The AI Startup Insurance Checklist: What Changes at Every Milestone

A startup does not need every policy on its first day. It does need to notice when a new lease, employee, customer, agent authority, contract, investor, or physical deployment changes the questions an insurance program must answer.

GuideStartup insuranceAI readiness

Short answer

Use milestones as prompts for review, not as a universal shopping list. A lease may trigger general liability; employees may trigger workers’ compensation; a customer contract can make Tech E&O and cyber urgent; a priced financing round can make D&O a closing condition; and a production agent or physical deployment adds an authority and evidence review that generic startup checklists miss.

Evidence frame

Established
A lease, employee, customer contract, production deployment, financing event, or physical operation can change the company’s people, property, services, obligations, or loss paths.
Clara inference
Milestones are better treated as review triggers than as a fixed shopping list because the same milestone creates different exposure for different AI companies.
Hypothesis
A company-owned readiness record that refreshes at each milestone will prevent important authority and contract changes from disappearing into annual renewal paperwork.
Unknown
The required lines, limits, deductibles, endorsements, and carrier appetite depend on the startup’s operation, jurisdiction, customers, contracts, and actual policy market.

Milestones create questions, not automatic answers

MilestoneWhat to reviewEvidence to gather
Office, lab, or leaseGeneral liability, property, landlord wording, and premises obligations.Lease, certificate requirements, locations, equipment, and visitors.
First employee or field technicianWorkers’ compensation, employment practices, safety, and supervision.Jurisdictions, payroll, roles, field work, training, and incident process.
First customer or production dataTech E&O, cyber, privacy, service promises, and vendor obligations.Customer contract, data flows, service description, controls, and limits requested.
Production agentAuthority, permissions, human approvals, monitoring, rollback, and policy wording.Agent inventory, tool map, change history, incidents, and near misses.
Priced financing or new boardD&O requirements, disclosures, governance, and investor diligence.Term sheet, board role, risk disclosures, claims history, and governance record.
Physical or customer-site deploymentGL, product, inland marine, workers’ compensation, auto/aviation, and umbrella.Operating envelope, site rules, maintenance, supervision, and equipment values.

The order is deliberately practical. A pre-revenue company may have little immediate exposure, while a company with one enterprise contract can have urgent obligations even before revenue is large. The SBA’s general guidance is a useful baseline; AI deployment adds the need to document what the product actually does.

The production-agent milestone is different

Shipping an AI feature is not the same as giving an agent authority to act. The review should ask whether the system can access data, call tools, create or modify records, communicate externally, move money, change code, or delegate. It should also ask what happens when the model, prompt, tool, credential, approval threshold, or customer changes.

  • Who sponsors the agent and who is accountable for its operation?
  • What can it do in declared, enforced, and observed practice?
  • Which actions require approval, dual control, or escalation?
  • Can the company reconstruct an action and reverse it?
  • What customer, vendor, model-provider, and insurance obligations attach to the deployment?

A checklist that only asks whether the company “uses AI” misses the material change. Authority is the event that should trigger a deeper review.

Enterprise readiness is an evidence problem

Enterprise procurement may ask for certificates, limits, additional insured status, cyber controls, audit rights, indemnity, or specific technology and privacy commitments. Those requests can arrive before the company understands whether its current policies match the promise in the contract.

Prepare a reusable packet: company and entity facts, operations, agent inventory, authority map, data and dependency map, controls and tests, incidents and near misses, current policy facts, renewal dates, and open questions. RISK.md is Clara’s public proposal for keeping that context company-owned, evidence-linked, and reusable without standardizing each market’s judgment.

What not to do

  • Do not buy by acronym alone. A line name does not tell you how an AI claim will be treated.
  • Do not wait for the signature. Contract limits and endorsements can take time, especially when the work is unusual.
  • Do not describe the system as a static feature. A new permission or tool can materially change the exposure.
  • Do not treat a certificate as proof of every promise.A certificate summarizes coverage; it is not the policy and does not rewrite exclusions or contract allocation.

The useful habit is a milestone review that records what changed, what the company knows, what it cannot yet establish, and which professional should make the next decision.

A checklist is the beginning of the record

Clara is interested in the information that survives the checklist: how a company’s authority changes, what evidence a reviewer can rely on, which controls are actually enforced, and whether the market makes a different decision when those facts are legible.

The tail-risk note argues that the distance between annual snapshots may be the first gap. The manifesto places that gap inside the broader practice → research → insure loop. The checklist is useful only if it leaves behind a better memory of the business.

Common questions

Do pre-revenue AI startups need insurance?

Some do and some do not. A lease, employee, pilot, investor, customer contract, regulated activity, or significant equipment can create an immediate requirement; a company without those triggers may have little reason to buy a full program on day one.

When should an AI startup buy Tech E&O?

The first customer contract or production service is a natural review point because the company’s technology begins creating a customer-facing financial obligation. The actual need depends on the product, contract, revenue, and policy wording.

When should an AI startup buy cyber insurance?

Review cyber when the company stores, processes, or accesses customer data, operates systems that could be compromised, or has contractual and regulatory response obligations. Cyber and E&O can overlap, so their wording should be read together.

Does launching an AI agent require a new policy?

Not automatically. It does require a review of authority, covered services, controls, exclusions, contracts, and material change. A new policy, endorsement, evidence refresh, or no change may be appropriate depending on the facts.

What should an AI startup put in its insurance checklist?

Track company facts, contracts, required limits, policy lines, exclusions, agents and authority, data and dependencies, controls, incidents, evidence freshness, renewal dates, and unknowns.