TwinLadder Weekly
Issue #38 — The Insurers Priced It First
30 May 2026 · Weekly intelligence on judgment, governance, and the boards accountable for both
Editor's Note
From Alex —
Three parties put a value on AI risk in the last week of May. An insurance bureau, an economist and a federal court. None of them sat on a board.
The Insurance Services Office added optional generative-AI exclusions to its 2026 commercial general liability forms, and several major carriers adopted them or similar language. Comparable wording is appearing in directors-and-officers cover. An underwriter who cannot price a hazard writes it out of the policy, and that is a valuation — made by the one party in the chain with its own capital behind the answer.
In MIT Technology Review, the economist Georgios Petropoulos described entry-level hiring in balance-sheet language: "an investment in the future stock of judgment inside the firm." That sentence arrived from outside our orbit, in a mainstream venue, with the asset named and the spending on it called capital.
And in the Northern District of California, a court held that a company's own AI bias-testing data was privileged and need not be produced, because its lawyers had curated it and the purpose was legal advice. The governance evidence turned out to be worth more as a litigation shield than as governance.
Three valuations, all reached in the same seven days. The board's own accounts carry no entry.
Liga has the analysis.
— Alex
What the Insurance Market Did
On 27 May the law firm Honigman published an analysis of what it calls the AI insurance gap. The Insurance Services Office — the body that drafts standard insurance policy forms — introduced optional generative-AI exclusions for 2026 commercial general liability policies. Several major carriers adopted them or similar language. Parallel exclusions are appearing in D&O.
Follow what that does to a contract a procurement team signed last year.
The vendor's agreement carries an indemnity. If the AI system causes a covered harm, the vendor makes the customer whole. That clause was the comfort the deal was approved on, and in a great many approval chains it was the last time the liability question came up at all.
Behind the indemnity sits the vendor's own insurance, which is what would actually fund a payout of any size. Honigman states the consequence plainly: "When a vendor agrees to indemnify, it may have no insurance to fund that obligation."
Then the second half. The enterprise buyer's own general liability policy — the fallback for anything the vendor cannot cover — may now exclude the same class of loss under the same new wording. So both legs of the arrangement can be hollow at once, and the residual exposure comes to rest where it was never priced: on the buyer's balance sheet.
Read the exclusion as what it is commercially. An insurer facing a hazard it can price charges a premium for it. An insurer facing a hazard it cannot price declines to carry it at any premium it is willing to name. The exclusion is the underwriter's statement that the loss distribution for generative AI is, for now, unknowable at the level of precision the business requires.
Hold that beside the sentence heard in most board discussions of AI capability risk: we will take a view when someone gives us a number.
The insurers face the same missing number. Their response to it was to move the exposure. The board's response has been to wait. One missing number, two opposite actions — and only one of them changes who is carrying the risk.
The Board Sits Where the Underwriter Sits
The instinct to wait for proof is the scientist's instinct, and it belongs in a laboratory, where the cost of waiting falls on nobody and the experiment will still be there next year.
A board occupies the underwriter's chair. The underwriter's question is never has this been proven. It is: what is our exposure, how would we know it is forming, and what do we provision against it before the loss event? A director who imports the laboratory's standard into the boardroom has mistaken the job.
Boards already run one risk on exactly these terms, and it has sat on the register for decades without a number attached: key-person and succession risk. No board waits for its most irreplaceable executive to die or defect before provisioning. The dependency is registered on plausibility — this person holds knowledge we cannot easily replace — long before any departure, and with no quantified loss figure, because none exists. The capability is partly tacit. The feedback loop is slow. The failure feeds itself: lose the one person who trains the others and you lose the means of training their replacements.
That sits in the formal disclosure record. Under the modernised US risk-factor rules in force since late 2020, a filer must disclose its material risks in narrative form, and dependence on key personnel is among the most common disclosures made. The disclosure is deliberately non-quantified. It is triggered by a materiality judgment and satisfied by naming the risk.
Set that beside the two risks usually offered as the friendly precedent. Pension obligations earned their line on the register in 2006, when the accounting standard moved a plan's funded status onto the face of the balance sheet where a director could see it. Cyber earned its line the same way, as it became quantifiable and reportable — the SEC's 2023 rule requiring incident disclosure within four business days, and quantification frameworks arriving to price the exposure. Each earned its line once it could be counted, which concedes the very thing in dispute.
Succession is the matching shape: slow, partly tacit, self-reinforcing, registered before the loss because the loss is the proof and the proof arrives too late to use. A board that registers succession on plausibility while demanding a decade of clean evidence before registering capability decay is running two standards against one family of risk.
Kevin Schwartz of Wachtell, Lipton, Rosen & Katz put the operative half of this on the Harvard Law School Forum on 25 May: "An AI tool is an instrument, not a decision-maker — but it is an instrument that can speak, decide, or act in ways once reserved for humans." His argument is about assignment. Where a machine now decides, documents or represents, a named human has to own the output, and that assignment is made deliberately or it is made by default.
