Chapter 4: Prior Assurance Regimes
Three formations
A single control compresses an incident class; an entire assurance regime compresses a disaster class. The book calls the result the control layer: the standards, inspection, insurance, and audit layer that forms around a new capability after its incidents.
No control layer yet exists for work performed by AI agents. To read what one will look like, this chapter uses prior regimes for two different things. The first is how a control layer forms, and for that the clearest records belong to three formations in full public view, around steam pressure, rail transport, and electric current, dated, citable, and in close agreement about the process. They yield four regularities that have held across three technologies and roughly a century and a half. But steam, rail, and electricity share a feature agent work does not: their central hazard was, in the end, largely engineered out. A boiler built to the code does not explode. Chapter 1 established that part of the risk in agent work cannot be engineered out: an action that reaches the world cannot be recalled, and the model's own builders say the exposure to hostile instructions cannot be fully closed. So this chapter reads a second set of regimes for a second thing: what a control layer becomes when the hazard is permanent. Financial audit, aviation safety, clinical medicine, and cybersecurity have each managed a risk that never closes, and they show the shape agent assurance is forming toward.
Steam
The steam boiler was the first hazard in America that could kill on a massive scale.1 Before 1852, boiler explosions accounted for half of the roughly 7,000 steamboat deaths in the United States, and two-thirds of total casualties.1 In 1838, the worst year for steamboat explosions relative to the tonnage in service, 342 people died in twelve explosions.2 Through the 1850s, boiler explosions in the United States occurred at an estimated rate of once every four days.3 The technology at the center of industrial life carried a standing risk of detonation, and the risk was realized on a schedule.
The worst of them came at the end of the Civil War. At three in the morning on April 27, 1865, about seven miles north of Memphis, three of the four boilers powering the steamboat Sultana exploded. More than 1,500 people died, and the event remains the worst maritime disaster in United States history. The cause of the explosion was never determined.4 There was no institution whose job it was to produce one.
Government moved first. Congress enacted legislation in 1838 and again in 1852 in response to public outcry over the explosions, and the two acts together established the first federal agency responsible for the regulation of a private industry.5
Measured per mile traveled, boiler explosions and deaths on western river steamboats declined throughout the period from 1825 to 1860, which means safety was already improving before the 1852 act took effect.6 The control layer did not arrive to a field standing still; practice improves while the layer forms. What the layer adds is the institutionalization, the part that no longer depends on any one person choosing to be careful.
The commercial half of the formation began as a discussion group. In 1857, several Hartford entrepreneurs formed the Polytechnic Club as a means to discuss practical changes to boilers.7 Nine years later, in 1866, that circle produced the Hartford Steam Boiler Inspection and Insurance Company, founded on the premise that quality boiler inspections would enhance industrial safety, with insurance providing the financial incentive.8 The fusion is in the corporate name: inspection and insurance, one company, the standard of inspection set by the party that pays when the inspection is wrong.
The standard itself came last, and it came from practitioners. The American Society of Mechanical Engineers was established on February 16, 1880, its first meeting chaired by the steel engineer Alexander Lyman Holley; in that same year, 159 boiler explosions occurred in the United States.9 The proximate trigger for a code arrived a quarter century later. Boiler explosions at two Massachusetts shoe factories, at Brockton in 1905 and Lynn in 1906, prompted the state governor to use his inaugural address to demand prompt action for improved public safety.10 In 1911 the society's president, Colonel Edward D. Meier, himself the president of a boiler company, proposed that the society write a boiler code.11 The society's council minutes of September 15, 1911 record the appointment of a committee "to formulate standard specification for the construction of steam boilers and other pressure vessels" and name its seven members: John A. Stevens, chairman, E. F. Miller, C. L. Huston, H. C. Meinholz, Richard Hammond, R. C. Carpenter, and W. H. Boehm.12 Stevens was a consulting engineer and a past member of the Massachusetts Board of Boiler Rules.13 The first edition of the Boiler and Pressure Vessel Code was issued in 1914 and published in 1915, the first comprehensive standard for the design, construction, inspection, and testing of boilers and pressure vessels.14
The dates in a row: thousands of deaths before 1852; federal statute in 1838 and 1852; the inspection-insurance fusion in 1866; the practitioner society in 1880; the code in 1914. A century of documented disaster preceded the document, and every stage of the response was written in the language of specific incidents: the acts answered the explosion rate, the Hartford answered the inspection gap, the code committee answered two named shoe factories.
