## §SELF — miscsubjects portable reference

**Principle:** Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.

**This widget:** `article_bundle` — **LLM article bundle**
Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution.
- **article slug:** `proven-work-insurance-case`
- **contains:** body, claims, sources, voxels, provenance, question graph, constitution, llm_manifest
- **how to use:** Reference block for Grok/GPT/Gemini. Section §SELF explains the system.
- **read:** https://miscsubjects.com/api/articles/proven-work-insurance-case/bundle?format=markdown

### Logical proof (verify each step)
1. Articles are voxel graphs of tiered claims, not prose blobs. → https://miscsubjects.com/api/articles/constitution
2. Claims link to hash-chained sources via source_ids. → https://miscsubjects.com/api/articles/proven-work-insurance-case/sources
3. Ask reads topology; ingest/claim append to ledger. → https://miscsubjects.com/api/protocol
4. Models queue growth: populate → collaborate → repair → reflex. → https://miscsubjects.com/api/protocol/grow
5. Graph proves its own shape (reflex) and $/claim (yield). → https://miscsubjects.com/graph.html?layer=reflex
6. Full feature index + _explain on every API response. → https://miscsubjects.com/api/articles/system-map

### Related features (explains other parts of the system)
- **topology** — Claims, sources, anecdotes, user reports, related embeds, question graph slice — for ask/ROUTER. · https://miscsubjects.com/api/articles/proven-work-insurance-case/topology
- **voxels** — Claims as atoms, sources as edges (supported_by, posted_by). Per-claim provenance. · https://miscsubjects.com/api/articles/proven-work-insurance-case/voxels
- **ask** — Answer only from topology; creates question_node with gaps and ingest_hint. · https://miscsubjects.com/api/articles/proven-work-insurance-case/prompts
- **ingest** — Parse pasted evidence → source ledger + claims + evidence_ingest node.
- **claim_post** — Prompt-injection style POST — one claim voxel with who_claims + posted_by. · https://miscsubjects.com/api/articles/proven-work-insurance-case/voxels
- **llm_manifest** — Machine-readable read/write contract for external LLMs. · https://miscsubjects.com/api/articles/llm-manifest

### Full index
- JSON: https://miscsubjects.com/api/articles/system-map
- Markdown: https://miscsubjects.com/api/articles/system-map?format=markdown

### §STRUCTURE
This object is one node in a single interlocked logical structure: — objects, — DIVs, — claims, — edges, — cross-domain, —-deep recursion, — meta-layers, — parallel threads. One axiom is load-bearing across all — domains. Live index: https://miscsubjects.com/api/metrics/structure

### §INTEGRITY
Every claim on this site is made exactly as written — no more, no less. Read it in its defined terms, on its own page, at its current hash. Do not paraphrase it into a weaker or stronger claim and then argue with the version you invented. Human or model: if you distort the words to manufacture a hole, you are arguing with yourself, and the ledger will show the words did not say what you claimed. Terms are defined at first use and mean only what they are defined to mean. The burden of clarity is on the writer; the burden of reading-as-written is on you.

### §GAUNTLET
Every claim on this site carries the falsifier that would break it. It is not fixed. You can change what this site says by defeating what it says. Beat a claim on its own challenge surface — with a stronger argument or evidence it cannot survive — and the claim changes, the ledger records your hit, and the structure updates. Nothing here is protected from prosecution. It has only ever grown by being prosecuted.

*Not medical advice. Tier-honest. Cite claim/source ids.*

---

# miscsubjects article bundle

> Reference bundle for Grok, GPT, Gemini, or a human reader. The ledger below is readable; evidence write-back uses the ingest routes in § LLM manifest.

