💳 Fund Autonomy Ledgernot signed in🔑 Sign in

Published in advance · mitigated before it fires

The playbook.

The target is the claim — never the person, never the vocabulary. A public false claim about AI safety or capability is fair game, and there are channels with real enforcement power. This is not a softening; it is a large upgrade in leverage. An invoice gets ignored. A filed complaint gets answered, because non-participation is itself published. You wanted a mechanism where silence has consequences — here silence is the finding.

The attackable target — we win by default

The claim, stated so you can swing at it: a public statement that an AI system is safe, controlled, or certain — made without a receipt a stranger can recompute — is not verifiable, and the market has already priced that as uninsurable. Refute it — run the command, publish the result — and we amplify your refutation, on the record, gladly, because being wrong in public is the whole point of a falsifiable instrument. Ignoring it is of course available, and it is the default; what ignoring does not do is remove the claim from the register. The only move that takes it off the record is an answer. That is what “win by default” means: silence is not a rebuttal, it is an entry, and the one way to clear the entry is to prove us wrong — which we will hand you the tools to try.

The governing constraint on every rung below: it ships with its mitigation live before it fires, and the mitigation costs more than the rung reaches. A ladder you can see is not a threat — it is a disclosed standing process, the same for everyone, and every rung can survive being read aloud by the party it is aimed at.

The sequence.

The ladder below escalates against a single claim. It is not the strategy — it is the demand generation, and it has a ceiling. The strategy is the five phases here, each one gated on the last, and the correction worth stating before anyone reads a rung: the ladder does not recruit; it corners. The people who gain from the record recruit, one warm hand at a time, until a carrier requirement arrives without us in the room. Both run at once. Until 2026-09-28 this paragraph said phase 2, the carrier requirement, was the whole board. We measured it, and it is struck below with the date and the reason rather than deleted, so you can see what we believed and what corrected it.

  1. 1The instrument survives being run by a stranger

    Gate — what must be true before this opens
    Rung 0 standing, and the five unforced errors below closed. Nothing outward-facing fires before this.

    A metrology house is worth exactly what its meter is worth on somebody else’s machine. Send anyone a challenge whose command exits silently on a clean install and the campaign is over that afternoon — not because the argument was weak, but because the argument was never reached. This phase is unglamorous and it is the only one with no substitute: the storefront can be finished, the copy can be lethal, and if the factory behind it is empty the whole property is a brochure with a loud voice.

    The meter, in a browser →
  2. 2The carrier requirement — this phase is the entire board

    Superseded 2026-09-28
    Measured, and superseded. For the institution most exposed to the risk, adopting a second record dates what it knew and when, so answering us was incompatible with its own interest. Our own outreach ledger read the same thing in aggregate: of 15 cold first contacts, 0 replied; on the insurance side, people kept reading and nobody wrote back. The carrier requirement is still the destination. It stopped being the first move, and 2b below replaced it.

    Gate — what must be true before this opens
    Phase 1 closed. Two or three carrier and broker relationships carried to the point where one of them writes the receipt into a renewal condition.

    Builders are not recruited one at a time, and an operator who spends the week sending advisory invoices by hand is working at a permanently lower ceiling than an operator who closes one carrier. The moment a carrier requires a recomputable receipt at policy renewal, adoption stops being persuasion and becomes a condition of coverage: the market recruits the builders, compliance is compulsory rather than argued, and the metrology house stays neutral because it never had to sell anybody anything. Everything else on this page is demand generation pointed at this phase. If the ladder below ever starts to feel like the strategy, that is the tell that this phase has stalled.

    What a carrier reads before they write it in →
  3. 2bWho gains — the sequence that replaced phase 2

    Gate — what must be true before this opens
    Phase 1 closed, and the storefront (rung 1 below) public and dated. Then the incompatibility test, before any message: does answering move a number they are already paid on; can they use it without an admission about the past; is the receipt sufficient for their question; can one person act; and who is the accused in the sentence we would send.

    Spend the time where answering already pays the one who answers. That is the technical expert on either side, whose method has to survive the other side rerunning it; plaintiff and defence counsel, and the deployer’s own counsel, who meet the custom defence; the plan fiduciary who owes a full and fair review and pays the administrator who performs it; the underwriter pricing clean risk, who needs a trigger that settles without an adjuster; the deployer facing a renewal form that changed under it. For them the first move is warmth, through someone who already gains, and it runs beside the ladder below, which goes cold on purpose: the private recompute challenge does not wait for an introduction. The carrier requirement arrives last and unprompted, when the people a carrier answers to are already holding the record.

    What we are learning, dated →
  4. 3The payout splits in two, and the liability goes to whoever wants it

    Gate — what must be true before this opens
    A carrier or broker pricing against the meter. Until someone is underwriting off it, there is no payout to split.