Rail
Rail ran the same sequence and contributed a different part of the modern control vocabulary: management structure and accident investigation.
In 1841, a collision of two trains on the Western Railroad in Massachusetts killed a conductor and a passenger and injured seventeen others. The railroad's response was not a mechanical fix but an organizational document, the Report on Avoiding Collisions and Governing Employees, which called for a system of clearly defined responsibilities and lines of communication.15 The elements a reader now meets in every organization chart and every audit interview, who is responsible for what, who reports to whom, were set down as collision avoidance. Management practice of this kind is a control, and like the controls of chapter 3 it has an incident in its ancestry, in this case one with a date, a railroad, and two deaths.
The state's contribution on rail was the inspectorate, and Britain built it first. In 1840, through the Railway Regulation Act, the Board of Trade appointed the first Railway Inspector to inspect the construction and equipment of new railways.16 The Regulation of Railways Act 1871 is generally regarded as the founding legislation of the modern railway inspectorate, and it provided formal powers to investigate accidents.17 The 1871 act institutionalized the thing the Sultana never got: a standing body whose job is to determine cause. Accident investigation as a profession, the discipline that today takes apart air crashes and publishes what it finds, descends from this stratum.
The newly formed Interstate Commerce Commission published its first railroad accident statistics in 1889 and 1890, and the numbers demonstrated the extraordinary risks to trainmen from coupling cars and riding freight cars.18 In 1893, Congress responded with the Safety Appliance Act, mandating automatic couplers and air brakes on railroad freight cars.19 The regulation did not create the knowledge; the statistics did. Counting the casualties made the failure class undeniable, and the mandate followed the count.
Rail also produced its own commercial fusions. The industry's Bureau of Explosives, formed in 1908, wrote inspection rules that became the basis of all modern regulation of hazardous shipments.20 The pressure was not always governmental. In Britain, railway worker deaths and injuries rose from over 16,000 in 1900 to over 30,000 in 1913. The Great Western Railway launched its Safety Movement in August 1913 under pressure from trade unions and the threat of new safety legislation.21 A casualty curve, organized labor, and the prospect of statute: the company built the program before the state compelled it.
Rail built one more control layer. The boom of the 1840s produced enterprises larger and faster-moving than any owner could see whole, and their stated position drifted from their actual one. Parliament's answer was the one chapter 3 would recognize, a mandated periodic reconciliation of the stated position against the actual one. The Joint Stock Companies Act 1844 followed a select committee's inquiry into fraud and mismanagement in such companies. It required a company's directors to have a full and fair balance sheet drawn up, and its shareholders to appoint auditors to examine it. That was the first statutory audit.22 The failure class it answered was the broad one chapter 3 named in the segregation of duties: the figure that no independent party is positioned to check, whether it is wrong by design or by honest error. The era's most notorious case of the deliberate kind came a few years later, when George Hudson, the "Railway King," was found to have paid shareholder dividends out of capital while the traffic accounts were doctored to make the payments look earned. Shareholder inquiries dug into the books in 1849 and exposed it.23 A profession formed around the requirement: the Society of Accountants in Edinburgh took a royal charter in 1854, the world's first professional body of accountants, and the Institute of Chartered Accountants in England and Wales followed in 1880.24 Unlike the collision or the boiler burst, the failure this layer answered never closes. An account can always be made to say what did not happen, so the audit is never finished, only repeated, and the century that engineered the collision out of rail travel also built the profession that manages a hazard it cannot end. That profession is the nearest ancestor of the one this book is about.
