Every answer and its explanation appears here once you have finished the path. Each one then links to the matching glossary entry, where the concept is set out in full with its worked example.
1. San Francisco, 1906: two percent of buildings are destroyed by the earthquake, which is excluded, and ninety-eight percent by the fire that follows, which is covered. Which legal notion alone decides the fate of the carriers?
Proximate cause, that is, the event that directly produced the loss
Proximate cause is the event that directly produced the loss, as against remote causes one could trace back indefinitely. The whole difficulty lies in where that cursor sits: go too far back in the chain and almost everything can be excluded, since every loss has a remote cause; do not go far enough and almost everything is covered, since every loss has an immediate one. In 1906, taking the shock or taking the fire did not change the facts, it changed who paid, and dozens of carriers turned on it. The operational lesson still holds: where an excluded peril triggers a covered one, wording that leaves the chain of causation in doubt will buy a lawsuit costing more than the saving the imprecision promised.
Glossary entry · cause-prochaine2. Insurers won the pandemic business interruption litigation, then the wildfire debris litigation. On which requirement do both victories rest?
The direct physical loss requirement, that is, a physical alteration of the insured property
The direct physical loss doctrine conditions indemnity on a physical alteration of the insured property. It was forged when perils destroyed things, and that is its weakness: contemporary perils, smoke, ash, contamination, radiation, corrupted data, degrade use without altering matter. A building that is unusable and intact fits neither box. The consequence runs past the case won: every victory built on that requirement erodes the perceived value of the product in the eyes of the people buying it, and brings closer the day the state takes the risk onto its own books because the private market stopped answering for it.
Glossary entry · dommage-materiel-direct3. An insurer's predictive model flags the imminent failure of an industrial installation. The alert is not passed on, the installation blows up. On what footing is the insurer pursued?
For its own fault, outside the register of the guarantee
The insurance contract is an aleatory contract: its performance depends on an uncertain event, which is what separates it from a supply of services, where the supplier answers under the ordinary law of liability. Predictive artificial intelligence blurs that line, because the moment the insurer knows and acts, it leaves the register of the guarantee and enters that of obligation. An insurer that detects and stays silent exposes itself to a liability for fault the premium never priced. The reversal is complete: the payer of losses becomes a possible author of them, and a liability appears that neither pricing nor reserving had anticipated.
Glossary entry · contrat-aleatoire4. A ransom payment is lawful on 18 November and a breach on the 20th, once the payee is designated by the sanctions authority. What flaw in the sanctions exclusion clause does this expose?
It makes the very existence of the cover depend on a later administrative act, taken by an authority that is not party to the contract
The sanctions exclusion clause, often added by endorsement, withdraws cover where performing it would breach a sanctions regime such as the US OFAC. Its flaw is not in the principle, it is in the timing: it does not tell the insured, at the moment of loss, whether the payee is designated, because nobody knows. Attributing an attack is months of intelligence work. The clause hands an insoluble question to the party least able to answer it, and under strict liability the lawfulness of an act is settled after the act. No underwriting model can represent that variable, which makes it a blind spot rather than a priced risk.
Glossary entry · clause-exclusion-sanctions5. A chief information security officer is prosecuted for obstruction. What does a final adjudication wording change in their directors and officers policy?
It conditions the trigger of the intentional conduct exclusion on a definitive, non-appealable judicial decision
What an executive facing criminal exposure buys is almost never an indemnity: on conviction, the intentional conduct exclusion bars it. What they buy is an advance of defense costs, that is, the means to fight through the years the case takes. The final adjudication clause is therefore the most important line in the contract for them, because it stops the insurer from invoking the exclusion on its own assessment. Without it, costs can be cut off at indictment, at the precise moment the insured needs them, and on the strength of a judgment nobody has yet handed down. The distance between the two wordings is the distance between being defended and holding a piece of paper.
Glossary entry · adjudication-finale6. A distributor passes on to their client, as is, an advice produced by a language model. Which limb of the duty to advise does this practice fail?
