The gap the survey put a number on
A Forrester Consulting survey commissioned by Boomi, reported by Express Computer on 20 July 2026, asked 409 director-and-above IT and technology decision-makers across North America, Europe and APAC how far their AI agents had gone into production. 86% of organisations have moved beyond the AI agent pilot stage. Only 34% say they trust the actions their AI agents are taking.
That spread is the interesting part. It is not a survey about whether agents work. It is a survey about whether the people who deployed them can vouch for what they do. A 52-point distance between deployment and trust means a majority of these organisations are running software with real authority that their own technology leadership will not stand behind.
An underwriter reads that finding differently from a CIO. For the CIO it is a maturity curve to be climbed. For the underwriter pricing a cyber, technology errors and omissions or D&O renewal, it is a base rate: if most insureds who have deployed agents cannot attest to their behaviour, then attestation stops being a nice-to-have on the proposal form and becomes a rating factor. The insurer's problem is that the 34% and the 66% look identical in a submission that does not ask.
Indian corporates are inside this population, not adjacent to it. KPMG's July 2026 paper The agentic AI imperative: Why Indian enterprises need a new deployment playbook frames the same problem for the domestic market: deployment velocity has outrun the operating discipline that is supposed to accompany it. The insurance consequence lands at the next renewal, and the questions have already started to change shape.
Agentic chaos, agentic control, and the $2.1 million figure
Forrester sorted respondents by operational readiness across three dimensions: governance, integration, and API and MCP management. The bottom quartile it labelled agentic chaos. The finding that matters for insurance is that being in that quartile did not slow anyone down. 77% of organisations in agentic chaos are moving into production anyway, and they expose themselves to an average of $2.1 million in added costs from four sources: compliance fines, lost customers, operational downtime and rework.
At the other end, organisations with agentic control report high confidence in their agents' actions and decisions at 55%, against 22% of those in agentic chaos. Decision-makers with agentic control were three times as likely to say that reliable, well-managed APIs determine readiness.
Two things follow for a risk manager preparing a submission.
First, the readiness variable that separates the groups is not model quality. It is governance, integration and API management, which are exactly the things an insurer can ask about, evidence and verify. There is no need for an underwriter to form a view on a foundation model. There is a need to form a view on whether the insured knows which systems its agents can reach and what they are permitted to do there.
Second, the $2.1 million is an average of four different loss types with four different insurance answers. Treating it as a single number is what produces a bad submission and a worse claim. It has to be taken apart.
Sorting the four cost buckets into the tower
The four categories Forrester names map onto Indian corporate programmes unevenly. Some sit inside cover that most large insureds already buy. Some sit outside it, and the insured usually finds out at notification.
- Compliance fines. Regulatory penalties are the hardest of the four to insure. Indian policy wordings routinely exclude fines and penalties where they are uninsurable at law, and where a carve-back exists it is usually narrow, sub-limited, and attached to a specific regime rather than offered at large. Under the Digital Personal Data Protection Act, 2023, an agent that exceeds its permitted purpose while processing personal data creates a penalty exposure that a cyber policy will typically respond to only on the investigation and defence costs side, not the penalty itself.
- Lost customers. Attrition following an agent failure is pure economic loss with no third-party claimant and no physical damage trigger. Nothing in a standard cyber, technology E&O or D&O wording pays for it. Business interruption cover under a cyber policy responds to loss of income during a period of interruption caused by a covered event, which is a narrower thing than customers leaving three months later because the agent mishandled them.
- Operational downtime. This is the bucket most likely to be insured, and the one most likely to be lost on definitions. Cyber business interruption is generally triggered by a security failure or a system failure, and the definition of system failure is where agentic incidents live or die. An agent that behaves exactly as coded and takes the wrong action has suffered neither a breach nor, on many wordings, an unintentional outage.
- Rework. Cost of correcting the agent's own output is first-party remediation. Technology E&O may reach it when the defective work was delivered to a client under contract. It rarely reaches internal rework, and mitigation-cost extensions usually require the insurer's prior written consent before the spend.
The gap map across cyber, PI, D&O, CGL and property sets out how a single AI incident splits across policies. The point here is narrower: the loss categories in this survey are already sorted by which of them an insurer will pay for, and the sorting was done in the policy wording, not in the incident.
What the proposal form is starting to ask
Cyber and technology E&O proposal forms in the Indian market have carried an AI question for a few renewal cycles now, mostly at the level of "do you use artificial intelligence in your operations". That question is now close to useless, since almost every answer is yes. The questions replacing it track the Forrester readiness dimensions closely, because those are the dimensions that separate a 22% confidence population from a 55% one.