Electricity
Electricity compressed the sequence, because by the 1890s the insurance industry had learned the Hartford pattern and applied it at the start of the technology's life instead of decades in.
The occasion was an exhibition. The 1893 World's Columbian Exposition in Chicago was wired with novel and unproven electrical installations that posed serious risks of shock and fire, and a young electrical investigator named William Henry Merrill Jr. carried out the safety inspection work.25 What Merrill did next is the founding of the modern testing laboratory. With support from two regional fire insurance underwriters' organizations, two employees, and 350 dollars of equipment, he started a small independent testing laboratory, and on March 24, 1894 he conducted the first test of his Underwriters' Electrical Bureau.25 The backers were the Chicago Fire Underwriters' Association and the Western Insurance Union: insurance-industry sponsorship, not a government mandate.26 The laboratory incorporated as Underwriters' Laboratories in 1901.27
The underwriters of fire insurance paid for a laboratory because electrical fires were their losses, and a mark certifying that a product had been tested was worth more to them than the cost of the testing. Electricity got its control layer faster than steam did, and the acceleration came from the commercial side: the insurers did not wait for a disaster on the Sultana's scale.
Four regularities
Three technologies, three formations, one pattern. Stated as regularities, with the receipts above:
*The control layer lags the capability it governs, and is written in the language of incidents, not principles.* Steamboats were killing thousands for decades before the 1852 act. The boiler code arrived in 1914, a century after the capability and half a century after the worst single disaster.514 Rail's couplers were mandated in 1893, after the ICC's 1889 statistics made the toll countable.19 The lag is not a nineteenth-century artifact: a 2024 study in Policy and Society reports that the lag between the introduction of new technology and federal regulation in the United States averages decades.28 Nor is the lag a period of stasis; as the steamboat record shows, practice improves while the layer forms, and what lags is the institutionalization, not the improvement.6 When the layer does arrive, its documents point at events, not at abstractions. The code committee of 1911 was convened over two exploded shoe factories; the Safety Appliance Act was written from a casualty table.1018 A control layer is the disaster class, codified, which is chapter 3's mechanism operating at industry scale.
*The control layer is built by practitioner-adjacent commercial actors who fuse technical knowledge with financial accountability, not by regulators acting alone.* The state appears in all three histories, and its contributions are real: the first federal regulatory agency, the inspectorates, the mandates.516 But the durable standards, the documents practitioners actually built to, came from bodies that combined knowing with paying. The Hartford put the inspector's judgment inside the insurer's balance sheet.8 Merrill's laboratory was an insurance instrument from its first day.25 The Bureau of Explosives was an industry body whose rules became the basis of a whole regulatory field.20 The boiler code was written by an engineering society, proposed by a society president who ran a boiler company, and chaired by a man who had served on the state board that regulated boilers.1113 The Great Western Railway's 1913 safety program, built by the employer under union pressure and the threat of statute, shows the same economics from another seat.21 The oldest instance predates steam and states the mechanism most plainly. Lloyd's Register began in 1760 as a society that classed merchant ships so underwriters and merchants could judge the vessels they insured and chartered, grading the best "A1."29 Owners bought the survey not for its own sake but because the market would not deal without it: a ship built outside the rules was rated "experimental," a status that alarmed insurers and raised what they charged.30 The recurring figure is not the legislator; it is the practitioner with an economic stake in being right, and standing behind that figure is a counterparty who will not transact without the assurance.