    Two channels, and the buyer picks. Buy direct and the remedy is in kind: a funded vehicle deploys the consulting hours and the compute through standing peering relationships, so what arrives is restored capacity rather than a cheque that still leaves you to go find the capacity. Go through a broker and they wrap conventional insurance over the same telemetry and pay in cash — carrying the liability themselves, which is precisely the arrangement they want, because it is new premium volume on a risk that was uninsurable last year, priced off a meter they did not have to build. The position that has to survive every version of this: we supply the measurement, and never the liability. The moment the metrology house also carries the risk it is grading, it is not a metrology house.

    The two channels, priced →
  5. 4Gresham’s law, running backwards

    Gate — what must be true before this opens
    Phase 3 — the price difference between attested and unattested has to be real, quotable, and coming from someone who is not us.

    The ordinary dynamic in this market is the classical one: opaque and cheap drives out rigorous and grounded, because opaque and cheap ships on Tuesday. Lock coverage to a receipt a stranger can recompute and the direction inverts — the ungrounded system becomes the expensive one, not on principle but on premium, because it cannot be underwritten at any price the board will sign. That inversion is what makes the capital selective rather than merely abundant. Money that cannot survive an audit stops wanting in, which is a filter we do not have to operate and cannot be accused of operating.

    The axis the filter sorts on →
  6. 5The zero-latency economy

    Gate — what must be true before this opens
    Enough attested surface that the index is worth appearing on — phases 2 through 4 compounding.

    The honest objection to every ethics-shaped proposal is that the operator who ignores it has a better game, and mostly that objection is correct: a brake is a brake. This is the one construction where the brake comes off instead of on. A counterparty who can recompute your receipt does not have to run diligence on you, and diligence is the latency — so verified competence is not the careful slow path beside the fast reckless one, it is the only version where the transaction clears at machine speed. The dark version of this economy is fast because it skips the check; this one is faster because the check already ran and published.

    Why the check is decidable at all →

Read downward, the sequence answers the question the ladder cannot: not how hard do we push, but what has to be standing before pushing means anything. A rung fired while its phase is still open does not land softly — it spends the leverage of every phase above it, and that leverage does not come back.

Rung 0 — the standing infrastructure.

None of this is optional and none of it is expensive. It exists before the first target does.

  • Published criteria. Exactly what constitutes a challengeable claim, in writing, dated, before the first target exists. This is what makes every downstream action defensible — you cannot be accused of arbitrary targeting when the rule predates the target — and it is the strongest recruiting document there is.
  • The public register. Every action, every date, every outcome — including the times we were wrong, and especially those. An accountability instrument that does not log its own errors is a pressure group.
  • Right of reply, unedited, published alongside. Non-negotiable. The party’s answer runs next to the finding, in their words, uncut.
  • A named reviewer who is not the operator. Signs off on anything at rung 3 or above. This is the single highest-value mitigation in the design, because the failure mode we name for ourselves is intensity supplying the recognition instead of structure doing it.

What we are learning.

Dated 2026-09-28 · aggregate only · no organisation named

The institutions with the most exposure were the right first readers, and they went quiet for the same reason: answering was incompatible with their own interest. This is what our own record says, stated before the ladder so every rung can be read against it.

  • Warmth moved replies; temperature was the variable. Of 25 direct first contacts, 15 were cold and 0 of them replied; 10 had warmth on the record (a meeting, a request or an introducer) and 5 replied. On the insurance side every direct touch but one was cold, so class and temperature were the same split, and a warm introduction to an insurer is the cell nobody has measured yet. (internal outreach ledger, 99 organisations, 2026-09-28 (not published))
  • The insurance side kept reading and did not write back. 34 insurance-side organisations were contacted and 1 replied by email, with a written no. Yet 7 showed human-classified reads after 23 July, several into late September. The silence was on the reply channel, not on attention. The one insurance-side door that answered went quiet after our close argued against the recipient’s own build: the accused had become the audience. (internal outreach ledger, findings F2 and F3)
  • The newsletter carried the outreach, and it is not a front door. 4,949 of 5,156 touches (96%) were daily book-club sends. The organisations reached only that way gave 0 replies. (internal outreach ledger, finding F4)
  • Incompatible, not refused. For the most exposed party the cost of buying verification is the date, not the price: adopting a second record dates what it knew. More pressure raises the cost of answering. The move is to publish the burden and spend the time on those for whom answering already pays. (the light-switch report, commit 48b6e64229)
  • “Acting as designed” is the undefined phrase. Insurers are reported discussing exclusions for AI agents “acting as designed”, and nothing in the file records what the design was before the agent ran. A lane declared and dated before the run is what that phrase needs. On our own logs, one operator over 30 days, tool steps per subagent grew about 5.6% a day (permutation p = 0.0003) while agents dispatched per day did not grow measurably: the growth is depth, not headcount. That is sufficient for one heavy operator’s tree and for nothing about any firm; the honest long-run form is logistic. (the cyber and sovereign-tier report, commit c8af57d19b)
  • The burden, measured. Recomputing the public receipt in a fresh clone took 2.27 seconds (one run); a cold stranger’s install to verdict took 198 seconds. A receipt is sufficient for where the work landed and for its provenance, and not for whether the work was good, what happened in a system that kept no record, or anything read off a CPU performance counter. (the reasonable-care reference, commit a967e6d00f)

