Skip to Content

Your AI Agent Just Made a Call. No One Signed Off On It.

Somewhere in your business right now, an AI agent is probably making a decision without waiting for a human to approve it. It's reconciling an invoice, flagging a transaction, adjusting a workflow, responding to a customer. Nobody told it to do that specific thing in that specific moment. It decided, on its own, based on how it was built. 

That's the point of agentic AI. It's also the problem. A new Australian survey has put a number on something most technology leaders have quietly suspected: when one of these agents gets it wrong, most businesses cannot explain to a regulator what the agent did or why, and a meaningful share cannot say who would be held responsible for it at all. 

We've written about that governance gap before, When AI Moves from Insight to Action [5] laid out why it's now measurable, not theoretical. What we haven't covered is what happens next: the insurance market has already started repricing around it, quietly, inside policy wording most businesses haven't reread since before their AI agents went live. 

If your business runs on autonomous tools, you didn't build and don't fully audit, that's no longer just a governance question. It's already showing up in your renewal. 


The gap isn't adoption. It's explanation.

Technology leaders have not been slow to adopt agentic AI. What has not kept up is the ability to explain what these systems do once they're live, or what happens to the cover a business assumed it had. 

A report from tax and compliance technology company Avalara, published 22 July 2026, surveyed 250 CFOs and senior finance leaders across Australia including those in financial services and insurance, who had deployed, piloted, or actively evaluated AI agents in financial processes over the past year. The findings, reported by Insurance Business Australia, were stark [1]

  • Most of these organisations cannot adequately explain their agents' actions to a regulator 
  • Nearly one in five cannot identify who would be held accountable if something went wrong 
  • 75% said they lack the in-house expertise to understand how their own AI agents function 
  • Only 59% were even somewhat confident they could explain an agent's actions to an auditor or regulator 

That's not a hypothetical governance gap. It's a live one, sitting inside businesses already running these tools in production. 

Regulators reached the same conclusion, independently

Australia's prudential regulator has reached its own version of this finding. On 30 April 2026, APRA published an open letter signalling a shift in its stance on AI adoption across the financial system. Its targeted review found a widening lag between how quickly organisations were adopting emerging AI tools and how slowly they were building the risk management to match including reliance on single AI vendors without robust exit or substitution arrangements, a gap the letter tied directly to obligations under Prudential Standard CPS 230 [1]

The pattern lines up with earlier joint research from the Insurance Council of Australia and CSIRO, published August 2025, which flagged the same disconnect from the insurance side of the market and called for governance frameworks to accompany AI adoption rather than trail it [1]. Two different regulatory bodies, looking at two different parts of the system, arrived at the same structural diagnosis. 

The market is already repricing around it

This is the part most AI-governance coverage skips. Insurers move on evidence faster than most industries, and the evidence is already showing up in how cover is written [2]

  • One in five insurance professionals reported their insureds had already experienced losses linked to AI risk, per Gallagher's 2026 survey data [4] 
  • The professional liability market shifted structurally between January 2025 and January 2026, as carriers moved from silently assuming AI wasn't in scope to either explicit affirmative wording or outright exclusions, per Willis research. 
  • Some carriers, including CFC, have added affirmative AI wording to technology errors and omissions, professional liability and cyber policies. 
  • A January 2026 ISO form now lets carriers exclude bodily injury, property damage and advertising injury arising from generative AI under standard general liability policies 

None of that is a warning shot. It's underwriters responding to claims experience that's already at play which means the policy wording a business is relying on today may already read differently to how it read twelve months ago. 

Governance is lagging inside the business, not just outside it

The accountability question doesn't start with the regulator or the insurer. It starts with whether anyone inside the business actually knows what's running. Research from security awareness firm KnowBe4, reported by Security Brief Australia, found [3]

  • 64% of organisations in Australia and New Zealand use agentic AI tools that act without direct human instruction — ahead of the 58% global figure 
  • 50% said their AI use was unapproved or ungoverned 
  • 59% of employees said they source their own agentic AI tools when sanctioned options aren't available or feel too restrictive 

That's the mechanism behind the accountability gap. It isn't one rogue system. It's shadow deployment, multiplied across teams, outrunning both internal governance and the insurance program built around an earlier version of how the business used AI. 


