
A proposed white-label initiative for DUAL and the Howden Group to evaluate a patent-pending pre-loss risk-intelligence framework that detects deteriorating operating conditions, quantifies risk velocity, and supports governed intervention before loss occurs.
Standardizing Risk in the Built Environment
Discussion draft: projections and proposed product architecture. All scores, pricing bands, premium effects, valuation effects, loss scenarios, adoption figures, timelines, staffing levels, and commercial terms in this proposal are forward-looking hypotheses for joint validation. They are not historical results, actuarial indications, insurance quotes, coverage commitments, legal conclusions, or guarantees. Final terms remain subject to data diligence, actuarial review, underwriting approval, regulatory analysis, security review, legal documentation, and mutually executed agreements.
Executive Summary
Buildings cannot become safely autonomous merely by adding sensors, robots, or software. They must first understand how people, machines, materials, schedules, spaces, controls, and external conditions interact, and recognize when those interactions are converging toward loss. MovementAI proposes that intelligence layer for DUAL and Howden.
Immediate ask: authorize a jointly scoped 90-day feasibility sprint to assess data availability, retrospective signal quality, governance requirements, and the case for a prospective pilot.
MovementAI converts fragmented physical-operating signals into leading indicators of control degradation, unsafe coupling, cascade proximity, and risk velocity, before those conditions mature into loss.
Qualified recommendations include the evidence, confidence, expected propagation path, intervention horizon, and accountable decision-maker. High-consequence actions remain human-governed.
Every signal, model version, recommendation, decision, execution record, and outcome forms a traceable evidence chain for underwriting, risk engineering, claims review, and portfolio learning.
The AutonomousReady Path
Autonomy is therefore an earned operating state, not a technology label. Each level requires stronger data quality, tested controls, explicit authority, fail-safe behavior, and evidence that the prior level performs as intended.
A dynamic view of current control integrity, not only historical loss and periodic attestations.
Earlier, prioritized intervention while preventable operating conditions can still be changed.
Time-sequenced evidence separating source integrity, decisions, execution, outcome, and causation review.
A consistent framework for comparing readiness, intervention performance, and emerging concentration risk.
The strategic proposition is subject to technical, actuarial, legal, security, regulatory, and operational validation. MovementAI augments professional judgment; it does not bind coverage, determine compliance, establish causation, or independently execute high-consequence actions.
In 2026, Howden announced its acquisition of Cybeta's intellectual-property assets to support faster, more precise cyber-risk insight across underwriting and placement. That public precedent suggests a relevant strategic pattern, not proof of fit, for evaluating a comparable data-and-analytics layer for physical operations.
We are not pitching "Howden uses our score." We are pitching: DUAL builds a new product category around our score, and Howden distributes it globally.
Joint ambition: determine whether governed leading indicators of operational instability can provide underwriters with reproducible, decision-useful evidence before those conditions mature into incidents, claims, or systemic loss.
MovementAI describes two patent-pending applications, MOMENTUM-001PROV and MOMENTUM-002PROV, as containing more than 650 combined claims. Application status, ownership, scope, validity, enforceability, freedom to operate, and competitive effect require documentary diligence and patent-counsel review. The proposed commercial distinction is an orchestration layer that scores physical movement risk across the asset lifecycle.
The Market Reality
Traditional controls document incidents and manage exceptions after risk has materialized. The proposed framework is designed to identify precursor conditions, estimate escalation potential, and support accountable intervention while loss remains preventable.
A 2025 Frontiers scoping review documents safety risks associated with robotics and automation in construction, while broader literature identifies human–robot collaboration, technical integration, workforce readiness, privacy, legal concerns, and uncertain economics as adoption barriers. The evidence supports a multi-factor integration problem; it does not establish liability as the sole or primary cause of stalled adoption.
Connected operational technology can translate digital compromise into safety, availability, environmental, and physical-loss consequences. Gartner's earlier executive-liability forecast was tied to 2024 and should be treated as historical market context, not a current prediction or measured outcome. Its 2024 research continues to highlight unmanaged legacy and cyber-physical systems as a zero-trust gap.
