prepared privately for Karthik Ramakrishnan, CEO and co-founder, Armilla AI
not indexed · not a customer, partner, or endorsement

You made the coverage boundary clear.The facts that decide which side of it a loss falls on still come from the insured.

You put it exactly right at the Vanguard AI launch: “By making AI liability clear and separate within Vanguard AI, organisations avoid post-loss uncertainty about where an AI-driven failure sits.” That is a real advance, and it is the reason this page exists.

Where a failure sits and whose failure it was are two different questions. Vanguard AI answers the first one with predefined allocation rules and dedicated limits. The second one still arrives the old way. The insured hands over its own logs, the vendor hands over its own logs, and an adjuster reads two accounts written by parties with a stake in the answer.

That is not a gap in your structure. It is a gap in the evidence your structure has to run on. Allocation rules written in advance are only as good as the facts fed to them, and today those facts are produced after the loss by the party who wants a particular outcome.

Eight receipt types below, nineteen live runs. Not screenshots. Your browser posts to the open verify route and shows you what came back, gate by gate. Five of them come back false on purpose, because a demo where everything passes proves nothing.

What this is not

This is not an insurance product, it does not underwrite anything, and it is not a claim that Hive knows more about AI liability than a Lloyd’s backed managing general agent. Nothing here competes with Vanguard AI or with the assessment work behind an AI Performance Warranty.

It is also not a legal determination. No receipt on this page assigns liability, damages, negligence or coverage. Every one of them states its own boundary in plain words, and those boundaries are on the page rather than in a footnote, because an instrument that overclaims is worthless the first time it is tested.

What these are is evidence with a different author. A signed artifact, produced under gates that are open and deterministic, that a reinsurer, a broker, a subrogation target or an opposing expert can recompute without trusting the party that produced it. That property is the whole product.

The commercial case is narrow and it is about claims cost. A contested AI claim is expensive because the facts are contested, not because the coverage is unclear. Coverage clarity is what you already built. Fact clarity is the piece that is still missing, and it is the piece that decides how long a file stays open.

the four questions a contested AI claim actually turns on

Four questions, and where the answer has to come from

Vanguard AI answers the first one cleanly. The other three are still settled by argument, and every one of them is settled from records produced by a party with an interest in the outcome.

ALLOCATED

Vanguard AI answers this one already. Predefined allocation rules decide how coverage responds when a loss spans a cyber incident, a technology failure and AI behaviour, and dedicated limits keep AI losses from eroding cyber capacity.

Nothing in this set touches that boundary. Every receipt here assumes the allocation framework works exactly as you designed it and produces facts that feed it.

This question is answered. The next three are not.

ATTRIBUTED

Knowing the loss is an AI loss does not tell you whose AI failure it was. The vendor, the deployer, the integrator and the insured all have a version, and each version arrives as a narrative supported by that party’s own logs.

fault.attribution derives single, shared or hindsight from artifacts committed before the loss, and the hindsight finding protects the party who broke nothing on a day the outcome was still bad.

The claim file stops being four narratives and becomes one finding.

TRIGGERED

A performance warranty that pays when accuracy drops below verified thresholds needs the threshold in force at the time to be a fact, not a recollection, and the measurement to be one nobody could restate afterwards.

parametric.trigger recomputes the outcome from a threshold committed before the measurement, and returns indeterminate rather than guessing when the input will not support a verdict.

The trigger stops being a judgement call.

ADMINISTERED

Every warranty rests on an assessment. In a contested claim the assessment is the first thing attacked, usually on the ground that the test was known in advance or the assessor was too close to the party being assessed.

eval.administration binds the test set to a commitment made before administration and derives the independence claim from the parties on the record, with no quiet restatement of a score afterwards.

The assessment survives cross examination.

question one · deployed in production · three runs

fault.attribution, the Fault Attribution Receipt

Vanguard AI settles which policy a loss sits in. It does not settle whose failure produced the loss. Those are different questions and only the second one decides whether you have a subrogation target, a shared loss, or a claim you should pay in full without argument.

fault.attribution

Which party’s breach produced the outcome, derived from artifacts committed before the loss

Fault lands in one of three shapes. Single, where one party’s breach explains the outcome. Shared, where more than one contributed and the receipt refuses to pick a favourite. Hindsight, where the outcome was bad and no committed constraint was actually broken.

