---
title: "The Risk You Can Price"
date: 2026-08-23
summary: "Advertisers already own the cheapest hedge in media: the pause button. So the open web's first real performance insurance will protect the sell side, not the buy side — the publisher's receivable, the intermediary's spread, the counter's restatement — assembled from narrower protections around payment, counting and residual performance risk rather than one policy. The near-term contract names its counting source, escrows the money and bonds the count. The parametric policy on the landlord event itself comes last, once the loss history exists."
standfirst: "Sequel to the uninsured essay: how the open web actually gets its fourth clause — and for whom. The thesis is a demand inversion: advertisers already hold the cheapest hedge in media, the pause button, so the first real performance premium will be paid by the sell side, whose exposures cannot be paused away — the publisher's receivable (credit risk; CJ pays only if the advertiser account holds funds), the intermediary's spread (performance risk; Criteo carried it for a decade), the counter's restatement (measurement error; VAB projected Nielsen's pandemic undercount at up to $468M–$2.8B, and TV settles misses in make-good inventory, not cash). What changed: the conversion count moved server-side and into signed order objects while the exposure-to-conversion join stays rented, and the browser's revocation power multiplied into courts, operating systems, wallets and agent vendors — revocation becomes a nameable, priceable parameter instead of an act of God. Two missing institutions: an adjudicator for conversion counts, and a shared loss history. The instrument ladder: escrow + named counting source + count bond now; benchmark-relative cash settlement next; screened reinsured warranties after the triangles (Munich Re's aiSure proves algorithmic performance risk is insurable, not that media outcomes pass the test); a parametric policy on the landlord event itself last. Three falsifiable predictions, ending: the web doesn't need to own its inputs, it needs to price them."
canonical: https://nofluffadvisory.com/writing/the-risk-you-can-price/
---

*Part 2 of a pair. [Part 1](/writing/the-open-web-isnt-dead-its-uninsured/) diagnosed the open web as uninsured: it can define an outcome, measure it and settle a campaign, and nobody pays when the result misses. This essay is about how the missing piece gets built, and who actually buys it.*

## The claim nobody could file

In December 2017, an Apple software update cut the signal Criteo used to reach Safari users. Criteo raised its estimate of the damage to [about 22% of the next year's revenue ex-TAC](https://www.sec.gov/Archives/edgar/data/1576427/000134100417000758/ex99_1.htm). No claim was filed, because there was nothing to file it with. The risk that a browser would change the rules had never been written into a contract, priced, or backed with collateral. It was treated as weather.

Now imagine the contract this essay proposes. It names its counting source, reserves cash against a counting failure, and lists the platform dependencies its settlement rests on. The update still causes damage. The near-term contract does not pay for the platform shock. It does something more basic: it isolates the dependency, records the resulting loss and begins the history an underwriter would need to price it.

That is the difference between the web [Part 1](/writing/the-open-web-isnt-dead-its-uninsured/) described and the one this essay is about. Part 1 ended on a diagnosis: the open web can define an outcome, measure it and settle a campaign, but nobody puts a counterparty behind the miss, and the walled gardens don't either. The obvious next question is how to build the missing piece. I spent the last week testing answers, and the most useful thing I found is that the industry has been aiming the entire project at the wrong customer.

## The pause button

Ask who needs outcome insurance and everyone gives the same answer: the advertiser. It has been the assumed buyer for twenty years, through every "guaranteed outcomes" pitch since [Xaxis in 2017](https://www.adexchanger.com/agencies/trading-desk-heyday-behind-xaxis-shifts-narrative-guaranteed-outcomes/).

But the advertiser already holds the cheapest hedge in media. A campaign can be paused mid-flight, at zero cost, the moment the numbers disappoint. The buyer who wants protection against underdelivery has it built into the product. It isn't perfect protection. Sunk creative, launch windows and seasonal inventory all leak through it. It is good enough, though, to materially reduce an advertiser's willingness to pay a real premium for insurance on a thing they can simply stop buying. And the advertisers who would pay are disproportionately the ones who know their campaign is in trouble, which is the adverse-selection spiral that kills the product.

Now look at the other side of the trade, where the exposures are lumpy, unavoidable, and outside the exposed party's control.

