Skip to content
The Proof-of-Control Insurance Working Group

Insurance has written the rules for new technology before.

The industry that wrote the rules for fire, electricity and the automobile is the one now being asked to write them for AI.

Insurers built the fire brigades that protected nineteenth-century cities. They funded Underwriters Laboratories to make electrical wiring safe enough to put in a home. They pushed seatbelts and sprinkler systems into building codes decades before regulators caught up. In each case, the industry did not wait for someone else to define the rules. It defined them, because it was the party left holding the loss if it did not.


The turn

4,078

generative-AI exclusions filed against commercial liability policies across 49 states and DC.

TWELVE MONTHS EARLIER: 0

SourceTrades Coverage, from a search of all 106,812 commercial filings in 50 states and DC, July 2025 to 31 July 2026.

02 / 12

The market is deciding what it will not cover before it has decided what it can price.

  1. Verisk files generative-AI exclusion forms with state regulators

  2. CG 40 47, CG 40 48 and CG 35 08 take effect on renewals

  3. 60+ P&C groups have filed. 2,369 exclusions already in force

  4. Verisk weighs exclusions for agentic AI

Macgregor & Gale, The Insurer, 23 July 2026 · Mia Macgregor, “Verisk Weighs New Exclusions for Agentic AI Risks,” The Insurer, 10 July 2026 · “AI Exclusions in Insurance Policies,” Policyholder Pulse, 13 April 2026.

A filing is not an endorsement on your policy. Carriers choose whether to attach these, and a buyer cannot tell which apply without reading their own endorsement schedule.


Why the existing frameworks do not close it

The market cannot price the risk because no standardized, openly verifiable evidence exists of what an agent did at runtime. SOC 2, the NIST AI RMF and ISO 42001 all evaluate management systems rather than execution. This is the Verifiability Gap: the widening distance between what AI agents do and anyone’s ability to openly verify that they stayed within the controls they were given.

AIUC-1 is the most insurance-relevant standard to date and the one this group studies most closely. What it was not built to carry is the claims-evidence vocabulary, control taxonomies by insurance function, and an insurability classification an actuary can price against.


Proof-of-Control is the property that closes that gap

Tamper-evident evidence, openly verifiable by anyone, that an AI system stayed within the controls it was given.

The detail worth an actuary’s attention is trust-assumption disclosure: every conformant implementation must disclose, in a standardized format, what must still be trusted for its evidence to be reliable. Two deployments can sit at the same conformance stage and carry materially different risk once you read what each of them still trusts, and that difference is a rating factor.

The Proof-of-Control Standard, open for public comment →

What Proof-of-Control does not settle

It shows what an agent did. It does not settle who testifies to that record under oath. That question is open, named as unresolved, and on this working group’s agenda.


What changes for insurers

Carriers pricing AI risk today are flying blind on questionnaires, vendor self-claims, and static security reviews, none of which produce evidence an outside underwriter can actually verify. Proof-of-Control replaces self-claims with tamper-evident evidence generated at the moment of execution.

Carriers cannot underwrite what they cannot audit. Adjusters can be deposed, underwriters can testify, and actuaries can defend reserves in court. An AI agent can do none of these, and “the model did it” is not a defense any regulator or court accepts. Proof-of-Control supplies the record.

Today With Proof-of-Control
Self-reported questionnairesEvidence produced at execution
Vendor compliance claimsOpenly verifiable, no party to trust
Logs that can be fabricatedTamper-evident by design
No standardized taxonomyStandardized shared taxonomy
No post-deployment evidenceMachine-verifiable at scale

What the group builds

With that evidence the exposure becomes assessable, and pricing it needs three things nobody has built. The group ships them in 90-day cycles.

A claims-evidence framework

Maps runtime evidence to covered loss events: the vocabulary that lets an adjuster, not just an engineer, reconstruct what an agent did and why.

Contextual control standards

Organized by insurance function, defining adequate versus inadequate agent control for underwriting, claims, fraud detection and payment execution specifically, not generic AI security.

An insurability classification

What is insurable at standard terms, what is insurable only with specific controls, and what must be excluded or retained, the way cyber insurance only became a real market once the industry agreed on exclusions.


Who is in the room

Founding carriers

Underwriting expertise, and a first-mover window before the group’s outputs become open standards.

Reinsurers

Who would rather help draw the insurability boundary than inherit it.

Insurtech & platform providers

They build the systems assessed against the control taxonomies, closing the loop between specification and production.

Underwriters & actuaries

As co-authors: no output of this group is operationally useful until an actuary confirms it can support a loss distribution.

Regulatory observers

Attending non-voting from the first meeting.


Separation of powers

Where one entity authors the standard, conducts the testing, issues the certificate and sells the insurance that certificate enables, the arrangement will not survive scrutiny from a sophisticated buyer, a regulator or a plaintiff’s expert witness. The standard-setter, the assessor and the capacity provider stay separate parties, and that separation belongs in the charter rather than in a later revision.


The window

Commissioners are drafting AI use guidance now, the NAIC model governance bulletin is being interpreted in real time, and adverse action requirements for AI-assisted decisions are already in litigation. The period in which practitioners still shape these rules rather than react to them is generally estimated at 18 to 24 months.

18–24

months

in which practitioners still shape these rules rather than react to them.


The ask

The Proof-of-Control Insurance Working Group, convened by Vidur Nayyar, brings carriers, reinsurers, and underwriters together to convert runtime verification into priceable risk models, claims-evidence frameworks, and a clear insurability classification.

Claims and first notice of loss is the recommended first 90-day cycle, and every use-case group carries a named chair, a defined deliverable and a sunset date.

Join the working group →

Vidur Nayyar

“Uninsurable is a verdict. Unstructured is a workstream.”

Vidur NayyarCo-chair, Insurance Working Group
Senior Advisor, AAI Society