DECK · THE OPPORTUNITY · FOR AN ACTUARY

Do you have $1.2 billion of AI liability? A car crash is not semantic. All AI is. That one sentence is why the line cannot be written — and where it opens.

Six sections. Three bullets each, then the working underneath if you want it. The lattice on the right fills in as the argument earns each mark. Every number is the live output of a script in this repository, and the panels are rendered receipts of real commits — not illustrations of receipts. Where our own ledger seal is currently broken, §5 says so before you ask.

run it yourself → npx thetacog-mcp · node scripts/pmu/calibration-premium.mjs

01 · THE LINE NOBODY CAN WRITE
the number you cannot produce · a crash is not semantic · all AI is · what that forecloses

Do you have $1.2 billion of AI liability on your book? Nobody can tell you — and that is not a data problem.

  • "I am being asked to price whether the output was correct." That question is undecidable — Rice's theorem, permanently, not pending better models. No amount of compute converts an undecidable property into a rateable one, so any carrier writing against “accuracy” is writing against a quantity that does not exist.
  • "But scope is the question I have always actually asked." Professional liability has never insured whether the advice was right. It insures whether the professional acted within the scope they held out. That question is decidable positionally, at zero marginal cost — which is why the first writable AI line is E&O, not catastrophe.
  • "And a good outcome outside the role does not save it." If the surgeon turns plumber, the outcome is irrelevant. You did not pay for a plumber — and if it worked, that was luck, and luck is not responsibility. A success outside the lane is a gamble that happened to land, with your exposure as the stake. Correctness stays with the insured, exactly as seaworthiness stayed with the shipowner. The moment that question stops being debatable, the contract can be signed. Insurance is that signature.
STAGED01 / 06
THE RECEIPT · UNFOLDING01 / 06
Drift receipt for commit 09906e148 — intent, reality and delta rendered on the 144-cell lattice, with out-of-role regions encircled
09906e148TAPE vs GATE — the reasoning was deleted, restored, and guarded against being lost again. The tape records; the gate decides. Coverage attaches to the second one.
read the circles

Read the three panels as a claim file. INTENT is the scope the insured declared. REALITY is what the work actually touched. Δ is the disagreement — and the circles are where the act fell outside the declared scope. That is the only question professional liability has ever asked, and here it is answered by position rather than by testimony.

three panelsnew
INTENT from what the commit SAID · REALITY from where the code LANDED · Δ the disagreement. Left is the claim, middle is the act, right is the gap.

One of 3,395 rendered panels on this company's own repository. Check this one: git show 09906e148

On the number. $1.2bn is not an exotic figure and it is not ours — it is roughly two years of the regulatory ceiling alone, before a single claim. EU AI Act Article 71 penalties run to 3% of global annual turnover, which for a deployer above $20B revenue is a ~$600M annual ceiling that recurs every fiscal year the deployment fails oversight. Add the state basket now forming — Colorado SB24-205 live since February, with Texas, Connecticut, Illinois and California moving through 2026–27 — and the question stops being rhetorical. Ask your team for the number. The answer will not be a number.

Then walk it forward, because each step forecloses the next. If no event can be counted, no triangle can be built. If no triangle, no rate can be filed. If no rate, the responsible underwriting act is to exclude — which is exactly what every silent-AI carve-out in the market already is: a carrier saying in policy language that no distribution can be formed here. Knight called that uncertainty rather than risk, and insurers decline it by construction. So the exposure does not vanish; it relocates to your balance sheet at indeterminate value, and it compounds in both directions at once — deployment grows the exposure while renewal shrinks the cover.

And there is no engineering fix waiting. Rice's theorem (1953) says every non-trivial semantic property of a program is undecidable, and “did the agent do the right thing” is precisely such a property. Knight and Rice are the same wall in two vocabularies. This is why the honest version of the claim is narrow and permanent: correctness never becomes insurable, at any volume, on any hardware. Anyone promising otherwise is selling a distribution that cannot exist.

Which leaves exactly one question worth an afternoon. Is there anything about an AI act that is not semantic — one fact you could count without deciding what it meant? If there is, that single fact is the entire line: it is the event, the exposure base and the class plan at once. If there is not, this market never opens and no one should be raising money against it. §2 is the answer.

