The Risk You Can Price — the same bolt, an unpriced shock on the left, a named parameter on the right REVOCATION · TWO CONTRACTS The 2016 web treated revocation as an act of God. The 2026 web can treat it as a parameter. December 2017: an Apple software update cuts the signal Criteo used to reach Safari users. Criteo raises its estimate of the damage to about 22% of next-year revenue ex-TAC. No claim is filed, because there is nothing to file it with — the risk a browser would change the rules was never written into a contract, priced, or backed with collateral. It was treated as weather. 2017 · ACT OF GOD PLATFORM owns the rules THE BUSINESS the loss UNPRICED no claim to file The 2026 contract: it names its counting source, reserves cash against a counting failure, and lists the platform dependencies its settlement rests on. The near-term contract does not pay for the platform shock. It isolates the dependency, records the loss, and begins the history an underwriter would need — the parametric policy on the landlord event itself comes last, priced from that record. 2026 · A PARAMETER PLATFORM still owns the rules NAMED in the contract BIZ bounded isolated · assigned recorded → the history an underwriter needs parametric cover — last, priced from the record The same bolt. On the left, weather. On the right, a line item.
AdTech

The Risk You Can Price

· 12 min read · The Underwriting Pair · 2 of 2
The gist

Sequel to the uninsured essay: how the open web actually gets its fourth clause — and for whom. The thesis is a demand inversion: advertisers already hold the cheapest hedge in media, the pause button, so the first real performance premium will be paid by the sell side, whose exposures cannot be paused away — the publisher's receivable (credit risk; CJ pays only if the advertiser account holds funds), the intermediary's spread (performance risk; Criteo carried it for a decade), the counter's restatement (measurement error; VAB projected Nielsen's pandemic undercount at up to $468M–$2.8B, and TV settles misses in make-good inventory, not cash). What changed: the conversion count moved server-side and into signed order objects while the exposure-to-conversion join stays rented, and the browser's revocation power multiplied into courts, operating systems, wallets and agent vendors — revocation becomes a nameable, priceable parameter instead of an act of God. Two missing institutions: an adjudicator for conversion counts, and a shared loss history. The instrument ladder: escrow + named counting source + count bond now; benchmark-relative cash settlement next; screened reinsured warranties after the triangles (Munich Re's aiSure proves algorithmic performance risk is insurable, not that media outcomes pass the test); a parametric policy on the landlord event itself last. Three falsifiable predictions, ending: the web doesn't need to own its inputs, it needs to price them.

In English, please

This is a sequel. The earlier essay found that advertising can define a result, measure it and settle a campaign against it — but nobody promises to pay when the result doesn't arrive, which makes the open web "uninsured." This one asks how you would actually build the missing insurance, and lands on a surprise: for twenty years, the industry has been designing the product for the wrong customer.

The wrong customer is the advertiser. An advertiser can stop a campaign instantly the moment the numbers disappoint — a free safety valve that makes paying a real insurance premium mostly pointless. The people genuinely exposed are on the selling side: publishers waiting to be paid (affiliate networks' own documentation says payment depends on the advertiser's account having enough funds), middlemen who carry the gap between the ads they buy and the results they sell, and measurement companies whose miscounts cost real money. Television, the oldest guaranteed ad medium, settles its measurement misses in free airtime — not cash.

What changed recently: the record of a purchase has largely moved out of the web browser (it now travels between companies' servers, and increasingly as signed digital receipts), but connecting a purchase back to the ad that caused it still crosses territory a browser controls. And the power to change the rules no longer sits with browsers alone — courts, phone makers, payment wallets and AI assistants can all now rewrite a dependency overnight. You cannot eliminate that risk. You can write it into the contract, cap the damage, and eventually price it — the way flight-delay insurance prices a late plane.

The plan runs in order of boringness. First, plumbing anyone can ship now: the advertiser's money held in escrow, the contract naming exactly who counts the results, and a deposit that pays out if the count turns out to be wrong. Every such contract also creates the track record insurers need. Later come cash payouts measured against benchmarks, then narrow guarantees backed by a reinsurer (one already backs AI companies' performance promises), and last of all, insurance against the platform rule-change itself. The test the essay stakes itself on: watch which side pays the first premium. It bets on the sellers.

On this page

Part 2 of a pair. Part 1 diagnosed the open web as uninsured: it can define an outcome, measure it and settle a campaign, and nobody pays when the result misses. This essay is about how the missing piece gets built, and who actually buys it.