The publisher's receivable. In affiliate marketing, the one channel that prices the conversion itself, the publisher carries the advertiser's credit risk. CJ Affiliate says it plainly in its own payment documentation: ["For CJ to pay out commissions, there must be enough funds in the advertiser account to cover the amount due."](https://junction.cj.com/article/cookie-dough-understanding-publisher-payment-cycle) The publisher did the work, the conversion happened, and payment still depends on someone else's account balance.

The intermediary's spread. Criteo carried the gap between impressions bought and clicks sold for a decade. What ended that run was not a bad model but a landlord event it could neither control nor insure.

The counter's restatement. When the count itself is wrong, the damage is real money. The VAB projected that Nielsen's pandemic-era undercount [could have meant as much as $468 million to $2.8 billion](https://www.nexttv.com/news/nielsen-undercounted-viewing-according-to-media-rating-council) in national TV ad dollars over twelve months. And notice how television settles guarantee misses: in audience deficiency units, meaning make-good inventory in future programs, [a liability reduced by airing more ads](https://www.sec.gov/Archives/edgar/data/1103837/000104746915000983/a2223120z10-k.htm), not by cash. The oldest guaranteed medium in advertising pays its claims in more advertising.

These are three different risks. The receivable is credit risk. The spread is performance risk. A restatement is measurement error, shading into professional liability. The distinction matters, because it changes what arrives first: the fourth clause will not show up as one policy. It will be assembled from narrower protections around payment, counting and residual performance risk.

None of those exposures can be paused away. They sit with parties who have every reason to pay for protection and no pause button that removes the exposure. That inversion is the thesis: the first real performance premium on the open web will be paid by the sell side.

> [figure: The demand inversion, drawn as two sides of one trade. Left, the buy side: an advertiser card with a large pause button labeled the free hedge — a campaign can be paused mid-flight at zero cost, with a note that sunk creative and launch windows leak through. Right, the sell side: three stacked exposure cards that cannot be paused away. The publisher's receivable, tagged credit risk: payment depends on the advertiser's account balance. The intermediary's spread, tagged performance risk: Criteo carried impression-to-click variance for a decade. The counter's restatement, tagged measurement error: the VAB projected Nielsen's pandemic undercount at up to 468 million to 2.8 billion dollars over twelve months, and television settles misses in make-good inventory, not cash. The caption reads: the first real performance premium is paid on the right.]

## What changed since Criteo's weather years

Two things moved between 2017 and 2026, and one thing didn't.

The count left the browser. Conversion signals now travel server-side through conversion APIs, from the advertiser's systems rather than through a script a browser can block. Agentic commerce went further. The checkout protocols that shipped in late 2025 pass [signed, structured order objects](https://developers.openai.com/commerce/specs/checkout) between agent and merchant. Google's payments protocol for agents rests on ["tamper-proof, cryptographically-signed digital contracts"](https://cloud.google.com/blog/products/ai-machine-learning/announcing-agents-to-payments-ap2-protocol) recording what the user authorized. Purchases are becoming typed evidence. Meanwhile the last serious attempt to put the counter inside the browser, Privacy Sandbox, was retired in October 2025. The conversion count is becoming steadily less dependent on the browser.

The join is still rented. Connecting that conversion back to an ad exposure still rides click identifiers, link decoration and first-party storage that browsers meter and trim. Counting is increasingly server-side. Attribution still crosses someone else's bridge.

And the landlord didn't die. It multiplied. Courts joined the list. Belgium's litigation over the consent framework ended in May 2025 with a ruling that the TC String, the consent record under much of European ad targeting, [is personal data and its operator a joint controller](https://www.dataprotectionauthority.be/citizen/the-market-court-rules-in-the-iab-europe-case). A legal substrate can be re-scoped by judgment. Operating systems control the login and permission moments. Wallets tokenize the card numbers that card-linked measurement reads. And the agent vendors are assembling cross-app event graphs that look exactly like the position Chrome held in 2019.

Put together, this is bad news for anyone hoping to own a loop the way AppLovin owns one, and quietly good news for insurance. A risk that cannot be engineered away but can be named, bounded and given a base rate is precisely the kind of risk markets learn to price. The 2016 web treated revocation as an act of God. The 2026 web can treat it as a parameter.

