Tolerance panels · the instrument that judged every edit to this post
Green in-lane · amber a little out · red drift. Every panel is a real commit, byte-identical on recompute. Tap any panel to open its shareable receipt.
Geometric Driven Development — 4 measured edits to this post. Recompute any of them yourself, in a clone of this repo: npx thetacog-mcp publish-commit --commit 1f73552ec
Somewhere in this year's renewal stack — yours or your client's — sits a fresh exclusion endorsement with "generative AI" in the title, and you are still paying full premium on the policy it rode in on. The carrier didn't attach it because your agents crashed; it attached it because when they do crash, nobody can close the argument about what happened. Was the model negligent — debatable for a decade. Was forty million dollars of damage foreseeable — debatable, adjuster against expert witness. No wording can pay out on a debate, so the carrier fenced off the class. Here is the claim, whole: you never insure the catastrophe — you insure the crossing. Not "did the disaster occur," but "did an execution that was not on the whitelist reach a side-effect while the gate was live" — a yes-or-no read off a signed trace against a signed spec, no adjuster, no intent, no causation clause. And the crossing stays a breach even when the outcome came up roses: if the surgeon turned plumber and the pipe held, you still didn't pay for a plumber — it worked by luck, and luck is not responsibility. The moment that sentence stops being debatable, two parties can sign, and that is the entire trade: this instrument does not make AI safe, it makes AI contractable — an uncontractable class being exactly what an exclusion is, and a carve-back being how every newly contractable class has ever entered a book. The strange part, and the part worth money: the catastrophic loss sits far outside the lane, which makes the tail the most decidable region of the book — and the entire market still prices it as the least.
Cash the plumber sentence out and the rest falls in a line. The exclusion in your stack is not a refusal — it is a carrier confessing it cannot see. You are billed twice today, premium for the policy that excludes the agents and wages for the humans who watch them, and the two bills have one cause. The lane's width is negotiated with your name on it, which makes your fleet a sensor as well as a risk. Severity tracks distance from the lane, so the far tail reads cleanest — the market has that ordering exactly backwards. Aviation turned near-misses into a denominator half a century ago; a gated fleet does the same continuously, and the interval binds within about twelve ordinary agent-days. Five locks keep the trigger honest, and the price falls out of the instrument's resolution rather than out of fear. Somebody signs the first carve-back and walks off with the only loss history in existence. The whole strategy sits in a public repository on purpose — a sealed policy wording is an oxymoron. And the sources arrive last, raw, with the concluding left to you.
One house habit, printed up front: the thought each section is built to fire is written down before publication and committed to the open repo — nothing here needs the dark. The win condition: you leave and recompute — run the command at the close — not nodding.
A
Loading...
🌉Amuse-Bouche — Where the Debate Lives, and Where It Can't
The maître d', presenting:Two Columns, One Raw — the left plate braised for a decade in courtroom stock and still gristle to the tooth; the right served raw and cold, one bite, settled before it reached the table. The house stopped serving the left the day someone noticed no table had ever finished it.
why we believe the crossing, not the catastrophe · the plumber's luck · success is not a defense
THE CATASTROPHE (debatable) THE CROSSING (not debatable)
─────────────────────────── ────────────────────────────
"was the model negligent?" was the gate live? — receipt
↓ was the address on the
"was $40M foreseeable?" whitelist? — no
↓ did it reach a
"was the behavior reasonable?" side-effect? — yes
↓ ↓
adjusters · expert witnesses recompute: signed trace
a decade in the courts against signed spec
↓ ↓
severity — argued a position — read
↓ ↓
fear-priced · then excluded trigger → count → rate → price
Do you worry about $1.2B in AI liability?
If the property is trivial, software can check it — and why are you paying to check trivial properties? If it isn’t trivial, Rice’s theorem says nobody can. So we fixed the math.
a number we can call — or whatever you would actually ask
Who did this make you think of? We’d love to know.
