Guarantee or Indemnity
One product pays when your AI fails to do its job. The other pays when your AI harms someone else. Buyers keep lumping the two together, and they are not the same purchase.
Joel R. Singh
Underwritten
Two Words That Do Two Jobs
A company shopping for AI insurance in 2026 walks into a market that is selling two products under names that sound almost interchangeable, and the confusion is costing buyers real money. One is a guarantee. The other is an indemnity. A vendor tells a prospective customer that the model is insured, a broker mentions AI coverage in a renewal call, a slide deck promises that the risk is covered, and in every case the words land the same way in the buyer's ear. Covered. Protected. Handled. None of those words answers the question that decides whether a policy ever pays, which is what specific event has to happen before anyone writes a check. Two products can both be described as insurance for AI and pay on two completely different triggers, and a business that buys one while believing it has bought the other has bought a false sense of safety at a real premium.
The distinction is old, and insurance has spent seven centuries learning to keep its promises apart from one another. A guarantee, in its plainest form, is a promise that something will perform to a stated standard, and a promise to make good if it does not. An indemnity is a promise to cover a loss that falls on you, most often because your activity has caused harm to somebody else and they have come to collect. The first is a warranty on a thing. The second is protection against the consequences of that thing loose in the world. When the thing is a shipment of tea, or a house, or a car, the difference between a warranty and a liability cover is intuitive enough that few people mix them up. When the thing is an artificial intelligence system, the difference collapses in the buyer's mind almost immediately, because the same model can both fail to work and cause harm, sometimes in the very same incident, and the marketing language rarely bothers to hold the two apart.
So this essay does one narrow, useful thing. It draws the line between a performance guarantee on an AI system and a liability policy for an AI system, as cleanly as the market's own product filings allow, and it shows you why the line matters before you sign anything. It is not a roster of every carrier, and it is not a checklist of what an underwriter will ask you. Those are separate pieces, and I will point you to them at the end. This one is about the single conceptual bifurcation within the entire AI insurance market, the fork that determines whether the policy you are holding responds to the loss you are actually going to have.
The Two Triggers
Everything in an insurance contract turns on the trigger, which is the specific event the policy names as the thing that opens the door to a payout. Get the trigger right and every other feature of the policy, the limit, the deductible, the exclusions, arranges itself around a coherent purpose. Get the trigger wrong and you can hold a generous limit against a loss that will never satisfy the one condition required to unlock it. The two AI products this essay is about differ, more than anything else, in their trigger, and the two triggers could hardly be more different from one another.
A liability policy is triggered by a claim. Something your AI did reached out into the world and harmed a third party, and that third party, or a regulator acting on their behalf, is now asserting that you owe them for it. The mechanism that pays you is the machinery of fault and defense. There is an allegation, there is a demand, and there is the whole apparatus of adjusting a claim, investigating what happened, defending you where you are defensible, and settling or paying where you are not. The loss the policy covers is not the failure of your model as such. It is your legal exposure to somebody else because of that failure. The classic AI liability products in the market read exactly this way. Testudo's generative AI liability cover, for instance, responds to third-party claims arising from AI-generated outputs, spanning hallucinations, intellectual property infringement, unauthorized data disclosure, bodily injury and property damage, and regulatory proceedings, and it explicitly reaches into the territory where an ordinary commercial general liability policy may decline to respond.[2] The event that matters is the claim against you, not the number on a dashboard.
[2] Testudo — GenAI Liability Insurance
A performance guarantee is triggered by a measurement. There is a defined performance threshold written into the contract, a level of accuracy, a bias ceiling, an uptime figure, some quantity that can be observed and recorded, and when the AI system breaches that threshold, the payout follows. Nobody has to allege that you were negligent. Nobody has to prove fault or defend a lawsuit or apportion blame across a chain of decisions. The Munich Re aiSure product, which has been on the market since 2018 and is distributed through the specialist insurer Mosaic as of early 2026, is described in exactly these terms: no negligence allegation is needed, and the breach of a predefined performance threshold triggers the payout, in a structure the carrier itself likens to a parametric one, with claims settled on measurable performance data rather than on a contested story of who did what.[3][4] The underwriting focuses on the model itself rather than on the insured's industry, which is the natural consequence of insuring the model's behavior rather than the insured's conduct.
