Free Agenarys resources

AI Insurance Readiness Remedy Library

Free public remedies for documenting AI controls that insurance underwriters may ask about.

Each remedy explains what failed, why it matters, how to fix it, and what evidence to keep. The supplied source contains 37 remedies across 12 modules.

Module 1

AI Discovery & Inventory

what AI does this business run, and who is responsible for it?

R1.1

No AI inventory exists

the first question on every AI-aware application is what AI the business uses. "We're not sure" is the answer underwriters trust least.

Open remedy
R1.2

No one owns the AI

tools without an owner drift — settings change, nobody reviews output, and nobody can answer the insurer's questions.

Open remedy
R1.3

Staff use personal AI accounts for work ("shadow AI")

business data flowing through personal accounts is invisible to you and to your insurer — and it's how customer data leaks without anyone noticing.

Open remedy
Module 2

Agent Authority & Permissions

what can your AI do on its own — and what stops it?

R2.1

No written limits on what an agent may do

AI insurers specifically cover "unauthorized agent actions" — wrong refunds, wrong purchases, wrong commitments. An agent with undocumented authority is the exact risk they price for.

Open remedy
R2.2

The agent can move money without a human

incorrect refunds and purchases are named examples in AI insurance coverage. A dollar threshold with human approval is the control underwriters look for.

Open remedy
R2.3

The agent runs on an account with broad access

an agent connected through an admin login can do everything that login can — and so can anyone who hijacks the agent.

Open remedy
Module 3

Human Oversight

does AI act alone, or does a person approve what matters?

R3.1

AI sends binding answers with no review

"AI drafts, human approves, AI sends" and "AI sends alone" are different risk classes. Quotes, prices, and health or legal statements sent unreviewed are the expensive kind.

Open remedy
R3.2

No escalation path to a human

the worst AI incidents happen when the bot keeps talking past a situation that needed a person — a legal threat, a medical symptom, a furious customer.

Open remedy
R3.3

Nobody reads what the AI actually said

unreviewed agents drift for months before anyone notices. A short, regular sample review is the cheapest control in this library.

Open remedy
Module 4

Reliability & Hallucination Controls

what stops your AI from inventing prices, policies, and promises?

R4.1

The AI answers from imagination, not your facts

hallucinated prices, hours, and policies are the most-cited AI risk in the new insurance products — because they turn into refunds, disputes, and claims.

Open remedy
R4.2

Accuracy has never been tested

"we test it monthly and it scored 19/20" is an underwriter-readable sentence. "It seems fine" is not.

Open remedy
R4.3

The AI makes promises you never authorized

an agent that says "guaranteed," "we'll cover it," or "always free" is writing commitments your business must honor — or litigate.

Open remedy
Module 5

Data & Privacy

what sensitive data reaches your AI tools, and under what settings?

R5.1

Sensitive data goes into AI tools

cyber insurers explicitly flag employees pasting sensitive data into public AI tools as a privacy exposure they now underwrite.

Open remedy
R5.2

Customers don't know they're talking to AI

undisclosed AI is a growing source of complaints and, in several states, a legal requirement issue. Disclosure is free and removes an entire category of dispute.

Open remedy
R5.3

You don't know what your AI vendors do with your data

the insurer's question is "where does customer data go?" — and the honest answer runs through your vendors' settings, not your intentions.

Open remedy
Module 6

AI Cybersecurity

can someone hijack your AI — its accounts, its keys, or its instructions?

R6.1

AI tools without MFA or with shared logins

multi-factor authentication is the single control cyber insurers ask about most. An AI tool connected to your calendar, phone, and payments is worth protecting like a bank login.

Open remedy
R6.2

API keys in email, documents, or never rotated

an exposed API key is your AI agent, in an attacker's hands, at your expense.

Open remedy
R6.3

The agent obeys instructions hidden in outside content

prompt injection — malicious instructions buried in an email or webpage your AI reads — is now named in cyber policies. The control is simple: outside content can inform your agent, never command it.