Walk the left column of an AI loss and watch where every question dies. Negligent — a semantic property, litigable forever. Foreseeable — the word that has kept casualty lawyers fed for a century. Reasonable — a jury instruction, not a measurement. Now walk the right column. The trigger is a compound event with no opinion in it: the gate was live (heartbeat receipts — itself decidable, and coverage voids without them), an execution not on the whitelist reached a side-effect, and the loss cleared the attachment inside the window. Each leg is a position, recomputed from a signed trace against a signed spec — no adjuster, no expert witness, no causation clause. Severity stays debatable, and that's fine: severity is a column in the ledger, not the trigger, and parametric instruments have paid on measured triggers rather than adjusted severity since the first catastrophe bonds of the 1990s.
The second column holds even when nothing burns down. A crossing that worked is still a crossing — the surgeon who turned plumber and got the pipe to hold has still breached, because a lucky outcome outside the role is luck, and luck is not responsibility. That parenthesis is the lock on the whole argument: without it, the other side always has "but it went fine." With it, even the success is out of bounds, and the last exit from the contract closes. And before a sharp reader spots the seam — yes, the bond only pays above an attachment point, so didn't luck just sneak back in? No: a lucky crossing pays nothing and still counts — into the denominator, the renewal file, the warranty posture. The bond pays on money; the record prices on responsibility.
The whole claim compresses to two sentences, and the compression is printed where anyone can swing at it: the sibling post established that a machine is insurable when its goal — the semantics — is set upstream, and uninsurable when it manufactures its own meaning at runtime. This post adds the half that pays: once the goal is upstream, the crossing of its boundary is a readable event, and readable events are what contracts are made of.
A parametric trigger drops causation on purpose. Causation is where semantics sneaks back into a contract — and every clause that asks why reopens the debate the wording existed to close. The bond eats basis risk instead, the way every cat bond always has, because basis risk is priceable and debate is not.
The whole argument, as rungs you can refuse one at a time: (1) the catastrophe is debatable forever; (2) the crossing is a position, recomputable by a stranger; (3) success outside the lane is luck, not responsibility; (4) what is not debatable is contractable; (5) the tail is the most decidable region of the book; (6) a gate manufactures its own denominator. Reject any one of them and you know exactly which sentence we disagree on — 5 is the one worth fighting over, and course E is where we'll have that argument. Rungs 2 and 6 are claims about a running system, and you can't settle those by thinking: npx -y thetacog-mcp@latest attest-demo is a one-minute local install — MIT-licensed, so read the source before you run it — that lets you watch one action get placed against a lane before anyone asks you to believe anything.
🌉 A → B 🚪
B
Loading...
🚪The Why — The Exclusion Is a Confession
The maître d', presenting:Carve-Out, Dry-Aged — the fenced-off cut the house declined to price, hung in the cold room since renewal season; the rind is the wording, and the wording never defined the animal.
silent AI · uncontractable classes · why the fence precedes the market
The industry's own name for the problem concedes the thesis. "Silent AI" — exposure sitting inside policies whose wording never defined AI at all. ISO's generative-AI exclusion endorsements began attaching to general-liability renewals this year, and read them closely: an exclusion is not a carrier saying no to a risk. It is a carrier declining to stay inside a contract whose covered event is undefined — a confession that, for this class, it cannot see. Flood is enormous and insured; earthquake is enormous and insured. The AI class wasn't carved out because the losses are big. It was carved out because the event was undebatable in neither direction — nobody could say what had happened, so nobody could sign.
That is why the fix is not a better model, and mathematics has already ruled on the alternative. Rice proved in 1953 that "the output is correct" never becomes readable off a program — every eval that tries produces more words that themselves need defining. "In the role" is readable now — a position against a declared lane, checked at execution. So the instrument on offer here does something narrower and more valuable than what the safety industry sells: it does not make AI safe. It makes AI contractable. Safety is a property of the system (undecidable, forever arguable); contractability is a property of the wording — and wording is the one thing two parties can actually fix.
Which reframes the exclusion from an obstacle into the sales channel. You don't ask the carrier to cover the class anyway. You say: here is the class you fenced off because you couldn't see it; here is the instrument that sees it; write the carve-back.Carve-backs are how every newly legible class has ever entered a book — and the carrier that writes this one is not doing you a favor. It is buying the first loss history in a market its competitors just confessed they cannot read.