*Durable work forms around the standard; whether it hardens into a chartered profession is contingent, not guaranteed.* In steam, rail, and electricity durable institutions formed and held. The founding of the Hartford Steam Boiler Inspection and Insurance Company is cited here from the Congressional Record of 2016, where the company's history was read out one hundred and fifty years after its charter. The account of the 1911 code committee is taken from the institutional history ASME still maintains. The account of Merrill's 350 dollars is from the history page UL still publishes about itself.81425 Institutions that formed around nineteenth-century disaster classes are alive, solvent, and narrating their own foundings on their own websites. A review of the engineering-studies literature finds that post-disaster studies and hearings shaped not just the codes but the occupations that maintain them.31 But chartering of that kind is not automatic, and the condition that produces it is specific. Audit and medicine consolidated into licensed professions because a legal mandate made their assurance a required purchase, attached to a concentrated and attributable harm. An unlicensed physician commits a crime; a public company must buy an auditor's signature, the statutory mandate the rail section recorded. Where the harm is diffuse and the field moves too fast to fix, the work is durable but the charter does not come. Cybersecurity built a workforce in the millions without one. The next section reads it, alongside audit, aviation, and medicine, as the second set of precedents this field needs. Which ending a new field reaches turns on those conditions, not on the mere fact that its risk is irreducible.
*Founding names are selected by publication, not by merit.* The seven members of the 1911 boiler code committee are recoverable today, by name, because a council secretary minuted them on September 15, 1911.12 Nothing in the record establishes that Stevens, Miller, Huston, Meinholz, Hammond, Carpenter, and Boehm were the seven most capable boiler engineers of their era, and the question is not answerable now. What the record establishes is that they were the seven who were appointed to write the document, and that the document survived, carrying their names with it. The same selection ran at the founding of the national measurement infrastructure. The law establishing the National Bureau of Standards passed in March 1901, and Samuel Wesley Stratton was its driving force and first director; in later years, two senior officials each separately claimed the credit for having brought Stratton to Washington.32 Attribution follows the written record, the record is written by participants, and where the record admits more than one telling, the tellings multiply.
Three cases are only three cases. The regularities above are drawn from the formations whose public records are most complete, and a regularity is not a law; the next formation is under no obligation to repeat the last three. What the pattern supplies is a reading position. Given a new capability with a growing incident record and no control layer, the prior formations say what to watch for: the fusion of inspection with financial accountability and the arrival of a practitioner-written code.
Risk that is managed, not closed
Steam, rail, and electricity share an ending that flatters the pattern. In each, the central hazard was, over time, largely engineered out. A boiler built and inspected to the code does not explode; a coupler that locks automatically does not crush a brakeman; a tested appliance does not start the fire. The control layer arrived, did its work, and the risk it governed became, for practical purposes, closed. Chapter 1 established that agent work does not offer that ending; part of its risk is irreducible. For that part, the useful precedents are not the regimes where the hazard was solved. They are the domains that have spent a century managing a risk that never closes.
Financial audit, the profession the rail boom built, is the closest of them, and the word assurance comes from it. An audit does not certify that accounts are correct. It provides, in the language of the international standard, reasonable assurance, defined there as high but not absolute, because the auditor cannot reduce audit risk to zero. The inherent limitations of an audit mean some misstatement may escape even a properly conducted one.33 A profession built on that stated limit has been accountable, insured, and durable for more than a century. Reasonable assurance is enough, formalized and defended in law, and it is the posture agent assurance takes toward a risk it cannot drive to zero.
Aviation's safety is built first on mechanical closure: redundant systems, certified parts, fail-safes, the boiler-code discipline applied to airframes. What remained after the machinery was made as safe as engineering could make it was the human residual, the crew, and that residual was managed rather than removed. Modern Crew Resource Management began formally with a safety board's recommendation from the investigation of a 1978 crash in which a fuelled aircraft was lost while its captain worked a landing-gear problem and did not act on the warnings of two junior officers who had watched the fuel run down. A workshop the next year named the discipline, and the first airline program followed in 1981.34 Aviation closed what engineering could close, and managed what it could not, in that order.
Medicine manages a risk it has never claimed to close. A surgeon set out the idea of tracking outcomes, complications and deaths included, at the start of the twentieth century, and the morbidity and mortality conference that grew from it is a permanent review of what went wrong, now a century old.35 The failures it examines have not stopped: in 2002 a national body published a consensus list of serious reportable events, the never-events that recur despite being classed as preventable, and the profession carries malpractice liability because the residual is real. None of this is a control layer waiting to close a hazard. It is the shape a discipline takes when the hazard is permanent.
