Short answer
Do not assume that a new AI capability is automatically covered or automatically excluded. Compare the changed operation with the policy’s covered services, definitions, exclusions, conditions, contract obligations, and application representations. Use material authority changes as review triggers and preserve the evidence needed to explain what changed, when, and why it matters.
Evidence frame
- Established
- Policy applications, definitions, exclusions, conditions, and endorsements describe an operation at particular terms, dates, and assumptions; they do not automatically update when a system changes.
- Clara inference
- New permissions, tools, credentials, customers, models, or delegation paths can be more consequential than a product-name change because they alter what the system can do.
- Hypothesis
- Continuous authority evidence may give underwriters a more useful view of changing AI operations than a once-a-year snapshot, without pretending every change requires a new policy.
- Unknown
- The exact change that triggers notice, underwriting review, exclusion, or coverage impact must be determined from the policy, application, endorsements, contracts, and carrier discussion.
Authority changes faster than product labels
An AI company can materially change its exposure without changing its homepage. It can connect an existing agent to a new database, give it a payment tool, lower an approval threshold, allow delegation, add a customer’s sensitive data, or permit production code changes.
The model may be identical. The authority is not. Clara’s language asks what the system may decide, spend, promise, publish, change, deploy, or transact because those actions connect capability to loss.
| Change | Why it may matter | Review evidence |
|---|---|---|
| New tool or credential | The agent can reach a new asset, system, customer, or account. | Permission graph, credential owner, tool scope, logs, and approval path. |
| New customer or regulated workflow | The service promise, data, jurisdiction, or consequence changes. | Contract, data map, service description, controls, and limits requested. |
| Lower human approval threshold | More actions can happen without a person seeing each decision. | Thresholds, exception handling, monitoring, rollback, and observed use. |
| Agent-to-agent delegation | One objective can propagate through systems with different controls. | Delegation chain, inherited authority, identity, and accountability. |
| New physical or financial action | The maximum plausible loss and reversibility change sharply. | Transaction limits, operating envelope, site rules, and stop controls. |
The policy is not a live copy of the system
Commercial policies generally describe an insured business, its operations, covered services, risks, and contractual context. They are not automatically a real-time inventory of every prompt, model, tool, or agent action. That does not make them obsolete; it makes the company’s change discipline important.
Some changes may be ordinary evolution inside the described business. Others can alter the covered services, application representation, contractual exposure, location, data, physical operations, or loss potential enough to require review. The line is not universal and should not be invented from a blog post.
The practical question is: what would a reasonable reviewer need to know to evaluate whether the risk remains the one described at inception?
Use authority triggers instead of calendar anxiety
Continuous underwriting does not mean asking a carrier to approve every configuration change. A better first step is to define review triggers around material authority:
- Access to money, production code, regulated decisions, or sensitive new data.
- New customers, jurisdictions, sites, physical systems, or third-party dependencies.
- Changes to approval, monitoring, shutdown, rollback, or delegation.
- Material changes to customer promises, indemnity, service levels, or limits.
- Incidents, near misses, control exceptions, or evidence that a declared boundary is not enforced.
Most configuration changes will not require a new product. They do require a record of what changed and a path to ask a professional when the change crosses a defined threshold.
The evidence loop is the bridge
Keep a dated authority record alongside policy and contract facts. For each material system, preserve its purpose, sponsor, model and tools, credentials, declared/enforced/observed authority, approvals, tests, monitoring, shutdown, rollback, incidents, and known unknowns.
NIST’s AI RMF describes risk management as continuous across the AI lifecycle. Clara’s tail-risk researchasks what that means when the insured company can change between annual snapshots. The answer may be a better evidence refresh before it is a dynamic policy.
A falsifiable Clara question
Clara is not assuming that continuous underwriting is a product the market wants. The test is narrower: do companies experience meaningful authority drift, will they maintain a reliable record, and do underwriters make different decisions when the evidence is current and comparable?
If the answer is no, the idea remains a compelling essay. If the answer is yes, the record can strengthen submissions, reviews, controls, and eventually new risk-transfer mechanisms.
Common questions
Does my insurance automatically cover a new AI capability?
There is no universal automatic answer. Compare the new capability with the policy’s covered services, operations, definitions, exclusions, conditions, application representations, contracts, and applicable law.
What is AI authority drift?
Authority drift is the widening or changing of what an AI system can do as tools, credentials, data, approval thresholds, customers, models, or delegation paths change over time.
Do I need to tell my broker about every prompt or model update?
Not necessarily. The useful trigger is material change to the business, covered services, authority, data, physical operations, contractual exposure, or loss potential—not every routine configuration edit.
What evidence helps with a mid-term review?
A dated inventory of systems and changes, authority and permission maps, controls and test results, incidents and near misses, customer and vendor contracts, and current policy facts helps a reviewer understand whether the operation changed materially.
Is continuous underwriting the same as dynamic insurance?
No. Continuous underwriting can begin as better evidence refreshes and material-change triggers under ordinary annual policies. Dynamic terms, usage-based limits, or new products would require separate evidence, market appetite, regulation, and product design.