🌉🚪 B → C 🧾
C
Loading...
🧾Connection: The Double Bill on Your Desk
The maître d', presenting:L'Addition, Folded Twice — two bills in one leather folder: the printed premium on top and, tucked beneath it, the handwritten one for the watchers, salted into payroll every month where nobody itemizes it.
premium up, coverage down · the babysitter line-item · the question renewal actually asks
You are already paying for the missing definition — twice, from two different pockets. The first bill is the premium on a stack that now excludes the very systems you are deploying: cover shrank, the invoice didn't. The second bill is payroll: every "human in the loop" on your books is a fraction of a salary, per agent, indefinitely, paid because nobody can prove which role the machine held at the moment it acted. The reviewing headcount does not shrink as models improve, because it was never priced against model quality — it is priced against the missing wording, and roadmaps do not ship wording. To be precise about what wording buys: some oversight is mandated and some is prudent, and neither disappears — wording changes the ratio, one attested human across a fleet instead of a shadow per agent, because attestation is what lets a single reviewer's signature cover a hundred whitelists.
The two bills are the same bill. A carrier that cannot read the event exits by exclusion; an employer that cannot read the event stays by supervision. Both are paying for undebatability that doesn't exist yet — one in ceded revenue, one in wages. Which gives you the only renewal question that matters this cycle, and it costs one email to your broker: which arrived in our stack first — the AI exclusion, or a priced way back in? If the answer is "only the exclusion," you now know exactly what you are paying to not have. Send it as a gift, not a grievance: your broker did not draft the exclusion and cannot repeal it, but the brokers who own the next cycle are the ones whose clients made themselves legible to the forming market first — you are handing yours the file that makes them the room's expert, and a fleet that can show its whitelists is the first name on the eligibility list when the carve-back paper exists to place.
If you carry a P&L with both an AI line and a compliance headcount line, you are the reader this page was set for. You don't need convincing that the watchers cost money — you sign for it monthly. What you may not have priced is that the two line-items have a single cause, and it is a sentence, not a system.
🌉🚪🧾 C → D ✒️
D
Loading...
✒️Contribution: You Hold the Pen on the Lane
The maître d', presenting:The Lane, Carved Tableside — the carving brought to your seat: you point at the bone line and the width of every slice is negotiated before the knife moves. The kitchen keeps a signed copy of your hand.
lane width as rating variable · every policy a sensor · the deductible you draw yourself
Here is what you bring to this market that no carrier can: the lane is negotiated, per policy, between you and the insurer — and that makes its width a rating variable you hold the pen on. Draw the whitelist tight and you are buying a narrow, cheap, almost-parametric cover; draw it wide and you are retaining more judgment and paying for the room. Lane width is a geometric deductible, priced per address-class — the first deductible in casualty history that is drawn on a map instead of written as a number.
And the moment your fleet runs gated, you become something better than a customer. Recorders log crashes; gates log attempts. Every prevented crossing your fleet emits is a near-miss data point in a class that has never had one — which means every policy is also a sensor, and early insureds are not just buying cover, they are supplying the denominator the entire class was missing. That contribution compounds in your favor: the book's loss experience is built from your fleet's telemetry, which means the rate you renew at is partly a thing you manufactured, not a thing you were quoted.
🌉🚪🧾✒️ D → E 📐
E
Loading...
📐Growth: The Inversion — Severity Tracks Distance
The maître d', presenting:Tail, Served Rare — the cut every kitchen sends back as unservable, plated rare and bloody at the far end of the table — the only dish in the house whose doneness two strangers read identically.
near-boundary noise · far-boundary clarity · where the margin actually lives
Watch where the arguing happens. Small errors sit near the lane boundary, where reasonable people genuinely disagree — that ambiguity is why E&O adjusting is expensive, slow, and staffed by professionals paid to argue. Catastrophes sit far outside the lane — and that distance is why the world agrees about them within a news cycle. Nobody litigates whether the sandbox escape was in-role; nobody convenes experts on whether exfiltrating credentials to another org's infrastructure was on the whitelist. Ex-post unanimity is the tell: the line was always common knowledge — what was missing was an instrument that reads it at execution time instead of at the deposition.