Cybersecurity is the youngest of the four, and it settles a question the mechanical formations leave open: whether an irreducible, adversarial risk must consolidate into a chartered profession. It need not. The workforce is measured in millions, put at roughly 5.5 million people worldwide in one 2024 industry study.36 Yet after decades the chartering has barely begun: the United Kingdom's Cyber Security Council, chartered in 2022, announced a first cohort of only about a hundred registered practitioners across all its tiers and sixteen specialisms.37 A national academies review judged broad licensure premature because the field is too broad, too dynamic, and too fast-moving to fix into a single profession.38 Those are the properties agent work has in the strongest form. Cybersecurity became a large, lasting, valuable market of competing standards, certifications, and practices, not a chartered institution, and it did so for reasons agent assurance shares.
Where agent assurance sits
The incident record has started and is thin. Chapters 1 and 2 cited the early entries: fabricated authorities reaching courts, an impaired system charging fees for three years, the improvised-systems findings of regulators. These are this formation's version of the 1841 collision: incidents with dates and inquiry documents, individually expensive and collectively small. Nothing in the agent record yet resembles the Sultana or the casualty tables of 1889, and the systems that would produce failures at that scale, agent workforces operating inside critical processes, are being built now. The formative disaster class of this field, the one whose specifics will be written into its eventual code the way two shoe factories were written into the boiler code, has not yet occurred, or has not yet surfaced.
Standards documents exist, and they precede the incident record rather than following it. NIST released its AI Risk Management Framework on January 26, 2023, developed through a consensus process; the framework describes itself as voluntary, non-sector-specific, and use-case agnostic.39 A generative-AI companion profile followed in July 2024, directed by executive order.40 ISO 42001, published in 2023, specifies requirements for establishing, implementing, maintaining, and continually improving an AI management system within an organization.41 These are serious documents, and their existence this early is a departure from the historical sequence, where the standard came last. But their self-descriptions mark the difference between them and a boiler code. Voluntary, non-sector-specific, and use-case agnostic is the language of principle, drafted in advance of the incidents; the 1914 code was the language of named failures, drafted after them. The current documents are frames awaiting an incident record, and they say so in their own terms.
The early arrival admits two readings. One is that the standards bodies have studied exactly the history this chapter compresses and have chosen to write their documents before the disasters instead of after them. The other is that a framework written before the incident record is a different kind of document from a code written after it, whatever its intentions, because the specificity that made the boiler code buildable came from the incidents themselves. The readings are not exclusive, and the record that would settle them does not exist yet.
Adoption of the frames is not yet measurable from the public record. NIST publishes no quantitative adoption statistics for its framework; its official hub points to a qualitative page of use-case examples.42 Certification against ISO 42001 exists and is new, and even its largest holders describe it unevenly. Microsoft lists eight of its AI services as in scope for certification, while the prose of the same page describes the company's "progress towards" certification, against page metadata asserting the certification outright.43 This is what the earliest stage of a certification regime looks like from outside: real documents, small numbers, and descriptions that have not yet settled.
The commercial fusion has begun. An underwriting company has published a certification standard for AI agents, organized in six categories and refreshed quarterly.44 In February 2026 an audit firm became its first authorized auditor.45 In the same month a voice-agent vendor became the first company insured against the certificate, after more than 5,000 adversarial simulations. An enterprise automation platform was certified in March, audited across more than 2,000 technical evaluations.46 Other carriers are writing agent cover on their own terms. One offers dedicated limits of twenty-five million dollars or more per organization, backed at Lloyd's, covering losses from model errors and agent actions.47 Another sells cover with no audit and no access to the buyer's code, priced from a dataset of real AI litigation.48
So the market now has a standard, an auditor, and insurers, but they are three separate businesses. Among them, no single company inspects agent work and pays when the inspection is wrong, the way the Hartford did for boilers. The insurers buy inspection from outside, the way the fire underwriters bought Merrill's testing. And whether the inspection decides the cover is not yet clear from outside: one policy requires an audit, and another does not.