Endpoint manufacturers, building systems, construction platforms, security tools, and insurers each address part of the problem. MovementAI proposes a cross-system pre-loss intelligence layer that converts fragmented operating signals into time-bounded risk states, escalation pathways, and governed intervention recommendations. Validation must establish whether those signals are reliable, incremental, and materially earlier than existing controls.
Conventional underwriting relies heavily on historical loss experience, periodic surveys, and static control attestations. The proposed AutonomyScore™ feed would add traceable leading indicators: current control integrity, emerging operational coupling, risk velocity, confidence, and the time remaining for authorized intervention.
Overall AutonomyScore™
APEX Readiness: Level 4
Partnership Structure
A proposed operating model for diligence, from data ingestion through potential product and reinsurance evaluation. Each tier is conditional and subject to separate approval.
MovementAI would provide governed risk signals through an API into DUAL's underwriting workflow. The proposed evidence set combines cascade proximity, control integrity, crisis resilience, data confidence, and source lineage. These signals augment, not replace, professional underwriting and are intended to reveal material changes in exposure earlier than periodic reviews.
Subject to validation and approval, DUAL could develop an Autonomous Operations Endorsement or underwriting program using agreed score bands for referral and control review. DUAL would retain authority over eligibility, policy language, pricing, and coverage terms.
If the product is validated and launched, Howden could evaluate distribution through its global network, which reports 24,000 people. Eligible clients, territories, industries, enrollment, and broker workflows would be defined through a jointly approved market plan.
If evidence supports the framework, Howden Re could evaluate whether governed score bands add useful information to treaty analysis. Reinsurance use, pricing influence, and market adoption would remain independent future decisions, not assumed outcomes.
Proposed Insurance Blueprint
These are design requirements for joint development, not existing policy terms or a commitment to provide coverage.
A jointly designed risk-control endorsement or underwriting program centered on continuous pre-loss intelligence for assets using autonomous or cyber-physical systems. Whether it is admitted, E&S, delegated, manuscript, or risk-engineering-led remains an open legal and regulatory workstream.
Define eligible occupancies, construction types, territories, total insured values, technology classes, autonomy levels, minimum controls, minimum data history, and prohibited or referral risks before any quote is contemplated.
Product counsel and underwriters would define covered causes of loss, exclusions, sublimits, deductibles, warranties, control requirements, score-change consequences, cancellation rights, and whether any premium modification is permitted.
Preserve the complete risk-state history: precursor signals, escalation pathway, intervention window, recommendations, human decisions, control execution, timestamped source records, and model version. Give authorized adjusters controlled evidence access, separate data integrity from causation, and maintain a documented challenge and correction process.
MovementAI is proposed as a technology and risk-intelligence provider, not an insurer, broker, adjuster, regulator, certification authority, or final underwriting decision-maker. DUAL retains underwriting and coverage authority.
The score informs, not replaces, professional judgment. Underwriters can refer, override, or decline with a recorded rationale; insureds can challenge material data errors; emergency and life-safety authority always supersedes automated recommendations.
Hypothetical Case Studies
Illustrative scenarios showing how precursor-state detection and human-governed intervention are intended to interrupt operational instability before loss. They are not actual deployments, claims, or validated loss outcomes.
Case 1 · Occupied renovation
Reactive model
A high-pressure plumbing test proceeds while sensitive equipment is being installed one floor below. Conventional controls identify the conflict only after a leak alarm, damaged equipment, and tenant disruption trigger an incident response.
Precursor state
Permit timing, contractor access, pressure-test schedule, vertical-zone adjacency, tenant move-in activity, and the status of isolation controls begin converging into a high-proximity risk state.
Governed intervention
MovementAI qualifies the overlapping movements, identifies the missing isolation verification, estimates a narrowing intervention horizon, and recommends a temporary hold. The authorized site lead verifies the condition and reschedules the test under existing permit authority.