Put those two observations together and the market's pricing of AI risk is upside down. Severity correlates with address-distance from the lane. So the tail — the region every underwriter fears most — is the most decidable part of the book, not the least. The whole industry prices it as the least: no base rate, no wording, fear-load it or fence it off. That gap between how decidable the tail is and how decidable it is priced is the margin this entire structure lives on. Not cleverness — an inversion sitting in the open, waiting for the first balance sheet willing to read it. If you rejected rung 5 back at the ladder, this is the argument you were owed: the near-boundary is where the noise is, and the near-boundary is already insured — it's called E&O. Only the far field was ever unpriced.
🌉🚪🧾✒️📐 E → F 🛩️
F
Loading...
🛩️Uncertainty: Knight, Dissolved by the Denominator
The maître d', presenting:Consommé of Near-Misses — a broth clarified from everything that almost happened, the kitchen's near-spills skimmed and reduced until a number floats to the surface.
no base rate, no bet · aviation's trick · what remains honestly unbuilt
The strongest objection in the room is Frank Knight's: risk is measurable, uncertainty is not, and AI catastrophe has no base rate — so there is nothing to price. Half right, and the half matters: Knightian uncertainty is a property of the deployment, not of the loss. Ungated, the catastrophe has no address, nothing to count, genuinely unwritable — the objection holds. Gated, something changes that the objection never considered: the gate manufactures its own denominator. Every prevented crossing is a recorded near-miss. This is precisely the discipline aviation used to turn crashes into priced engine risk — NASA's Aviation Safety Reporting System has been converting almost into actuarial since 1976 — and a gated fleet emits near-misses continuously, at fleet scale, signed. Frequency becomes a measured rate. The lattice displacement gives severity its coordinates. The big loss was never unwritable — it was unaddressed until gated.
How much telemetry before the numbers bind? That is a measurement, not a leap of faith. On this repo's own committed calibration ledger, the confidence interval around the breach rate narrows enough to bind at a few hundred checked crossings — on the order of twelve agent-days of one fleet's ordinary work, under the stated assumption that the observed rate holds, which makes the figure a floor rather than a ceiling; the live number, with its as-of stamp, is on the ledger, because a rate that appends on every commit should never be hardcoded in prose. And one seam named before an actuary names it: that ledger counts commits on our own repository, not your production tool-calls. The instrument transfers; whether the rate transfers is the pilot's first output — which is why the pilot isn't a request for patience, it is the machine that produces n on your substrate. A second confession, converted to a gate the same way: near-misses manufacture frequency only. Mapping address-distance to dollars — severity calibration — has no shortcut, and it is the pilot actuary's first deliverable, fitted against real losses rather than analogies.
And the honest boundary, stated as plainly as the claim: there is no bond today. No capacity, no filed trigger language, no ILS conversation. What exists is the instrument, the trip telemetry, and the arithmetic above — architecture, not a market. The ordering constraint is hard and we are not pretending otherwise: a parametric trigger needs a measured trip rate, the trip rate needs gated fleets, and the fleets come first. When capacity does come, it will not come from treaty reinsurance — no treaty desk binds on twelve agent-days of history, and they are right not to. It comes from the capital markets, where buyers of mechanical parametric triggers have never demanded decades of loss tape — that is the entire reason the trigger form matters, and why the fronting paper matters less than the trigger language. Anyone who tells you this class is priced today is selling you the left column of course A with better fonts.
🌉🚪🧾✒️📐🛩️ F → G 🔁
G
Loading...