Open remedy
R6.4

Unknown third-party connections

every integration (automation platforms, plug-ins, connected apps) is a door. Doors nobody remembers are the ones left unlocked.

Open remedy
Module 7

Content & IP

can your AI-made marketing get you sued?

R7.1

AI content publishes without human review

AI-generated marketing that infringes copyright is a named scenario in the new SMB AI liability products — the insurer's example is literally a small business's AI-made ad.

Open remedy
R7.2

AI images imitate brands, people, or artists

"in the style of [famous artist]," celebrity likenesses, and borrowed logos are the shortest path from a Facebook ad to a demand letter.

Open remedy
R7.3

AI writes claims nobody verified

"#1 in the county," "guaranteed results," invented review counts — AI writes confident claims, and unsubstantiated claims are advertising-injury and consumer-protection exposure.

Open remedy
Module 8

Deepfake & Fraud Controls

can a convincing fake voice or email move your money?

R8.1

Payment instructions accepted from a single channel

AI-enabled funds-transfer fraud — a cloned voice or perfect fake email authorizing a payment — is now covered (and asked about) by cyber insurers. The control they look for is out-of-band verification.

Open remedy
R8.2

No internal code word for urgent requests

a cloned voice can sound exactly like the owner. It can't know a secret you never wrote down.

Open remedy
R8.3

Refunds and account changes on an unverified say-so

fraudsters increasingly target the refund path — often through the AI agent — because it's the least-guarded way money leaves.

Open remedy
Module 9

Physical & Operational Risk

can your AI's output cause injury or property damage?

R9.1

AI-generated technical instructions go unchecked into physical work

the SMB AI liability products literally cite an employee following AI-generated installation instructions and causing water damage. For trades, this is the module that matters most.

Open remedy
R9.2

AI controls physical equipment without limits

an AI adjusting thermostats, schedules, locks, or machinery can create physical consequences at machine speed.

Open remedy
R9.3

No fast way to shut an automation off

in every automation incident, the first minutes are about one question: how do we stop it? A written kill-switch list turns panic into procedure.

Open remedy
Module 10

Governance & Accountability

is there a written policy, and does anyone follow it?

R10.1

No written AI policy

the one-page policy is the document that ties every other remedy together — and "do you have a written AI policy?" is now a standard application question.

Open remedy
R10.2

Staff never trained on the rules

a policy nobody was taught is, to an underwriter, a policy that doesn't exist.

Open remedy
R10.3

No record of which vendors you depend on

when your AI fails, the cause is often a vendor's change. Underwriters ask what you depend on; the inventory should answer in one look.

Open remedy
Module 11

Incident Response & Logging

when the AI gets it wrong, will you know — and can you prove what happened?

R11.1

No logs of what the AI did

without records, an AI dispute becomes your word against the customer's. Logs are the difference between an incident and a claim.

Open remedy
R11.2

No plan for an AI incident

the response in the first hour decides whether an AI error becomes a story, a refund, or a lawsuit.

Open remedy
R11.3

AI mistakes happen and vanish

an incident log — even a short one — shows an underwriter a business that notices and corrects. No log reads as "no idea."

Open remedy
Module 12

Insurance Documentation

what coverage exists today, and does your AI use match what you told your carrier?

R12.1

No inventory of current coverage

you can't find a gap in coverage you haven't listed. This is the map the rest of the conversation stands on.

Open remedy
R12.2

Your carrier doesn't know how you use AI

applications and renewals increasingly ask about AI use, and answers that don't match reality can matter later. Accuracy protects you; your AI inventory makes accuracy easy.

Open remedy
R12.3

Nothing to hand an underwriter

every remedy above produces a document. Together they are the evidence package — the thing that turns "we use AI carefully" into something an underwriter can actually read.

Open remedy