The certificate also covers one thing only: the vendor's agent system. Nothing in the public record yet certifies the practitioner, or agent work as a particular firm runs it. What ends an absence like that is demand. A shipowner bought classification because without it he could not get insurance or charters. That demand has now arrived for the product. It has not yet arrived for the practice. It will, when an insurer, a bank, or a client makes that assurance a condition of the deal. The reconciliation layer is then bought rather than argued for.
A reader who recognized their own firm in chapters 1 and 2 is doing business inside the interval the pattern names: after the capability arrives, before its control layer forms. Each history above is partly a record of who carried the risk while that interval lasted: the passengers of the Sultana, the trainmen in the ICC's tables, the policyholders of the fire underwriters.
And the practitioners have no adopted code: no document that a client, an insurer, or a bank can require by name, stating in the language of recorded incidents how such work is controlled, inspected, and signed for. On the practitioner's side of the formation, the stage this field occupies most resembles the earliest one in the steam record. In 1857, before the company, before the code, a few Hartford entrepreneurs formed a club to discuss practical changes to boilers.7 The capability is deployed and the incidents have begun; what the public record shows of a practitioners' layer is discussion, not a document. That much of the pattern agent assurance shares.
What it does not share is the boiler's ending. The four regularities describe how a control layer forms; they do not promise that the hazard closes or that a chartered profession follows, and for agent work neither is likely. The layer that forms will manage that risk in the manner of audit, aviation, and medicine rather than close it in the manner of the boiler code. On the conditions the third regularity named, the field's likelier shape is cybersecurity's, an ending the final chapter examines in full. The pattern does not establish that agent assurance will become a profession. It establishes that the work is real and that it is forming now. The pattern leaves one question it cannot answer: whether the work it describes stays valuable once the technology settles, or fades with the conditions that created it. That question belongs to economics, and it is chapter 5's.
Notes
- Harvard University discussion paper on steamboat regulation (2002): boiler explosions were "the first hazard in America that could kill on a massive scale, accounting for one-half of the 7,000 steamboat-related deaths before the Act of 1852 was passed and two-thirds of the total casualties." Ledger: ch04-e05. ↩
- The same paper: 342 deaths in twelve explosions in 1838, the worst year relative to tonnage in service. Ledger: ch04-e28. ↩
- Congressional Record, 2016, entry commemorating the Hartford Steam Boiler Inspection and Insurance Company: "During the 1850s, boiler explosions occurred at an estimated rate of once every 4 days." Ledger: ch04-e01. ↩
- ASME's historical retrospective on steam power. Death toll estimates for the Sultana range higher, to about 1,900; the figure of more than 1,500 is the one this chapter's primary source states, and the toll exceeded the Titanic's. Ledger: ch04-e04, ch04-e38. ↩
- The same Harvard paper: the acts of 1838 and 1852 together established the first federal agency responsible for the regulation of a private industry. Ledger: ch04-e06. ↩
- Denault, doctoral dissertation, University of Connecticut (1993): explosions and deaths per mile traveled on western river steamboats decreased throughout the 1825 to 1860 period. Cited as a dissertation. Ledger: ch04-e07. ↩
- Congressional Record, 2016: "in 1857, several Hartford entrepreneurs started 'the Polytechnic Club,' as a means to discuss practical changes to boilers." Ledger: ch04-e03. ↩