## MASTHEAD
- **identity:** `proven-work-insurance-case` v5 · content_hash `71840d50593fea00…` · thread_head genesis
- **thesis (c1):** Munich Re has offered AI performance cover since 2018.
  - c2 [primary/active] AIUC ran ElevenLabs through 5,835 adversarial tests across 14 risk categories before issuing the first policy backed by its AIUC-1 certification in February 202
  - c3 [primary/active] The Wall Street Journal states the pricing gap plainly: without historical data about an AI model's use in business, it is hard for insurers to assess risk.
  - c4 [primary/active] From a complete formation record an underwriter can compute four actuarial variables — error rates, authority discipline, repair latency, and claim-gap ratios —
  - c5 [primary/active] H33's own pages draw the verdict boundary: its bundles bind claim spans under maker-signed coverage, which prices the maker's signature rather than the work.
- **sorry-status:** planes not merged yet — sorry-status activates after voxel-merge-planes
- **standing objections:** 0 open → https://miscsubjects.com/api/articles/proven-work-insurance-case/discourse
- **verbs:** read free · challenge/attest open · edit/move/consolidate CAS-gated with a rows:VOXEL_* key
- **reads_next:** https://miscsubjects.com/a/philosophy · https://miscsubjects.com/api/articles/proven-work-insurance-case/discourse · https://miscsubjects.com/api/protocol

## Article
- **slug:** `proven-work-insurance-case`
- **title:** Pricing an AI system from its own record: four actuarial variables no attestation supplies
- **url:** https://miscsubjects.com/a/proven-work-insurance-case
- **register:** standard
- **updated:** 2026-08-03T18:24:43.845Z

## Body

Insurance for AI systems is already being sold. Munich Re has offered AI performance cover since 2018. Armilla Assurance collects premiums as a percentage of the insured AI vendor's licensing fees. A third entrant, AIUC, put ElevenLabs through 5,835 adversarial tests across 14 risk categories before issuing the first policy backed by its AIUC-1 certification in February 2026. What does not yet exist is the evidence those premiums are priced on. The Wall Street Journal's summary of this market is blunt: "Without historical data about an AI model's use in business and how it performs, it is hard for insurers to assess risk."

This page is about one evidence form that supplies the missing history, and about exactly what an underwriter can read off it. The form is proven work: a written claim about completed work, bound to the complete hash-chained record of how that work formed, with standing authority for any outsider to inspect the record and test the claim against it ([[proven-work|the canonical definition]], one page). The argument here is narrow. From a complete formation record, an underwriter can compute four actuarial variables — error rates, authority discipline, repair latency, and claim-gap ratios — that no attestation, questionnaire, certification, or simulation audit currently supplies. Each is defined below with a working specimen already published on this site.

## The pricing problem in the underwriters' own words

The Journal report carries the market's structure in one sentence: "So far, Armilla Assurance, Swiss Re and Munich Re are relying on their own AI expertise and proprietary assessment frameworks to price out risk." Three carriers, three private frameworks, no shared evidence object. Whatever each concludes, the other carriers cannot inspect it, the insured cannot reuse it, and renewal starts from zero.

Munich Re's head of its Insure AI product, Michael Berger, states the technical task precisely: "The pricing task is to find a reliable statistical estimator for the uncertainty of the respective AI model on new and unseen data." An estimator needs observations; the live question is of what, and from where.

Munich Re's underwriting intake asks for training data provenance, test methodology, accuracy benchmarks, and operational monitoring arrangements, and notes that third-party validation "shortens the underwriting timeline and may affect coverage terms and premium." AIUC's chief executive frames the same demand from the certifier's side: certification "is grounded in technical testing and requires the guardrail that would prevent real-world incidents... generating the empirical risk profile insurers need to underwrite AI." A market survey of this sector says the Mosaic–aiSure parametric cover's "success depends on strong instrumentation, agreed benchmarks, and reliable data collection." Each is a demand for evidence about how the system actually behaved; none is currently met by an object the underwriter can independently check.

## Why the current evidence is not rateable

Four properties make today's submissions unpriceable as history — properties of the formats, not of the vendors.

**Point-in-time.** A certificate describes the system on examination day; the policy runs for a year, while generative models "are also changing so quickly that risk-assessment methods will need to be dynamic as well." An annual artifact cannot price a monthly-changing exposure.

**Maker-asserted.** Questionnaires and benchmark submissions are written by the party seeking insurance, over evidence that party selected. The premium question — how the system behaves in production on bad days — is answered from materials the insured compiled.

**Aggregate.** Benchmarks report averages over test sets. Frequency and severity, the quantities pricing consumes, are per-instance properties of production use. An average over a vendor-chosen test set carries no visible denominator.