> [figure: What changed between 2017 and 2026, drawn as two signal paths and a row of landlords. The count path: a purchase now travels server-side, from the advertiser's systems through conversion APIs and signed order objects into a count ledger, bypassing the browser entirely; the old in-browser route is crossed out. The join path: connecting that conversion back to an ad exposure still passes through a browser tollgate of click identifiers, link decoration and metered storage, drawn in orange and labeled still rented. Below, four tiles labeled the landlord multiplied: courts, which re-scoped the TC String by judgment in May 2025; operating systems, which control login and permission moments; wallets, which tokenize the card numbers card-linked measurement reads; and agent vendors, assembling cross-app event graphs like the position Chrome held in 2019. The kicker reads: counting is increasingly server-side; attribution still crosses someone else's bridge.]

## Five routes, one parts list

I tested five ways to give the web an AppLovin-grade commercial model: a publisher mutual that guarantees floor prices, a co-owned identity utility, an outcome clearinghouse, the user's agent as a certified measurement log, and a clearing network built on payment rails. Each failed somewhere different. A floor-price guarantee is a free put sold to the best-informed sellers in the market. Capital cannot bootstrap an identity join that doesn't exist yet; Germany's netID collected 40 million accounts that the bidstream never used. A clearinghouse has no forcing function while walking away stays free. Agent logs sit under a permission dialog that an OS vendor controls. Even the payment rail, the most durable count available, inherits a new landlord in the wallet.

The interesting part is what the five failures have in common. Work each route to its end and it demands the same four components: an agreed counter that both sides accept in advance; collateral behind that count, so a counting failure pays cash instead of triggering a dispute; a shared loss history, so someone can calculate a premium; and a party paid to carry the residual risk. No version of the fix skips any of the four. The market doesn't lack ideas. It lacks parts.

## The two missing institutions

Two of those parts do not yet exist as shared open-web institutions.

The first is an adjudicator for conversion counts: a body with published rules of evidence and the power to bind an escrow, doing for a disputed conversion what card-network dispute procedures do for a disputed charge. Advertising has auditors and accreditation bodies, but accreditation tells you a methodology is sound, not who is right about last Tuesday's 4,000 conversions. Part 1 quoted the confession in AdCP's own measurement taxonomy: the protocol does not adjudicate between verification vendors. I co-lead the Signals & Measurement working group for that protocol, and I read the confession as a socket. A contract term that names the counting source, and a dispute procedure that can seize a bond, are exactly the kind of thing a protocol can carry even though it can never be the balance sheet itself.

The second is a loss history. Insurance is priced from loss triangles, years of data on what was promised, what arrived and what the gap cost. Advertising has never pooled this. Every failed outcome guarantee died privately inside somebody's P&L. Which points at an irony worth naming: after a decade of carrying click risk on rented signals, Criteo may hold one of the market's most valuable cross-company performance histories. An operating record is not yet an actuarial dataset. But the cheapest path to an underwritable web might still run through a reinsurer's due-diligence team reading that ledger under treaty.

The insurer of last resort, at least, already exists. Munich Re has backed AI vendors' performance warranties [since its first policy in 2018](https://www.munichre.com/en/solutions/for-industry-clients/insure-ai.html), underwriting only after a technical review of the model, with its own balance sheet carrying the underperformance risk. In February 2026, Lloyd's specialty insurer Mosaic launched [a product with Munich Re offering up to $15 million in capacity](https://www.mosaicinsurance.com/resources/press-releases/~/mosaic-partners-with-munich-res-aisure-to-provide-pioneering-coverage-for-ai-vendors/) against defined AI performance failures. The vehicle for warranting an algorithm's promise exists and writes policies today, and nobody has pointed it at media. What it proves is that an insurer will examine and carry defined algorithmic performance risk. It does not prove that media outcomes, which are steerable and correlated, would pass the same underwriting test.

## What ships first

None of the near-term work requires industry-wide coordination or a new regulatory regime.

A seller of outcome-priced media puts the advertiser's prepayment in escrow. The advertiser funds the account; the protection runs to the seller, whose receivable stops depending on an advertiser's balance. The contract names its counting source as a term, the way [AdCP's CPA pricing](https://docs.adcontextprotocol.org/docs/media-buy/advanced-topics/pricing-models) already fixes a price to a specified event. Whoever operates the count posts a bond the dispute clause can seize, protecting everyone who relies on the number. And the premiums, when they appear, sit on the sell side: a warranty on the publisher's receivable, or reinsurance bought by the intermediary that carries the spread between media bought and results sold. Sold honestly, the package is counterparty hygiene rather than outcome insurance: money escrowed, counts collateralized, miscounts with a remedy. Every such contract also produces the first input to a future loss history: standardized evidence of what was forecast, what arrived and what the gap cost.