Shareholders are supplying little pressure to make it. Boardroom Alpha's proxy tracking for the season to 21 May recorded eight AI-focused proposals across four US issuers, roughly four times the same-period activity in 2025, one of them asking a board to "update the Audit Committee charter to provide formal oversight on responsible development and deployment of AI". Seven were still pending. The one that had already reached a vote, at IBM's annual meeting in April, drew 2.4% support.
The insurance market moved this month. The proxy season stayed where it was. Whatever gets priced inside a listed company this year gets priced by the people in the building.
The Asset, Named From Outside
On 26 May, MIT Technology Review published Georgios Petropoulos on the state of entry-level work. His argument is that the weakening of the first rung of the career ladder is hidden beneath stable aggregate employment figures, and the line at the centre of it is a balance-sheet line:
"Entry-level hiring is not just an expense. It is an investment in the future stock of judgment inside the firm."
The evidence he assembles is specific. Workers aged 22 to 25 in the most AI-exposed occupations have experienced a 16% relative employment decline since generative AI spread, on a Stanford Digital Economy Lab working paper from November 2025. Recent-graduate unemployment stood at 5.6% in the fourth quarter of 2025, with underemployment for the same cohort at 42.5%. His prescription is paid co-ops, apprenticeships and employer-linked projects, so that judgment forms in a real workplace before graduation.
Take the accounting seriously, because the accounting is the whole problem. A graduate hired into a bank, an audit practice or a claims department appears in the ledger as salary, national insurance, desk, laptop and a supervisor's time. Every element of that is a cost, arrives this year, and can be cut this year. The thing the money buys — the reps out of which a competent thirty-five-year-old is eventually assembled — appears in no column at all.
Klarna ran the clean version of this. In 2024 it put an AI assistant in front of its customers and reported, on its own unaudited account, average handling time falling from eleven minutes to under two, with the system doing the work of seven hundred agents. By 2025 its chief executive Sebastian Siemiatkowski was walking it back. Cost, he said, had been too predominant a factor, and the result was lower quality. The company was rehiring, and promising there would "always be a human if you want."
The useful part of that case is the bookkeeping. The same company defined the win and defined the loss, both on its own say-so, and nobody outside measured either. The saving was legible and bookable in the quarter it occurred. Whatever judgment had been forming inside the nine cut minutes — the read of a customer in trouble, the texture of an ordinary complaint that an agent files away and recognises next time — was never on any number. So it could be removed without anyone watching it go.
That is the mechanism, and no board chose it. A saving and a loss simply never appeared on the same page. The saving books into a column that exists. The loss sits in one nobody has drawn.
Which is what makes Petropoulos worth reading in a board pack. He is an economist writing in a technology magazine, with no stake in your competence programme, and he reached for the same accounting concept: a stock, held inside the firm, funded by a spending line currently classified as overhead.
The Third Valuation: Governance Evidence, Repriced as Privilege
On 28 May, in the AI hiring-discrimination collective action Mobley v. Workday, Inc., Case No. 23-cv-00770-RFL (LB) in the Northern District of California, the court held that Workday's AI bias-testing data was protected by attorney-client privilege and need not be produced.
The holding turned on three findings. Workday's attorneys had curated the data used in the testing. The overall purpose was to obtain legal advice, and the results were kept out of business use. And the data had never been submitted to a regulator. The court also rejected the argument that publicly referring to the existence of bias testing waived the privilege. As the record puts it: "Workday has represented that its attorneys curated the data it used in the bias testing. The overall purpose of the testing was to provide legal advice and not to be used in a business capacity."
This is a discovery ruling. It settles nothing about liability, and the collective action continues.
It settles a great deal about value.
Bias testing has two possible careers inside a company. As governance, its worth is that the result reaches a person with the standing to change the system — the product owner who retunes the model, the HR director who suspends a screen, the committee that stops a rollout. Its value is realised at the moment somebody acts on it. As privilege, its worth is that a plaintiff never sees it. Its value is realised at the moment somebody tries to.
The same dataset supports both careers, and the design choices that produce one foreclose the other. Curate the data through counsel for legal advice, hold it back from operational use, keep it away from the regulator, and you have built the shield. Route it into operations, brief it to a committee on a schedule, hand it to a supervisor as evidence of compliance, and you have built the instrument — and very likely spent the privilege.
Workday's arrangement was priced as a shield, and a federal court has now confirmed the price was real. That is the third valuation of the week, and it is the one a risk committee has to answer for itself, because a great many large employers running an automated screening tool have a testing programme structured the same way and have never asked which career it is having.
Two questions follow for a director. When the bias-testing results come to your committee, do they arrive through counsel, written to survive a deposition? And if a supervisor asked for the same file tomorrow, would producing it cost you the protection you have been quietly relying on?
Where the Number Comes From If Nobody Books It
A risk with no owner still gets priced eventually. It gets priced by the event.