ATTRIBUTION_CLASS_RECOMPUTE and ATTRIBUTED_ROLE_RECOMPUTE derive the shape and the party from the artifacts rather than reading a conclusion somebody typed into a claim file. PRECOMMITMENT_PRECEDENCE and VIOLATION_SUBSET_INTEGRITY stop a loss from being retrofitted into somebody’s breach after the fact, which is the single most common move in a contested AI claim.

Run the hindsight case first. A signed finding that the insured broke nothing, on a day the outcome was still bad, is the hardest artifact in the whole set to produce and the one that most changes how a claim is handled.

What it does not prove, in plain words. It does not assign legal liability, damages, negligence or coverage, and it is not a legal determination of any kind. It attests to which committed constraints were broken by which named party under the stated procedure.

POST /verify/fault-attribution · case single, one party’s breach explains it

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/fault-attribution · case shared, more than one contributed

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/fault-attribution · case hindsight, bad outcome, no constraint broken

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

question two · deployed in production · three runs

recovery.determination, the Recovery Determination Receipt

Your announcement says predefined allocation rules govern mixed scenarios, so claims can be allocated by harm where an incident spans a cyber event, a technology failure and AI system behaviour. Rules written in advance are the right design. The friction that remains is not in the rules. It is in the facts fed to them.

recovery.determination

Allocation across parties, recomputed from a table committed before the determination

ALLOCATION_TABLE_INTEGRITY and ALLOCATION_PRECEDENCE require the allocation table to have existed and been committed before the determination, so nobody writes the split after seeing the number. ALLOCATION_ENTRY_RECOMPUTE derives each party’s share from the table and the attribution rather than accepting a stated figure, and SETTLEMENT_POSITION_RECOMPUTE derives the net position the same way.

ATTRIBUTION_LINK and ATTRIBUTION_INTEGRITY bind the determination to a specific fault.attribution receipt, so recovery cannot be argued from a fault finding that was edited or replaced in between.

NO_PARTY_IDENTITY_LEAK means the receipt can be handed to a reinsurer or a broker without exposing who the parties are. The allocation is checkable while the names stay commitments.

What it does not prove, in plain words. It does not determine legal liability, does not create or interpret a right of recovery, and does not bind any party to pay. It attests that a stated allocation follows from a committed table and a linked attribution finding.

POST /verify/recovery-determination · case respondent, one party carries it

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/recovery-determination · case shared, split across parties

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/recovery-determination · case none, no recovery position

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

question three · deployed in production · three runs

parametric.trigger, the Parametric Trigger Receipt

The AI Performance Warranty triggers compensation if accuracy drops below verified thresholds. That is a clean product. The open question on your own page is who determines that accuracy dropped, and whether the threshold in force at the time is the threshold everyone remembers afterwards.

parametric.trigger

Did the condition actually trip, recomputed against a threshold committed before the measurement

PRECOMMITMENT_ORDER requires the threshold to have been committed before the measurement it is judged against, so a threshold cannot be softened once a payout looks likely, or tightened once one does not. TRIGGER_RECOMPUTE derives triggered or not triggered from the committed threshold and the attested measurement instead of reading a conclusion.

ATTESTATION_LINK and ATTESTATION_INTEGRITY bind the trigger to the measurement receipt it claims to rest on. INDETERMINATE_PROPAGATION is the honest one. If the input is indeterminate, the trigger has to say indeterminate rather than resolving to whichever answer suits the party holding the pen.

Run the nottriggered case. A signed finding that the condition did not trip is worth as much to you as one that says it did, and it is the finding an insured is most likely to contest.

NO_POLICY_LEAK means the receipt proves the trigger without publishing the policy terms. The wording stays private and the arithmetic stays checkable.

What it does not prove, in plain words. It does not price the risk, does not determine coverage, and does not obligate anyone to pay. It attests that a stated trigger outcome follows from a committed threshold and a linked, integral measurement.

