When Your Insurer Collects the Bounty
The self-dealing case, which is mostly self-defeating, except in the one place that matters.
Someone raised this with me and my first reaction was that it was a non-problem. My second reaction, after actually doing the arithmetic, was that the non-problem has a sharp edge on one side of it.
The scenario: a researcher buys bounty insurance. The insurer, in the course of underwriting, learns the researcher is over the line. Rather than merely repricing, the insurer files the claim itself and collects the bounty.
The naive version is self-defeating
Write it out. The researcher owes a fine . The claimant receives a bounty , which is or some share of it. The insurer has contracted to pay on the researcher’s behalf.
If the insurer turns in its own policyholder, it pays out of one pocket and receives into the other. Where the state takes any cut at all, , and the insurer has just paid for the privilege of destroying its own customer relationship. Even at it nets zero minus legal costs and minus every future customer who reads the news.
So the obvious version does not pay. It is not a moral result, it is an accounting one: you cannot profit by paying yourself.
There is a second reason it will not happen, which is that the insurer already has a much cheaper instrument. If a policyholder looks bad, you do not file a claim against them — you reprice them, attach conditions, or decline to renew. Non-renewal costs nothing and sheds the whole risk. Filing a claim costs and sheds one risk. No underwriter picks the second.
The version that does pay
Now add the exclusion.
Liability policies generally do not cover deliberate wrongdoing, and this is not an oversight — it is close to a requirement. Most jurisdictions treat insurance against one’s own intentional harms as void on public policy grounds, on the straightforward reasoning that a policy which pays out for deliberate misconduct is a subsidy for it. Any real bounty policy would carry that exclusion, and I would have written it in myself.
But look at what the exclusion does to the arithmetic. If the researcher’s violation was deliberate, the insurer owes nothing. It pays and collects . The self-dealing is no longer a wash. It is pure profit, and it is available precisely in the cases the mechanism cares most about, because deliberate violations are the ones the whole apparatus exists to deter.
So the insurer’s incentive inverts at exactly the wrong threshold. For the marginal, ambiguous, probably-fine cases it wants to keep you as a customer. For the flagrant ones it wants to turn you in and bill the state for doing it. An underwriting process that starts as risk assessment ends as evidence collection, funded by the person being assessed.
Why I still think this is survivable
Two reasons, and the first one is the one that was put to me.
The insurer is one claimant among many. The arithmetic this site runs on is , and is the number of people who know. Cutting-edge AI research is not a thing one person does in a garage; that is an assumption the whole argument leans on and it is doing work here too. The insurer is a single additional potential claimant appended to a list of colleagues that is already dozens long. Remove it entirely and barely moves. The deterrence does not depend on this channel, so a rule that closes it costs almost nothing.
That is the key asymmetry. The self-dealing problem is expensive to leave open and cheap to close.
And closing it is a one-line rule. Bar an insurer from collecting a bounty on its own policyholder — or from collecting one at all, treating underwriting and enforcement as incompatible functions the way we separate auditing from consulting, badly but for the right reasons. Route any such claim to the state or to a fund. The insurer keeps the information, keeps the pricing power, and loses the claim. Since the claim was never why it wanted the information, it loses very little.
The real cost is somewhere else
What this actually threatens is not deterrence. It is the disclosure channel , and that is a much more annoying loss.
The case for telling your own underwriter about your unease depends entirely on the underwriter not being your adversary. The moment a researcher has to assume their insurer might convert a nervous phone call into a bounty claim, the honest advice is to tell them nothing beyond the minimum, and a channel I think is one of the better features of this design closes before it opens. Combine it with the fact that there is no insurer-insured privilege in most of American law and the researcher is being asked to confide in someone who may profit from the confidence and cannot refuse a subpoena about it either way.
Those two problems have the same solution and it is statutory. You would need a privilege for disclosures made to a bounty insurer, and a bar on that insurer claiming against its own insureds. Neither is exotic — both have analogues in existing practice — but both have to be written down in advance, and if they are not, the mechanism still deters and simply loses the part of it I liked best.
I want to be clear that I did not anticipate this when I first proposed the mechanism. The bounty arithmetic survives contact with the objection. The nicer half of the design does not survive without a legislature paying attention to a detail no one would think to mention.