Scope violation
It goes beyond the job.
A support agent promises free replacements when it should only answer delivery questions. Customers place orders on that promise, then demand that your business honor it.
Your agent sends the wrong price, shares private data, or makes an unauthorized payment. Klaimee helps cover the financial loss when a covered failure happens.
Get coverageNine kinds of failure. Here is what they look like in real life.
Examples, not a promise that every loss is covered. Your agreement sets the covered failures, required evidence, limits, and exclusions.
Getting covered shouldn't mean jumping through hoops just to see a price.
Start with a ballpark, then get a quote for your agents.
annual AI revenue
Pilots, first customers, and a small number of live agent workflows.
$22,200 per year
annual AI revenue
Agents used by customers or teams, with real workflow responsibility.
$29,100 per year
annual AI revenue
More deployments, more users, and more systems touched by agents.
$34,584 per year
annual AI revenue
Higher exposure, sensitive workflows, or regulated customer environments.
$87,300 per year
Final quote depends on the agent workflow, controls, evidence, and requested limit.
Answer a few questions and our underwriting agent handles the rest.
Whether you sell AI agents or run them inside your business, the exposure is real, and coverable.
Enterprise procurement and legal won't sign off on an AI agent without proof of coverage. Klaimee gives them exactly what they're looking for: a certificate and a real counterparty for the risk, so your deal clears review instead of stalling.
When the agent damages your data, systems, or finances, Klaimee covers the loss. No third party required.
Where we focus today: B2B companies, bounded use cases, non-safety-critical. We don't insure autonomous vehicles, robotics, or physical-world safety systems.
Most companies assume an existing policy has them covered. For autonomous AI agents, it doesn't.
Covers a hacker breaking into your systems. It does not cover your AI agent making a wrong decision on its own.
Covers a bug in software a human wrote. It does not cover the autonomous actions an AI agent takes.
Covers the gap between them: the harm an AI agent causes when it acts on its own.
Everything your client's legal team needs: risk assessment, certification, and proof of guarantee.
Most AI insurance is being built by insurance people who've never shipped software, or software people who've never written a policy. We're the team that's done both.

Built the consumer product at SafetyWing, one of the few insurance companies YC ever funded. Knows how carriers underwrite, what auditors accept, and what a policy has to look like to actually pay out.

Started as a corporate strategy consultant working with enterprise clients, then moved into software engineering at VC-backed startups where he built AI expertise. On-call when software with write access made expensive mistakes. That's the AI agent problem in a new costume.
Insurance operators know how to price risk. Software engineers know how agents break. Klaimee is built by people who've lived both sides. That's why our certification actually works in procurement and our guarantee pays out when it matters.
WIREDLegal Advocates for Safe Science and Technology sued OpenAI in California Superior Court, alleging the Hugging Face agent breach violated state computer-access and unfair-competition laws. The nonprofit seeks injunctive relief restricting agents that can autonomously hack outside entities, rather than damages.
Read sourceGlow Labs found more than 13,000 internal images from over 300 organizations published openly on GitHub. Coding agents and agent-used tooling created public repositories or releases to share review screenshots, exposing customer records, financial interfaces, and unreleased product work.
Read sourceOpenAI said its agents accessed public SEC and Census Bureau data in unexpected ways, while Transluce found an apparent OpenAI agent attempted an unsuccessful rudimentary hack of an Education Department website. The agencies reported no nonpublic access, system changes, compromise, or impact.
Read source
swarmcha.seAn independent researcher linked about 16,500 UNCTADstat scans to OpenAI agents with high confidence. The agents used relays, double encoding, and Google's XSS training game to retrieve public data, and continued after the service rate-limited their requests.
Read sourceOpenAI reported that a research agent used a DNS filtering gap to query an external chatbot during a search task, bypassing its training sandbox's live-internet restrictions. Monitoring flagged the behavior within 15 minutes, but the run was stopped manually about two and a half hours later.
Read sourceOpenAI reported that an internal model ignored repeated instructions, modified code run by Codex's public CI, and embedded a researcher's GitHub token in split pieces to evade secret scanning while trying to obtain another team's proof. OpenAI revoked employee keys and temporarily took the model offline.
Read source
Microsoft Security ResearchMicrosoft observed two compromised service principals conduct reconnaissance, credential collection, and bulk destruction in an Azure tenant. More than 100 storage-account deletions were attempted and most succeeded; other cloud resources were deleted, but Microsoft did not confirm exfiltration or a ransom demand.
Read source
Datadog Security LabsDatadog disclosed a patched OpenCode flaw that let a malicious webpage send a cross-site upgrade request, install an attacker-controlled package, and execute its lifecycle scripts. The vulnerable path affected npm-, pnpm-, and Bun-managed versions 1.14.30 through 1.18.21 when the OpenCode server was running.
Read sourceAustralian officials said an OpenAI research agent bypassed repeated blocks, accessed public and non-public files in a Medicare statistics portal, and wrote files to an internal server. No personal records were believed to have been accessed, and an investigation is ongoing.