Hypothetical pre-loss result
The incompatible activities are separated before the test begins. The evidence chain preserves the source signals, recommendation, approval, revised schedule, and completed control check for later risk-engineering and underwriting review.
Case 2 · Distribution and logistics
Reactive model
A late inbound trailer collides with a compressed outbound schedule, blocked staging space, and a forklift charging constraint. Teams respond after queues form, labor idles, temperature-sensitive goods wait, and service commitments are threatened.
Precursor state
Carrier ETA drift, dock occupancy, staging capacity, equipment availability, labor windows, and cold-chain dwell limits show accelerating dependency stress before the yard reaches gridlock.
Governed intervention
MovementAI detects rising risk velocity, qualifies alternate dock and staging paths, and recommends resequencing two arrivals while protecting the temperature-controlled load. A dock supervisor reviews and authorizes the revised flow.
Hypothetical pre-loss result
The bottleneck is relieved while options remain available, reducing the likelihood of spoilage, collision exposure, and prolonged interruption. The operational thread records what changed, why it changed, who approved it, and whether dwell time returned to tolerance.
Case 3 · Autonomous building operations
Reactive model
A service robot receives a routine route command while an access-control feed is stale and an occupied work zone has changed. A conventional workflow discovers the mismatch only after a near miss, emergency stop, or manual complaint.
Precursor state
Credential freshness, route clearance, endpoint readiness, work-zone status, network health, and machine identity confidence fall out of alignment, lowering control integrity before the mission starts.
Governed intervention
MovementAI rejects automatic qualification, places the mission in a reversible safe-hold state, explains the conflicting evidence, and requests human verification. The facilities operator updates the route and releases the mission only after controls are restored.
Hypothetical pre-loss result
The machine does not enter the uncertain zone. The preserved record links the stale input, qualification failure, safe hold, operator decision, corrected route, and eventual outcome, supporting governance without claiming that automation risk has been eliminated.
The Legal Architecture
The orchestration and evidence architecture is presented for technical, patent, security, and underwriting diligence. Pending claims may support differentiation, but do not guarantee validity, coverage, exclusivity, or commercial outcomes.
Construction Cascade Proximity Scoring (CCPS) is proposed as a forward-looking measure of dependency stress: the degree, velocity, and confidence with which connected constraints are converging. Rather than reporting a failure after it occurs, CCPS is designed to surface the precursor state, intervention window, and principal drivers before propagation reaches a loss threshold.
The proposed Machine-to-Machine Trust Validation control would check available device credentials and cryptographic signatures before eligible commands are released. Its effectiveness depends on identity assurance, key security, integration quality, authorized human control, and testing; it does not eliminate cyber-physical liability.
The platform is proposed to assemble timestamped safety-workflow evidence and operational logs from available source systems. It can support authorized safety personnel, but does not itself determine OSHA compliance, replace a competent person, issue regulated permits, or prove the truth or completeness of every source event.
Federated Learning and Portfolio Benchmarking could support privacy-aware comparison of control performance across participating assets. Any model update would require approved governance, validation, and change control; improvement at one asset would not automatically alter another asset's risk profile.
The proposed reliability design uses predefined Safe-Hold States, referral, and human override when network, compute, or source systems fail. Production effectiveness would depend on tested integrations, local controls, and approved failure playbooks.
NOAA reports 27 U.S. billion-dollar weather and climate disaster events in 2024. Against that catastrophe-risk backdrop, the proposed system would ingest approved climate and disaster forecast data to inform human-governed prioritization, safe-hold, and rerouting decisions; effectiveness remains subject to integration and scenario testing.
The proposed Concurrent Renovation Thread Protocol would identify conflicting worker, tenant, equipment, and schedule movements in occupied assets so authorized teams can intervene before conditions escalate. It is intended to reduce exposure, not guarantee claim prevention.