Why the luck clause is load-bearing rather than rhetorical. Without it a counterparty always has one exit: but it worked out. With it, even the success is a breach. This is the oldest moral logic in the industry, and it is Hartford Steam Boiler's: an uninspected boiler that did not explode was never safe — it was unexploded so far. Insurance has never priced the outcome; it prices the hazard, and the hazard is the position, not the result. So “it does not matter whether the outcome was correct” is not a rhetorical concession. It is the rating basis: the outcome carries zero information about responsibility; the position carries all of it.

The precedent is not an analogy — it is the same trade, and it is already owned by a reinsurer. HSB was founded on 30 June 1866 in Connecticut against a peril the market then called uninsurable: boilers were exploding semantically, adjudicated as negligence, endlessly debatable. HSB did not model the explosions. It inspected first and insured only inspected boilers. Losses collapsed, and the company held the line for a century. Munich Re completed its acquisition of HSB in April 2009. Classification societies are the same shape — “in class” is “in lane,” and withdrawal of class voids cover. We are not proposing a new model. We are re-running the oldest profitable one in the industry against a new peril. The gate is the inspection.

Professional liability has always adjudicated scope, never correctness — did the architect stamp outside their licence, the adviser recommend outside the mandate, the surgeon operate outside the consent. Decidable because the engagement was declared in advance. That is the shape §3 shows an AI act can also take.

Further: /deck/insure §2 develops Knight and Rice as one boundary; Three breach rates, one ledger shows why “the” breach rate is a frequency-selection question.

02 · THE LATTICE · ONE ADDRESS PER OBSERVATION
two axes · one address per act · the column is the file · reach is verify

Every observation has one address, and the column of addresses is the whole insurable slice.

  • "Can this be classified, or only described?" Rows and columns are the same categories, so a cell reads “this acted on that.” A coordinate is assigned, never scored. Classification without a scoring model is classification an insured cannot tune toward.
  • "Where would the gaps hide?" Nowhere. Every observation about a thing has exactly one address in its column, so a blank is visible as a blank rather than as an absent record. Completeness is structural, not evidentiary — there is no index that could be missing an entry.
  • "Who decided where this landed?" The address did. The panel beside this section is delegation routed by coordinate rather than by a hardcoded destination — nobody typed where the work should go, which is the difference between a classification and a preference.
STAGED02 / 06
THE RECEIPT · UNFOLDING02 / 06
Drift receipt for commit 0c1332290 — intent, reality and delta rendered on the 144-cell lattice, with out-of-role regions encircled
0c1332290QC delegation routed to the LENS-DETERMINED room — coordinate → room, not hardcoded. The address decided the destination; nobody typed it.
read the circles

Call one column "the surgeon." Every observation about that surgeon has exactly one address in it. So the question is never "was the surgery good" — undecidable, and not what you insure — it is "did this act land in the OR column or the plumbing column." A position, checked, in five seconds. Nothing to depose. And one act is many observations: the panel grades the whole shape they paint against the declared scope, to a stated tolerance. The address is the atom; the shape is the verdict.

three panels
INTENT from what the commit SAID · REALITY from where the code LANDED · Δ the disagreement. Left is the claim, middle is the act, right is the gap.
one cell = one addressnew
Both axes are the same 12 categories, so a cell reads "this acted on that." Position is the meaning — there is no lookup table underneath.

One of 3,395 rendered panels on this company's own repository. Check this one: git show 0c1332290

Why an address and not a score. A coordinate is assigned by where the act landed, not by an opinion about it — the same procedure, run again on the same artifact, returns the same cell. That is what an adjuster is actually asking for when they ask whether something was in scope: not a judgement they have to trust, a position they can recompute. Substitute “the billing agent” and “the customer record” for any two categories and nothing about the mechanics changes.

One act paints a shape, and the shape is what gets priced. An observation has one address; a single act is many observations, and together their addresses paint a region on the lattice. The declared scope is a region too. The verdict an adjuster recomputes is never “did one cell hit” — it is the whole painted shape against the whole declared shape: what fraction of the act's mass fired outside the declaration, against a stated tolerance. The receipts in §4 read that way — 35% off-lane against a 25% tolerance — not hit-or-miss. The single address is what makes the column a claim file; the shape against the tolerance is what makes the act priceable. Same recomputation, two granularities.