What is the AI insurance repricing gap?

The AI insurance repricing gap is the distance between how quickly insurers are rewriting cyber, professional liability and general liability wording in response to AI-driven losses, and how slowly most businesses are checking their own policies against those changes. It sits downstream of the AI accountability gap: once an organisation can't explain how its AI agents act, it usually also can't say with confidence which policy would respond if one of those agents caused a loss. Australian survey data shows insurers already treating this as live, priced risk — well ahead of most businesses reviewing their own coverage against it. 

The Knightcorp point of view

None of this means agentic AI should be pulled back. It means the businesses moving fastest also need the clearest answer to a simple question: if an agent gets it wrong, which policy responds, and has anyone actually checked? 

At Knightcorp, we help leadership teams test how their insurance program would respond to the risks their AI agents create, while that's still a choice rather than a discovery made mid-claim. We turn assumption into evidence, and exposure into a plan. That clarity, ahead of the market, is the advantage. 

Frequently Asked Questions

  1. Is agentic AI different from a chatbot for insurance purposes? 

Yes. A chatbot responds to a prompt within a defined scope. An agent can take a sequence of actions across systems without a human approving each step, which is why insurers increasingly treat it as a distinct exposure from earlier generative AI tools. 

  1. Does cyber insurance or professional indemnity cover AI agent errors? 

It depends on the wording of your specific policy, and this is general information rather than a view on any individual policy. Many cyber and professional indemnity policies were written before autonomous, decision-making AI became operational, so some exclude algorithm-driven failures, stay silent on non-malicious AI errors, or were never designed to respond to regulator-led action tied to AI behaviour. 

  1. Why are insurers changing how they write AI-related cover? 

Because claims experience linked to AI risk is starting to show up. Insurers reprice and rewrite wording in response to evidence, and evidence of AI-related losses is now being reported by both insurers and their insureds. 

  1. Is this only a concern for regulated industries like financial services? 

No. The governance and repricing gap identified in Australian research spans organisations broadly, and any technology business running agentic tools in finance, operations or customer-facing functions carries some version of this exposure. 

  1. What's driving ungoverned AI agent use inside businesses? 

Employees adopting their own tools when sanctioned options are unavailable or too restrictive. Australian and New Zealand research puts this at well over half of employees surveyed. 

  1. Isn't the answer just to buy more insurance? 

On its own, no. A business can hold a large cyber or professional indemnity limit and still find it doesn't respond, if the wording was never built for what an autonomous agent actually does. The fix isn't more limit — it's confirming the wording matches how the agent operates, before a loss forces that conversation. 

  1. How can a business find out whether its insurance would respond to an AI agent loss? 

The reliable way is to test it against the organisation's actual AI use and actual policies rather than assume, since general statements about cover can't tell you how specific policies would respond. Knightcorp helps leadership teams work through exactly this kind of review before an incident forces it. 

References

[1] Insurance Business Australia, "Who is accountable when your AI agent gets it wrong?", accessed 28 July 2026. 

[2] Insurance Business Australia, "Insurers face hidden AI liability as agent risks multiply", accessed 28 July 2026. 

[3] Insurance Business Australia, "Australia and New Zealand AI adoption outpaces governance", accessed 28 July 2026. 

[4] Gallagher, "Not So Silent: Tackling the Complexities of AI Liability", published 7 May 2026. published 7 May 2026. 
 
[5] Knightcorp, "When AI Moves from Insight to Action", published 2 July 2026. 

Disclaimer: This article contains general information only and has been prepared without taking into account your objectives, financial situation or needs. Any third-party references or links are provided for information only. Knightcorp is not responsible for the content or accuracy of third-party material.