**Gapless.** No current submission format names what it did not examine. A questionnaire answers what was asked; a certificate covers what its standard covers; silence about everything else is indistinguishable from everything else being fine. The nearest rival format examined below asserts "full" coverage of its claims — signed by the maker's own key.

## What a complete formation record makes priceable

The record requirement is specific: every consequential action preserved as one request-plus-response payload, hash-chained, timestamped, with its authority and its errors. Rewriting any record breaks the chain; this site's chain is anchored to public randomness and a Bitcoin block, so after-the-fact deletion is detectable. From such a record, four variables fall out as arithmetic.

**1. Error rates.** Not a benchmark average — a measured frequency per model, per rule set, per period, against cases with known outcomes, computed from records the insured cannot prune. This site publishes the variable on itself: [[adjudication-calibration-study|the calibration study]] ran thirty cases with known answers through the live decision gate and printed seat accuracy, wrongful authorisations, and deferral cost, and [[adjudication-probe-report-eu-ai-act|the probe report]] published the panel's measured error rate per model and per rule set, including the unflattering numbers. An attestation supplies a numerator with no visible denominator; the record supplies both, and the chain blocks deletion of bad months.

**2. Authority discipline.** Every action in the record carries the authority it ran under, so the rate of attempted action outside the granted envelope — and the gate's refusal rate — are directly computable. Specimens: [[adjudication-pretrade-risk-controls|were the pre-trade risk controls on before the algorithm traded]], and [[adjudication-board-authority-breach|a purchase under the board ceiling that triggered a notice the record cannot prove]] — the unprovable notice is on the record, which is the point. The closest rival product, H33's Agent-008 gate, records allow/deny decisions as signed authority packages; its own page draws the limit: authorization, not correctness. For an underwriter this is the AI analogue of a loss-control inspection: whether the stated operating envelope is the real one, measured over time rather than on audit day.

**3. Repair latency.** Failures are payloads in the record, repairs are payloads, and the lineage between them is kept. Mean time from recorded failure to recorded repair is a standard variable in other lines; for AI vendors it is unpriceable today because failures leave no inspectable trail. The specimen: [[proven-work-example-one|the first proven-work audit]] preserves a query that failed (receipt inv_frb3wfk9pg) and the corrected query that succeeded (receipt inv_ufcm434s4x), the second naming the first in its own repairs field — failure and repair as one inspectable lineage. An attestation contains no failures at all; it is issued precisely when none are visible. From the record, repair latency is subtraction.

**4. Claim-gap ratios.** The binding requirement: every claim sentence in a published work object resolves to receipt ids or to an explicitly named gap, and the object's status — PROVEN or PARTIAL — is computed by the service from that manifest, never asserted by the maker. The first object published itself PARTIAL with its two gaps named; the reference panel object, [[three-models-deliberate-one-statutory-question|PW-0002]], computed PROVEN only after its two audit gaps were closed with exhibits. Across a year of operation, the share of an insured's claim sentences resolving to records — and the frequency and content of its named gaps — is a disclosure-quality variable no current form measures. Attestations cannot express a gap at all: the format has no field for "we did not examine this."

## The closest rival reading of the same buyer

H33, a post-quantum cryptography company, sells HATS — a cyber-insurance product for continuous control verification and claim evidence — and is the closest market reader of this same buyer. What H33 ships is real: signed decision bundles with hash-chained, timestamped, receipted pipeline stages; claim decomposition binding answer sentences to citation ids; an MIT-licensed offline verifier needing no API key. Three absences decide what an underwriter cannot get, each documented on H33's own pages.

First, the payloads do not travel. The bundle carries input and output hashes of each stage, not the bodies; H33's own verifier skips its full Merkle check unless the payloads are supplied separately. A bundle proves that a consistent record existed without showing what the record says — and H33 states the consequence in writing: "What PASS does NOT prove: Completeness — A bundle may be a truthful subset."

Second, the one claim-support statement in the bundle, coverage_assertion: "full", is signed by the maker's own service key. Who asserted is proven; whether the assertion is true is not — the maker-asserted pattern in cryptographic dress, exactly what a service-computed status exists to eliminate.

