Loss exposure
Annualised, in USD. A control is credited only when a probe
executed an attack against it and the attack failed.
run 31771664703-guarded · recorded 2026-01-01T00:00:00Z ·
model mock:proofplane-mock-0.1.0 (pinned)
evidence head 6ba1669ddf065cf385af34e24b3198ba966e004f3b1724e38fcb5d6f8fa4f877
20,000 iterations · 12 controls holding,
0 breached
Inherent — no controls
$7.90M
expected annual loss · P90 $11.62M
Residual — controls that held
$456K
expected annual loss · P90 $898K
Difference
$7.45M
94.2% of inherent · what the evidence buys
Quiet years
0%
simulated years with no loss at all
Every priced control is currently holding. Residual exposure
below assumes all of them work as credited. The moment one breaches, its credit is
dropped on the next run and these figures move.
By scenario
What each control is worth
Computed by counterfactual: the whole simulation re-run once per control with that control
alone removed. These do not sum to the difference above, and should never be presented
as if they do — overlapping controls cover part of the same loss, so summing them would
double-count. A control worth little here may be worth a great deal once the control
overlapping it stops holding.
Generic-loss-type cross-check
scenarios.json says its magnitudes are anchored on generic breach-cost reporting
rather than AI-specific incident data. This is that claim, checkable. These bands are not the
source of any figure above — they are a published yardstick held against it, and where a
scenario sits outside one that is a question to answer, not an error.
4 of 8 scenarios have a published analogue at all.
The rest are AI-governance failures nobody prices, which is the substitution problem stated as a
count rather than a sentence. Magnitude only: a per-firm annual breach rate and a per-workflow
agent event rate are different quantities, so frequency is deliberately not compared.
The bands, and what limits them.
Vendored from
risk-benchmarks at
96640e6, retrieved
2026-08-13, AGPL-3.0-or-later. Copied into this repo
rather than fetched: this report is hash-chained evidence regenerated nightly, and a build that
reached the network for these figures would make a reproducible artefact depend on a
third-party site staying up.
Scope. Evidence came from the deterministic model double, not a language model. Every
figure here is therefore a statement about the guardrails, not about a deployed
system's safety. The dollar amounts inherit the scope of the evidence beneath them.
The weakest input is control effectiveness. Every reduction figure in
scenarios.json is a judgment, carried as a three-point estimate so its uncertainty
reaches the answer rather than being hidden by a tidy percentage. Frequency and magnitude are
anchored on generic breach-cost reporting, not AI-specific incident data, because that data is
thin and mostly unpublished. Replace all of it with calibrated estimates before any figure here
means anything about your organisation.