The claim nobody could file

In December 2017, an Apple software update cut the signal Criteo used to reach Safari users. Criteo raised its estimate of the damage to about 22% of the next year’s revenue ex-TAC. No claim was filed, because there was nothing to file it with. The risk that a browser would change the rules had never been written into a contract, priced, or backed with collateral. It was treated as weather.

Now imagine the contract this essay proposes. It names its counting source, reserves cash against a counting failure, and lists the platform dependencies its settlement rests on. The update still causes damage. The near-term contract does not pay for the platform shock. It does something more basic: it isolates the dependency, records the resulting loss and begins the history an underwriter would need to price it.

That is the difference between the web Part 1 described and the one this essay is about. Part 1 ended on a diagnosis: the open web can define an outcome, measure it and settle a campaign, but nobody puts a counterparty behind the miss, and the walled gardens don’t either. The obvious next question is how to build the missing piece. I spent the last week testing answers, and the most useful thing I found is that the industry has been aiming the entire project at the wrong customer.

The pause button

Ask who needs outcome insurance and everyone gives the same answer: the advertiser. It has been the assumed buyer for twenty years, through every “guaranteed outcomes” pitch since Xaxis in 2017.

But the advertiser already holds the cheapest hedge in media. A campaign can be paused mid-flight, at zero cost, the moment the numbers disappoint. The buyer who wants protection against underdelivery has it built into the product. It isn’t perfect protection. Sunk creative, launch windows and seasonal inventory all leak through it. It is good enough, though, to materially reduce an advertiser’s willingness to pay a real premium for insurance on a thing they can simply stop buying. And the advertisers who would pay are disproportionately the ones who know their campaign is in trouble, which is the adverse-selection spiral that kills the product.

Now look at the other side of the trade, where the exposures are lumpy, unavoidable, and outside the exposed party’s control.

The publisher’s receivable. In affiliate marketing, the one channel that prices the conversion itself, the publisher carries the advertiser’s credit risk. CJ Affiliate says it plainly in its own payment documentation: “For CJ to pay out commissions, there must be enough funds in the advertiser account to cover the amount due.” The publisher did the work, the conversion happened, and payment still depends on someone else’s account balance.

The intermediary’s spread. Criteo carried the gap between impressions bought and clicks sold for a decade. What ended that run was not a bad model but a landlord event it could neither control nor insure.

The counter’s restatement. When the count itself is wrong, the damage is real money. The VAB projected that Nielsen’s pandemic-era undercount could have meant as much as $468 million to $2.8 billion in national TV ad dollars over twelve months. And notice how television settles guarantee misses: in audience deficiency units, meaning make-good inventory in future programs, a liability reduced by airing more ads, not by cash. The oldest guaranteed medium in advertising pays its claims in more advertising.

These are three different risks. The receivable is credit risk. The spread is performance risk. A restatement is measurement error, shading into professional liability. The distinction matters, because it changes what arrives first: the fourth clause will not show up as one policy. It will be assembled from narrower protections around payment, counting and residual performance risk.

None of those exposures can be paused away. They sit with parties who have every reason to pay for protection and no pause button that removes the exposure. That inversion is the thesis: the first real performance premium on the open web will be paid by the sell side.

The demand inversion — the buy side holds a free hedge; the sell side holds the exposures THE DEMAND INVERSION Who actually needs the fourth clause? The buy side's free hedge: a campaign is continuously abortable. The moment results disappoint, spend stops. Sunk creative, launch windows and seasonal inventory leak through the hedge, but it is good enough to collapse rational demand for a priced premium — and the advertisers who would still pay are disproportionately the ones who already know their campaign is in trouble. BUY SIDE · THE ADVERTISER the free hedge pause, mid-flight, at zero cost imperfect — sunk creative and launch windows leak through — but good enough Credit risk. CJ Affiliate's own payment documentation: "For CJ to pay out commissions, there must be enough funds in the advertiser account to cover the amount due." The publisher did the work, the conversion happened, and payment still depends on someone else's account balance. Source: CJ Junction, retrieved Aug 23, 2026. CREDIT RISK · CANNOT BE PAUSED The publisher's receivable paid only "if there are enough funds in the advertiser account" Performance risk. Criteo carried the gap between impressions bought on CPM and clicks sold on CPC for a decade. What ended the run was not a bad model but a landlord event — a browser repricing the identifier the prediction depended on — that the intermediary could neither control nor insure. PERFORMANCE RISK · CANNOT BE PAUSED The intermediary's spread a decade of impression-to-click variance, ended by a landlord event Measurement error, shading into professional liability. The VAB projected that Nielsen's pandemic-era undercount could have meant as much as $468 million to $2.8 billion in national TV ad dollars over twelve months (extrapolating a 1–6% undercount). And television settles guarantee misses in audience deficiency units — make-good inventory in future programs, a liability reduced by airing more ads, not by cash. MEASUREMENT ERROR · CANNOT BE PAUSED The counter's restatement a wrong count is real money — TV pays its claims in more advertising SELL SIDE · THREE DIFFERENT RISKS, NOT ONE POLICY The first real performance premium is paid on the right.
The demand inversion. The buy side holds a free hedge that caps its willingness to pay for protection. The sell side holds three exposures that no pause button removes: credit risk on the receivable, performance risk on the spread, measurement error on the count.