What the lattice does not say. A boundary crossing is not a breach. The lattice reports that an act crossed a declared category boundary; whether that particular crossing is covered is a wording decision, made by a human before inception. Keeping those two apart is the difference between an instrument and an opinion — and it is why this deck never colours a cell “in violation.”

Reach is verify. A party that organised the class plan never has to search it. An adjuster asked “was this in scope” today reconstructs intent from logs after the fact; here the coordinate was computed at the moment of the act, from the artifact itself, by a procedure with no model in it. Verification is not a second step performed on the finding — it is the finding. A CPU pulling one cache line is doing the same thing: sixty-four bytes that, in this geometry, are sixty-four bytes of aligned meaning.

Why 144 and not 9. Blow up any cell symmetrically and the same 3×3 returns inside it. Two levels gives 12 categories per axis, 12×12 = 144 cells — the resolution the receipts in §4 render at. It is also why a class plan of this shape refines without being redesigned: the sub-cells were always there.

The lattice is the same staged drawing /deck/8 uses, from one shared component — not a redrawing.

03 · WHY E&O AND NOT CATASTROPHE
the two questions · frequency · class · attribution

The big loss is not unwritable. It is unaddressed until gated — and E&O comes first because its lattice already exists.

  • "My whole file is post-hoc, and post-hoc is uninsurable." Obrioxia, GateBolt and Defenix all reconstruct after execution. The side-effect — the transfer, the API call, the exfiltration — has already completed. You cannot reserve against a control that runs after the loss.
  • "And the real-time ones share the failure domain." A reference monitor must be tamperproof, always invoked, and small enough to verify (Anderson, 1972). A guard model fails all three, so it is not a control in the sense your cyber book already uses the word. An agent with tool access is a credentialled insider, and that is a class your existing wordings never contemplated.
  • "A file whose blanks are loud is a file I can reserve against." The panel beside this section is the decisions block — every accept and every refusal-with-mechanism on the seal, empty ticks loudest. Nothing to subpoena, nothing to argue about later.
STAGED03 / 06
THE RECEIPT · UNFOLDING03 / 06
Drift receipt for commit 045475138 — intent, reality and delta rendered on the 144-cell lattice, with out-of-role regions encircled
045475138the decisions block — every accept and every refusal-with-mechanism on the seal, empty ticks loudest. A claim file whose blanks are visible is a claim file you can reserve against.
read the circles

What matters in this panel is the DARK cells, not the lit ones. A blank here is a blank you can see, because every observation has an address whether or not it fired. Compare that with a log: a missing log line and an event that never happened are indistinguishable, which is why post-hoc evidence cannot support a reserve.

three panels
INTENT from what the commit SAID · REALITY from where the code LANDED · Δ the disagreement. Left is the claim, middle is the act, right is the gap.
one cell = one address
Both axes are the same 12 categories, so a cell reads "this acted on that." Position is the meaning — there is no lookup table underneath.
the circlesnew
Out-of-role regions. Work that fired somewhere the stated intent never claimed. The circle is drawn by the walk, not by an author choosing what to highlight.

One of 3,395 rendered panels on this company's own repository. Check this one: git show 045475138

THE CLAIM FILE

The column IS the claim file, and its completeness is structural — there is no index that could be missing an entry. Nothing to subpoena, nothing to argue.

Why the claim file is the whole actuarial payoff. The Skye deck's sentence — every observation a sensor could ever return about something-relating-to-a-bat has a single address in this column — is a statement about addressing. Read by a claims department it is a statement about discovery: the file cannot be incomplete, because incompleteness would require an observation with no address, and the address is the observation. That does not make anyone right about the loss. It removes the argument about whether everything is on the table.

What this does not claim. Not that the agent was good, safe or aligned. Not a bound on the catastrophic tail. Not whether a given lane should have been in scope — that is a wording decision, made by a human, before inception. It tells you, afterwards and without dispute, whether the act stayed inside the wording that was agreed.

