Somewhere in your company's accounts there is a €43 overcharge that would cost €200 to find. It is not hidden. Nobody is lying about it. It survives for a purely economic reason: establishing that it exists costs more than getting it back. Now imagine the check costs €2. The error didn't get bigger — the economic boundary moved. Multiply that across every invoice line, every indexed price term, every insurance claim, every formula-governed charge in the economy, and you are looking at a large class of losses and rents sustained simply because checking was not worth its cost — the quiet subsidy the world pays to whatever is not worth checking.
That subsidy is now being repriced.
Two cost collapses define the economics of artificial intelligence. The first — the cost of doing cognitive work — is the one everyone watches: machines draft, code, reconcile, calculate. The second is quieter and, I will argue, more institutional in its consequences: a collapse in the cost of establishing whether economically consequential claims are true — correct, substantiated, and actionable.The essay distills two working papers: Gill (2026a), "The Economics of Machine Verification," which builds the formal model, and Gill (2026b), "Machine Verification and the Institutions of Trust," which traces the institutional consequences. Both are on the papers page. Most claims in commerce are verifiable in principle: an invoice line can be reconciled against a contract formula, a supplier charge against an indexed pricing term, a reported number against its source records. What protects them from inspection is rarely logic. It is cost.
If the cost of checking collapses, three things follow — each developed below:
- Small errors become worth checking. €43 against €200 becomes €43 against €2, and the boundary between "tolerated" and "contested" moves across whole classes of claims at once (Section 1).
- Correct doesn't mean optimal. A contract can be perfectly performed and still be the wrong contract — the wrong tariff, term, or structure for your realized data. When computing the better alternative gets cheap, those fully legal mismatches get repriced too (Section 4).
- Institutions adapt before disputes happen. Counterparties clean up claims under threat rather than after inspection, suppliers reprice before customers switch, brands shift from assurance toward identity, and opacity migrates to whatever remains hard to measure (Sections 3–4).
Section 1The frontier: which claims are worth checking
Economics has understood for fifty years how costly verification disciplines behavior — that literature runs from Townsend's costly state verification through optimal auditing and tax enforcement.Townsend (1979); Border and Sobel (1987); Mookherjee and Png (1989); at state scale, Kleven et al. (2011) and Pomeranz (2015). The question this framework puts at the center is the one machine intelligence now forces: which claims become worth verifying at all when the technology of verification changes?
Model verification as a technology with real structure, not a single "it gets better" dial: a marginal cost c per claim checked, a fixed cost K to build the checker in the first place, a pipeline of reliabilities running from detection to enforcement, and a false-positive rate f. Then for any class of claims — a type of invoice line, a network charge rule, an indexed price component — there is a minimum economically contestable claim value: the verification frontier, written L*(τ, N).Gill (2026a), Proposition 2 and equation (8). The frontier is the rearranged entry condition of a monitoring model with an explicit strategic response, pipeline, and error structure. Below the frontier, discrepancies are economically protected — not hidden, just not worth finding. Above it, they are contestable.
Two properties of the frontier organize almost everything else.
Volume amortizes fixed cost. A €2 discrepancy repeated two million times can justify verification infrastructure that no human would rationally deploy on any individual €2 case. That is why the transition arrives volume-first: billing, procurement, standardized transactional layers — not courtroom drama, but reconciliation at scale.
Different costs unlock different territory. Falling marginal cost c moves the frontier for high-volume claim classes whose checkers already exist. Falling fixed cost K — machine intelligence turning bespoke parsers and reconciliation pipelines from engineering projects into configuration — unlocks the mid- and low-volume tail: the bespoke contracts and idiosyncratic counterparties no institution could previously afford to check. Which territory converts first in any market tells you which cost fell there.
What becomes worth checking?
The stakes of that shaded band are not small. U.S. federal agencies alone reported an estimated $186 billion in improper payments for fiscal year 2025, with cumulative estimates around $3 trillion since 2003 — overwhelmingly formula-eligible, document-based claim classes of exactly the kind the frontier governs.GAO (2026), as read in Gill (2026a), Section 10: the composition claim is the paper's reading, not GAO's conclusion. Historically tolerated small discrepancies are not evidence that they don't matter. They are evidence that the cost of challenge exceeded the private gain from correction.
Section 2The dashboard limit: detection is not verification
Here is a mistake common among "AI audit" products, and one reason a decade of anomaly-detection dashboards changed less than promised: detection is the cheapest and least binding stage of verification.
For a checked claim to matter economically, it has to survive a pipeline: the discrepancy must be detected, then substantiated against the governing rule, then assembled into evidence some institution accepts, and then that institution must impose a consequence — a refund, a sanction, a repriced contract. The pipeline is multiplicative, and deliberately unforgiving: if any stage is near zero, a hidden discrepancy almost never becomes an economic consequence.
Why does detection alone change nothing?
The formal version is what the papers call the dashboard limit: as evidentiary and enforcement reliability go to zero, the verification frontier goes to infinity — no finite claim is economically contestable, however cheap and accurate detection becomes.Gill (2026a), Corollary 1. The regulatory twin is Jin, Sokol, and Wagman (2026): AI-augmented monitoring below an institutional-capacity threshold generates enforcement workload without reducing harm. A system with 99.9% anomaly detection and no path to consequence is not a verification technology. It is a dashboard, and its economics are the economics of decoration.
