No AI inventory exists
the first question on every AI-aware application is what AI the business uses. "We're not sure" is the answer underwriters trust least.
Open remedyFree Agenarys resources
Free public remedies for documenting AI controls that insurance underwriters may ask about.
Each remedy explains what failed, why it matters, how to fix it, and what evidence to keep. The supplied source contains 37 remedies across 12 modules.
what AI does this business run, and who is responsible for it?
the first question on every AI-aware application is what AI the business uses. "We're not sure" is the answer underwriters trust least.
Open remedytools without an owner drift — settings change, nobody reviews output, and nobody can answer the insurer's questions.
Open remedybusiness data flowing through personal accounts is invisible to you and to your insurer — and it's how customer data leaks without anyone noticing.
Open remedywhat can your AI do on its own — and what stops it?
AI insurers specifically cover "unauthorized agent actions" — wrong refunds, wrong purchases, wrong commitments. An agent with undocumented authority is the exact risk they price for.
Open remedyincorrect refunds and purchases are named examples in AI insurance coverage. A dollar threshold with human approval is the control underwriters look for.
Open remedyan agent connected through an admin login can do everything that login can — and so can anyone who hijacks the agent.
Open remedydoes AI act alone, or does a person approve what matters?
"AI drafts, human approves, AI sends" and "AI sends alone" are different risk classes. Quotes, prices, and health or legal statements sent unreviewed are the expensive kind.
Open remedythe worst AI incidents happen when the bot keeps talking past a situation that needed a person — a legal threat, a medical symptom, a furious customer.
Open remedyunreviewed agents drift for months before anyone notices. A short, regular sample review is the cheapest control in this library.
Open remedywhat stops your AI from inventing prices, policies, and promises?
hallucinated prices, hours, and policies are the most-cited AI risk in the new insurance products — because they turn into refunds, disputes, and claims.
Open remedy"we test it monthly and it scored 19/20" is an underwriter-readable sentence. "It seems fine" is not.
Open remedyan agent that says "guaranteed," "we'll cover it," or "always free" is writing commitments your business must honor — or litigate.
Open remedywhat sensitive data reaches your AI tools, and under what settings?
cyber insurers explicitly flag employees pasting sensitive data into public AI tools as a privacy exposure they now underwrite.
Open remedyundisclosed AI is a growing source of complaints and, in several states, a legal requirement issue. Disclosure is free and removes an entire category of dispute.
Open remedythe insurer's question is "where does customer data go?" — and the honest answer runs through your vendors' settings, not your intentions.
Open remedycan someone hijack your AI — its accounts, its keys, or its instructions?
multi-factor authentication is the single control cyber insurers ask about most. An AI tool connected to your calendar, phone, and payments is worth protecting like a bank login.
Open remedyan exposed API key is your AI agent, in an attacker's hands, at your expense.
Open remedyprompt injection — malicious instructions buried in an email or webpage your AI reads — is now named in cyber policies. The control is simple: outside content can inform your agent, never command it.
Open remedyevery integration (automation platforms, plug-ins, connected apps) is a door. Doors nobody remembers are the ones left unlocked.
Open remedycan your AI-made marketing get you sued?
AI-generated marketing that infringes copyright is a named scenario in the new SMB AI liability products — the insurer's example is literally a small business's AI-made ad.
Open remedy"in the style of [famous artist]," celebrity likenesses, and borrowed logos are the shortest path from a Facebook ad to a demand letter.
Open remedy"#1 in the county," "guaranteed results," invented review counts — AI writes confident claims, and unsubstantiated claims are advertising-injury and consumer-protection exposure.
Open remedycan a convincing fake voice or email move your money?
AI-enabled funds-transfer fraud — a cloned voice or perfect fake email authorizing a payment — is now covered (and asked about) by cyber insurers. The control they look for is out-of-band verification.
Open remedya cloned voice can sound exactly like the owner. It can't know a secret you never wrote down.
Open remedyfraudsters increasingly target the refund path — often through the AI agent — because it's the least-guarded way money leaves.
Open remedycan your AI's output cause injury or property damage?
the SMB AI liability products literally cite an employee following AI-generated installation instructions and causing water damage. For trades, this is the module that matters most.
Open remedyan AI adjusting thermostats, schedules, locks, or machinery can create physical consequences at machine speed.
Open remedyin every automation incident, the first minutes are about one question: how do we stop it? A written kill-switch list turns panic into procedure.
Open remedyis there a written policy, and does anyone follow it?
the one-page policy is the document that ties every other remedy together — and "do you have a written AI policy?" is now a standard application question.
Open remedya policy nobody was taught is, to an underwriter, a policy that doesn't exist.
Open remedywhen your AI fails, the cause is often a vendor's change. Underwriters ask what you depend on; the inventory should answer in one look.
Open remedywhen the AI gets it wrong, will you know — and can you prove what happened?
without records, an AI dispute becomes your word against the customer's. Logs are the difference between an incident and a claim.
Open remedythe response in the first hour decides whether an AI error becomes a story, a refund, or a lawsuit.
Open remedyan incident log — even a short one — shows an underwriter a business that notices and corrects. No log reads as "no idea."
Open remedywhat coverage exists today, and does your AI use match what you told your carrier?
you can't find a gap in coverage you haven't listed. This is the map the rest of the conversation stands on.
Open remedyapplications and renewals increasingly ask about AI use, and answers that don't match reality can matter later. Accuracy protects you; your AI inventory makes accuracy easy.
Open remedyevery remedy above produces a document. Together they are the evidence package — the thing that turns "we use AI carefully" into something an underwriter can actually read.
Open remedy