[3] Mosaic Insurance — aiSure · [4] Munich Re — Insure AI
[5] Swiss Re — What is parametric insurance
The trigger does more than decide whether a policy pays. It decides how the payment happens, how fast, and how much room there is to argue about it. A measured trigger is close to mechanical. The metric is defined in advance, the two parties agreed to watch it, and when it crosses the line the obligation crystallizes with very little left to dispute beyond whether the measurement was taken correctly. That is the appeal of a parametric structure and the reason Munich Re reaches for the comparison: settlement runs off data rather than off argument, and the friction that makes ordinary claims slow and contentious is engineered out of the process from the start.[4] A claim trigger works the other way. It invites exactly the argument the parametric trigger avoids, because whether you owe a third party is rarely obvious, and establishing it means investigation, defense, and the slow apportioning of blame across a chain of decisions in which your model was one link among several. A liability insurer signs up for that argument on your behalf, which is most of the value it provides, and it is a value a performance guarantee does not even attempt to deliver.
Hold those two triggers side by side and the whole confusion dissolves. Fault and a claim on one side. A measured breach of a stated number on the other. One asks whether somebody else has come after you and whether you owe them. The other asks only whether the model did what the contract said it would do, as recorded by the metric both parties agreed to watch. They are answers to different questions, and a business that has only ever asked itself whether it is covered has never actually confronted the question that decides which product it needs.
A liability policy asks whether someone else has a claim against you. A performance guarantee asks only whether the model hit its number. Those are not the same question, and one premium does not answer both.The distinction that decides which policy pays
What Each One Does, and Does Not, Do
Start with the performance guarantee, because it is the one buyers most often mistake for something broader than it is. A guarantee makes good on a promise about how the model behaves. If a vendor has told a customer that its document-classification model will hit a defined accuracy, or that its fraud-detection system will stay under a defined false-positive rate, or that its outputs will keep a measured bias below a stated ceiling, a performance guarantee stands behind that promise with a payout when the number is missed. Armilla's market offering illustrates the split cleanly within a single provider. Alongside its affirmative AI liability policy, Armilla offers a separate product, Armilla Guaranteed, described as a performance warranty that pays compensation when the AI fails contractual key performance indicators such as accuracy or bias thresholds.[6][7] The word warranty is doing precise work there. It is a promise about the thing.
[6] Armilla — AI Insurance · [7] Chaucer — Vanguard AI structure
What a performance guarantee conspicuously does not do is defend you against a third party. It does not retain lawyers when a customer sues you for the downstream damage your model's failure caused. It does not respond to a regulator's proceeding. It does not answer a claim of discrimination brought by a rejected applicant, or an intellectual property demand from a rights-holder whose work your model reproduced, or a bodily-injury suit from someone hurt by an automated decision. The guarantee closes out the moment the number is settled and the agreed compensation is paid for the missed threshold. Everything that happens after that, in the courtroom rather than on the dashboard, is somebody else's product to sell. A vendor who buys a performance guarantee to backstop the promises it makes to its own customers, which is precisely the use case Munich Re names for aiSure, has bought a genuinely useful thing, and it has bought nothing at all that will show up when a lawsuit lands.[4]
Now the liability policy, which does the opposite job. It exists for the moment the harm has left your building and become somebody else's grievance. Its natural home is the third-party claim, and the AI liability products clustering in the market read consistently in that register. They do not, however, reach the same set of harms, and the differences are structural rather than cosmetic.
Vouch
Standalone AI E&O
Sold direct, underwritten through the Corix arm now inside Hiscox. The tightest and most AI-specific of the three.[8]
Relm PONTAAI
Excess DIC wrap
Attaches above programs that exclude AI, for deployers already holding cover with an AI-shaped hole in it. Reaches widest.[9]
CFC
Embedded, core lines
Affirmative AI cover written inside the professional and management-liability policies a business already carries.[10]
| Exposure | Vouch | Relm | CFC |
|---|---|---|---|
| Hallucination / harmful output | ● | ● | ● |
| IP infringement | ● | ● | · |
| Bias & discrimination | ● | ● | · |
| Regulatory investigation defense | ● | · | · |
| Privacy | · | ● | · |
| Bodily injury & property damage | · | ● | · |
| Civil fines, where insurable | · | ● | · |
| Model drift | · | · | ● |
Three structures, one shared purpose: to answer for you when the world comes to collect. Where they differ is how much of the world they answer for.
[8] Vouch — AI Insurance for startups · [9] Relm — PONTAAI · [10] CFC — Affirmative AI cover
It is worth being concrete about where a liability policy's coverage ends, because the boundary is often drawn inside a product that already calls itself AI insurance. Coalition's affirmative AI endorsement is a clean example. It expands a cyber policy's security-failure and data-breach definition to include AI security events, and it adds coverage for deepfake reputational harm, which sounds comprehensive until you read the scope note the carrier itself attaches. The endorsement covers AI as an attack vector, meaning the ways an adversary can use AI against you, and it explicitly does not cover liability for your own AI's outputs.[12] That is a third boundary running through the market, orthogonal to the guarantee-versus-liability line, and it catches buyers who assume that any policy with AI in the title answers for the harm their model does. It does not. It answers for a different peril entirely, and reading the trigger is the only way to see which one you are holding.