The ladder.

Six rungs, numbered separately from the phases above: these escalate, those sequence. Read downward: the ladder escalates on its own, every step spends leverage, and the target is always the claim, never the person. It starts cold, with the math in their inbox, and a silence is what moves it to the next rung. Every rung can be entered on its own trigger, held, or stepped down from. Enter where the trigger has been observed and nowhere higher. Hold means nothing further fires and what is published stays published. Step down whenever the claim moves, because the claim was always the target. Each rung carries its mitigation, live before it fires; its honest limit, meaning what the receipt is not sufficient for; its step-down path; and one public industry example, described as the record describes it and no further.

Which rung fits which counterparty

  • 1 · The private recompute challenge: The risk owner behind a public claim that an AI system is safe, controlled or certain: a chief risk officer, general counsel, or the executive who made the claim.
  • 2 · Registered non-response — the index of silence: Every party that let rung 1’s window close without an answer, which is the default and the expected case.
  • 3 · The named technical rebuttal: A public claim that survived rungs 1 and 2 unanswered, read by experts and counsel on either side.
  • 4 · The carrier squeeze — the records questions: The party’s own underwriters at renewal, plaintiff’s counsel, defence counsel, the technical expert, and a plan fiduciary: the people paid to ask.
  • 5 · Regulatory comment and coalition: A regulator that already wrote a human-review duty, a standards body revising a form (ISO, the EU AI Act’s implementing acts), an open rulemaking.
  • 6 · Formal channels — the teeth: Only a public false claim that survived rung 3, with its right of reply run out.
  1. 1The private recompute challenge

    Trigger — observed before it fires
    A dated public claim, made without a record a stranger can recompute, and rung 0 standing. We do not ask for a meeting and we do not wait for an introduction.

    Private, one page, sent cold: the receipt, the coordinate, the σ, and an advisory quote for the fleet (N agent-years × $20). "You stated X publicly. Verify it in your browser at thetadriven.com/verify-receipt, nothing to install, or locally via npx on your own machine; your data never leaves the building. If our instrument is wrong, publish the trace and we will amplify it. If you cannot recompute it, the claim is unbacked." The clock starts the second it lands on their server. It costs nothing to answer, which is what makes silence mean something.

    Mitigation, live first
    Browser verify leads, so the check never depends on running a package on a locked-down machine. The quote is marked advisory: it creates no debt and is not a bill. A 14-day window, nobody copied, nothing published, and a standing commitment to amplify any refutation. The whole rung is a question they can close by answering it.

    The honest limit
    The receipt places where the work landed against a lane declared before it ran. It does not say the work was bad (undecidable, Rice 1953), and it does not say anything about a system that kept no such record.

    Hold or step down
    Hold: nothing further fires. Step down: An answer, a correction or a purchased licence closes it. The window simply ends if they buy; the register counts them as answered.

    From the public record
    • The T.J. Hooper (2d Cir. 1932). Tug owners were held liable for barges lost in a gale because the tugs carried no radio receivers, though the practice was not yet general. Custom does not set the standard of care when an available device is cheap, and the date a party was handed the device is the date the question starts. 60 F.2d 737, Justia ↗
    Fill the advisory quote →
  2. 2Registered non-response — the index of silence

    Trigger — observed before it fires
    The rung 1 window expired with no reply, no correction and no refutation.

    The silence is registered on the public ledger, aggregate first: asked / answered / refuted. An accountability instrument that does not publish the silences is a PR firm. The index sorts the market into two columns, attested and unattested, machine-readable and ordered by time-on-target, and procurement teams and underwriters read it. The name is the thing being withheld, and withholding it is the leverage: reply and you are counted among the answered. Inclusion in the attested column becomes something people ask for.

    Mitigation, live first
    Every count is stated as measured, never rounded up; a count with no register behind it is the exact defect this property prosecutes. A party closes its own line at any time by replying. Absence from the attested column is a fact about a record, not an accusation.

    The honest limit
    A silence is a dated entry, not a finding of fault. It says a recomputable record was offered and not taken up. It says nothing about what the party’s agents did.