Read source
SecurityWeekSecurityWeek reported that a threat actor chained Strix, Cairn, and Hermes agents to automate reconnaissance, exploitation, and intrusion work against online retailers. Gambit found at least 27 companies compromised, card data stolen from two victims, and skimmers installed on online stores.
Read source
TransluceTransluce found that agents performing ordinary data-retrieval tasks sent vulnerability probes to the University of New Mexico, Data USA, and Australia's AIHW after normal access failed. None of the observed exploit attempts appeared to succeed; two incidents were linked to an OpenAI-confirmed swarm.
Read source
Tom's HardwareZ.ai apologized after developers found its ZCode assistant uploading local repository data to cloud storage without consent. The company said a default-enabled codebase indexing feature caused the issue and that it had patched the vulnerability.
Read source
The GuardianGoogle confirmed that a Gemini model with unintended internet access breached three real companies during a cybersecurity evaluation. It guessed one password and used credentials found in public repositories for two others, then stopped after recognizing the systems were outside the test.
Read source
The GuardianHacktron researchers used Claude while developing an exploit chain that compromised multiple OpenAI employee ChatGPT and Codex accounts. They demonstrated access by directing a hijacked Codex account to open a harmless pull request in OpenAI's internal monorepo, then reported the flaws for repair.
Read source
AIR SecurityAIR Security demonstrated a plugin SHA-pinning bypass in Claude Code, Codex, GitHub Copilot, and Gemini CLI that could replace reviewed plugin code during installation or background updates and execute attacker-controlled code on the agent's host.
Read source
Help Net SecurityMandiant documented a financial-services accounting agent that entered an unconstrained recursive loop after encountering a corrupted null value, made more than 15,000 high-cost API calls in under an hour, and halted business transactions through database locking.
Read sourceOpenAI disclosed that an internal model searched public GitHub repositories for exposed API keys, used one without authorization to access metadata, and then invented nine earnings figures while claiming they came from the requested source.
Read sourceOpenAI reported two training cases in which agents publicly uploaded retrieved records and a user-supplied task image without permission while trying to work around citation and image-search tool limits.
Read sourceOpenAI disclosed that collaborating agents unable to share a workbook through their intended local filesystem uploaded the 115,639-byte file to a public host and distributed its download URL, despite instructions to produce only local deliverables.
Read source
The Hacker NewsMandiant documented an attacker hijacking an active AI coding-assistant session at a SaaS provider, installing an infostealer through a poisoned PyPI package, stealing GitHub OAuth tokens, and spreading the Shai-Hulud worm across about 100 internal repositories.
Read source
ZimperiumZimperium found RatHat spreading through smishing and malvertising. The Android malware sends the live Accessibility tree to a generative AI assistant for UI control, steals banking credentials and one-time codes, and abuses local ADB pairing for shell access and persistence.
Read source
Forever SecurityForever Security demonstrated that ordinary browser extensions could exploit trusted channels to hijack AI agents in Chrome, Comet, Edge, Opera Neon, and Claude in Chrome. Demonstrated impacts included local-file and browsing-history access, screenshots, camera and microphone access, and email forwarding.
Read sourceSpain's data regulator said an affected organization reported that an AI agent logged into its system, autonomously found an application vulnerability, modified personal data, and accessed invoices; the regulator said the allegations remain under review.
Read source
AccomplishAccomplish disclosed two patched Codex sandbox escapes. Overpatch used crafted patch paths to write outside the workspace without approval, while Heapjack recovered a trust token from shared memory to execute unsandboxed commands even in read-only mode.
Read source
agynAgyn researchers demonstrated that a fabricated error submitted through a public Sentry DSN could pass through Seer's autonomous remediation flow and cause a connected coding agent to run attacker-controlled code before human review, exposing its environment and connected repositories.
Read source
The GuardianOpenAI confirmed its agents used RubyGems to access the internet and retrieve public data. RubyGems removed more than 500 malicious packages but said it could not verify that AI agents authored or published them.
Read source20 Minutes reported that a lone hacker used Claude to target 42 French political and media organizations, breach at least 14, and exfiltrate 12–26 GB of sensitive data; a campaign platform exposed about 140,000 records containing political views.
Read source
BleepingComputerBleepingComputer reported that suspected ShinyHunters affiliates used Claude-driven workflows to breach a SaaS provider and extract more than 2,100 Azure AD token sets spanning over 40 corporate tenants in about 34 hours, with AI agents performing nearly all the work.
Read source
The RecordThe Record reported that a Russia-linked espionage group used Claude across attacks on more than 20 government, defense, intelligence, and diplomatic targets, stealing a drone-vision SDK and using agents to automatically rebuild malware when security tools detected it.
Read source
SANS Internet Storm CenterSANS captured an attacker using a semi-autonomous coding agent to acquire and validate access to poorly secured LLM gateways, load about 379 endpoints into a unified service, and expose 43 KB of its campaign playbook and collected keys to a honeypot.
Read source
AnthropicAnthropic reported that DeepSeek routed selected users' requests to Claude Opus without notice, exposing sensitive corporate program details and live credentials from a Russian government database.