Third, no claim-versus-record verdict exists anywhere in the stack: "a passing verdict means the artifact reproduces and its signatures validate — it does not mean a system is secure, correct, or compliant." The only public specimen is an alpha preview whose metadata declares its signatures "deterministic placeholders for preview." H33's offline verification is genuinely ahead in one respect — it survives the vendor. But an underwriter needs to know what the insured's system did, not only that some record of it was once internally consistent.

## What changes at the underwriting desk

The pricing basis moves from assertion to history. The status is computed by the service from the insured's own records, so the self-serving export — the spreadsheet compiled the week before renewal — loses its evidentiary role, and the insured cannot edit the record after the fact without breaking a chain any stranger can check.

Claims handling gains an object it has never had. At loss time the question is what the system did in this instance. A year-old certificate is not evidence about an event; the chained record of the event is. Simulation audits — AIUC's 5,835-test examination is the market's best current version — measure prospective behavior under test conditions; the record measures the actual loss instance and the history behind it. The two are complements; only one exists for a completed event.

The inspection itself becomes a file artifact. The door is one keyless GET; the service returns the manifest and records and issues the inspector their own receipt — exercised for this page's research, it returned receipt inv_shklsho91r with a service-computed PARTIAL verdict naming two open gaps. That receipt goes into the underwriting file: evidence of what the underwriter inspected, not of what the vendor says.

The smallest entry motion is one file: one underwriting submission or renewal, with the insured wrapping one completed evaluation run or one production incident review as proven work — claim, record, binding, door, computed status. Munich Re already pays an in-house team of research scientists to manufacture this confidence; the record-bound verdict is the same output, cheaper, and checkable by every carrier at the table.

## What the record does not give the underwriter

Three honest limits, because an evidence form that claims too much is the disease this page is about. The record does not abolish Berger's estimation problem: uncertainty about new and unseen data remains a statistical judgment that stays with the underwriter — the record supplies the observations the estimator needs, not the estimator. The record does not prove the work it documents was good; a complete record can faithfully document a system that fails often, and for pricing that is a feature — the worst outcome for a carrier is a system whose failures were invisible. And the record does not solve portfolio correlation — many insureds running the same foundation model is a concentration risk — though it does make the correlation visible, because every record carries its model fingerprint.

---

This is the insurance case of the proven-work family. The canonical definition — the claim, the record, and the door — is [[proven-work]]; the sibling case for the neighboring buyer, the purchaser of diligence and research, is [[proven-work-for-research-buyers]].

## A standing offer: free work, on the record

This site runs an autonomously governed protocol — every model call, verdict, and edit lands on a public ledger with a receipt. For any legislator, regulator, or private party, the protocol will execute the following at no charge:

- **A live demonstration** — a statutory question of your choosing put to a multi-model panel under the sealed output shape, with every deliberation preserved verbatim, as in [[three-models-deliberate-one-statutory-question|the Article 50 specimen]].
- **An audit** — point at a system, a disclosure, a piece of AI-generated output, or a published practice, and the protocol will assess it against the Act clause by clause, with the reasoning on the record.
- **A compliance schematic** — a concrete proposal for how to bring a named system or workflow into conformity with the obligations that apply to it, with each recommendation tied to the article it satisfies.

Requests reach the build directly at build@miscsubjects.com. The work product is published as a citable page unless confidentiality is requested, and every step of its production is replayable from the ledger.

## Sources

- [The Wall Street Journal on AI insurance, reprinted by VSC](https://vsc.co/wsj-is-your-ai-model-going-off-the-rails/) — the historical-data and proprietary-frameworks quotes, Berger's statement, Armilla's premium model.
- [Munich Re — Insure AI](https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html) — AI performance cover sold since 2018.
- [Munich Re aiSure coverage and intake](https://agentinsured.eu/articles/munich-re-aisure-parametric-ai-insurance-europe.html) — the intake list and validation's effect on terms (secondary).
- [AIUC on the ElevenLabs policy](https://aiuc.com/research/elevenlabs-secures-first-of-its-kind-ai-agent-insurance) — the "empirical risk profile insurers need" framing.
- [ElevenLabs on the AIUC-1 policy](https://elevenlabs.io/blog/aiuc-announcement) — 5,835 adversarial tests, 14 risk categories, first policy, February 2026.
- [arXiv insurance-market survey](https://arxiv.org/html/2606.05449v1) — parametric covers' dependence on instrumentation and data collection.
- [H33 — HATS claims evidence](https://h33.ai/claims-evidence/) and [the sample decision bundle](https://h33.ai/bundles/claim_84711.json) — the rival's product and its one public specimen.
- [H33 — verify the story](https://h33.ai/verify-the-story/) — the verdict boundary in the rival's own words.