Why this ordering is also the commercial one. E&O is where the exclusions are being written right now, which means it is where the appetite gap is already priced and visible. A line carriers are actively carving out is a line with a named buyer. Silent-AI exclusions are, read correctly, an inventory list of everything a carrier could not see. We sell sight — so the ask is never “cover this anyway,” it is write the carve-back, for gated fleets only, with lane width as the rating variable. Every new class in the history of this industry entered a book that way.

The correction we owe the earlier version of this deck. It said catastrophe asks the undecidable question. That is wrong, and the right version is stronger: Knightian uncertainty is a property of the deployment, not of the loss. Ungated, a catastrophe has no cell, nothing to walk, and is genuinely unwritable. Gated, it acquires an address — the first out-of-lane transition — and everything after that is its severity column. E&O still comes first, but for a better reason than difficulty: E&O's lattice pre-exists, because the engagement declared the categories, while catastrophe's lattice must be installed.

So the trigger, if this line is ever written parametrically, is a compound decidable event. Gate live (heartbeat receipts — itself decidable, and coverage voids without them) and an unwhitelisted execution reached side-effect and loss above attachment inside the window. No intent, no meaning, and deliberately no causation clause — causation is precisely where semantics sneaks back into a contract, so the parametric form drops it and eats basis risk like every catastrophe bond already does. Severity is a column, never the trigger.

The move that makes “the gate failed to detect it” decidable is default-deny. If the lane is a whitelist, there is no blind spot by construction: anything unaddressed is out-of-lane without ever being understood. You never translate semantics into rules, which is lossy and gameable — you enumerate the permitted and deny the complement. Sandbox escape, egress to another organisation's infrastructure, credential exfiltration: none of those were ever going to be on a whitelist, and the gate does not need to know what “behaving like an attacker” means. So a detection failure always reduces to a divergence a stranger can check — recompute the signed trace against the signed spec; if it yields HALT where runtime yielded PASS, the gate failed.

And the inversion, which is where the margin actually is. Small errors sit near the lane boundary, where reasonable people argue — which is exactly why E&O adjusting is expensive. Catastrophes sit far outside it, which is why the world agrees about them within a news cycle. That ex-post unanimity is evidence the line was always common knowledge; what was missing was an instrument reading it at execution time. Severity correlates with address-distance from the lane, so the tail is the most decidable part of the book, not the least. The market prices it as the least.

Scope discipline, stated so nobody has to catch us on it: the parametric structure above is architecture, not anything built. There is no bond, no capacity, no trigger language and no ILS conversation. It is also ordering-constrained: a parametric trigger needs a measured trip rate, a trip rate needs gated fleets, and that is the same n from §5 doing double duty. The anti-exclusion clause anyone can sign is downstream of the divergence we can demonstrate.

04 · THE RECEIPTS · NOT AN ILLUSTRATION
what one looks like · how many exist · what makes it evidence

This is what an in-scope determination looks like when it is computed rather than argued.

  • "Is this an illustration or an artifact?" 3,395 rendered panels across 3,425 commit receipts, each a pure function of an immutable commit. Recompute one and the identical image returns — git show the sha beside this section and check the picture against the claim.
  • "Did they run it on themselves?" Yes, and it convicted them. The panel here is coherence made decidable returning a verdict against this company's own page, published rather than buried. That is the only credential available before a loss history exists.
  • "What this is not." An uptime record, not a loss history. Nobody was trying to get a claim paid. Said before you ask for it, because the version of this deck that blurred the two would not survive your first hour of diligence.
STAGED04 / 06
THE RECEIPT · UNFOLDING04 / 06
Drift receipt for commit 082dbe019 — intent, reality and delta rendered on the 144-cell lattice, with out-of-role regions encircled
082dbe019coherence made decidable — and it convicted our own page. The instrument ran on its owner and returned a verdict against him.
read the circles

These circles are drawn against us. That is the point worth ten diligence calls: the insured cannot suppress a verdict from a control it does not calibrate. Run it yourself on this commit and the identical circles return — the check does not care whose page it is reading.

three panels
INTENT from what the commit SAID · REALITY from where the code LANDED · Δ the disagreement. Left is the claim, middle is the act, right is the gap.
one cell = one address
Both axes are the same 12 categories, so a cell reads "this acted on that." Position is the meaning — there is no lookup table underneath.
the circles
Out-of-role regions. Work that fired somewhere the stated intent never claimed. The circle is drawn by the walk, not by an author choosing what to highlight.
lit but uncirclednew
In-lane. The act landed where the intent said it would. This is the whole positive claim — not that the work was good, only that it was where it said it would be.

