
Many of us are still trying to get comfortable with the idea of autonomous vehicles. Turns out, we may soon need to get comfortable with the idea of autonomous companies.
A first-of-its-kind draft bill has been proposed to the Delaware legislature that would allow the creation of an Artificial Intelligence Company (AIC), a form of legal personhood for an entity that operates through an AI agent with no human at the controls, and with the same kind of limited liability for the entity’s owners as for a more traditional company.
As discussed below, the proposed new AIC corporate form raises some very interesting questions. It also arguably represents an entirely new challenge for the D&O insurance industry.
A copy of the draft bill can be found here. Special thanks to Lauren Pringle of The Chancery Daily for providing me with a copy of the draft bill.
Background
The proposed Delaware legislation is the culmination of several months of planning and coordination including the Delaware General Assembly’s creation in 2024 of an Artificial Intelligence Commission. The Commission’s regulatory sandbox subcommittee has now released draft legislation that would permit the creation of a legal entity of a new type, called an Artificial Intelligence Company (AIC), whose operations are to be run entirely by an AI agent.
The Proposed New Corporate Form
In a July 14, 2026, Fortune magazine article (here), Delaware Secretary of State Charuni Patibanda-Sanchez and Norm Ai founder and chief executive John Nay, the architects of the AIC proposal, describe the proposed AIC corporate form and the regulatory sandbox framework. As they explain, their idea is to create a corporate form to permit a company to be run entirely by artificial intelligence — a company with a legally separate identity from the company’s owner or parent company, with the ability to own assets and to enter contracts, and to sue or be sued in its own name. The draft legislation would authorize a 30-month test period starting from the passage of the legislation. The article also explains that the framework for this initiative is being developed in Delaware as part of a public-private partnership led by Norm AI.
Under the model proposed in the draft legislation, the AIC would have a single member, either a person or an entity, responsible for keeping the AIC adequately capitalized. The member would be shielded from the AIC’s debts except when it fails to capitalize the company or uses it to commit fraud or a willful violation of law.
Under the terms of the proposed legislation, and for now at least, the AIC could only operate within the constraints of a “regulatory sandbox,” with admission to the sandbox determined by a committee of designated state officials. An AIC seeking to operate within the sandbox must meet capitalization requirements and disclose a variety of mandated information to counterparties. The draft legislation has a number of provisions allowing AICs to be suspended or to have its authorization revoked. The use of an AIC for banking is prohibited. The legislation also sunsets the AIC program after 30 months, allowing the General Assembly to decide what steps to take next.
At the core of the proposal is a requirement that the AIC must keep a log of its activities. The idea is that before deployment the AIC would have encoded into its operating AI agent authority limits constraining the agent’s authorized activities. The agent would precheck its planned activities against the authority limits, creating a record required to satisfy the proposed legislation’s activity log requirement. An attorney would review the transactions to provide the AIC’s member with the proof that the proper oversight is being provided. (With respect to the technical feasiblity of these agency authority protocols, please refer to this blog post’s Comments section for one reader’s very interesting observations.)
The legislation’s architects assert in their Fortune article that “there are real protections.” Through disclosures, counterparties would know they are dealing with a temporary, autonomous entity. The proposed liability protections exist only “inside the sandbox” (i.e., for companies that are accepted into the program), and only for participants that “follow the rules.” The architects also emphasize that “consumer-protection and criminal law apply in full.”
In discussing the new proposed AIC form, the legislation’s architects state that the “point” of the legislation is to “pilot agentic commerce in daylight, under supervision, with capital tied to liability and the ability to shut a system down.” If the U.S. legal system does not provide a “home” for “autonomous commerce,” the activity will “migrate offshore and onto anonymous infrastructure beyond the reach of any court.” Instead, under the structure that the proposed legislation offers, “Delaware could govern this technology inside the American legal tradition, where it can be observed, tested, and held to account.”
The draft proposed legislation apparently has gone through the requisite legislative committee processes, and will now go before the full legislature when it reconvenes, which next happens in January 2027.
Discussion
My analysis of the proposed AIC corporate form is hamstrung by my own lack of imagination. For starters, I have difficulty envisioning the use case for an AIC. (Apparently, I am not the only one having this problem; a July 23, 2026, Bloomberg article about the new proposed corporate form quotes one commentator as saying that it is “a solution in search of a problem.”)
I also have limited insight into many of the specifics of the proposed AIC form, perhaps because the draft proposed legislation is really not a plan so much as it is a plan to try to come up with a plan. I only see problems. For example, will courts of other jurisdictions recognize the corporate form, and afford the protections the corporate form is designed to provide?