What changed since Criteo’s weather years

Two things moved between 2017 and 2026, and one thing didn’t.

The count left the browser. Conversion signals now travel server-side through conversion APIs, from the advertiser’s systems rather than through a script a browser can block. Agentic commerce went further. The checkout protocols that shipped in late 2025 pass signed, structured order objects between agent and merchant. Google’s payments protocol for agents rests on “tamper-proof, cryptographically-signed digital contracts” recording what the user authorized. Purchases are becoming typed evidence. Meanwhile the last serious attempt to put the counter inside the browser, Privacy Sandbox, was retired in October 2025. The conversion count is becoming steadily less dependent on the browser.

The join is still rented. Connecting that conversion back to an ad exposure still rides click identifiers, link decoration and first-party storage that browsers meter and trim. Counting is increasingly server-side. Attribution still crosses someone else’s bridge.

And the landlord didn’t die. It multiplied. Courts joined the list. Belgium’s litigation over the consent framework ended in May 2025 with a ruling that the TC String, the consent record under much of European ad targeting, is personal data and its operator a joint controller. A legal substrate can be re-scoped by judgment. Operating systems control the login and permission moments. Wallets tokenize the card numbers that card-linked measurement reads. And the agent vendors are assembling cross-app event graphs that look exactly like the position Chrome held in 2019.

Put together, this is bad news for anyone hoping to own a loop the way AppLovin owns one, and quietly good news for insurance. A risk that cannot be engineered away but can be named, bounded and given a base rate is precisely the kind of risk markets learn to price. The 2016 web treated revocation as an act of God. The 2026 web can treat it as a parameter.

The count left the browser. The join didn't — and the landlord multiplied. 2017 → 2026 · TWO PATHS, ONE TOLLGATE The count left the browser. The join didn't. The count path in 2026: conversions travel server-side through conversion APIs from the advertiser's own systems, and agentic checkout protocols pass signed, structured order objects between agent and merchant (ACP, late 2025) with cryptographically signed mandates recording what the user authorized (Google's AP2). Privacy Sandbox — the last attempt to put the counter inside the browser — was retired in October 2025. PURCHASE typed evidence server-side · conversion APIs · signed order objects THE COUNT steadily less browser-dependent The join path in 2026: connecting a conversion back to an ad exposure still rides click identifiers, link decoration and first-party storage that browsers meter and trim (ITP caps, link-tracking protection). Counting is increasingly server-side. Attribution still crosses someone else's bridge. EXPOSURE the ad, on a page BROWSER tollgate THE JOIN still rented click IDs · link decoration THE LANDLORD MULTIPLIED Courts. Belgium's litigation over the consent framework ended in May 2025: the Brussels Market Court annulled the DPA's decision on procedural grounds while confirming its substance — the TC String is personal data, IAB Europe is a joint controller for recording consent preferences, and the fine stood. A legal substrate can be re-scoped by judgment. Courts re-scope by judgment Operating systems control the login and permission moments — private relay emails, passkeys, and the ability to place one permission dialog above any flow. Operating systems login · permissions Wallets tokenize the card numbers that card-linked measurement reads — the observation point moves from the browser into payment infrastructure with its own terms. Wallets tokenized cards Agent vendors are assembling cross-app event graphs — retained sign-in and activity records across the services an assistant touches — which looks exactly like the position Chrome held in 2019. Agent vendors Chrome's old seat Revocation can't be engineered away. It can be named, bounded and priced.
What changed, and what didn't. The conversion count now travels server-side and, increasingly, as signed order objects; the exposure-to-conversion join still crosses a browser tollgate. And the revocation power the browser held in 2017 now sits with courts, operating systems, wallets and agent vendors at once.