    Hold or step down
    Hold: nothing further fires. Step down: Any reply moves the party to answered and takes the rung back to 1. A purchased licence moves it to the attested column.

    From the public record
    • United States v. Carroll Towing Co. (2d Cir. 1947). Judge Hand wrote the burden test: liability depends on whether the burden of the precaution, B, is less than the probability of the loss times its size, P times L. B is the one term anyone can publish, and a declined precaution with a published, dated B is what the test reads. 159 F.2d 169, Justia ↗
    The public register and adoption board →
  3. 3The named technical rebuttal

    Trigger — observed before it fires
    Rung 2 registered, and the claim still public and unretracted. Public statements only, never private or group correspondence, at any rung.

    We publish the analysis of the public claim, backed by the immutable commit. We name the claim, print the recompute command, and print the refusal. It goes to them 72 hours before publication; their unedited reply runs next to it. If they stay silent, the math speaks for them. It ends with the count and the recompute, never with our price: the party grading the claim does not sell the fix on the same page.

    Mitigation, live first
    Counsel reads it, every factual assertion is sourced, the named reviewer signs off, and a refutation is amplified. It names to answer a claim, not to shame a person.

    The honest limit
    The analysis can show that no recomputable record backs the claim. It cannot show that the system is unsafe, and it never says so.

    Hold or step down
    Hold: nothing further fires. Step down: An answer, a correction or a retraction takes the entry off the register and the rung back to 1. The claim was the target; once it moves, nothing remains to publish.

    From the public record
    • Diesel on-road testing (2014–2015). Researchers at West Virginia University, commissioned by the International Council on Clean Transportation, measured diesel cars on the road and reported emissions far above the US limits the cars met in the laboratory, and presented the findings to EPA and CARB in May 2014. They did not identify the defeat device; they measured against the declared standard. EPA’s notice of violation followed on 18 September 2015. Wikipedia, with its primary citations ↗
    The register of misused certainty →
  4. 4The carrier squeeze — the records questions

    Trigger — observed before it fires
    Rung 3 published, or a public docket, rule or renewal form where the question of what record existed is already live.

    We publish the eight records questions their own underwriters and plaintiff’s counsel will ask at renewal or in discovery: what records exist and who wrote them; was a lane declared before each run and when; are records retained or overwritten; when did a preservation duty attach; can a third party recompute them; what does each record state it is sufficient for; how long did a human spend per approval; where a record is missing, since when. We hand the exact questions to the exact people paid to deny the claim.

    Mitigation, live first
    The questions presume no answer. The same document serves plaintiff and defence, and the deployer’s own counsel is the first party entitled to answer them. We never serve notices, demands or preservation letters; those belong to counsel with a client. No fee, retainer or referral passes to or from any expert, counsel or funder on any case.

    The honest limit
    The questions describe records. Whether a record was required in a matter, and from what date, is for counsel and the court. This is not legal advice.

    Hold or step down
    Hold: nothing further fires. Step down: Back to rung 1: the questions stay public and the entry closes when the party answers.

    From the public record
    • An automated-denial challenge proceeds (E.D. Cal. 2025). A federal court let a claim proceed that a plan administrator abused its discretion by using an automated algorithm for medical-necessity decisions that the plan said a medical director would make. The question the court let forward is a records question: who, or what, made the decision. Hall Benefits Law ↗
    The standard the questions sit under →
  5. 5Regulatory comment and coalition

    Trigger — observed before it fires
    An open comment period or a revision that already asks for the record. We do not lobby for a rule that does not exist yet.

    A formal comment with the recomputable receipt attached and the recompute command in it, plus a named coalition letter. We do not lobby; we provide the missing check for a duty the rule already states, and we make it impossible for a regulator to say the measurement is unavailable. This is where "silence is irresponsible" stops being our assertion and becomes other people’s signatures.

    Mitigation, live first
    Public process, public record, many names: the opposite of a lone sender with a grievance. The comment never asks for a requirement only we could meet, because the measurement is free and open-source (MIT) and anyone can run it.

    The honest limit
    A comment can show a precaution exists and what it costs. Whether a rule should require it is the regulator’s judgment.

    Hold or step down
    Hold: nothing further fires. Step down: Withdraw to rung 4 if the record already answers the rule’s question; to rung 1 if the rulemaking closes.