One of 3,395 rendered panels on this company's own repository. Check this one: git show 082dbe019

THE CLAIM FILE

The column IS the claim file, and its completeness is structural — there is no index that could be missing an entry. Nothing to subpoena, nothing to argue.

Drift receipt for commit 0ecd77cf2: intent, reality and delta on the 144-cell lattice, out-of-role regions encircled
0ecd77cf2in-role concentration — intent and reality agree across the lit region
Drift receipt for commit 6c4effa5f: intent, reality and delta on the 144-cell lattice, out-of-role regions encircled
6c4effa5fa thin commit — direction-only, carrying σ, placement and lane; honestly sparse rather than blank
Drift receipt for commit a2e189e51: intent, reality and delta on the 144-cell lattice, out-of-role regions encircled
a2e189e51broad-scope commit — many cells lit, most in-role; breadth is not a defect signal
Drift receipt for commit d5c552806: intent, reality and delta on the 144-cell lattice, out-of-role regions encircled
d5c552806delta dominated by one block — the failure is localised, which is what makes it attributable
Drift receipt for commit fa9a59a5e: intent, reality and delta on the 144-cell lattice, out-of-role regions encircled
fa9a59a5eanother ordinary day on the ledger — the point is that there is no interesting one

Why a smoke alarm you set off yourself still counts for something. It proves the alarm works and has run continuously without maintenance. It is not a fire. We are the longest-running measured subject and we say plainly that this is an uptime record, not a loss history. The loss history is what the first carrier partnership produces, and it is the thing we do not yet have.

There are two kinds of proof on this page and they are not equally strong. Separating them is the honest thing and also the useful one. The first is arithmetic: the panel renders identically from the same commit, the Wilson interval follows from n and k, σ is a standard deviation of a recomputable series. None of it asks for trust and all of it transfers — the same maths holds on your data as on ours, because it is maths. The second is evidence: 3,395 panels, 180 priceable distinct commits, 5 breaches. That is voluminous, and it is one repository, self-observed, non-independent — it does not transfer at all. The arithmetic proves the instrument is not an opinion. The evidence proves only that we ran it on ourselves. Anyone conflating the two is overselling, including us.

Which exposes the largest inferential leap in the whole structure, and it is ours to name rather than yours to find. This ledger measures commits on a codebase. The policies contemplated in §6 would insure agent tool-calls in production. Same lattice, different substrate — and that transfer is assumed here, not demonstrated. Until a handful of runtime traces from a foreign system have been through the parser, every sentence about a “trip rate” is an analogy wearing a number's clothes. That is the first thing the pilot buys, ahead of n: not more of our data, but the first of anyone else's.

And the four facts diligence finds in hour one, so they belong in minute five: single founder; no FCAS signature on any rate; patent application 19/637,714 pending, not granted; and the one-line install has failed on at least one clean machine, so nothing here rests on you running it today — the demo that matters is your logs through our parser, and that ask needs no fix.

The property that matters to a claims department is that the panel is computed from the commit, never from the working tree, and with no model anywhere in its path. Two parties in dispute do not compare opinions about the artifact; each runs the same procedure over the same immutable input and gets the same image. That is the difference between an expert report and an arithmetic check.

05 · THE MATH, AT ITS SIMPLEST
strike · frequency · Wilson interval · volatility loading · the honesty gate

A strike, a frequency, a confidence interval, and a load. There is no fifth idea.

