | Portfolio surveillance |
| Incident response & claims | AI-literate claims handling feeding forensic findings back to underwriting | Claims-to-pricing feedback loop |
The component ordering is the argument. The report treats accumulation research and catastrophe modeling as a prerequisite for pricing rather than an adjunct to it, and a workable rate structure follows from that: a base rate reflecting the insured's own agent use case, evaluation results and usage telemetry, multiplied by a provider-concentration factor scaling with how much of that insured's stack runs on the same handful of models as the rest of the portfolio.
The difference the multiplier captures is invisible per policy. A book where every insured's claims, procurement and service agents run on the same one of three providers carries materially more correlated tail risk than an identically sized book spread across five or six, even when each policy's expected loss looks the same in isolation. Per-risk pricing built without a cross-portfolio accumulation model solves the easier problem and leaves the solvency-determining one open. The governance gap sets how far an event travels once started: nearly 50% of Lloyd's underwriters assume adequate policyholder controls against 1 in 5 businesses reporting mature agent governance.
The Exposure Is Already Written, and the Scanners Do Not Transfer
None of this is prospective. The accumulation sits inside general liability, D&O, technology errors and omissions, and cyber books written before agents could act on their own, the dynamic covered in this site's silent-exposure analysis of the same report. Provider concentration sharpens that finding rather than repeating it: silent exposure explains why a loss can occur inside a policy never priced for it, while concentration explains why that loss is unusually likely to occur across many policies simultaneously. A reserving actuary treating each silently-exposed line as an independent IBNR problem misses the correlation running across all four at once.
Diversification does not fix it. Even a broad book of standalone AI policies is not diversified the way a casualty book is, because the peril generator is the same handful of models however many insureds sit on the schedule, the complication set out in this site's work on pricing AI liability with no loss triangle.
The closest existing tool was built for a different target. The aggregate-scanning discipline cyber reinsurers developed to find silent cyber wording buried in conventional P&C policies, covered in this site's reporting on AI wording scanners and cat model certification, searches for cyber-specific language. It does not trace a shared foundation-model dependency across GL, D&O, tech E&O and cyber cessions at the same time.
Calibration is thinner still. A European Actuarial Journal paper on cyber accumulation already identifies dependence-structure calibration as the weakest link in cyber cat modeling, because the loss data needed to fit a correlation copula barely exists. Foundation-model accumulation starts further back, with no full-severity systemic model-failure event to calibrate against at all. The regulatory scaffolding does not close that gap: the NAIC's AI model bulletin has been adopted in more than 20 jurisdictions and its AI Systems Evaluation Tool is in a twelve-state pilot through September 2026, but both govern how insurers use AI internally, not how they model accumulation in the systems their policyholders deploy.
Further Reading
- Silent AI Exposure: 90% of Insurer Risk Sits Unpriced – The AIUC report's finding on how agentic AI risk sits unpriced inside GL, D&O, tech E&O, and cyber policies.
- How Actuaries Price AI Liability Coverage When the Loss Triangle Has No Rows – The credibility and analogical-transfer methods carriers use where AI loss history barely exists.
- Silent Cyber PML: How AI Wording Scanners Are Changing Actuarial Cat Model Certification – The aggregate-scanning discipline the cross-line AI accumulation problem still needs.
- NAIC Flags Agentic AI as Insurance's Next Governance Gap – The regulatory side of the governance-maturity gap this report quantifies from the underwriting side.
Sources
- Artificial Intelligence Underwriting Company, "Underwriting the Agent Economy: The Blueprint," July 2026
- Trout et al., "Underwriting the Agent Economy: The Blueprint for an AI Insurance Stack," arXiv, July 2026
- Lloyd's Market Association, "AI Adoption More Than Doubles Across the Lloyd's Market in 12 Months," April 2026
- NAIC, "Insurance Topics: Artificial Intelligence," 2026
- European Actuarial Journal, "Is Accumulation Risk in Cyber Methodically Underestimated?" 2024