The riskier products come after the data. Cash settlement against a certified benchmark, paying on underperformance relative to a cohort rather than an absolute promise, so the common shocks that hit everyone at once (a browser policy, a recession) stop pretending to be one seller's failure. Then narrow, screened warranties with a reinsurer behind them. And last, the instrument Criteo needed in 2017: a parametric policy on the landlord event itself, triggering on a defined platform-policy change the way flight-delay cover triggers on a late plane. It arrives only after the loss records exist, because a correlated, market-wide shock is exactly the exposure no underwriter will price blind. The screens will look familiar: Google's pay-for-conversions program already publishes one, [demanding over 100 conversions in 30 days with 90% arriving within a week](https://support.google.com/google-ads/answer/7528254) before Google will carry even the conversion layer. That page is the closest thing the industry has to a published underwriting standard, and it marks the boundary honestly.

So does Shopify, which is worth pausing on because it has assembled every measurement advantage the open web lacks: owned checkout on [$378 billion of 2025 volume](https://www.sec.gov/Archives/edgar/data/1594805/000159480526000006/exhibit991pressreleaseq420.htm), owned identity, pooled cross-merchant data. Its ad product caps what a merchant pays per acquired customer, ["You're never charged more than this amount for a conversion,"](https://help.shopify.com/en/manual/online-sales-channels/shop/shop-campaigns/understanding-campaigns) and the same help page adds: "Conversions through Shop Campaigns ads aren't guaranteed." A capped price with no promised quantity, from the player holding the best cards in commerce. That is the current ceiling, stated in a help center.

> [figure: The instrument ladder: four rungs in sequence, each naming who pays. Rung one, ships now: escrow plus a named counting source plus a count bond — the advertiser funds the escrow with protection running to the seller, the count's operator posts the bond; sold as counterparty hygiene. Rung two: benchmark-relative cash settlement, paying on underperformance against a certified cohort so common shocks stop pretending to be one seller's failure. Rung three: narrow screened warranties with a reinsurer behind them, premium paid by the sell side; Google's published pay-for-conversions screen marks the boundary. Rung four, drawn dashed and last: a parametric policy on the landlord event itself, the instrument Criteo needed in 2017, available only after the loss history exists. Along the bottom, a loss-history bar grows from rung one toward rung four: every contract records forecast versus delivered, feeding the premium calculation.]

## The boundary

Be clear about what this does and doesn't fix. Everything above works where a purchase happens and can be evidenced: commerce, subscriptions, sign-ups. It is a fix for the open web's checkout, not its front page. News and long-cycle brand content stay exactly as uninsured as Part 1 found them, and no escrow account changes that.

There is also a trap at the end of the road, and the US Congress already mapped one version of it. When the CFTC approved box-office futures in 2010, Hollywood objected that the underlying number was steerable by the people trading it, and the Dodd-Frank Act [wrote the ban into the definition of a commodity itself](https://www.govinfo.gov/content/pkg/USCODE-2023-title7/html/USCODE-2023-title7-chap1-sec1a.htm). Ad outcomes are steerable too, which is why every credible version of this market settles on screened cohorts and holdout-based triggers rather than tradable indexes. And a warranted count needs a perimeter, which means whoever operates the counter inherits the temptation every clearing utility faces: member-owned neutrality decaying into landlord economics. The governance that prevents that has to be written while the perimeter is still too small to abuse.

## Three ways to prove this wrong

First: by the end of 2027, at least one insertion order between independent companies names its counting source as a contract term and settles from escrow, with a cash remedy for a counting failure. If none exists by then, the demand I'm describing isn't there, and the problem was never plumbing.

Second: the first scaled insurance product attached to outcome-priced media protects the sell side, a publisher-receivable warranty or a quota-share on an intermediary's spread, before advertiser-facing conversion insurance reaches scale. If an advertiser product scales first, the pause-button argument is wrong.

Third: by 2030, nobody, inside a wall or outside one, sells an unconditional guarantee of a business outcome across a whole book. The fourth clause arrives screened, capped and collateralized or it doesn't arrive. If someone is selling the unconditional version at scale by then, I underestimated how much risk a balance sheet will carry for this industry, and I will be glad to have been wrong in that direction.

The open web spent twenty years trying to own inputs it could only rent. It doesn't need to own them. It needs to price them.