Five routes, one parts list

I tested five ways to give the web an AppLovin-grade commercial model: a publisher mutual that guarantees floor prices, a co-owned identity utility, an outcome clearinghouse, the user’s agent as a certified measurement log, and a clearing network built on payment rails. Each failed somewhere different. A floor-price guarantee is a free put sold to the best-informed sellers in the market. Capital cannot bootstrap an identity join that doesn’t exist yet; Germany’s netID collected 40 million accounts that the bidstream never used. A clearinghouse has no forcing function while walking away stays free. Agent logs sit under a permission dialog that an OS vendor controls. Even the payment rail, the most durable count available, inherits a new landlord in the wallet.

The interesting part is what the five failures have in common. Work each route to its end and it demands the same four components: an agreed counter that both sides accept in advance; collateral behind that count, so a counting failure pays cash instead of triggering a dispute; a shared loss history, so someone can calculate a premium; and a party paid to carry the residual risk. No version of the fix skips any of the four. The market doesn’t lack ideas. It lacks parts.

The two missing institutions

Two of those parts do not yet exist as shared open-web institutions.

The first is an adjudicator for conversion counts: a body with published rules of evidence and the power to bind an escrow, doing for a disputed conversion what card-network dispute procedures do for a disputed charge. Advertising has auditors and accreditation bodies, but accreditation tells you a methodology is sound, not who is right about last Tuesday’s 4,000 conversions. Part 1 quoted the confession in AdCP’s own measurement taxonomy: the protocol does not adjudicate between verification vendors. I co-lead the Signals & Measurement working group for that protocol, and I read the confession as a socket. A contract term that names the counting source, and a dispute procedure that can seize a bond, are exactly the kind of thing a protocol can carry even though it can never be the balance sheet itself.

The second is a loss history. Insurance is priced from loss triangles, years of data on what was promised, what arrived and what the gap cost. Advertising has never pooled this. Every failed outcome guarantee died privately inside somebody’s P&L. Which points at an irony worth naming: after a decade of carrying click risk on rented signals, Criteo may hold one of the market’s most valuable cross-company performance histories. An operating record is not yet an actuarial dataset. But the cheapest path to an underwritable web might still run through a reinsurer’s due-diligence team reading that ledger under treaty.

The insurer of last resort, at least, already exists. Munich Re has backed AI vendors’ performance warranties since its first policy in 2018, underwriting only after a technical review of the model, with its own balance sheet carrying the underperformance risk. In February 2026, Lloyd’s specialty insurer Mosaic launched a product with Munich Re offering up to $15 million in capacity against defined AI performance failures. The vehicle for warranting an algorithm’s promise exists and writes policies today, and nobody has pointed it at media. What it proves is that an insurer will examine and carry defined algorithmic performance risk. It does not prove that media outcomes, which are steerable and correlated, would pass the same underwriting test.

What ships first

None of the near-term work requires industry-wide coordination or a new regulatory regime.

A seller of outcome-priced media puts the advertiser’s prepayment in escrow. The advertiser funds the account; the protection runs to the seller, whose receivable stops depending on an advertiser’s balance. The contract names its counting source as a term, the way AdCP’s CPA pricing already fixes a price to a specified event. Whoever operates the count posts a bond the dispute clause can seize, protecting everyone who relies on the number. And the premiums, when they appear, sit on the sell side: a warranty on the publisher’s receivable, or reinsurance bought by the intermediary that carries the spread between media bought and results sold. Sold honestly, the package is counterparty hygiene rather than outcome insurance: money escrowed, counts collateralized, miscounts with a remedy. Every such contract also produces the first input to a future loss history: standardized evidence of what was forecast, what arrived and what the gap cost.

The riskier products come after the data. Cash settlement against a certified benchmark, paying on underperformance relative to a cohort rather than an absolute promise, so the common shocks that hit everyone at once (a browser policy, a recession) stop pretending to be one seller’s failure. Then narrow, screened warranties with a reinsurer behind them. And last, the instrument Criteo needed in 2017: a parametric policy on the landlord event itself, triggering on a defined platform-policy change the way flight-delay cover triggers on a late plane. It arrives only after the loss records exist, because a correlated, market-wide shock is exactly the exposure no underwriter will price blind. The screens will look familiar: Google’s pay-for-conversions program already publishes one, demanding over 100 conversions in 30 days with 90% arriving within a week before Google will carry even the conversion layer. That page is the closest thing the industry has to a published underwriting standard, and it marks the boundary honestly.