Gathering the client's demands and needs, analyzing a sufficient number of contracts, then giving a reasoned proposal
The duty to advise requires the distributor to gather the client's demands and needs, analyze a sufficient number of contracts, then give reasons for what they put forward. It is a duty of care, and a duty of care is measured by comparing the professional's conduct with that of a normally competent peer. That comparison assumes an intelligence reasoned at the origin of the advice. The language model breaks the chain of imputation: it sits at exactly the link where judgment forms, without being blamable as an agent or auditable as a tool. Advice passed on untouched becomes advice with no author, which nobody can answer for in the old way.
Glossary entry · devoir-conseil7. A board refuses a fifteen million euro security overhaul budget against its security chief's advice. Eighteen months later, ransomware causes eighty million of losses. What will the directors and officers insurer examine?
Whether the decision was made in good faith, on an informed basis and without self-interest
The business judgment rule grew out of nineteenth century American case law and was formalized notably in Smith v. Van Gorkom, decided in Delaware in 1985. It holds that courts should not substitute their hindsight for the directors' own on business decisions, subject to three conditions: good faith, an informed decision, no self-interest. The presumption is rebuttable, and that is where cases are won: if the claimant shows one of the three is missing, the burden flips and the director must prove the decision was entirely fair. A refused budget is therefore not in itself a breach. What separates the protected board from the exposed one is a documented minute, an external expert consulted, an absence of conflict. The doctrine has spread through several European jurisdictions, France among them, where it colors the assessment of mismanagement, and it now reaches cyber decisions and AI deployments: what is protected is the traceability of the process, not the correctness of the bet.
Glossary entry · business-judgment-rule8. A fall in interest rates raises the expected frequency of claims on liability exposures already written, with no error made on the facts. Through what mechanism?
Through third party funding, which makes claim frequency sensitive to the cost of capital
For two centuries, the number of claims brought against a company never reflected the number of breaches it committed. It reflected the number of people who at the same moment held four things: a grievance, knowledge of their rights, the means to act, and tolerance for the risk of losing. That conjunction was rare, and the gap between wrongs done and actions filed was a free and considerable filter whose effect observed loss experience never isolated, because it was invisible. Third party funding does not change substantive law: it changes the rationing function. Frequency stops being a function of how many wrongs were done and becomes a function of capital hunting a return in litigation, and therefore a function of what that capital costs. No liability pricing model carries a financial market variable to this day, while a growing share of frequency depends on one.
Glossary entry · financement-contentieux9. An operator loads a third party control policy onto its industrial robot, an operation its supplier presents as ordinary use. What can it become under the European machinery regulation?
Manufacturer of the modified machine, with conformity assessment, technical file, declaration and marking
The European machinery regulation defines substantial modification and draws a heavy consequence from it: whoever modifies a machine in a way that creates a new hazard becomes the manufacturer of the modified machine, and inherits every obligation that follows. The rule existed in substance before, it is now written down, and it expressly covers digital modifications as much as physical ones. The difficulty sits in applying it to a learning system: training a robot on a new task, loading a third party control policy, allowing continuous learning in operation, does that create a new hazard? The test requires knowing what the machine will do afterwards, which is precisely what is undetermined. An operator can therefore become a manufacturer without knowing it. And the cover that then matters is product liability, which many machine users never had reason to consider, since they manufacture nothing.
Glossary entry · modification-substantielle10. A German industrial group, an essential entity under NIS2, relies on its ISO 27001 certificate to demonstrate conformity with the article 21 measures. What makes that demonstration admissible?
ENISA's technical guidance, which maps ISO 27001 controls onto the article 21 requirements
The European Union Agency for Cybersecurity, ENISA, was founded in 2004 and its mandate made permanent and broader by the Cybersecurity Act of 2019. It assists the Commission and the member states, publishes technical baselines, and runs the European cybersecurity certification scheme known as EUCS for cloud service providers. Under NIS2, its June 2025 technical guidance on the article 21 measures plays a particular role: it bridges a legal obligation, written in terms of outcomes, and existing standards companies already run, ISO 27001 among them. That bridge is what lets an entity demonstrate conformity by leaning on a recognized certification instead of starting from nothing. For the insurance market these baselines carry a double value: prescriptive, since they set the expected standard, and informational, since they give a homogeneous basis on which to judge an insured's security level across Europe.
Glossary entry · enisa