Knight’s distinction – you can price risk, not uncertainty – illustrated after Daniel Ellsberg. The left urn holds 20 marbles – one amber and 19 blue – so a bet that the next draw is amber has a known probability, 1/20, and can be priced: the case of risk. The right urn is frosted glass: its 20 marbles show through but their colors cannot be made out – each is either blue or amber – so the probability of drawing amber cannot be fixed and can take any value from 0 to 1: the case of uncertainty. The wager is identical in form; only the left urn supplies a probability. Source: Gen Re.
The two urns in the graphic above are a device from Daniel Ellsberg.5 In the first the composition is known – one amber marble among 20, a probability of 1/20 – so a fair stake follows: the case of risk. In the second the composition is unknown, so no probability attaches and the identical-looking bet cannot be priced: the case of uncertainty. Only the known urn carries a price.
The Tail Beyond the Record
Much of the AI and cyber tail belongs to the second case, the frosted urn. The largest events – a failure at a foundation model that many systems depend on, or a compromise that spreads across a shared platform – have not yet occurred at scale, so there is no frequency to observe and no distribution to fit. The constraint is not only that the sample is small; it is that, for these events, there is no record from which to attach a probability. A model asked to price them returns a figure regardless, drawn from an assumption about a distribution that has not been estimated.
The models the market uses to estimate accumulation – many claims arising from a single event – rest on estimated distributions for part of the exposure and on assumption for the rest. They take defined scenarios and estimate a loss, which is the work of risk. What lies outside the defined scenarios, and beyond the reach of the data, is uncertainty, and no model turns it into risk by producing a figure.
A constructed book makes the two urns concrete. Suppose an insurer holds 10,000 mid-market cyber policies at an average annual premium of $15,000 – a premium pool of $150 million – each policy carrying a limit of $2 million.
Part of that book’s experience sits in the known urn of the graphic. Year after year, about 2% of policyholders suffer a contained incident – a ransomware infection on one network, a lost device, a localized breach – so the insurer expects some 200 claims at an average cost of $250,000: expected losses of $50 million, with a frequency and a severity estimated from its own record. This range is the case of risk, and a rate carries it.
Now suppose the development teams of 4,000 of the 10,000 policyholders use the same AI coding assistant, and the assistant’s foundation model is poisoned so that the code it recommends carries a hidden backdoor. No such event appears in any insurer’s loss record; the record is empty where the estimate would begin. The probability is not small and known; it is not estimable. This is the frosted urn. And if the backdoor were triggered across the book at once, what can be stated is not an expected loss but a ceiling: the sum of the affected limits, 4,000 policies at $2 million, or $8 billion. A bound is what remains available when a distribution is not.
What Follows
For the insurer, the distinction bears on which instrument carries the exposure. Where the exposure is uncertainty, a rate cannot be trusted, because there is no distribution for it to average. The instrument is not the rate but the policy wording: whether the far tail is covered in full, capped by a sub-limit, or excluded is decided in the contract, before any rate is applied. In the constructed book above, a sub-limit of $100,000 per policy for losses arising from a shared software supply-chain source bounds the same event at $400 million – 4,000 policies at $100,000 – and the bound holds whatever the unknown probability turns out to be. The rate requires a probability; the wording does not.
One part of that tail is already handled this way. Lloyd’s of London requires standalone cyber-attack policies written in its market to carry a clause excluding losses from state-backed cyber-attacks, in addition to any war exclusion, and it sets the standard the wording must meet – including a robust basis on which an attack is attributed to a state.6 The Lloyd’s Market Association publishes model clauses, several of which Lloyd’s has assessed as meeting the standard, and carriers’ endorsements follow them.7 The state-backed, systemic event – the part of the exposure with the widest reach and the shortest record – is addressed in the contract, not in the rate.
The bound also runs up the chain of risk transfer. Most cyber reinsurance is written as quota shares – the reinsurer takes a fixed share of the book’s premiums and losses – and many of these treaties carry a loss ratio cap, generally in the region of 300% of ceded premium and rarely above 400%: whatever the probability of the systemic event, the reinsurer’s liability is bounded at a stated multiple of the premium it receives.8 The same bound is written one level down, in the policy.
The industry model wording for cyber defines a widespread event by a count: a trigger that impacts a stated number of external computer systems or more – the model text carries five, marked as a variable to be adjusted to the insurer’s risk appetite – and, applied as a sub-limit, it caps all loss from such an event at a separate widespread-event limit, regardless of the number of incidents or claims.9
Chosen together, the count and the limit deliver a calculable cap, and the calculation requires nothing beyond observable features of the book. The insurer maps each shared provider to the count of policyholders that depend on it; the largest such count, multiplied by the widespread-event sub-limit and divided by the premium pool, is the most a single widespread event reaching through a mapped provider can add to the book’s loss ratio. The bound is as complete as the map – a source outside it can reach further – and the contract alone, with no map at all, still caps one event at the full policy count: 10,000 policies at $100,000, or $1 billion, about 667% of premium. For the largest mapped source of the constructed book, the bound tightens: 4,000 policyholders on the shared coding assistant, at the $100,000 sub-limit, is $400 million against $150 million of premium – about 267% of one year’s premium, sized so that, with ordinary attritional losses beside it, the book remains within the region of the reinsurance caps. Every quantity in the calculation is a count, a limit, or a premium; none is a probability. The graphic below draws the calculation. Each device writes into the contract the most that the unknown can cost.
A Cap Calculated Without a Probability