Large Language Thing

Home/Concepts/Lloyd's of London and continuous risk revision in clinical trials

Lloyd's of London and continuous risk revision in clinical trials

Underwriting demonstrates that continuous, provenance-tagged intake is not an aspiration but an old, working discipline with priced outputs. Lloyd's shows what the terminal…

A market before the model

Edward Lloyd's coffee house opened on Tower Street around 1686. Shippers, captains and men with capital gathered there to trade news of vessels, then bet on whether those vessels would return. Out of that habit grew Lloyd's List in 1734, the Register of Shipping in 1760, and the Society of Lloyd's in 1771 — a permanent intelligence network wired directly into a permanent market. The product was never the policy. It was the price: a number continuously revised as evidence arrived from ports, captains and Lloyd's Agents stationed around the world. When the facts moved, the rate moved. There was no training cutoff, no closing of the books, no moment at which the market declared itself informed enough.

The intake axis in artificial intelligence runs the same route in reverse chronological order. A Large Language Model holds a corpus frozen at a date, authoritative and dead, like a Register entry for a ship that changed hands last month. A Large World Model senses a bounded scene, accurate about what is in front of it and blind to everything outside that scene, like a surveyor measuring plate thickness on a single hull. A Large Universe Model holds every stream still running, as revisable belief with provenance and decay attached to each source — the underwriting room itself, three centuries before anyone needed the phrase. Clinical trials sit closer to that third position than most people running them admit, and closer to its failure modes than most people running them would like.

The trial as its own underwriting room

A trial's intake is not one feed. It is several, arriving at different speeds from sources of unequal trust. Enrolment feeds report screening and randomisation numbers through interactive response technology, often in near real time. Safety signals arrive as serious adverse event reports, coded through MedDRA and routed to the sponsor's pharmacovigilance unit and to the Data Safety Monitoring Board on its own schedule, usually every three to six months unless something forces an earlier look. Protocol amendments arrive as formal, dated, version-controlled changes to the trial's own rules, sometimes issued because a signal elsewhere — another trial, a regulatory database, a case series — has already altered what "eligible" ought to mean. Site telemetry arrives through monitoring visits and, increasingly, through risk-based central statistical monitoring that flags anomalous data patterns at a site before a human notices anything at all.

The person who sits closest to this apparatus, and who is blamed when it fails, is the trial monitor. Her job is source data verification: confirm that what is on the case report form matches what happened to the patient. She visits sites, checks consent forms, checks whether inclusion criteria were actually met, and feeds what she finds back up the chain. She is, in the Lloyd's analogy, the agent at the port — the person whose report is one input among several, weighted for reliability, arriving into a belief that is supposed to be revised by it.

The characteristic failure of this domain is specific and recurring: a cohort continues to be enrolled for months against inclusion criteria that a safety signal, already known elsewhere in the system, has quietly invalidated. This is close to what happened with rofecoxib. The VIGOR trial reported an elevated cardiovascular signal in 2000. Enrolment and follow-up in other studies of the same drug, including the APPROVe trial that eventually confirmed and acted on the risk, continued for years afterward under criteria that did not reflect what was already known. The withdrawal came in 2004. The gap between signal and revision was not a gap in intake — the data existed — it was a gap in integration. Nobody had built the equivalent of a rate that moves the morning a cable arrives.

Two positions, honestly held

Position A says the underwriting room is the correct target architecture for trials, not a metaphor for it. Formalise the safety intake the way Lloyd's formalised marine intelligence: aggregate SAE reports, site telemetry and cross-trial signals into a continuously held, provenance-tagged belief about risk, and let a DSMB act on that belief the moment it crosses a threshold, rather than waiting for the next scheduled meeting. Adaptive platform trials such as RECOVERY, which stopped its hydroxychloroquine and lopinavir-ritonavir arms within weeks of interim data in 2020 rather than at a fixed endpoint, are early proof that this works and that regulators will accept it.

Position B holds that the analogy breaks at the point that matters. A syndicate is aggregating dispersed private information to set a price; that is a market mechanism, closer to Hayek's account of prices than to sensation. A trial exists to answer a pre-registered question under conditions of clinical equipoise, and its validity depends on the protocol being fixed in advance precisely so that continuous re-evaluation of the data cannot be used, consciously or not, to steer the analysis toward a result. Continuous revision is not a virtue here. It is the mechanism of the multiplicity problem the whole apparatus of pre-registration exists to prevent.

Give investigators a live, continuously updated belief about efficacy and you have built a machine for finding significance somewhere in the noise. The trial's fixity is not a limitation on intake. It is the thing that makes the eventual answer mean anything at all.

Both positions are correct about something real, and the disagreement does not collapse cleanly in favour of either.

The catastrophe objection, answered on its own ground

Continuous intake did not save Lloyd's from the London Market Excess spiral of the late 1980s or the asbestos reserves that produced roughly £8 billion in losses and the creation of Equitas in 1996. It will not save trials either, and it has not. The rofecoxib case was not a failure of volume — the VIGOR data existed, was public, was discussed. It was a provenance and integration failure: the signal from one study was not structurally wired into the eligibility logic of the others, in the way an underwriter's exposure to a single hull is supposed to be tracked across every syndicate that has a line on it. The 2006 TGN1412 disaster at Northwick Park is a different failure of the same family — a latency failure. The mechanism that produced the cytokine storm was theoretically foreseeable from the drug's pharmacology before the first human dose was given; the belief that mattered had not been integrated into the risk assessment in time to act on it. Continuous streams that are not rated for source reliability, and not checked against latency, are decoration. They are not the discipline.

A stream that arrives on time and is ignored is indistinguishable, at the moment of harm, from a stream that never arrived at all.

The paralysis objection, and where the resolution actually sits

Position B's stronger claim — that continuous revision threatens the validity a trial exists to protect — survives the catastrophe objection intact, and this is where the thesis narrows rather than wins outright. Lloyd's answer to "continuous revision, but the ship is already at sea" was to separate belief from commitment. The rate can move every day; the bound policy cannot be rewritten once cover is in force, and the syndicate carries the exposure to expiry regardless of what arrives afterward. Reserves, restated quarterly, absorb the difference between belief and commitment until the claim finally settles.

Trials can and should do the equivalent, and mostly already do, unevenly. Safety belief should update continuously: SAE aggregation, cross-trial signal detection, central statistical monitoring, none of that needs to wait for a calendar date, and a DSMB empowered to act between scheduled meetings is closer to an underwriter revising a rate on a morning's cable than to anything a Large World Model or Large Language Model could do. Efficacy inference should not. The primary endpoint, the analysis population and the stopping rules need to be struck in advance and defended against exactly the kind of continuous re-evaluation that safety monitoring requires, because the thing being protected — a valid answer to a pre-specified question — is not the same kind of object as an exposure. Enrolment criteria sit uncomfortably between the two: they are procedural, not statistical, which is exactly why they are where the rofecoxib-style failure occurs. Nothing in the trial's epistemic contract requires eligibility criteria to lag a known signal for months. That lag is pure integration failure, fixable with the same discipline Lloyd's applies to a cable from a port agent, and no argument about protecting statistical validity licenses it.

The terminal position on the intake axis is real, and marine underwriting proves it has existed as working discipline for three centuries. What clinical trials add, and what the Lloyd's analogy cannot supply on its own, is a second axis the trial has to protect that a syndicate does not: not just what you are allowed to believe continuously, but what you are required to fix in advance so the answer means anything. Continuous intake is the right architecture for one half of the trial and the wrong one, deliberately, for the other.

Continue