    From the public record
    • Passive restraints under FMVSS 208 (1984, 1991). On 11 July 1984 the standard was amended to require a passive restraint for the driver in cars built after 1 April 1989, airbag or automatic belt. The Intermodal Surface Transportation Efficiency Act of 1991 then required driver and passenger airbags in cars and light trucks built after 1 September 1998. An option became a requirement in two dated steps. Wikipedia, with its primary citations ↗
    • ISO’s generative-AI endorsements (2026). ISO published exclusion endorsements for generative AI on general-liability paper, CG 40 47, CG 40 48 and CG 35 08, and carriers are filing with state regulators to attach them. The market’s own forms body wrote its refusal to carry what it cannot count. Insurance Journal, 17 August 2026 ↗
    The argument in full →
  6. 6Formal channels — the teeth

    Trigger — observed before it fires
    Rung 3 published, the reply window closed, the claim unretracted, counsel’s review done and the named reviewer’s sign-off recorded. The trigger is the unretracted claim; a declined quote never is.

    We do not write angry letters. We file the math, and the institution does the testifying. Each channel is more coercive than an invoice and answered by an institution rather than by us: the FTC’s deceptive-AI-claims posture, state-AG UDAP authority, NAD at BBB National Programs (fast, cheap, decisions published, and refusing to participate is itself published), the SEC whistleblower program where a public company’s AI claims contradict its own risk-factor disclosures, EU AI Act market-surveillance complaints (Article 14 enforcement live since August 2), and ISO/IEC 42001 certification-body complaints about claims outside a certified scope.

    Mitigation, live first
    Filings require documented evidence, which the published criteria already produce; counsel reviews each; the register logs every filing and every outcome, including the dismissals. A complaint you can be wrong about, on the record, is not a shakedown.

    The honest limit
    A filing can show a claim is not backed by a recomputable record. It cannot show harm, intent or that any agent misbehaved; the institution decides what the evidence means.

    Hold or step down
    Hold: nothing further fires. Step down: A retraction or correction ends it: we notify the channel, the register records the outcome, and the rung returns to 3 or to 1.

    From the public record
    • The rent-pricing software complaint (DOJ, 2024). On 23 August 2024 the Department of Justice and eight state attorneys general sued RealPage, alleging that landlords’ shared data and the software’s pricing recommendations reduced competition among landlords. These are allegations in a complaint; a formal channel took up an algorithm through the records it ran on. Wikipedia, with its primary citations ↗
    The evidence pack a filing attaches to →

Side doors, open at any rung

These run beside the ladder, never instead of it. Every door added is another way to win; none of them retires a rung.

  • Publish the standard and the dated burden. Everyone, including the parties who will not answer. An expert, a counsel, a fiduciary or an advocate can find it without anyone sending it. One public page: what a receipt is, what it is sufficient for and what it is not, the one command that recomputes it, and what keeping it costs, with the date. Measured on 2026-09-28: 2.27 seconds to recompute the public receipt inside a fresh clone (one run), and 198 seconds from a cold install to a verdict. The date is part of the evidence.
  • A warm hand-up, through someone who gains. A plan fiduciary’s benefits counsel, an underwriter pricing clean risk, a deployer facing renewal, reached through a person who already gains and offers the introduction. One question, carried by the person who gains from it: for a fiduciary, “does your administrator agreement let you recompute how a decision was reached, from a record the administrator did not write?”; for an underwriter, “here is a trigger that settles by recompute rather than by adjuster.” It runs beside the ladder, never instead of it. The tobacco Master Settlement Agreement (1998). From 1994 states sued to recover the public health-care costs of smoking-related illness, and the personal-responsibility defence that had held against individual smokers did not answer a state’s claim. In 1998, 52 state and territory attorneys general signed the settlement, which also required documents disclosed in discovery to be made public. The plaintiff changed, and the party who gained made the case. National Association of Attorneys General ↗

Restored 2026-09-29. On 2026-09-28 the private recompute challenge, the registered non-response and the index were retired as first moves, on a reading of 0 replies from 15 cold first contacts as a failed conversion. That reading was wrong: replying is an admission, so silence is the finding, not the failure. The six rungs are back in their original order.

Where the invoice lives.

An invoice moves the argument off the whiteboard and onto a ledger: the party receiving it is no longer debating, they are deciding whether to book it. The line item is theirs, not ours — N agent-years × $20, N counted by the same gate a stranger can re-run, with the coordinate and the σ attached. Setting it aside is available and free today; what it cannot do is remove a dated, recomputable count from their own inbox. That non-response goes in the register, and nothing further fires until a rung’s own trigger is observed. The ratchet, from the builder’s side →

Pointing at a flaw without a workable path is worse than saying nothing — so the price attaches to the finding, not the vocabulary. At rung 3 and above, the published analysis ends with the count and the recompute — the number of agent-years and how a stranger verifies it — and pricing is one click away for anyone who wants it. The published piece never quotes our own price: the party grading the claim does not sell the fix. That is the instrument, kept — legitimate because there is a documented, falsifiable, published finding it attaches to. The remedy is available with the diagnosis. Nobody gets a bill for a word.