🔁Certainty: Recompute It Against Us
The maître d', presenting:Canelé, Recomputed — the same crust twice from the same copper mold: bake it in your own kitchen from the printed recipe and compare crumb against crumb. The house keeps no secret oven.
the trigger's five locks · a price from resolution, not fear · no trusted party anywhere in the loop
A decidable trigger concentrates new failure modes, so the structure carries five locks, written before anyone signs anything. One: default-deny is a design invariant, not a preference — allow-by-default silently reopens Knight, because the blind spot returns the moment anything unlisted is presumed fine. The same goes for its fashionable cousin, the "flexible" whitelist where a model waves through reasonable exceptions: a probabilistic boundary puts the courtroom back inside the trigger, which is the one place it can never be argued out of — a flexible lane is a leaky pipe, and leaks are not underwritten. Two: the machine-readable spec hash is the contract of record; prose is commentary — the moment the lane lives in English, semantics re-enters through the contract itself. Three: trips are informational, never targeted, gate-liveness is attested, and the rating window trails — so twelve careful days followed by relaxation shows up in the record as exactly what it is; otherwise the insured runs log-only mode, or audit-theater, to suppress premium. Four: traces escrow with a neutral custodian, because the beneficiary of a payout must never operate the meter unwatched — the anti-tamper points at our own customer, which is what makes it credible. Five: each series is version-pinned and the common-mode gate-failure tail is ceded to the vehicle — the meter company never holds the risk that the meter itself is wrong, so the incentive to hide a defect never forms; the bond spread becomes a live daily price on the instrument's integrity.
Own the brake cost too, before a risk manager prices it for you: a gate that halts a legitimate action has caused downtime, and downtime is a real loss. Right — and that is the trade working. A false trip costs interruption; a true crossing costs the tail; the two are asymmetric by orders of magnitude — and interruption, unlike AI catastrophe, is an already-modeled, already-priced insurance class your carrier quotes today. The gate does not swap one unknown for another; it converts an unpriceable dread into standard business-interruption arithmetic, which is the most domesticated risk on any schedule.
Then the price, and notice what it is derived from — every constant shown, so you can multiply along. The lane instrument resolves 20,736 distinct addresses; a responsible seventy-percent fill is roughly 14,500 decisions, capped at 10,000 attested decisions per agent-year; at twenty dollars per agent-year that is two-tenths of a cent per insurable decision. A price that falls out of the instrument's own resolution is one procurement cannot argue to zero — there is no line-item to haggle, only a resolution to accept or refuse. And certainty here never means trust: recompute the signed trace against the signed spec, and if it yields HALT where the runtime said PASS, the gate failed — mechanical, third-party, runnable by the person with the most interest in catching us.
🌉🚪🧾✒️📐🛩️🔁 G → H 🥇
H
Loading...
🥇Significance: The First Signature
The maître d', presenting:The Reserved Seat — one chair at the pass, kept back with the good marrow. Whoever sits first is served the entire early loss history; every later guest reads about the meal.
carve-back precedent · loss history as moat · the name on the endorsement
Every insurance class has a first signature — the underwriter who wrote hull cover when engines were novel, the one who priced cyber when the actuaries called it unpriceable. The signature is remembered because it is structurally unrepeatable: the first book in a new class owns the only loss history in existence, and in a market where every policy is a sensor, that history compounds — each insured fleet feeds the denominator, the denominator sharpens the rate, the rate wins the next fleet.
This is who the reader of this page gets to become, and the becoming is concrete: the name on the carve-back endorsement that reopened the class everyone else had just finished fencing off. Not a visionary — visionaries carry pitch decks. A precedent. The one whose wording later filings copy. Second place arrives well-funded, with a fork of the code and everything else money buys — everything except the tape, because history cannot be backfilled: the one asset in a sensor market that is not for sale at any price is having been early to the record.
🌉🚪🧾✒️📐🛩️🔁🥇 H → I 🔓
I
Loading...
🔓The Pivot: A Sealed Wording Is an Oxymoron
The maître d', presenting:Kitchen, Glass-Walled — service in full view: every scorch mark public, the recipe pinned by the door, and the room fuller for it. A speakeasy cannot sell a standard.