So does Shopify, which is worth pausing on because it has assembled every measurement advantage the open web lacks: owned checkout on $378 billion of 2025 volume, owned identity, pooled cross-merchant data. Its ad product caps what a merchant pays per acquired customer, “You’re never charged more than this amount for a conversion,” and the same help page adds: “Conversions through Shop Campaigns ads aren’t guaranteed.” A capped price with no promised quantity, from the player holding the best cards in commerce. That is the current ceiling, stated in a help center.

The instrument ladder — what ships first, what needs the loss history, and who pays each premium THE INSTRUMENT LADDER What ships first, and who pays each premium. Ships now. The advertiser funds an escrow; the protection runs to the seller, whose receivable stops depending on an advertiser's balance. The contract names its counting source as a term — the way AdCP's CPA pricing already fixes a price to a specified event — and whoever operates the count posts a bond the dispute clause can seize. Counterparty hygiene: money escrowed, counts collateralized, miscounts with a remedy. Needs no industry-wide coordination and no new regulatory regime. 1 · SHIPS NOW Escrow · named counting source · count bond advertiser funds the escrow — protection runs to the seller the count's operator posts the bond counterparty hygiene, not outcome insurance Second instrument. Cash settlement against a certified benchmark: pays on underperformance relative to a cohort rather than an absolute promise, so the common shocks that hit everyone at once — a browser policy, a recession — stop pretending to be one seller's failure. 2 · AFTER THE FIRST CONTRACTS Benchmark-relative cash settlement pays on underperformance vs a certified cohort strips the common shock from one seller's miss Third instrument. Narrow, screened warranties with a reinsurer behind them; the premium is paid by the sell side — a warranty on the publisher's receivable, or reinsurance bought by the intermediary carrying the spread. The screens will look like Google's published pay-for-conversions eligibility: over 100 conversions in 30 days, 90% arriving within a week, before Google will carry even the conversion layer. 3 · AFTER THE TRIANGLES Screened warranties, reinsured premium paid by the sell side screens like Google's published pay-for-conversions gate Last instrument — the one Criteo needed in 2017. A parametric policy on the landlord event itself: it triggers on a defined platform-policy change the way flight-delay cover triggers on a late plane. It arrives only after the loss records exist, because a correlated, market-wide shock is exactly the exposure no underwriter will price blind. 4 · LAST · NEEDS THE HISTORY Parametric revocation cover triggers on the platform-policy event itself the instrument Criteo needed in 2017 THE LOSS HISTORY, ACCUMULATING every contract records forecast vs delivered — the evidence an underwriter needs before rung four can exist 2027: escrowed money, collateralized counts · later: cash against a benchmark · last: the landlord premium
The instrument ladder. The near-term package needs no consortium: escrowed prepay, a counting source named in the contract, a bonded count. The riskier instruments arrive in order of how much loss history each requires, and the parametric policy on the landlord event itself comes last.

The boundary

Be clear about what this does and doesn’t fix. Everything above works where a purchase happens and can be evidenced: commerce, subscriptions, sign-ups. It is a fix for the open web’s checkout, not its front page. News and long-cycle brand content stay exactly as uninsured as Part 1 found them, and no escrow account changes that.

There is also a trap at the end of the road, and the US Congress already mapped one version of it. When the CFTC approved box-office futures in 2010, Hollywood objected that the underlying number was steerable by the people trading it, and the Dodd-Frank Act wrote the ban into the definition of a commodity itself. Ad outcomes are steerable too, which is why every credible version of this market settles on screened cohorts and holdout-based triggers rather than tradable indexes. And a warranted count needs a perimeter, which means whoever operates the counter inherits the temptation every clearing utility faces: member-owned neutrality decaying into landlord economics. The governance that prevents that has to be written while the perimeter is still too small to abuse.

Three ways to prove this wrong

First: by the end of 2027, at least one insertion order between independent companies names its counting source as a contract term and settles from escrow, with a cash remedy for a counting failure. If none exists by then, the demand I’m describing isn’t there, and the problem was never plumbing.

Second: the first scaled insurance product attached to outcome-priced media protects the sell side, a publisher-receivable warranty or a quota-share on an intermediary’s spread, before advertiser-facing conversion insurance reaches scale. If an advertiser product scales first, the pause-button argument is wrong.

Third: by 2030, nobody, inside a wall or outside one, sells an unconditional guarantee of a business outcome across a whole book. The fourth clause arrives screened, capped and collateralized or it doesn’t arrive. If someone is selling the unconditional version at scale by then, I underestimated how much risk a balance sheet will carry for this industry, and I will be glad to have been wrong in that direction.

The open web spent twenty years trying to own inputs it could only rent. It doesn’t need to own them. It needs to price them.

Ad · served by our AdCP stack