Research details
Context
After an AI-mediated loss, the organisation needs to piece together what the system was doing and why. The system’s permissions, inputs, tool calls, and outputs may have changed at each step, and the final harmful event alone does not explain how the system got there. Without that reconstruction, proving causation for an insurance claim is guesswork. The CER Framework structures this problem into three connected requirements.
Key takeaways
- Understanding what went wrong is not enough. You need to reconstruct what the system was doing at each step. An AI system's permissions, context window, tool calls, and outputs can shift throughout a single interaction. Evidence strong enough to support a claim requires capturing the system's state at every stage, not just the final outcome.
- CER connects three questions that must all be answered. Did enforceable controls exist that defined what the system was permitted to do? Can the system's actual behaviour be reconstructed from retained evidence? And does the resulting loss, connected to both the control gap and the evidence, support an insurance response under the placed coverage?
- If any one link is missing, the organisation carries the risk. A control boundary without evidence means you cannot prove the system violated it. Evidence without controls means you have no baseline to compare against. And both without applicable coverage means the loss is unrecoverable regardless. Claim recovery depends on all three.
Contributors
- Alex LeungVulcan
- Rex ZhangOneInfinity
- Kentaroh ToyodaVulcan
- SiewMei LohVulcan
Related Research

The Insurability Frontier of AI Risk
Mapping 55 AI threat classes across 26 insurance products to identify where coverage exists, where exposure is ambiguous, and where exclusions leave gaps.
Read the paper
Bybit Incident Research
How a supply-chain compromise bypassed multi-signature controls in the largest crypto theft in history, and what custody operations can learn from it.
Read the analysis
Recent Centralized Platform Hack Tactics & Mitigation
Mapping the attack tactics behind over $2 billion in centralized platform losses and the layered controls that can disrupt them.
Read the analysisInterested in working together?
Our team is expanding research across Web3, Cybersecurity, and AI.