And here is what a liability policy does not do, which is the mirror image of the guarantee's blind spot. It does not pay you simply because your model underperformed. If your fraud-detection system slips below its promised accuracy and costs you money internally, with no third party harmed and no claim asserted against you, a liability policy has nothing to respond to, because nothing has happened that the policy is built to catch. There is no allegation, no demand, no defense to mount. The loss is real, it sits on your own books, and it is first-party in nature, the very category a third-party liability form is designed to leave alone. This is not a defect in the liability policy. It is the policy doing exactly its job and declining to do a different one it never promised to do.
The Comparison, Side by Side
It helps to see the two structures laid against each other on the fields that actually decide a claim. The grid below is deliberately narrow. It compares the products on the mechanics that determine whether either one pays, and it draws its examples from the verified filings of carriers active in the market today.
Performance guarantee / warranty
Pays when the AI fails to perform
Liability policy / indemnity
Pays when the AI harms a third party
Product examples reflect publicly available carrier filings and announcements as compiled in the Buyer's Guide carrier dataset. Coverage terms vary by insured and by state; confirm current wording with the carrier.
The Trap in the Overlap
The reason the confusion is so durable is that a single AI incident can set off both triggers at once, and the buyer who has only felt the incident, not read the two contracts, cannot see where one product's job ends and the other's begins. Picture a model that a company has deployed to screen loan applications. It drifts, quietly, over a few months, and its accuracy falls below the level the vendor guaranteed. That drift is a measured breach of a performance threshold, and it is squarely the kind of event a performance guarantee is built to pay on. But the same drift, in the same months, has been steering the lending decisions in a skewed direction, and now a group of rejected applicants brings a discrimination claim. That claim is a third-party demand, and it is squarely the kind of event a liability policy is built to answer. One incident, two triggers, two different products, and only a buyer holding both is actually covered end to end.
This is where the marketing language does its quiet damage. A vendor that holds a performance guarantee can say, with a straight face, that its AI is insured, and a customer can hear that and reasonably assume the vendor stands behind the harm the model might do to the customer's own downstream clients. The vendor has said nothing false. It has simply allowed a word that means one thing to be heard as if it meant both. The reverse happens too. A deployer that carries an AI liability policy can believe it is protected against a model that fails to perform, and discover only after a costly internal failure that its policy was always waiting for a third-party claim that, in this instance, never came. Each buyer held a real product. Each buyer held the wrong one for the loss they actually suffered.
Some of the newer entrants blur the line further by bundling. AIUC pairs its AIUC-1 certification standard, built on thousands of adversarial simulations across security, safety, reliability, privacy, and accountability, with insurance for AI agents, and its first live deployment placed that coverage behind a vendor's voice agents.[11] Bundling certification with coverage is a sensible commercial move, because a tested model is a more insurable model, but it also means a single sales conversation can present testing, a performance promise, and a liability backstop as one undifferentiated thing called insurance. The buyer's job is to pull the bundle apart and ask, of each strand, what event makes it pay. The certification tells you the model was tested. The performance guarantee pays if it misses its number. The liability cover pays if a third party comes after you. Three different promises, and the word insurance stretched across all of them.
Segment matters here more than buyers expect, because the loss that would actually hurt a company depends heavily on what kind of company it is. A small business that uses AI to generate marketing copy or triage customer messages is unlikely to be selling a performance-guaranteed model to anyone, so a performance guarantee has little to backstop. What that business faces instead is the risk that its AI-generated advertising defames a competitor or that an automated response causes a harm a customer sues over, which is squarely third-party liability territory. It is telling that when HSB, a Munich Re subsidiary, built the first standalone AI liability product aimed at small and mid-sized businesses, it framed the cover around lawsuits arising from the use of AI, including bodily injury, property damage, and advertising injury from AI-generated content, and positioned it to fill the gaps that general liability policies exclude.[13] That is a liability product for a segment whose exposure is almost entirely liability. A model vendor selling into the enterprise sits at the opposite end, carrying performance promises worth backstopping and third-party exposure worth insuring at the same time, which is why the two-product answer shows up most often at that end of the market.
Which product a buyer needs depends on which loss would actually hurt them, and for many businesses the answer is both. A vendor selling an AI product to enterprise customers has made performance promises it may need to backstop, which points toward a guarantee, and it also faces the risk that its model harms one of those customers' own clients, which points toward liability cover. A deployer running someone else's model inside a consequential process faces mostly the second risk, the third-party claim, and may care less about the first, because the performance promise was the vendor's to make and the vendor's to insure. The point of drawing the line is not to send every buyer toward one product. It is to make sure that whichever product a buyer signs, they signed it knowing which loss it answers and which loss it leaves on the table.