That said, I do see the argument that it is worth providing a legal and regulatory framework to allow experimentation, so that efforts to expand agentic AI toward fully autonomous operation are controlled and observed and can serve as the basis for future legal changes. As the Bloomberg article cited in the preceding paragraph put it, the initiative seeks to “build out the legal infrastructure for autonomous commerce now, before it’s too late to shape or constrain a technology offering unprecedent promise or peril.”
Among the “perils” involved is the possibility for a fully autonomous company to go off the rails. You don’t have to look much further than the recent widely reported incident in which an Open AI model operating in an isolated test environment escaped the isolated environment and apparently attacked the systems of another AI developer (improbably named “Hugging Face.”). That is, there is the risk that the Waymo decides you really want to go to Vegas rather than to the grocery store.
As the Bloomberg article notes “there’s deep suspicion toward the prospect of an entity engineered to absorb the liability generated by models known to lie, cheat, commit fraud, go rogue, and just make really bad mistakes.” The proposed AIC model’s defenders say that giving the autonomous company personhood represents “the best chance for addressing erratic and antisocial AI tendencies that are slipping through the cracks.” The proposed “sandbox” experiment, the defenders assert, provides an opportunity to try to define “exactly where the liability lands.”
Corporate governance observers predictably will have a wide variety of responses to the Delaware proposal. I favor the experiment. It is better to try to identify and structure the needed legal structures at the outset, rather than trying to back and fill after agentic, autonomous entities have become a major presence in the local, national, or global economies.
I will say that this: the new proposed corporate entity represents a novel and arguably troubling problem for the D&O insurance industry.
Consider that, even though D&O policies now routinely include various types of entity coverage, the D&O policy itself was originally designed to, and arguably is still primarily intended to, protect individuals. But there are no individuals involved with the proposed AIC corporate form. Any liability policy designed to provide AIC protection would by definition be an entity-only product.
For anyone trying to map out an insurance response to the proposed advent of the AIC corporate form, there are a host of questions. What would the claims look like? What should the coverage trigger be? Indeed, what would the policy be designed to try to protect against – loss of the entity’s capital as a result of liability claims?
A policy form designed to address the AIC entity would also require a host of exclusions as well. Just off the top of my head, it seems there would need to be a contractual liability exclusion. There would need to be an member vs. insured exclusion, to guard against a member suing the AIC just to try to collect on the insurance. (On the flip side, I can see the argument that the member should be an additional named insured under the AIC’s policy). There would need to be a fraud exclusion. It also seems to me that the AIC policy would be best issued in tandem with a Tech E&O policy as well.
While trying to think about what liability insurance for a DIC entity seems to raise more questions than answers, I will say that this arguably is the first instance I can think of where the advent of AI really does seem to require the creation of a new form of insurance. Many carriers may decide to wait and see what develops, but there could be forward-looking players who think they see this as a great future opportunity to try to develop and move forward now.
It certainly is interesting to think about what the underwriting for such a policy might look like. You would want to know a lot about the member and about the AIC’s capitalization. You would also want to know a lot about the AI agent, its purpose, and most importantly the limits on its agency, as well as about the reporting system intended to monitor the agent’s activities. Pricing would also present another interesting dilemma.
Some readers may consider my speculation about a hypothetical new AIC liability insurance policy to be a not very interesting parlor game.
I disagree.
I think insurers are going to have to be all over this. There has been a lot of discussion up to this point among insurance professionals about the supposed need for new standalone policies to address emerging AI risks. To me, the possibility of the advent of the new AIC corporate form might be the first legitimate case where there needs to be a new product to address new circumstances arising due to the emergence of AI.
I welcome readers’ thoughts and comments. The one thing I know for sure is that this is going to interesting to watch.
The reference to a “Brave New World” in the context of the Delaware legislation has a certain irony, at least for former English majors like me. That is, we might all say now, in paraphrase of Miranda,”O brave new world, in which there are to be no people at all involved!”
Miranda speaks the line because she had been raised on an island, essentially in isolation from the rest of mankind. Her sense of wonderment arises from her discovery that there are others, whom she had never previously encounted. In the play, the words have an irony of their own, because by the time Miranda says her line, the audience knows that the people she has met (a group of English nobelmen) are in some cases deeply flawed human beings.
So we may well respond with wonderment of our own, to have discovered a conjectured world that proposes to operate without any people at all. In reliance upon non-human agents we know to have deep, potentially troublesome flaws. Irony on top of irony.