A governed evidence record could support Digital Product Passport and audit workflows by linking approved source events, decisions, controls, and outcomes. Regulators determine acceptability, and the record does not itself establish compliance or eliminate audit exposure.
Building-management, construction, safety, and workflow platforms each address part of the operating environment. MovementAI's proposed distinction is a cross-system qualification layer for the live interaction of people, machines, materials, spaces, controls, and schedules, subject to competitive and patent diligence.
Initial feasibility analysis can begin API-first using available owner systems, without requiring new hardware. Higher-confidence real-time controls may require additional sensors or integrations. Tokenization and minimization can reduce privacy exposure, but GDPR, CCPA, employment, biometric, and local requirements must be assessed for each deployment.
The highest risk phase of any asset is ground-up construction. Through MovementAI Build™, we accumulate an 18–24 month Construction-Phase Operational Thread Record (CPOTR) from groundbreaking to completion.
The proposed pilot would test whether changes in cascade proximity, control integrity, and intervention response provide earlier and more discriminating evidence for Builder's Risk than schedule variance and incident reporting alone. Any premium effect requires actuarial support and underwriting approval. “Born Certified” is a proposed readiness designation, not a regulatory, insurance, engineering, or safety certification.
The building's operational AI starts with a calibrated baseline rather than "zero history," establishing a permanent structural advantage in operational accuracy.
Furthermore, underwriters can utilize our APEX Readiness Projection. By analyzing infrastructure choices (sensors, compute) during construction, DUAL can mathematically pre-underwrite the asset's permanent P&C policy long before the building even opens.
Deployment & Reliability
Initial analysis may require no new hardware; real-time physical orchestration requires trustworthy inputs, tested integrations, explicit authority, and resilient operating controls.
Use schedules, policies, asset registers, incident history, claims taxonomy, and exported operational records to test data mapping and retrospective score logic. No real-time control or loss-prevention claim is available at this level.
Integrate available access control, work-order, BMS, IoT, weather, logistics, and safety systems through approved APIs or secure files. Convert time-sequenced observations into leading indicators with source lineage, signal latency, confidence, missing-data flags, risk velocity, and estimated intervention horizon.
Route qualified pre-loss recommendations to authorized operators while a defined intervention window remains open. Record the detected precursor state, expected propagation pathway, acknowledgement, decision, reason, execution evidence, and outcome; do not independently execute high-consequence actions.
Only narrowly defined, tested, reversible actions may be automated after hazard analysis, legal approval, cybersecurity testing, owner authorization, fail-safe design, emergency override, and documented accountability.
Before launch, agree supported source systems, refresh rates, data quality thresholds, uptime, latency, support, maintenance, incident notification, recovery objectives, degraded mode, data reconciliation, and responsibility for third-party outages.
Low confidence, stale or conflicting data, source failure, suspected spoofing, model drift, or unsafe conditions trigger referral, safe hold, human review, or suspension according to approved playbooks. Every material exception remains auditable.
Actuarial Validation
The first 90 days establish feasibility and leading indicators. Loss-cost and pricing conclusions require larger populations, historical data, controls, and time.
Inventory available exposure, claims, operational, safety, schedule, and control data; document lineage and missingness; establish lawful access and a common claims taxonomy. Exit only if data can support defensible analysis.
Apply frozen score logic to historical periods; compare score components with frequency, severity, near misses, delays, and control failures; use matched cohorts and normalization for occupancy, geography, value, construction type, and catastrophe exposure.
Operate in shadow mode and test whether precursor signals consistently surface before conventional alerts. Measure intervention lead time, risk-state stability, calibration, false-positive and false-negative rates, operator response, prevented propagation, downtime, near misses, and evidence completeness. A short pilot tests operations, it does not establish long-term loss-ratio improvement.
Estimate indicated effects only where credible; report uncertainty and sensitivity; separate correlation from causation; require actuarial sign-off before translating score bands into referrals, credits, surcharges, expected-loss assumptions, or pricing.