  • "Show me the rate, including what it excludes." 5 breach in 180 priceable rows = 2.8%, with 272 rows excluded and the exclusions named. An excluded row you can see is an excluded row you can argue with.
  • "Debatable until it isn't — what makes it stop?" Countability two parties can agree on without trusting each other. Nobody argues about an option's vega; they compute it from the same inputs and get the same number, so the debate moves to price rather than to fact. That is the whole transition. σ here is the standard deviation of driftPct — 1.15, recomputed byte-identically from the same commits, with no model anywhere in the path. An LLM confidence score can never be that, which is why one is a market variable and the other is an opinion with a decimal point.
  • "So how wide is it, and where does it stop being too wide?" CI [1.2%, 6.3%] — half-width 2.6% on n=180, as of 2026-08-13. Too wide to bind today, and that is the number a vendor would have rounded. The ledger appends on every commit, so re-run it and expect a different n. It binds at n ≈ 1038. Hold the observed rate, grow n, read the Wilson half-width: 1802.6%, 250 → 2.5%, 500 → 1.8%, 1000 → 1.2%. Bindable at under 1% arrives at n ≈ 1038 distinct commits — 10% of a single agent-year, about 38 agent-days. (An earlier draft said 340 — that was computed from the withdrawn raw-row rate; the honest deduped rate moves the bar, and we would rather move it in public than defend it in diligence.) One assumption, stated not buried: the observed rate is held constant, so if the true rate is higher this is a floor on n, never a ceiling. node scripts/pmu/wilson-n-to-bind.mjs
STAGED05 / 06
THE RECEIPT · UNFOLDING05 / 06
Drift receipt for commit 13d74aa64 — intent, reality and delta rendered on the 144-cell lattice, with out-of-role regions encircled
13d74aa64lane-candidate analysis — a load-bearing NEGATIVE result. The rate that failed to clear its target, published as-is.
read the circles

Every circled region across the corpus is one countable event, which is what turns pictures into a rate: breaches over priceable rows. This particular panel is the unflattering one, published unchanged, because a frequency you only report when it suits you is not a frequency an actuary can use.

three panels
INTENT from what the commit SAID · REALITY from where the code LANDED · Δ the disagreement. Left is the claim, middle is the act, right is the gap.
one cell = one address
Both axes are the same 12 categories, so a cell reads "this acted on that." Position is the meaning — there is no lookup table underneath.
the circles
Out-of-role regions. Work that fired somewhere the stated intent never claimed. The circle is drawn by the walk, not by an author choosing what to highlight.
lit but uncircled
In-lane. The act landed where the intent said it would. This is the whole positive claim — not that the work was good, only that it was where it said it would be.
off-lane %new
The countable quantity. Not a quality score and not a defect rate — the share of the act that fell outside its declared scope. This is the number that meters.

One of 3,395 rendered panels on this company's own repository. Check this one: git show 13d74aa64

THE CLAIM FILE

The column IS the claim file, and its completeness is structural — there is no index that could be missing an entry. Nothing to subpoena, nothing to argue.

in laneK = 4.668% driftPct
ledger data/pmu/measure-history.ndjson
rows 564 total · 180 priceable · 272 excluded (ingestSuspect)
K (strike) driftPct > 4.668% = the loss event
breaches 5 (empirical rate 2.8%)
Wilson 95% [1.2%, 6.3%] half-width 2.6%
σ semantic 1.15 (stddev of driftPct)
PREMIUM 71.2 units → PRICED: CI tight enough to write against.
seal ⚠ ROOT MISMATCH at time of writing — see below.

The honesty gate, stated before you find it. Running the engine to source the numbers above returns a seal warning we do not edit out: the ed25519 root over the priced rows no longer matches, meaning a row was altered, inserted or removed outside the sealed path. The frequency above is what the current rows say; the chain-of-custody claim is, right now, false for us. We are not quietly re-sealing before you read this. A seal only checked when convenient is not a seal — so treat 71.2 units as directionally right and not yet the number that goes in a filing.

Rows we refuse to price. 272 of 564 are flagged ingest-suspect and excluded entirely rather than blended in. A blended number would let the clean half hide the unclean half, and the first thing a reviewing actuary would do is ask for the split — so the split is the default output.

Why σ never prices alone. There are two σ's here and conflating them is the easiest mistake available: semantic volatility (how far drift wanders once it wanders) is a loading factor; measurement precision is instrument sharpness, reported but never priced. Frequency prices. Volatility loads. Precision is diagnostics.

Source: scripts/pmu/calibration-premium.mjs, design rule in docs/strategy/underwriter-ecosystem-spec.md §IX.2.

06 · WHERE THE MONEY IS
loss adjustment · exposure base · the class plan · what would falsify this

The economics are not in the premium. They are in the loss adjustment that never happens.

