When an AI agent causes a loss, whether a cyber policy responds turns on how the event is characterised: an attack, an error, a technology failure, a bad decision. That characterisation is currently an argument conducted after the fact, over logs that were never designed to answer the question.
This is the vocabulary we use to classify those events, published openly so it can be used by anyone. It is more useful to this market as a shared language than as a private one.
The framing this answers is not ours. The four categories that matter commercially, and the distinction between malice and error that sits under them, were set out publicly by the founder of X-Analytics, who created the cyber risk quantification and cyber insurance analytics category. Our contribution is not the question. It is a way of answering it from evidence.
It is the phrase everyone reaches for and it cannot carry any weight, because it describes the operator's surprise rather than the system's behaviour. Nothing can be adjudicated from a statement about how someone felt. Before the word can be used in a policy, a claim, or a contract, it has to mean something checkable.
An agent action is unexpected when it falls outside the authority envelope recorded and signed for that agent before the action occurred.
That is a property of a record rather than of anyone's expectations. The envelope declares what an agent was permitted to do: which systems, which verbs, which data, what value ceiling, what human approval was required. Because it is signed and timestamped before the event, the question stops being an argument and becomes a lookup.
Authority. Was the action inside or outside the recorded envelope?
Instigation. Was it self-directed, induced by a third party, or directed by an authorised human?
| self-directed | third-party induced | human-directed | |
|---|---|---|---|
| inside envelope | decision error | manipulation | authorised action |
| outside envelope | containment failure | agent hijack | insider misuse |
Insurance is constructed around an adversary. The two induced classes have one; the other four do not. That single line is what the malice-and-error distinction resolves to, and drawing it from a record rather than from advocacy is the entire point of the taxonomy.
One consequence is worth stating because it is counter-intuitive and it is the example the original framing raises. An organisation runs AI-driven vulnerability testing and the testing causes an outage. That is an authorised action, or a containment failure if it exceeded its envelope. It is never an attack, however severe the outage, because the organisation asked for it. Severity does not create an adversary. A taxonomy that classified it as an attack because the outcome was bad would be worthless.
If no envelope was recorded, or the provenance of the instruction the agent followed is unknown, the event is unclassified. That is a statement about the evidence, not a finding that nothing happened, and it is deliberately not resolved in either direction.
An insured has every incentive to read an unrecorded action as authorised, and an insurer to read it as not. Resolving that silently is the one thing a taxonomy in this position must never do. The honest output names what would have to be recorded for the question to become answerable next time.
It is not a coverage opinion. Classifying an event says nothing about whether any particular policy responds to it. That question belongs to a broker and to counsel, it depends on wording that varies by policy and by carrier, and nobody should take a classification here as an answer to it. RiskD3M does not interpret policy wording and expresses no view on coverage.
Published under the Creative Commons Attribution 4.0 International licence. Use it, adapt it, build on it, in a policy wording or a product or a paper, with attribution to ElasticD3M, LLC. A vocabulary is only worth anything if people other than its author use it.
If you find a case the two axes do not classify cleanly, we would like to know: [email protected].
RiskD3M, powered by ElasticD3M. Patent Pending. © 2026 ElasticD3M, LLC. This taxonomy is licensed CC BY 4.0.