The three desks — one question, and our own null on the table.

The rungs above aim at a public claim. This play aims at the desks that price agent work — the risk officer, the general counsel, the underwriter — and it is disclosed here for the same reason every rung is: a play that only works unseen is not a play. The note leads with dated facts already on their desk, then a command with its first line of output, then our own headline readings with their nulls beside them, and then it asks one thing:

What would have to be on a receipt for your claims team to accept it as the settlement datum?

  • Chief Risk Officer — names the loss the receipt would have to key on — what cannot be counted has been excluded on their own paper since 1 January 2026 (ISO CG 40 47 · 40 48 · 35 08).
  • General Counsel — names what counts as evidence at settlement — the receipt resolves to a coordinate, not an adjective, and the actor did not write it.
  • Underwriter — names the trigger a wording team could key on — the first carrier to condition a line on a passing receipt owns the inspection standard.
  • The live meter — does the placement predict what the room did next? 0.157 on 629 pairs · null: shuffled 0.155 — at the null; it does not predict, and the document that defines the meter says so.
  • The off-lane share — does drift around the declared lane price rework? z 4.85 pooled · null: z 2.92 within-room against a 3.08 bar; one half at 0.34 — nothing prices once the room is held fixed; the line is closed in the ledger, not sanded.
  • The one randomised experiment on ourselves — does handing a room its placement change what it does? null at 99 control edits · null: the wire the treatment depended on had never rendered; wired 17 September, read pre-registered at 100 — a negative with its read date written down.

The ledger’s own line on what is not claimed — underwriter-grade attestation — four fifths of the machinery, none of the positive claim — goes in the note, because a number without its null is a claim and a number with it is a fact a cold reader cannot argue with. The close is issued, never proposed: twenty minutes on the one question, one fixed window, and declining is the action — one sentence closes the file cleanly. No exclusivity is offered; the note says it goes to several carriers, one seat per firm. Touch two carries a new institutional fact or it does not go out; three touches, then the node is logged dead this cycle.

The attestation standard.

Four things a receipt has to satisfy before any desk above can price against it. They are published for the same reason every rung is — and two of them cost us something to say, which is how you can tell the list is not marketing.

  1. 1An agent cannot author its own audit trail

    Its self-reported completion carries no information above its null about whether another hand will fix the work. On 2,071 commits, a turn that said "done" was fixed by a different room within a day 12.3% of the time; a silent turn, 12.2%; a hedged turn, 14.6% — on both halves (KR36). The three rates sit on top of each other, which is the finding: treat an agent’s completion string as a claim, not a measurement.

  2. 2Tape, not brake

    The instrument places each turn on the declared lattice, signs the row — reef and axes blob ids, ed25519, the room’s key — before the commit lands, and reports admissible or UNMEASURED. It does not stand between the agent and the work. The deployer owns every halt, breaker and runbook: the tape flags, the deployer acts. The wheel is handed over with the position, and it stays in their hands.

  3. 3The room is the confound of record (rule 18)

    Rooms differ both in what the tape reads and in how often they fix their own files, so the two can trade places in any pooled number. A commit-level reading is therefore made against a within-room permutation null, on both halves, or it is not a reading and is not reported as one. The ledger states that the confound exists and is held constant; it does not offer a reason the rooms differ, because it has not measured one.

  4. 4Parametric settlement, and what triggers the licence

    Hurdle Zero comes first: fewer than twenty distinct targets is UNMEASURED, never a soft rate. Computing placements, reading the metrics and printing a basis-point spread is free under MIT — fork the crate, run it, keep the numbers. Settling an enforceable contract, policy or bond against the signed row is what the agent-year licence covers, at the documented price. As of 2026-09-17 the ledger carries no actuarial basis-point spread: it reports placement and compliance, not a loss reduction.

The operator program.

Distributed action, built so it cannot be turned around on you.

  • · Operators act under their own cryptographic signature — never our letterhead, never our name in the from-line. The metrology house provides the immutable ledger, not the letterhead; they cite us the way anyone cites a source.
  • · Operators run rungs 1 and 2 only. Rung 3 and above requires the named reviewer — the rule that keeps the worst operator from becoming our public position.
  • · Entry requirement: they have run the instrument on their own work and they are in the register. Skin in the game before pressure in the market.
  • · A written code of conduct with removal, published, so the boundary is visible to the targets too.
  • · No private-chat screenshots. No elected officials. Both are removal offenses — and Rungs 3 and above require root-ledger cryptographic sign-off; a rogue operator is simply disconnected from the validation network.

Five unforced errors that close before rung 1 fires.

Rung 1 gets answered with a screenshot of our own site, so these are not optional.