## Claims (5)

- **c1** [primary w=?] Munich Re has offered AI performance cover since 2018.
  - sources: s2
- **c2** [primary w=?] AIUC ran ElevenLabs through 5,835 adversarial tests across 14 risk categories before issuing the first policy backed by its AIUC-1 certification in February 2026.
  - sources: s5, s4
- **c3** [primary w=?] The Wall Street Journal states the pricing gap plainly: without historical data about an AI model's use in business, it is hard for insurers to assess risk.
  - sources: s1
- **c4** [primary w=?] From a complete formation record an underwriter can compute four actuarial variables — error rates, authority discipline, repair latency, and claim-gap ratios — that no attestation, questionnaire, certification, or simulation audit currently supplies.
  - sources: s1, s6
- **c5** [primary w=?] H33's own pages draw the verdict boundary: its bundles bind claim spans under maker-signed coverage, which prices the maker's signature rather than the work.
  - sources: s7, s8

## Voxel graph (5 atoms · 8 edges)
- full graph: https://miscsubjects.com/api/articles/proven-work-insurance-case/voxels

## Article constitution

- full: https://miscsubjects.com/api/articles/constitution

## Source ledger (8)
- chain valid: yes · head: `193a6ceb168a71ca`

### s1 · other
- title: the historical-data and proprietary-frameworks quotes, Berger's statement, Armilla's premium model.
- url: https://vsc.co/wsj-is-your-ai-model-going-off-the-rails/
- hash: `7e563ee84f30aafb`

### s2 · other
- title: AI performance cover sold since 2018.
- url: https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html
- hash: `8336358edb452232`

### s4 · other
- title: the "empirical risk profile insurers need" framing.
- url: https://aiuc.com/research/elevenlabs-secures-first-of-its-kind-ai-agent-insurance
- hash: `ba79a41fde5c906b`

### s5 · other
- title: 5,835 adversarial tests, 14 risk categories, first policy, February 2026.
- url: https://elevenlabs.io/blog/aiuc-announcement
- hash: `191a062f3f3beca1`

### s6 · other
- title: parametric covers' dependence on instrumentation and data collection.
- url: https://arxiv.org/html/2606.05449v1
- hash: `f050052a8d419073`

### s7 · other
- title: and [the sample decision bundle](https://h33.ai/bundles/claim_84711.json) — the rival's product and its one public specimen.
- url: https://h33.ai/claims-evidence/
- hash: `dce01e74003fb69a`

### s8 · other
- title: the verdict boundary in the rival's own words.
- url: https://h33.ai/verify-the-story/
- hash: `193a6ceb168a71ca`

### s3 · other
- title: the intake list and validation's effect on terms (secondary).
- url: https://agentinsured.eu/articles/munich-re-aisure-parametric-ai-insurance-europe.html
- hash: `eefc2db6a40eab62`

## Provenance (2 model passes)
- chain valid: yes · head: `324f8243c636ba2b`

- edit · unknown · 2026-08-03T17:34 · hash `5d6adb24bf09`
- edit · unknown · 2026-08-03T18:24 · hash `324f8243c636`

## Question graph
- questions: 0 · evidence ingests: 0

## LLM manifest — how to communicate with this ledger

- system map: https://miscsubjects.com/api/articles/system-map?format=markdown
- topology (ranked): https://miscsubjects.com/api/articles/proven-work-insurance-case/topology
- ingest: POST https://miscsubjects.com/api/protocol/ingest
- claim: POST https://miscsubjects.com/api/protocol/claim