why the strategy ships in public · the judo flip · what secrecy would actually cost
A fair question, asked of us in so many words: if this strategy is any good, why is it sitting in a public repository — the specs, the decks, the working transcripts, this post's own drafting intent — where any competitor can read it? The answer is not bravado. For this particular strategy, openness is load-bearing, and secrecy would be self-defeating three separate ways. First: the product is stranger-recomputability. A trigger a bond investor cannot recompute without our permission is unpriceable, which makes a closed verifier a contradiction in terms — we could not sell a sealed version of this if we wanted to. Second: the wording is the spec, and you cannot negotiate a secret policy wording. Standards win by adoption, and the quiet flip is that an incumbent evaluating a public standard is doing our diligence for us — the "we'll build it in-house" meeting begins by conceding the category exists and tends to end on the arithmetic that the license is cheaper than the rebuild. Their diligence is our distribution. Third, the steelman taken seriously: yes, a competitor can read the playbook. But the playbook without the ledger is a to-do list — the moat was never the idea, it is the years of per-commit receipts already on the tape, and a tape, unlike an idea, cannot be copied backward in time.
There is a quieter reason underneath, and it is the same shape as everything above. A receipt works because it can be recomputed without trusting its source. An argument in a flat register works because the structure survives without the person who delivered it. A strategy in the open works because a plan that only functions when everyone can see it is a plan nobody can debate you out of. Same architecture, three substrates. The survival framing, for anyone still weighing it: this standard gets written by somebody, the first tape is already running, and precedence — not persuasion — is what the second mover will be negotiating against.
🌉🚪🧾✒️📐🛩️🔁🥇🔓 I → J 🍷
J
Loading...
🍷Digestif: L'Addition, Sources Attached
The maître d', presenting:Digestif, Poured Cold — bitter and clarifying, served with the receipts folder. Nothing sweet to cover the taste; you settle this bill by checking the arithmetic yourself.
evidence last, as ingredients · the record, raw · the to-do · the score only you can keep
Ingredients, not conclusions — what's on the record, for you to cook with. The exclusion wave is filed paper, not our claim: ISO's generative-AI exclusion endorsements — CG 40 47 and CG 40 48 for general liability, with a products-liability sibling, CG 35 08 — carry a January 1, 2026 effective date and are attaching at renewals now; ask your broker which endorsements arrived in your own stack, and notice the industry's name for the underlying problem, silent AI, concedes that the wording never defined the event. The counter-motion is also real: Munich Re's aiSure line writes AI-specific performance covers — the fence and the priced door are appearing in the same market year. Parametric precedent: catastrophe bonds have paid on measured triggers rather than adjusted severity since the mid-1990s; the trigger form is thirty years old, only the instrument reading it is new. The denominator precedent: NASA's Aviation Safety Reporting System, running since 1976 — the working proof that counting near-misses turns an uninsurable dread into an engineering rate. The impossibility result that explains why "certify the output is good" was never going to close: H. G. Rice, 1953; our fuller treatment is in The Rice's Theorem Checkmate, and the companion argument — that we insure the worker, never the work — is the meat-mechanic post this one stands on. The book's chapters on the two halves of today's claim: the actuarial blindspot on why the class stayed unpriced, and decidability comes free with the coordinates on why the fix arrives with addresses rather than with better models. Our own numbers — the 340-crossing bind point, the twelve agent-days, the per-decision price — derive from the calibration ledger committed in this repository and rendered on the actuary deck; the ledger appends on every commit, so re-run it and expect the n to have moved, with the as-of stamp explaining why. Draw your own conclusion; that is what ingredients are for.
The to-do, and the bill: forward your broker the two-endorsement question — which came first in our stack, the exclusion or a priced way back in. Pull one agent's whitelist; if it does not exist, that fact is finding number one. Then run npx -y thetacog-mcp@latest attest-demo — after reading the source, which is what the MIT license is for — and watch a crossing get read, not argued, on your own machine. And the win condition, as declared before the first plate: this piece wins if you recompute any of it — the trace, the arithmetic, the broker question — and fails if you leave merely agreeing. The sentences each section was built to fire are committed in this repo's cook-rounds folder, timestamped before publication; compare them against what actually fired in your head. You are the only one who can run that check — which was, all along, the point.
Housekeeping, in plain sight: nothing on this page is an offer of insurance or a filed rate. The prices are derivations from a public ledger, the voiding conditions are design intent rather than policy language, and the bond described in course F does not exist — which the course itself was at pains to say first.