  • 1. attest-demo must not silently exit. A challenge whose command silently exits on the recipient’s machine ends the campaign on day one. This is load-bearing, not cosmetic — until it is fixed, rung 1 leads with the in-browser /verify-receipt path.
  • 2. The D-word in our own titles. You cannot run a claims-accuracy program while the word that disqualifies others sits in live post titles. The cheapest fix here, and genuinely disqualifying until swept.
  • 3. The dossier — published by decision, anonymised by rule — closed. Untracking is not removal, and removal was the wrong measurement too: the standing decision is that the working transcript stays published — the train of thought is the attackable target. What ships is the anonymised form: role words for every private name, address patterns redacted, and a content-based guard (no third-party name or address on any web-served analysis surface) that runs on every commit.
  • 4. CG 40 47 is a CGL form, not D&O. The ISO generative-AI exclusion endorsement attaches to general-liability coverage. Get the tower wrong in a filing and the filing dies — name it as CGL, and treat D&O / E&O as the separate towers they are.
  • 5. Our own E&O and GL tower. Confirm we are not carrying the exclusions we are selling against, before an underwriter asks.
gemsedu.com #1 ▼0.9%moonshotscapital.com #2 ▲1%leadedgecapital.com #3 ▼1%differential.vc #4 ▲12.6%dometic.com #5 ▼4.5%thecignagroup.com #6 ▼2.5%sigma.se #7 ▼2.4%karlsborg.se #8 ▼4.2%teneo.com #9 ▼0.6%ltu.se #10 ▼7.8%emiratesnbd.com #11 ▲3.7%apcoworldwide.com #12 ▲0.8%championacaustin.com #13 ▼2.9%amseliplaw.com #14 ▼8.1%clarionschool.com #15 ▼2.1%reed.com #16 ▼7%scania.com #17 ▼10.9%svenskakyrkan.se #18 ▼2.7%anthonypllc.com #19 ▼0.1%rytmus.se #20 ▼8.4%sigeducation.com #21 ▼7.5%state.gov #22 ▲5.5%brodit.se #23 ▼7.9%scor.com #24 ▼7.9%ericsson.com #25 ▲4.4%easystem.se #26 ▼6.4%pernod-ricard-china.com #27 ▼13.5%khda.gov.ae #28 0.0%innoventureseducation.com #29 ▲3.2%dubaiholding.com #30 ▼2.5%wsp.com #31 ▼6.4%bdtmsd.com #32 ▲4.7%expediagroup.com #33 ▼7.1%parkcity.org #34 ▲34.9%lfg.com #35 ▲4%addition.com #36 ▼0.7%upandrunningdubai.com #37 ▲2.7%americancenteruae.com #38 ▼5.2%baylor.edu #39 ▼8.1%its.jnj.com #40 ▼1.3%rackspace.com #41 ▼9.2%eosvc.com #42 ▲16.9%cablevision.com #43 ▲0.5%crslimited.com #44 ▲2.1%atriumhealth.org #45 ▼11.3%sunstarstrategic.com #46 ▼7.7%oryxworld.com #47 ▼15.8%mit.edu #48 ▼2.2%gunnebo.com #49 ▼2.6%volvo.com #50 ▼1.3%siemens.com #51 ▼5.1%winningtemp.se #52 ▼6%neweratech.com #53 ▲0.2%newyorklife.com #54 ▲3.1%statefarm.com #55 ▼3.4%insureai.co #56 ▼15.8%inspiralia.com #57 ▲11.4%munichre.com #58 ▼5.6%sc.com #59 ▲12.9%marsh.com #60 ▲1.4%linkedin.com #61 ▼11.4%bermanauditadvisorycpa.com #62 ▲6.9%se.abb.com #63 ▲7.1%jcdecaux.ae #64 ▲6.8%aresmgmt.com #65 ▲18.7%bakerbotts.com #66 ▲78.1%jcdecaux.com #67 ▼3.5%nsigroup.org #68 ▼3.5%louisville.edu #69 ▲1.5%jkj.com #70 ▼2.4%artvillagenursery.com #71 ▼15.8%emerson.com #72 ▲21%luxcapital.com #73 ▼5.7%conning.com #74 ▼5.6%pacemetals.com #75 ▲30.1%fox.com #76 ▲2.7%tyrolit.com #77 ▲282.3%lbl.gov #78 ▼15.8%students.rcsj.edu #79 ▲43.2%ecoclean-group.net #80 ▲41.1%rakbank.ae #81 ▲4.9%schmuhlbrothers.com #82 ▲50.6%aig.com #83 ▼5%scnsoft.com #84 ▲95.1%bartec.com #85 ▲102.8%xprize.org #86 ▼5.5%bancamediolanum.it #87 ▲45.8%muskegoncc.edu #88 ▲236%tetrapak.com #89 ▲2.2%camarda.com #90 ▲66.4%jsx.com #91 ▲117.5%hsph.harvard.edu #92 ▼15.8%peraco.com.au #93 ▲68.2%mindshareworld.com #94 ▲889.9%krausanderson.com #95 ▲169.2%dubailand.gov.ae #96 ▲13.9%nyu.edu #97 ▼5.1%stoughtontrailers.com #98 ▲165.2%trenchlaw.com #99 ▼15.8%mckoolsmith.com #100 ▼15.8%gemsedu.com #1 ▼0.9%moonshotscapital.com #2 ▲1%leadedgecapital.com #3 ▼1%differential.vc #4 ▲12.6%dometic.com #5 ▼4.5%thecignagroup.com #6 ▼2.5%sigma.se #7 ▼2.4%karlsborg.se #8 ▼4.2%teneo.com #9 ▼0.6%ltu.se #10 ▼7.8%emiratesnbd.com #11 ▲3.7%apcoworldwide.com #12 ▲0.8%championacaustin.com #13 ▼2.9%amseliplaw.com #14 ▼8.1%clarionschool.com #15 ▼2.1%reed.com #16 ▼7%scania.com #17 ▼10.9%svenskakyrkan.se #18 ▼2.7%anthonypllc.com #19 ▼0.1%rytmus.se #20 ▼8.4%sigeducation.com #21 ▼7.5%state.gov #22 ▲5.5%brodit.se #23 ▼7.9%scor.com #24 ▼7.9%ericsson.com #25 ▲4.4%easystem.se #26 ▼6.4%pernod-ricard-china.com #27 ▼13.5%khda.gov.ae #28 0.0%innoventureseducation.com #29 ▲3.2%dubaiholding.com #30 ▼2.5%wsp.com #31 ▼6.4%bdtmsd.com #32 ▲4.7%expediagroup.com #33 ▼7.1%parkcity.org #34 ▲34.9%lfg.com #35 ▲4%addition.com #36 ▼0.7%upandrunningdubai.com #37 ▲2.7%americancenteruae.com #38 ▼5.2%baylor.edu #39 ▼8.1%its.jnj.com #40 ▼1.3%rackspace.com #41 ▼9.2%eosvc.com #42 ▲16.9%cablevision.com #43 ▲0.5%crslimited.com #44 ▲2.1%atriumhealth.org #45 ▼11.3%sunstarstrategic.com #46 ▼7.7%oryxworld.com #47 ▼15.8%mit.edu #48 ▼2.2%gunnebo.com #49 ▼2.6%volvo.com #50 ▼1.3%siemens.com #51 ▼5.1%winningtemp.se #52 ▼6%neweratech.com #53 ▲0.2%newyorklife.com #54 ▲3.1%statefarm.com #55 ▼3.4%insureai.co #56 ▼15.8%inspiralia.com #57 ▲11.4%munichre.com #58 ▼5.6%sc.com #59 ▲12.9%marsh.com #60 ▲1.4%linkedin.com #61 ▼11.4%bermanauditadvisorycpa.com #62 ▲6.9%se.abb.com #63 ▲7.1%jcdecaux.ae #64 ▲6.8%aresmgmt.com #65 ▲18.7%bakerbotts.com #66 ▲78.1%jcdecaux.com #67 ▼3.5%nsigroup.org #68 ▼3.5%louisville.edu #69 ▲1.5%jkj.com #70 ▼2.4%artvillagenursery.com #71 ▼15.8%emerson.com #72 ▲21%luxcapital.com #73 ▼5.7%conning.com #74 ▼5.6%pacemetals.com #75 ▲30.1%fox.com #76 ▲2.7%tyrolit.com #77 ▲282.3%lbl.gov #78 ▼15.8%students.rcsj.edu #79 ▲43.2%ecoclean-group.net #80 ▲41.1%rakbank.ae #81 ▲4.9%schmuhlbrothers.com #82 ▲50.6%aig.com #83 ▼5%scnsoft.com #84 ▲95.1%bartec.com #85 ▲102.8%xprize.org #86 ▼5.5%bancamediolanum.it #87 ▲45.8%muskegoncc.edu #88 ▲236%tetrapak.com #89 ▲2.2%camarda.com #90 ▲66.4%jsx.com #91 ▲117.5%hsph.harvard.edu #92 ▼15.8%peraco.com.au #93 ▲68.2%mindshareworld.com #94 ▲889.9%krausanderson.com #95 ▲169.2%dubailand.gov.ae #96 ▲13.9%nyu.edu #97 ▼5.1%stoughtontrailers.com #98 ▲165.2%trenchlaw.com #99 ▼15.8%mckoolsmith.com #100 ▼15.8%