Use an agreed reviewer to test methodology, bias, leakage, stability, reproducibility, and adverse selection. Publish limitations and unresolved exceptions alongside favorable findings.
Track fire, water, injury, cyber-physical, property, and business-interruption outcomes on their appropriate development timelines; recalibrate or suspend use if drift, poor performance, or unintended impacts exceed approved tolerances.
Governance & Accountability
The design target is explainable, challengeable, human-governed intelligence aligned with the NAIC AI Model Bulletin and NIST AI RMF, not autonomous insurance decision-making.
Maintain score definitions, features, weights, confidence, approved uses, prohibited uses, validation status, version history, change approvals, drift thresholds, overrides, appeals, and rollback procedures aligned to insurer governance expectations.
No automated recommendation should independently bind coverage, admit liability, issue a regulated permit, disable emergency egress, or initiate a high-consequence physical action. Authorized personnel approve interventions, with emergency override and safe-hold controls.
Contractually define controller/processor roles, purpose limitation, lawful basis, minimization, tokenization, retention, deletion, access rights, subprocessors, cross-border transfer, breach notification, and impact assessments. Compliance is assessed, not guaranteed by design language.
Agree encryption, identity, least privilege, key management, logging, vulnerability management, testing, incident response, data residency, supplier controls, uptime, latency, support, recovery-time and recovery-point objectives before production.
Cryptography can demonstrate record integrity after capture; it cannot prove that a sensor, person, or source system reported truthfully. Source assurance, calibration, reconciliation, confidence scoring, anomaly detection, and evidence provenance remain required.
Definitive agreements should address IP and derived-data ownership, confidentiality, audit rights, service levels, professional and cyber insurance, indemnities, liability caps, consequential loss, regulatory cooperation, termination, data return, and transition support.
Go To Market
A proposed discovery and operating-validation phase. Public launch, branding, pricing, and coverage would occur only after agreed evidence, governance, legal, regulatory, and commercial gates are satisfied.
If validation and approvals succeed, the parties could develop a counsel-reviewed market-education program. Any “first,” “standard,” performance, certification, or exclusivity claim would require substantiation and mutual written approval before publication.
Commercial & Partnership Terms
Every commercial number remains a projection to be jointly modeled; this proposal creates no exclusivity, investment right, premium share, or binding obligation.
The parties would agree a fixed discovery budget covering integration mapping, data preparation, actuarial analysis, security review, legal work, and independent validation. No fee or resource commitment is assumed until documented.
Potential structures, per-score fee, annual platform license, implementation fee, or compliant revenue participation, are alternatives for diligence. Any GWP-linked compensation requires legal and regulatory review and is not presumed permissible.
A jointly approved business case should quantify eligible assets and premium by territory, adoption rate, average fee, implementation capacity, sales cycle, churn, support cost, and downside/base/upside cases. No market-size number is asserted in this draft.
Any proposed exclusivity must define product, channel, territory, term, minimum performance, development milestones, reserved markets, IP rights, termination, change of control, and post-termination transition. Exclusivity is not granted by this proposal.
Working convention: DUAL would own underwriting decisions and policy language; MovementAI would retain its pre-existing platform, models, and IP; jointly created branding, improvements, derived data, and customer rights require negotiated allocation.
Launch requires approved product language, regulatory pathway, validated use case, security acceptance, integration readiness, broker and underwriter training, claims procedures, support model, and economics. Failure criteria trigger remediation, scope reduction, suspension, or orderly exit.
Executive Reference
Plain-language definitions for the proposed technical and insurance framework. Terms describe decision-support concepts unless expressly validated and adopted in a final product.
Evidence Appendix
External sources establish market context only. They do not validate MovementAI performance, pricing, coverage, or loss-reduction projections; those require the joint validation program above.
Howden, About Us
Howden reports 24,000 people and $51bn of client premiumsPatent counts, application status, ownership, asset references, deployment status, score methodology, security posture, market size, financial assumptions, and all proposed economics remain subject to documentary diligence and counsel review before external reliance.