Reading the Trigger Before You Buy
If you take one working habit from this, let it be this. When a carrier, a broker, or a vendor tells you that an AI product is insured or covered, do not accept the word and move on. Ask the single question that forces the trigger into the open. What specific event has to happen before this pays. If the answer is that a measured performance threshold has to be breached, and payment follows the metric without any allegation of fault, you are looking at a performance guarantee, and you should judge it on whether the threshold is one you actually care about and whether the payout is enough to matter when the number is missed. If the answer is that a third party has to bring a claim against you, and the policy defends and indemnifies you against that claim, you are looking at a liability policy, and you should judge it on whether the claims it names are the claims your particular use of AI could realistically attract.
The two answers are not interchangeable, and no amount of confident language collapses them into one. A performance guarantee will not walk into court with you. A liability policy will not write you a check for a model that merely disappointed you. The word covered, spoken warmly across a renewal call, tells you nothing about which of those two very different promises you are being offered. Only the trigger tells you that, and the trigger is written down, in the product, waiting to be read by anyone willing to ask.
This site keeps the full roster of who is actually selling these products, liability and guarantee alike, in a companion piece on the carriers in the market, and it keeps the list of questions an underwriter will put to you before writing either kind of cover in a second companion piece on preparing for the policy. Those are the next two steps once you know which product you are shopping for. The step before both of them, the one this essay exists to force, is deciding whether the loss you are insuring against is a model that fails to perform or a model that reaches out and harms someone else. Answer that first, and the rest of the market stops being a wall of interchangeable reassurance and becomes a set of specific promises you can finally tell apart.
Before you go
Now that you know which product answers your loss, see who actually sells it.
The carrier comparison lays out every AI insurer we track, liability writers and performance guarantors alike, with the trigger, target segment, and verified source behind each one, so you can match the product to the loss you just identified.
See the full carrier comparisonEvery AI insurer we track, side by side, with sources. Companion essays: Who Insures the Machine (the full market roster) and The Questions Before the Policy (underwriting prep).
Works Cited
Every factual claim about a carrier's product in this essay is sourced below, drawn from carrier filings, announcements, and the Buyer's Guide's own source-verified dataset. The numbers match the citation after each paragraph. Where a source describes a product structure rather than a single figure, the note says so.
- 1Encyclopaedia Britannica, Insurance: Historical development (marine insurance and the separation of the premium, Genoa, 1343). ↩
- 2Testudo, GenAI Liability Insurance (third-party claims from AI-generated outputs; responds where CGL may not). ↩
- 3Mosaic Insurance, aiSure (breach of a predefined performance threshold triggers payout; no negligence allegation needed; parametric-style; settled on measurable performance data). ↩
- 4Munich Re, Insure AI / aiSure (AI performance guarantee; backstop for AI vendors' contractual performance promises; underwriting centred on the model). ↩ aiSure has been offered by Munich Re since 2018; the Mosaic distribution partnership dates to February 2026.
- 5Swiss Re, What is parametric insurance (payout on a defined, measurable parameter rather than proven indemnified loss). ↩
- 6Armilla, AI Insurance (affirmative AI liability policy, and a separate Armilla Guaranteed performance warranty paying on contractual KPI failures such as accuracy or bias thresholds). ↩
- 7Chaucer, Chaucer and Armilla AI launch Vanguard AI coordinated insurance structure (affirmative AI liability underwritten by Lloyd's capacity). ↩
- 8Vouch, AI Insurance (AI E&O for hallucinations and misleading outputs, algorithmic bias, regulatory defence, IP infringement; via the Corix / Hiscox partnership). ↩
- 9Relm Insurance, PONTAAI (excess difference-in-conditions wrap for deployers whose programs exclude AI; professional negligence, IP, discrimination, privacy, bodily injury and property damage, and insurable civil fines for AI-regulation violations). ↩
- 10CFC, CFC responds to customer demand for affirmative AI cover (affirmative AI embedded across core commercial lines; addresses hallucinations, AI-generated content, and model drift). ↩
- 11ElevenLabs, ElevenLabs secures first-of-its-kind AI agent insurance (AIUC-1 certification across security, safety, reliability, privacy, and accountability, bundled with agent insurance). ↩
- 12Coalition, Coalition adds new affirmative AI endorsement to cyber policies (covers AI as an attack vector, including deepfake reputational harm; does not cover liability for the insured's own AI outputs). ↩
- 13HSB (a Munich Re company), Introducing AI Liability Insurance for Small Businesses (lawsuits from use of AI; bodily injury, property damage, and advertising injury from AI-generated content; fills gaps GL excludes). ↩