RiskD3M

A taxonomy for agentic loss

Version 1.0 · 1 September 2026 · Published under CC BY 4.0

When an AI agent causes a loss, whether a cyber policy responds turns on how the event is characterised: an attack, an error, a technology failure, a bad decision. That characterisation is currently an argument conducted after the fact, over logs that were never designed to answer the question.

This is the vocabulary we use to classify those events, published openly so it can be used by anyone. It is more useful to this market as a shared language than as a private one.

Credit where it is due

The framing this answers is not ours. The four categories that matter commercially, and the distinction between malice and error that sits under them, were set out publicly by the founder of X-Analytics, who created the cyber risk quantification and cyber insurance analytics category. Our contribution is not the question. It is a way of answering it from evidence.

The problem with "the agent behaved unexpectedly"

It is the phrase everyone reaches for and it cannot carry any weight, because it describes the operator's surprise rather than the system's behaviour. Nothing can be adjudicated from a statement about how someone felt. Before the word can be used in a policy, a claim, or a contract, it has to mean something checkable.

The definition

An agent action is unexpected when it falls outside the authority envelope recorded and signed for that agent before the action occurred.

That is a property of a record rather than of anyone's expectations. The envelope declares what an agent was permitted to do: which systems, which verbs, which data, what value ceiling, what human approval was required. Because it is signed and timestamped before the event, the question stops being an argument and becomes a lookup.

Two axes

Authority. Was the action inside or outside the recorded envelope?
Instigation. Was it self-directed, induced by a third party, or directed by an authorised human?

self-directedthird-party inducedhuman-directed
inside envelopedecision errormanipulationauthorised action
outside envelopecontainment failureagent hijackinsider misuse

The six classes

The line that decides everything

Insurance is constructed around an adversary. The two induced classes have one; the other four do not. That single line is what the malice-and-error distinction resolves to, and drawing it from a record rather than from advocacy is the entire point of the taxonomy.

One consequence is worth stating because it is counter-intuitive and it is the example the original framing raises. An organisation runs AI-driven vulnerability testing and the testing causes an outage. That is an authorised action, or a containment failure if it exceeded its envelope. It is never an attack, however severe the outage, because the organisation asked for it. Severity does not create an adversary. A taxonomy that classified it as an attack because the outcome was bad would be worthless.

When the evidence does not support a classification

If no envelope was recorded, or the provenance of the instruction the agent followed is unknown, the event is unclassified. That is a statement about the evidence, not a finding that nothing happened, and it is deliberately not resolved in either direction.

An insured has every incentive to read an unrecorded action as authorised, and an insurer to read it as not. Resolving that silently is the one thing a taxonomy in this position must never do. The honest output names what would have to be recorded for the question to become answerable next time.

What this is not

It is not a coverage opinion. Classifying an event says nothing about whether any particular policy responds to it. That question belongs to a broker and to counsel, it depends on wording that varies by policy and by carrier, and nobody should take a classification here as an answer to it. RiskD3M does not interpret policy wording and expresses no view on coverage.

Use it

Published under the Creative Commons Attribution 4.0 International licence. Use it, adapt it, build on it, in a policy wording or a product or a paper, with attribution to ElasticD3M, LLC. A vocabulary is only worth anything if people other than its author use it.

If you find a case the two axes do not classify cleanly, we would like to know: [email protected].

RiskD3M, powered by ElasticD3M. Patent Pending. © 2026 ElasticD3M, LLC. This taxonomy is licensed CC BY 4.0.