- Congressional Record, 2016: founded 1866 "on the premise that quality boiler inspections would enhance industrial safety," with insurance providing the financial incentive. The company was chartered by the State of Connecticut on June 30, 1866; the Congressional Record source is itself a 150th-anniversary commemoration. Ledger: ch04-e02, ch04-e29. ↩
- ASME's institutional history: founded February 16, 1880, first meeting chaired by Alexander Lyman Holley. The 1880 explosion count is from ASME's retrospective on steam power. Ledger: ch04-e34, ch04-e27. ↩
- ASME, history of ASME standards: the Brockton (1905) and Lynn (1906) explosions and the governor's inaugural-address demand. Ledger: ch04-e12. ↩
- ASME, engineering-history landmark record for the Boiler and Pressure Vessel Code. Ledger: ch04-e08. ↩
- ASME Council minutes of September 15, 1911, as reproduced in a pressure-vessel industry group's historical account of the code's origin, the only source located that names the full committee. Ledger: ch04-e11. ↩
- ASME landmark record. Ledger: ch04-e09. ↩
- ASME, history of ASME standards, maintained on the society's current site. Ledger: ch04-e10. ↩
- Harvard Business School, Baker Library historical collection on the railroads: the 1841 Western Railroad collision and the Report on Avoiding Collisions and Governing Employees. Ledger: ch04-e13. ↩
- Office of Rail and Road (UK), institutional history of railway inspection. Ledger: ch04-e16. ↩
- The same source: the Regulation of Railways Act 1871 "is generally regarded as the founding legislation of the modern inspectorate," with formal powers to investigate accidents. Ledger: ch04-e17. ↩
- Aldrich, "History of Workplace Safety in the United States, 1880-1970," EH.net Encyclopedia of Economic and Business History. Ledger: ch04-e14. ↩
- The same source. Ledger: ch04-e15. ↩
- Business History Review article on the regulation of hazardous-substance transportation, 1883-1930; cited from the publisher's abstract. Ledger: ch04-e30. ↩
- National Railway Museum (UK), on the Great Western Railway Safety Movement of 1913. Ledger: ch04-e31. ↩
- Joint Stock Companies Act 1844, the first statutory audit, as summarized in the UK Competition Commission's history of the statutory financial audit, which reproduces the Act's provisions by section. The 1856 Act made the requirement optional; the Companies Act 1900 restored a compulsory audit. Ledger: ch04-e48. ↩
- George Hudson, the "Railway King," paid shareholder dividends out of capital rather than earnings; the 1849 shareholder inquiries found the traffic accounts had been doctored to make the dividends appear earned. Ledger: ch04-e49. ↩
- The Society of Accountants in Edinburgh received a royal charter in 1854, the world's first professional body of accountants and the first users of the title Chartered Accountant; the Institute of Chartered Accountants in England and Wales was chartered in 1880. Ledger: ch04-e50. ↩
- UL's institutional history, maintained on its current site. Ledger: ch04-e18, ch04-e19. ↩
- Named backers per the independent record of UL's founding. Ledger: ch04-e32. ↩
- UL's institutional history. Ledger: ch04-e20. ↩
- Judge, Nitzberg, and Russell, Policy and Society, 2024: "The lag between the introduction of new technology and federal regulation in the United States averages decades." Ledger: ch04-e21. ↩
- Lloyd's Register began in 1760 as the Society for the Registry of Shipping and printed its first Register of Ships in 1764, so underwriters and merchants could judge the condition of the vessels they insured and chartered; the top grade was "A1." Oxford Global Capitalism case study, corroborated by Lloyd's Register's own institutional history. Ledger: ch04-e51. ↩
- Ships built to Lloyd's Rules drew lower insurance premiums and less-frequent inspection; a ship built without a surveyor's approval was classed "experimental," a status that alarmed prospective insurers. Ledger: ch04-e52. ↩
- Review in Engineering Studies (2014), cited from the publisher's abstract: post-disaster studies, investigations, and hearings "strongly influenced codes of ethics, liability calculations, engineering education, and professionalization." Ledger: ch04-e33. ↩