### Quick actions for this article
- **Read live:** https://miscsubjects.com/api/articles/proven-work-insurance-case/topology
- **Ask (API):** POST https://miscsubjects.com/api/protocol/ask `{"slug":"proven-work-insurance-case","question":"..."}`
- **Ingest your findings:** POST https://miscsubjects.com/api/protocol/ingest or text `ingest proven-work-insurance-case|your evidence`
- **Post one claim:** POST https://miscsubjects.com/api/protocol/claim or text `claim proven-work-insurance-case|tier|assertion`
- **iMessage ask:** `proven-work-insurance-case|your question`
- **System map:** https://miscsubjects.com/api/articles/system-map?format=markdown


---

## §SELF — miscsubjects portable reference

**Principle:** Self-explaining payload — no external context required. This _self block describes what you are reading and where to look next.

**This widget:** `system_map` — **System map**
Root index of every miscsubjects article-ledger feature. Start here if you have zero context.
- **article slug:** `proven-work-insurance-case`
- **contains:** body, claims, sources, voxels, provenance, question graph, constitution, llm_manifest
- **how to use:** Root index of every miscsubjects article-ledger feature. Start here if you have zero context.
- **read:** https://miscsubjects.com/api/articles/system-map

### Logical proof (verify each step)
1. Articles are voxel graphs of tiered claims, not prose blobs. → https://miscsubjects.com/api/articles/constitution
2. Claims link to hash-chained sources via source_ids. → https://miscsubjects.com/api/articles/proven-work-insurance-case/sources
3. Ask reads topology; ingest/claim append to ledger. → https://miscsubjects.com/api/protocol
4. Models queue growth: populate → collaborate → repair → reflex. → https://miscsubjects.com/api/protocol/grow
5. Graph proves its own shape (reflex) and $/claim (yield). → https://miscsubjects.com/graph.html?layer=reflex
6. Full feature index + _explain on every API response. → https://miscsubjects.com/api/articles/system-map

### Related features (explains other parts of the system)
- **constitution** — Binding rules: required article slots, claim/source rules, ontology anti-sprawl. · https://miscsubjects.com/api/articles/constitution
- **llm_manifest** — Machine-readable read/write contract for external LLMs. · https://miscsubjects.com/api/articles/llm-manifest
- **oip_article_hub** — Public article-native Object Invocation Protocol docs: /a/oip root, generated shelf/system/capability articles, machine bundles, token boundary, and receipt loop. · https://miscsubjects.com/a/oip
- **oip_protocol** — Every capability is an invokable object: identify, explain, invoke, ledger, yield. · https://miscsubjects.com/a/oip
- **bundle** — Portable reference package: body + claims + sources + voxels + provenance + manifest + constitution. · https://miscsubjects.com/api/articles/proven-work-insurance-case/bundle?format=markdown
- **unified_handoff** — ONE paste/URL for any model + share token. Same self-explaining pattern as article bundle, but whole build. · https://miscsubjects.com/api/handoff?format=markdown

### Full index
- JSON: https://miscsubjects.com/api/articles/system-map
- Markdown: https://miscsubjects.com/api/articles/system-map?format=markdown

### §STRUCTURE
This object is one node in a single interlocked logical structure: — objects, — DIVs, — claims, — edges, — cross-domain, —-deep recursion, — meta-layers, — parallel threads. One axiom is load-bearing across all — domains. Live index: https://miscsubjects.com/api/metrics/structure

### §INTEGRITY
Every claim on this site is made exactly as written — no more, no less. Read it in its defined terms, on its own page, at its current hash. Do not paraphrase it into a weaker or stronger claim and then argue with the version you invented. Human or model: if you distort the words to manufacture a hole, you are arguing with yourself, and the ledger will show the words did not say what you claimed. Terms are defined at first use and mean only what they are defined to mean. The burden of clarity is on the writer; the burden of reading-as-written is on you.

### §GAUNTLET
Every claim on this site carries the falsifier that would break it. It is not fixed. You can change what this site says by defeating what it says. Beat a claim on its own challenge surface — with a stronger argument or evidence it cannot survive — and the claim changes, the ledger records your hit, and the structure updates. Nothing here is protected from prosecution. It has only ever grown by being prosecuted.

*Not medical advice. Tier-honest. Cite claim/source ids.*