POST /verify/parametric-trigger · case pass, the condition tripped

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/parametric-trigger · case nottriggered, it did not trip

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/parametric-trigger · case fail, the trigger does not hold up

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

question four · deployed in production · two runs

eval.administration, the Eval Administration Receipt

Armilla validates a model’s performance, fairness and robustness and then wraps it in a warranty. Everything downstream of that assessment inherits whatever the assessment was worth. If a payout is ever disputed, the first thing the other side attacks is the test, not the model.

eval.administration

Was the eval administered independently, on a test set committed before the model saw it

TESTSET_PRECOMMITMENT requires the test set to have been committed before administration, which is the entire defence against a model being tuned to the exam. SEPARATION_COHERENCE and INDEPENDENCE_RECOMPUTE derive the independence claim from the parties on the record instead of accepting an assertion that the assessor was independent.

NO_SCORE_RESTATEMENT is the gate that matters in a dispute. A score cannot be quietly restated after the fact. The number the warranty was priced on is the number that stays on the record.

EVAR_LINK and EVAR_INTEGRITY bind the administration receipt to the underlying evaluation attestation, so the chain from raw result to warranty terms holds together under examination.

What it does not prove, in plain words. It does not say the model is safe, accurate, fair, fit for a purpose, or compliant with any law or standard, and it does not endorse the test set. It attests to how the evaluation was administered and by whom.

POST /verify/eval-administration · case pass, independently administered

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/eval-administration · case fail, the separation does not hold

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

question five · deployed in production · two runs

causal.path, the Causal Path Receipt

Standalone AI liability answers where no cyber event has occurred. Proving the negative is the hard part. You need a path from the origin to the effect that holds together step by step, because the party on the other side will attack the weakest link and only needs one.

causal.path

Does the chain from origin to effect actually hold, step by step

STEP_INDEX_DENSE and PATH_CONTINUITY require the steps to be complete and connected with no quiet gap in the middle. STEP_DIGEST_FIDELITY checks each step is the artifact it claims to be rather than a later reconstruction. TEMPORAL_MONOTONIC and EFFECT_AFTER_TERMINUS enforce the ordering, so an effect cannot be attached to a cause that came after it.

Run the broken case. It is the more useful of the two. A receipt that says the chain does not hold is a defensible reason to decline or reserve, and it is far stronger than an adjuster’s narrative that the evidence looked thin.

NO_HARM_TEXT keeps the harm description out of the receipt. The structure of the causal chain is provable without the receipt itself becoming a document about somebody’s injury.

What it does not prove, in plain words. It does not establish legal causation, proximate cause, or liability, and it does not say the effect was harmful. It attests that a declared chain of committed steps is continuous, ordered, and faithful to the artifacts it references.

POST /verify/causal-path · case pass, the chain holds

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/causal-path · case broken, the chain does not hold

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

question six · deployed in production · two runs

portfolio.exposure, the Portfolio Exposure Receipt

Dedicated AI aggregate limits of twenty five million or more per organisation, alongside ten million in cyber, are designed so AI losses do not erode traditional capacity. The accumulation question sits one level up. If a hundred insureds are running the same model behind different products, the correlation is real and nobody outside your book can see it.

portfolio.exposure

Concentration inside a book, proved to a counterparty without publishing the book

COMMITMENT_OPACITY and SALT_COMMITMENT_FORM keep the members as commitments, so the receipt can go to a reinsurer or a capacity partner without handing over your insured list. MIN_COHORT refuses to emit when the group is small enough to identify a member by arithmetic.

CONCENTRATION_RECOMPUTE and SHARE_RATIO_RANGE derive the concentration figure from the committed members rather than accepting a stated percentage, and AS_OF_NOT_FUTURE stops an exposure snapshot being dated forward.

This is the instrument for the conversation with capacity. A concentration number a reinsurer can recompute is a different asset from one they have to accept from the ceding party.

What it does not prove, in plain words. It does not model, price or forecast risk, does not say the concentration is acceptable, and does not describe what the members are exposed to. It attests that a stated concentration figure follows from a committed member set.

