5+ years delivering systems inside heavily regulated risk environments at CIBC, ABN AMRO, and Westpac. 10+ years leading AI products used by 500M+ people at Microsoft Copilot, Amazon Alexa, and Expedia.
Personal auto insurance was built to price human error. We underwrite the risk that autonomous systems create — for the fleet operators, OEMs, and software companies who now carry it.
Insurance has always priced the party who controls the outcome. As the human does less of the driving and the software does more, that party changes — away from the driver, toward the manufacturer, the software provider, and the fleet operator.
Almost every collision is one person's lapse arriving at the same place as another's. Fault is established at the scene, and a personal auto policy responds. Autonomy shows up only as a discount on a human's premium — never as a risk with a shape of its own.
A driver and an autonomous system share the road, and often the same vehicle. The question stops being who was careless and becomes who held authority at the moment it mattered — the human, the system, or the handoff between them. Fault turns into a product question, and personal auto has no clean answer to it.
The loss is the product of two systems interacting: a perception gap, a conflicting driving policy, an over-the-air update that changed behaviour last Tuesday. There is no driver to hold liable. The risk sits entirely with whoever built, released, and operated the software — and it has to be underwritten that way.
Splits are illustrative — they show the direction of travel, not a forecast.
None of these are edge cases. Each one is a structural assumption that personal auto insurance depends on, and that autonomy quietly removes.
As the human does less of the driving and the software does more, liability shifts away from the driver and toward manufacturers, software providers, fleet operators, and other commercial actors.
The risk mix moves toward product liability, commercial liability, cyber, and technology E&O — because the source of failure is increasingly the system rather than individual driver behaviour.
After a crash, an insurer needs to know whether the human or the autonomous system had control, which software version was running, what the sensors observed, and what the system decided. Event logs and telemetry become claims infrastructure.
Risk changes dramatically depending on how much authority the system holds, its operating domain, whether a human can intervene, and under what circumstances. Underwriting has to be that granular or it is guessing.
An insurer may underwrite a vehicle today and have an over-the-air update materially change its behaviour tomorrow. Annual underwriting assumes a far more static insured asset than this.
A bad human driver creates repeated individual risk. A defective software release can expose an entire fleet simultaneously. That is concentration and aggregation risk, and it has to be modelled as such.
A failure could originate with an OEM, a sensor manufacturer, a mapping provider, an autonomy software company, a fleet operator, a maintenance provider, or a cybersecurity breach. Insurance has to handle overlapping policies and contractual indemnification across that whole stack.
Autonomy could remove many ordinary collisions while making the remaining claims far more technically complex and potentially more expensive. Lower frequency does not mean lower complexity.
Instead of asking people what they remember, insurers need machine-generated evidence: logs, video, sensor data, system state, software version, intervention history, and model behaviour.
Whoever holds high-quality fleet and autonomy telemetry can price this risk far better than a carrier working from demographic and historical driving variables. That is the whole game.
When the failure can start at a sensor supplier and end at a fleet operator, a single line of cover leaves gaps that only surface after a loss. We write the towers together, so the liability path is settled before anything goes wrong.
Design defect, failure to warn, and post-deployment claims arising from behaviour the system actually shipped with. This is the cover that replaces the driver's policy once the code makes the decision.
Primary and excess liability for vehicles operating with nobody in the seat — rated on how the stack behaves within its operating domain, not on a driver record that no longer exists.
For the autonomy developer, mapping provider, or remote-operations vendor whose service underperforms without a physical defect to point at. The failure is in the service, so the cover has to be too.
Compromise of the update channel, the fleet backend, or the vehicle itself. A malicious intrusion and a defective release have the same shape from an underwriting view: fleet-wide, and overnight.
Where an OEM, sensor manufacturer, or maintenance provider owns part of the failure. We write cover that follows the contractual indemnities across the stack instead of pretending they are not there.
Structured for the failure mode that traditional books are least ready for: one defective release producing a single correlated event across a whole fleet, rather than a thousand independent ones.
We do not rate autonomy off a ZIP code and a vehicle year. We rate it off what the fleet already records: how much authority the system holds, where it runs, when it hands back, and what changes every time you ship. Each stage has a fixed scope and a clear deliverable.
Book an exposure reviewA call directly with the founders. Where your vehicles run, what the stack is authorised to do, which entity currently carries the risk, and what your existing carrier will and will not cover. Most operators discover a gap in this conversation. No pitch, no decks.
We work with your safety and engineering teams to map what the fleet already records — disengagements, interventions, near-misses, sensor health, ODD boundaries, release history. Most operators are sitting on better underwriting data than any carrier has ever been handed, in a format no carrier can read.
A written view of your autonomy risk: frequency and severity modelled on your own miles rather than an industry average, the liability path for each failure mode, and where the exposure actually lands between you, your OEM, your software vendor, and your operator. Board-ready and broker-ready.
A priced program structured for how you actually operate: the towers and how they sit together, the retention you keep, the triggers, and exclusions written against an operating design domain rather than a driver's licence class. Aggregation is modelled explicitly, not assumed away.
Cover goes live and the telemetry keeps flowing. Because a release can change the risk overnight, rates move with demonstrated behaviour instead of an annual guess — and a disciplined rollout history earns a lower rate rather than a renewal argument.
Claims are resolved from the log, not from two conflicting statements. Control state, software version, sensor observations, and intervention history are agreed up front as the evidentiary record — so attribution is a retrieval question on day one instead of a litigation question three years later.
Most carriers are pricing autonomy with the tools they already had, because rebuilding underwriting around software is expensive and the loss history does not exist yet. Here is the honest version of the difference.
Rate autonomy off the driver's record, ZIP code, and vehicle year — proxies for a human who is no longer doing the driving.
Rate off the system's own evidence: how much authority it holds, its operating domain, intervention and disengagement rates, and release history.
Underwrite once a year and treat a software release like a vehicle modification — reviewed at renewal, if at all.
Treat every over-the-air release as a risk event. Staged rollout, regression testing, and rollback discipline are rated controls that move your price.
Settle the "was it the human or the system" question years later, in court, once the logs have already been overwritten.
Write the attribution standard into the policy up front — what gets logged, retained, and shared — so the question is answerable from day one.
Price a whole fleet as independent vehicles, then discover after one bad release that every unit was really a single correlated risk.
Model aggregation explicitly. A fleet running one software version is one exposure, and the program is structured to survive that being true.
Underwriters who have never read a disengagement report, an ODD definition, or a release changelog.
15+ combined years inside regulated risk functions at global banks, plus production AI systems at Microsoft Copilot and Amazon Alexa. We read the stack and the regulation.
Combined experience inside heavily regulated risk functions at global banks — where capital, model risk, and audit are the product — plus production AI systems at Microsoft Copilot, Amazon Alexa, and Expedia. You work directly with us, every engagement.
5+ years delivering systems inside heavily regulated risk environments at CIBC, ABN AMRO, and Westpac. 10+ years leading AI products used by 500M+ people at Microsoft Copilot, Amazon Alexa, and Expedia.
6+ years building AI/ML systems and model risk tooling at Wells Fargo and American Express. Co-creator of SAFE-MCP, the AI agent security framework adopted by the Linux Foundation and OpenID Foundation.
30 minutes. Tell us where your vehicles run and what your current policy says. We'll give you a candid read on where your liability sits today, and whether anything is covering it. No pitch.