Gartner said as much on 26 May: "By next year, 40% of enterprises will have their autonomous AI efforts in part derailed by gaps in governance discovered only after production incidents." The discovery mechanism is named in the sentence. The gaps get found by the incident.
Gartner's diagnosis is that enterprises apply uniform governance across agents regardless of autonomy level and trust boundary, which produces two symmetrical failures — over-restricted agents that deliver nothing, and over-trusted agents that act outside their scope. Its remedy is a set of instruments: explicit guardrail definitions, rollback capability, continuous monitoring, and a mechanism to stop an agent that breaches its thresholds. All four are things a company builds before the incident or explains afterwards.
The week supplied the small version of the same shape. A California appellate court reversed and remanded after finding that a trial judge, Judge Irene A. Luna, had issued a ruling incorporating language nearly identical to the father's brief — including a citation to a fictitious case, "Enrique M. v. Angelina V. (2005) 15 Cal.App.5th 788", and a misstatement of Family Code §6203. Opposing counsel had already flagged both errors before the ruling issued. The check existed, arrived on time, and was not read. The appellate court's finding: "Reliance on fake cases is fundamentally incompatible with an informed exercise of discretion controlled by genuine principles of law."
Behind that docket is a family whose case turned, for a time, on an authority that had never existed.
And on 28 May Anthropic released Claude Opus 4.8, with a one-million-token context window by default across the Claude API and the major cloud platforms, and a claim about its own error rate: "Opus 4.8 is around four times less likely than its predecessor to allow flaws in code it has written to pass unremarked." Read that as a commercial signal. The vendor is selling the quality of the model's self-checking, which invites a buyer to check less. Every improvement of that kind raises the value of the human check, because the errors that survive a better filter are the ones a tired reviewer will pass.
Insurer, economist, court, analyst house, vendor. Each of them, inside seven days, put a value on some part of this. The board that carries the residual has yet to put one on its own accounts.
What This Means for Boards Right Now
One. Put the insurance question on the agenda by name, this quarter. Which policies covering this company now carry a generative-AI exclusion, on what wording, and from which renewal date? Which AI-related loss scenarios fall in the gap between a vendor's indemnity and our own cover? Ask management to show the vendor's evidence of insurance behind the indemnities in the three largest AI contracts, because "when a vendor agrees to indemnify, it may have no insurance to fund that obligation." Where the answer is that the residual sits with us, that is a decision, and it belongs in minutes with a name against it.
Two. Register the capability risk on the terms you already use for succession. The board does not have a number for what thinning the junior bench costs, and it will not get one in time to act. It has the mechanism, the slow feedback loop and the self-reinforcing failure. That is the standard this house already applies to key-person dependence, in a formal disclosure, without a figure. Add the line, name the owner, fix the date it is re-read. A risk without a clock is a topic.
Three. Decide deliberately whether your AI testing is built for governance or for privilege, and record which. Mobley shows the two designs diverge at the point of curation, and that a company can say publicly that it tests for bias while keeping every result out of discovery. Both are legitimate. Holding both by accident is the failure. If the tests are privileged, accept that the board's picture of model behaviour arrives filtered through counsel, and ask what independent reading exists alongside it.
Which leaves the question this week put on the table, for the next meeting: who is carrying this risk now that the policy excludes it?
Reading List
-
What the Klarna reversal actually demonstrates about efficiency numbers, and why the saving and the loss in these programmes never appear on the same page: The Hollowing: What Klarna Learned, What Block Is About to
-
The longer argument on what happens to the pipeline when the first-draft work disappears, and what would have to replace the tuition juniors used to absorb for free: The Apprenticeship Is Breaking — and Almost Nobody Is Saying So
-
A practical read of vendor diligence, and the questions that reach past the indemnity clause to what funds it: How to Evaluate Your AI Vendor in 30 Minutes (And Why It's Not Enough)
-
Where automated screening tools sit under employment and data protection law, and what a defensible testing programme has to demonstrate: AI in Recruitment: The Compliance Minefield HR Teams Must Navigate
What We Are Watching Next
- Whether any major carrier publishes the operative wording of a generative-AI exclusion it has adopted, and whether the D&O market follows the general liability market on the same terms
- Whether any listed issuer discloses, in a risk factor, the AI exposure it now retains after its own policies exclude it
- Whether a court in another AI matter reaches a different conclusion on privilege over bias-testing data, or a supervisor asks an employer for the same file directly
- Whether the European Commission's targeted consultation on high-risk classification, which runs to 23 June, draws submissions specifically on employment and recruitment screening tools
- Whether any board describes entry-level hiring in its own reporting as an investment in future capability, in the language Petropoulos used
The next issue goes deeper into one of these. If you want a specific function or sector covered, reply to this email.
— Liga
TwinLadder Weekly is a weekly intelligence report on judgment, governance, and the boards accountable for both. Subscribe at twinladder.ai/newsletter. Forward this issue freely.