Expect some version of the following at your next renewal:
- An inventory question. How many autonomous agents are in production, in which functions, and who owns each one.
- An authority question. What actions can an agent take without a human approving them, and what is the financial ceiling on those actions.
- An integration question. Which internal systems and third-party APIs can each agent reach, and how is that access scoped and rotated.
- A logging question. Is every tool invocation recorded, with inputs and outputs, in a store the insured cannot silently edit.
- A kill-switch question. Who can stop an agent mid-task, how fast, and when was that last tested.
- A third-party question. Which agents were built by vendors, and what do those contracts say about liability and indemnity.
D&O submissions are moving in parallel but from a different angle. The board question is not what the agents do, it is what the board knew. If agentic deployment is on the risk register with a named owner and reports to a committee, a subsequent shareholder or regulatory allegation about inadequate oversight meets a documented answer. If it is not, the allegation meets silence.
What counts as evidence, and what does not
Underwriters have learned to discount narrative answers on AI questions, for the same reason they discount narrative answers on patch management. A submission that says the company has a governance framework buys almost nothing. A submission that attaches artefacts buys rate.
The artefacts that carry weight are ordinary and mostly already exist somewhere in the business:
- An agent register. One row per production agent: function, owner, systems it can reach, actions it can take unattended, monetary limit, date of last review. This is the single highest-value document in an agentic submission because it converts an unbounded question into a bounded one.
- Access scoping documentation. API credentials and permission scopes per agent, showing that the agent's reach was designed rather than inherited from a service account with broad rights.
- Immutable action logs. Evidence that tool calls are recorded in a tamper-evident store. This does double duty: it supports the underwriting answer and it is what makes a claim provable later.
- Human-in-the-loop thresholds. A written rule for which actions require approval, with the threshold values, and evidence the rule is enforced in code rather than in policy documents.
- Incident history. Agent-caused errors in the past 12 months, what they cost, and what changed afterwards. Disclosing a handled incident reads better than an implausibly clean record.
The governance side of this, and how agentic risk gets onto the register in the first place, is covered in the risk-register treatment of agentic AI.
What a weak answer costs, in rate and in wording
A poor agentic disclosure rarely produces a decline. It produces a worse contract, which is harder to notice and more expensive later.
The three levers an underwriter reaches for, in order:
- Sub-limits. AI-related loss capped well below the policy limit, often on the business interruption and remediation heads where agentic incidents concentrate. A cyber tower with a headline limit that carries a small AI sub-limit is, for this exposure, a small policy.
- Exclusions and conditions. An AI or autonomous systems exclusion, or a condition precedent requiring human review of specified action classes. A condition precedent is the sharper instrument: breach it once and the claim fails regardless of causation.
- Rate and retention. Higher pricing and a larger self-insured retention on the affected heads.
Retention economics compound the problem. If the average added cost sits near the $2.1 million Forrester found, and the AI sub-limit and retention together cover only a fraction of it, the insured is carrying most of a foreseeable loss on its own balance sheet while paying for a policy it believed responded.
There is also a disclosure dimension. Indian insurance contracts run on utmost good faith, and material facts include the extent of autonomous authority granted to software. Answering an agent-inventory question incompletely because the inventory does not exist is a poor position to be in when the insurer investigates a claim and reconstructs what was actually running at inception.
Moving from chaos to control before the renewal
The gap between the two Forrester groups is operational, which means it is closable inside one renewal cycle for most Indian corporates. A workable sequence:
- Inventory first. Find every agent in production, including the ones inside SaaS products that were switched on by a feature release rather than a procurement decision. Expect the list to be longer than IT believes.
- Scope authority. For each agent, write down the unattended actions and set a monetary or volume ceiling. Anything above the ceiling routes to a human. Enforce it in the integration layer.
- Fix logging. Every tool invocation, inputs and outputs, in a store with restricted write access. Without this there is no underwriting evidence and no claim evidence.
- Assign ownership. A named business owner per agent, not a shared engineering queue. Underwriters ask who owns it, and "the platform team" is not an answer that survives follow-up.
- Rehearse the failure. Run one tabletop on an agent taking a wrong high-value action: who notices, how fast it stops, who calls the insurer, what the notification says.
- Take it to market early. Present the register and the logs at the pre-renewal meeting rather than in the proposal form, so the underwriter forms a view on evidence before pricing rather than after.
The commercial argument for doing this is not abstract. Agentic readiness has become a rating variable, and it is one of the few where the insured controls the inputs completely. Cyber insurance placements in the Indian market already reward demonstrable controls on identity and backup. Agent governance is heading into the same category, and the organisations that document it first will buy the same cover on better terms than the ones that answer the question honestly and vaguely at the same time next year.