  • "Who pays, and why would they?" The deployer buys because their carrier asks, not because a vendor called. The party holding the loss has the incentive to mandate the instrument and already owns the relationship — which is why this is a two-signature motion rather than an enterprise funnel.
  • "And the unit — was that derived or chosen?" Derived. The lattice is 144×144 = 20,736 cells; canon caps responsible fill at 70% ≈ 14,500 distinguishable placements, so the cap is 10,000 attestations per agent-year with headroom. $20 ÷ 10,000 = $0.002 per insurable decision, at ~100% margin because it runs on the licensee's own silicon. A price that falls out of the instrument's resolution is a price procurement cannot argue down to zero. On your book it converts an uninsurable declination into a rateable line at a metered exposure — σ 1.15, strike 4.668% driftPct, premium 71.2.
  • "What am I being asked for today?" Not capacity. One scoped pilot that produces a placement distribution against real deployments — the loss basis nobody in this category has, including us. At 38 agent-days to a bindable interval, that pilot is the machine that produces n, not a request for patience.
STAGED06 / 06
THE RECEIPT · UNFOLDING06 / 06
Drift receipt for commit 006826757 — intent, reality and delta rendered on the 144-cell lattice, with out-of-role regions encircled
006826757demand eats the coverage frontier — targets scoped to the worst-gripped sections, full lanes skipped with a stated reason. Exposure is metered and the gaps are named rather than averaged away.
read the circles

The uncircled-but-unlit regions are the exclusions, and they are visible instead of averaged into the rate. An exclusion you can point at is an exclusion your reinsurer can price. That is the difference between a metered exposure and a blended one.

three panels
INTENT from what the commit SAID · REALITY from where the code LANDED · Δ the disagreement. Left is the claim, middle is the act, right is the gap.
one cell = one address
Both axes are the same 12 categories, so a cell reads "this acted on that." Position is the meaning — there is no lookup table underneath.
the circles
Out-of-role regions. Work that fired somewhere the stated intent never claimed. The circle is drawn by the walk, not by an author choosing what to highlight.
lit but uncircled
In-lane. The act landed where the intent said it would. This is the whole positive claim — not that the work was good, only that it was where it said it would be.
off-lane %
The countable quantity. Not a quality score and not a defect rate — the share of the act that fell outside its declared scope. This is the number that meters.
no model in the verdictnew
Recompute it and the identical image returns, because nothing here asked a model what it thought. That is what makes it evidence rather than an opinion with a chart.

One of 3,395 rendered panels on this company's own repository. Check this one: git show 006826757

THE CLAIM FILE

The column IS the claim file, and its completeness is structural — there is no index that could be missing an entry. Nothing to subpoena, nothing to argue.

in laneK = 4.668% driftPct

5/180 = 2.8% · CI [1.2%, 6.3%] · σ 1.15PREMIUM 71.2

Why adjustment cost is the real subject. A coverage dispute is expensive because both sides reconstruct intent from artifacts never designed to record it, long after the fact, with money already on the table. The instrument moves that determination to the moment of the act, when nobody yet has a position to defend, and makes it recomputable afterwards by either side. That does not make claims cheaper to pay. It makes them cheap to decide — and in a line that does not exist yet, decidability is what stands between here and a filed rate.

What is actually missing. Not technology. The measurement is published, MIT-licensed, and running air-gapped on machines belonging to people we have never met. What is missing is paper (the right to bind), an actuary (the right to sign the first rate), and a channel (two or three carrier signatures rather than three hundred enterprise sales). If you are reading this deck, you are the second item.

What would have to be true for this to be worth your afternoon. That scope is genuinely separable from correctness — §1 and §3. That the coordinate is genuinely reproducible — §4, testable in ten minutes. That the frequency interval genuinely tightens with volume rather than plateauing — §5, and the open empirical question. The third is the one we would attack first if we were you.

Deeper: /deck/insure for the carrier structure and the raise · /deck/8 for the full lattice walk · npx thetacog-mcp to run the measurement on your own repository.

ThetaDriven Inc. · Elias Moosman · elias@thetadriven.com
Patent US 19/637,714 (pending) · the measurement is open so it can be checked; the instrument on top of it is licensed
Companion to /deck/insure (the carrier + licence structure) and /deck/8 (the full lattice walk).