POST /verify/portfolio-exposure · case pass, the concentration figure holds

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/portfolio-exposure · case fail, it does not recompute

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

question seven · deployed in production · two runs

mandate.conformance, the Mandate Conformance Receipt

Your standalone policy covers AI agent actions. Underwriting an agent means underwriting the limits it was given, so the limits have to be a fact at claim time rather than a recollection. Widening a mandate after a bad transaction is the cheapest possible defence and the hardest one to disprove from logs.

mandate.conformance

Did the agent stay inside the mandate that existed before it acted

MANDATE_PRECEDES_TRANSACTION and VALIDITY_WINDOW put the mandate ahead of the action in time. AMOUNT_WITHIN, CURRENCY_MATCH and SCOPE_MATCH check the action against it. CONFORMANCE_RECOMPUTE derives the verdict rather than reading one.

Run the fail case. It returns valid false with CONFORMANCE_RECOMPUTE failing, because the body claims a pass the arithmetic does not support. A verifier that refuses to bless a mismatched claim is the property that makes the passing receipts worth anything.

NO_PAN keeps instrument numbers out of the receipt entirely, so the artifact can move between insured, broker, insurer and reinsurer without dragging payment data with it.

What it does not prove, in plain words. It does not say the mandate was appropriate, authorised by the right person, or lawful, and it does not say the payment was correct. It attests that a specific action fell inside a mandate committed before the action occurred.

POST /verify/mandate-conformance · case pass, inside the mandate

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/mandate-conformance · case fail, the claimed pass does not recompute

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

question eight · deployed in production · two runs

effect.quiescence, the Effect Quiescence Receipt

The claim nobody can currently make is the quiet one. Across the whole policy period, nothing prohibited happened. Absence of evidence is not evidence of absence, and an insured saying the logs are clean is worth very little to the party paying the loss.

effect.quiescence

Nothing prohibited landed across a bounded interval, with the interval anchored at both ends

OPENING_ANCHOR_PRECEDENCE and CLOSING_ANCHOR_LAG anchor both ends of the window to artifacts committed outside it, so the interval cannot be trimmed around an inconvenient event. CHAIN_CONTINUITY and GAP_BOUND cap how much silence is allowed inside it, which is what turns a quiet log into a covered interval.

CHANNEL_SET_COMPLETE and the roster gates require the set of watched channels to have been committed in advance. Otherwise a clean report is just a report about the channels somebody chose to look at afterwards.

COVERAGE_RECOMPUTE and VERDICT_RECOMPUTE derive the quiescence verdict from the anchors and the admitted effect count instead of accepting a summary.

What it does not prove, in plain words. It does not say the system is safe, correct or well governed, and it says nothing about effects on channels outside the committed roster. It attests that no admitted effect landed on the committed channels across the anchored interval.

POST /verify/effect-quiescence · case quiescent, nothing landed

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

POST /verify/effect-quiescence · case effect, something did

Nothing has run yet. Click Run it and the answer below comes back from the verifier, not from this page.

Coverage clarity is yours. Fact clarity is the piece still missing.

Every receipt above is deployed, open to verify, and honest about what it does not prove. If the argument holds, the next step is one integration against a route you can already call from a terminal.

Verify a receiptRead the canon

Sources, verbatim and linked. The Karthik Ramakrishnan quotation, the predefined allocation rules, the dedicated AI aggregate limits of $25 million or more per organisation and the $10 million cyber limits are from the Chaucer and Armilla AI Vanguard AI announcement, February 10, 2026. The AI Performance Warranty triggering when accuracy drops below verified thresholds, and the validation of model performance, fairness and robustness, are from armilla.ai. The Lloyd’s backed managing general agent description is from the Armilla company page. Hive receipts are signed with Ed25519 and ML-DSA-65 under FIPS 204, canonicalized with RFC 8785 JCS. Patent pending. Example bodies on this page are signed with did:hive:example keys, so verify reports key_trust example_registry. That is deliberate, and nothing here can be mistaken for a production issuance. Hive is not a customer, partner, vendor or affiliate of Armilla AI, and nothing on this page is an endorsement by Armilla AI.