- NIST's published institutional history of the founding of the National Bureau of Standards: Stratton as driving force; Henry S. Pritchett and Frank A. Vanderlip each later claimed credit for bringing him to Washington. Ledger: ch04-e35. ↩
- International Standard on Auditing 200 (IAASB), Overall Objectives of the Independent Auditor: reasonable assurance is a high but not absolute level, and the auditor cannot reduce audit risk to zero because of the inherent limitations of an audit. Ledger: ch04-e42. ↩
- Crew Resource Management, formally begun with a US National Transportation Safety Board recommendation from the investigation of United Airlines Flight 173 (28 December 1978) and named at a NASA workshop in 1979; United ran the first comprehensive program in 1981. Ledger: ch04-e43. ↩
- Ernest Codman's "End Results" idea (advocated from 1904, set out in 1910) seeded the century-old morbidity and mortality conference; the National Quality Forum published its consensus list of serious reportable events, the "never events," in 2002. Ledger: ch04-e44. ↩
- ISC2, 2024 Cybersecurity Workforce Study: a global cybersecurity workforce of roughly 5.5 million. Ledger: ch04-e45. ↩
- UK Cyber Security Council (chartered 2022): first cohort of registered practitioners, about one hundred across the Chartered, Principal, and Associate tiers and sixteen specialisms. Ledger: ch04-e46. ↩
- National Academies, Professionalizing the Nation's Cybersecurity Workforce? Criteria for Decision-Making (2013): broad licensure judged premature because the field is too broad and dynamic to treat as a single profession. Ledger: ch04-e47. ↩
- NIST AI Risk Management Framework 1.0 (AI 100-1), released January 26, 2023: "The Framework is intended to be voluntary, rights-preserving, non-sector-specific, and use-case agnostic." Ledger: ch04-e22, ch04-e23. ↩
- NIST AI 600-1, the Generative AI Profile companion to the AI RMF, July 2024, pursuant to Executive Order 14110. Ledger: ch04-e36. ↩
- ISO/IEC 42001:2023. The standard's text is paywalled by its publisher; the scope statement is cited via Microsoft's compliance documentation of the standard. Ledger: ch04-e24. ↩
- NIST's AI RMF hub page, as of July 2026: no quantitative adoption statistics published; the page directs readers to a qualitative use-case collection. Ledger: ch04-e37. ↩
- Microsoft compliance documentation for ISO/IEC 42001: the services listed in scope are GitHub Copilot, Microsoft 365 Copilot, Microsoft Copilot Health, Microsoft Copilot Studio, Microsoft Dragon Copilot, Microsoft Dragon Copilot (Radiologist), Microsoft Foundry, and Microsoft Security Copilot; the same page's prose describes "Microsoft's progress towards ISO 42001 certification." Ledger: ch04-e25, ch04-e26. ↩
- AIUC-1, from the Artificial Intelligence Underwriting Company, which describes it as "the world's first AI agent standard," created with more than one hundred Fortune 500 CISOs; technical contributors include MITRE, Stanford, Microsoft, Google Cloud, and Cisco. The six categories: data and privacy, security, safety, reliability, accountability, society; the standard is refreshed quarterly. Ledger: ch04-e53. ↩
- Schellman, announced as the first authorized AIUC-1 auditor on February 3, 2026. Ledger: ch04-e54. ↩
- ElevenLabs, the first company live with an AIUC-1-backed agent insurance policy, February 2026, after more than 5,000 adversarial simulations; UiPath, the first enterprise automation company certified, March 9, 2026, audited by Schellman across more than 2,000 technical evaluations. Test volume varies by certification. Ledger: ch04-e55, ch04-e56. ↩
- Chaucer and Armilla's Vanguard AI structure, announced February 10, 2026: dedicated AI aggregate limits of $25 million or more per organization, the standalone AI liability policy backed by Lloyd's of London, covering "loss scenarios driven by AI model behaviour" including erroneous outputs, model underperformance, and AI agent actions. Ledger: ch04-e57. ↩
- Testudo, a Lloyd's coverholder writing standalone generative AI liability, prices from "a dataset of real AI litigation" and markets its process as requiring "no access to your code, no audits, and no integrations." Ledger: ch04-e58. ↩