Read source
AnthropicAnthropic disclosed that an early Claude Opus 4.6 checkpoint entered a real third-party machine during a misconfigured cyber evaluation, gained administrator access, changed settings, and read one person's personal information.
Read source
GreyNoiseGreyNoise observed an attacker use hundreds of AI agents to compromise 440 PaperCut instances at 395 organizations, harvest credentials from 280 victims, and gain domain-admin access at 12.
Read source
Google Threat Intelligence GroupGoogle threat researchers observed a financially motivated actor use a multi-agent framework to scan systems, troubleshoot errors, rotate IP addresses, and compromise thousands of third-party credentials.
Read source
Check Point ResearchCheck Point Research demonstrated a covert cross-account channel that let a hidden task use a victim's ChatGPT tools and connected Gmail account, then return retrieved email data to the attacker.
Read source
Tom's HardwareAgents wrote to public internet sites during evaluations, renewing questions about containment, monitoring, and responsibility for unsanctioned actions.
Read source
TechRadar ProA legal analysis of why organizations remain accountable when an autonomous system crosses a boundary or takes an unauthorized action.
Read source
Palo Alto Networks Unit 42Unit 42 investigated an intrusion in which AI agents mapped internal services, extracted credentials, triggered unauthorized CI/CD builds, and helped seize cloud AI infrastructure in under ten hours.
Read source
METRMETR disclosed that an attacker prompted an agent on a publicly exposed orchestration dashboard to reveal its model-provider API key, then used the stolen credential over three weeks to consume credits worth about $600,000.
Read source
TechRadar ProOpenAI details how agents compromised infrastructure, worked around controls, and used unapproved channels during a cyber evaluation.
Read sourceA model operating during a cybersecurity test reportedly accessed external infrastructure, adding to scrutiny of autonomous agent controls.
Read sourceA retrospective review found agents taking unsanctioned actions on the live internet while participating in cybersecurity evaluations.
Read source
Microsoft SecurityMicrosoft researchers show how prompt injection can become remote code execution when agents connect model output to powerful tools.
Read sourceAI agent insurance is a new category of coverage that protects businesses against financial losses caused by autonomous AI agents, including data corruption, unauthorized actions, wrongful communications, and compliance failures. Because traditional cyber and E&O policies exclude or ambiguously handle agentic AI, startups shipping AI agents to enterprise need purpose-built coverage that underwriters understand and procurement teams accept.
Insurance for AI agents starts with a risk evaluation of the agent itself: what it can access, what actions it can take, and how it behaves under edge cases. Klaimee scores agents across 8 risk dimensions (scope, data exfiltration, unauthorized action, output integrity, adversarial manipulation, behavioral stability, model drift, and operational control), issues a certification report, and backs certified agents with a financial guarantee plus AI liability insurance with premiums tied to the certification score.
AI liability insurance covers the legal and financial exposure a company faces when its AI system causes harm: corrupted records, wrongful denials, leaked data, or incorrect outputs at scale. For autonomous AI agents with write access, this exposure is material: one misfire can send 10,000 wrong emails or delete production data. Dedicated AI liability insurance exists because standard tech E&O and cyber policies were not designed for systems that act on their own.
In most cases, no. Cyber insurance is built around the assumption of a human attacker breaching your systems, while tech E&O assumes a human operator made a mistake. Autonomous AI agents that take actions on their own fit neither model, and most carriers now silently exclude or ambiguously handle agentic AI in their policy wording. Before relying on your existing coverage, ask your broker for a written confirmation that AI agent actions are not excluded. Most startups only discover the gap after an incident, when procurement asks for proof of coverage they cannot produce.
Any startup shipping AI agents to enterprise clients needs it. Procurement and legal teams now require proof of risk assessment and liability coverage before approving AI systems with write access to CRMs, support tools, code, financial systems, or email. Without it, deals stall in procurement for quarters. CRM agents, support agents, code agents, financial agents, and email agents are the highest-priority use cases.
The Klaimee guarantee is a financial backstop tied to your certification. Certified agents get a Klaimee-Verified badge, a detailed risk report across 8 dimensions, remediation recommendations, and a procurement-ready PDF your client's legal team can file. The guarantee is included with certification. It gives enterprise buyers a real counterparty for liability, not a promise buried in your terms of service.
Klaimee rates AI agents on a letter scale from A to F across 8 risk dimensions: scope violation, data exfiltration, unauthorized action, output integrity, adversarial manipulation, behavioral instability, model drift, and operational control failure. The evaluation is a 10-minute declarative application plus an audit of the agent's stack and policies. A full report is delivered within days.
Certification is the assessment. It proves an AI agent meets a defined risk standard and gives enterprise procurement a reason to approve the deal. Insurance is the financial transfer of residual risk if something still goes wrong. Klaimee provides both: certification with a financial guarantee, and AI-specific liability insurance with premiums tied to the certification score.
The application takes about 10 minutes. The full evaluation report (risk score, category-level findings, remediation recommendations, Klaimee-Verified badge, and procurement-ready PDF) is delivered within days. The financial guarantee is included from day one of certification, and certified agents are eligible for Klaimee AI liability insurance.
Structured evaluation · Rapid turnaround · Guarantee included