This single condition does most of the essay's disciplinary work. It is why the blockchain-era prophecy that "trustless verification will reorganize commerce" aged badly — verifiability-in-principle required migrating economic activity onto new rails, and detection without an enforcement pipeline changes nothing. Machine verification differs in the decisive respect that it reads the existing substrate: contracts, invoices, ledgers, and meter feeds as they already are.Gill (2026a), Section 10, "Why this is not the previous trust prophecy," building on Catalini and Gans (2020). And it is why every claim in this essay is conditional on the pipeline clearing: where evidence standards or enforcement are missing, the old institutions persist by default.
Section 3The threat does the work
Suppose a claim class crosses the frontier. What do you expect to see? More audits, more disputes, more recovered money?
Mostly, no — and the reason is the oldest result in enforcement economics wearing new clothes. In the inspection game, cheaper verification lowers equilibrium misstatement without raising equilibrium inspection frequency: the counterparty, knowing checking is now rational, stops misstating; the principal, facing cleaner claims, doesn't inspect more. The threat does the work.Gill (2026a), Proposition 3, in the classic inspection-game setting of Tsebelis (1989) and Graetz, Reinganum, and Wilde (1986). Empirically: near-zero evasion for third-party-reported income in Denmark (Kleven et al. 2011); the VAT paper trail deterring before audits are realized (Pomeranz 2015).
The field already contains a clean, almost comic, demonstration. After a German court ruled that dynamically embedding Google Fonts violated the GDPR, a single Austrian lawyer deployed automated detection and claim generation against websites at scale. Within three months, non-compliance in Austria fell 22.7 percentage points — nearly half — across claims individually too small ever to have justified human enforcement. For most of the affected population, the enforcement instrument remained exactly that: an instrument, a threat, scarcely fired relative to the compliance response it produced.Merane and Stremitzer (2026), the first credibly identified field study of automated private enforcement; read through the model in Gill (2026a), Section 8.1.
This has a consequence for how the transition will be measured, and it inverts the natural evaluation instinct. Verification systems are habitually judged by recovered money. But recoveries are the product of two opposing forces: remediation effectiveness (rising with the technology) and the stock of misstatements left to find (shrinking as deterrence bites). Under mild conditions the result is a hump: recoveries rise while the technology harvests the pre-existing stock of misstatements, then fall as deterrence shrinks the flow — while avoided loss rises throughout.Gill (2026a), Proposition 4. Consistent field evidence: the deterrence value of U.S. tax audits substantially exceeds their direct revenue (Boning et al. 2025); China's computerized VAT enforcement produced large short-run revenue gains that attenuated over time (Fan et al. 2020); Medicare audits generated savings predominantly through deterrence and induced compliance investment rather than recoveries (Shi 2024).
Why can a verification system that works recover less and less money?
A successful verification technology should eventually look unproductive on a recovery dashboard. Procurement teams will read that as failure. It is the signature of success — and any serious evaluation of machine verification must measure coverage, incidence, counterparty behavior, and avoided loss, not recovered cash.
Section 4The institutions of trust get re-selected
Now the larger claim, the one the second paper is built on. Much of the architecture of commerce is not a response to misstatement. It is adaptation to expensive checking:
- fixed-price contracts written where cost verification was uneconomic;
- brands posted as forfeitable bonds for quality no buyer could inspect;
- grading, standardization, and commoditization as economies of measurement;
- statistical sampling, materiality thresholds, and episodic audit as rationing devices for scarce verification;
- escrow, letters of credit, payment-term conventions;
- intermediaries whose margin is, in substantial part, a verification wage.The lineage: Klein and Leffler (1981) on price premia as quality bonds; Barzel (1982) on measurement costs and market organization; Diamond (1984) on delegated monitoring. Gill (2026b) puts these on one menu and shocks it.
Each of these embeds a shadow price of verification calibrated to the human technology. Where the full pipeline clears, that shadow price collapses — and the structures built on it lose their economic foundation. Modeling trading relationships as choosing the cheapest credibility technology — opacity, reputation bond, third-party certification, or direct machine verification — reproduces the observed institutional landscape at high K, and then predicts where each region moves as costs fall.
Where do the technologies of trust live today?
Four re-selections deserve their own statements.
Certifiers: collapse by tipping, not decay
A certifier's economic advantage is fixed-cost amortization — spreading K across M clients. That advantage is proportional to K, so as construction costs collapse, any positive intermediation margin eventually makes direct verification strictly cheaper. But the sharp result is about how certification markets end. Because the shared cost recovery falls on whoever remains, adoption is strategically complementary: each client who leaves raises the fee on those who stay, which pushes the next client out. Markets held together by amortization alone do not shrink smoothly — they tip: long apparent stability, rising per-client fees as the book shrinks, then abrupt collapse, with hysteresis. Certifiers whose fee is covered by genuine outsourcing value survive as a niche; certifiers priced above it are held together by amortization alone, and amortization-held markets end discontinuously.Gill (2026b), Proposition 2 and the closed-form worked example in Appendix A.2. Recovery-audit firms and benchmarking consultancies share the certifier cost structure and are candidates for the same dynamics.
Why might a certification market collapse suddenly rather than shrink?
Drag K down. In the amortization-held regime the stable equilibrium and its unstable twin merge and vanish at an interior Kcrit — the clientele drops discontinuously to zero. In the niche regime the clientele declines smoothly to the clients who value outsourced attestation itself.
Intermediaries do not disappear in this story. Where credible evidence requires recognized standing and someone to bear liability, the intermediary survives on exactly that margin — and intermediation rents migrate from amortization to recognition.
Brands: migration, not death
Decompose brand value into a bonding component (the capitalized premium that makes cheating irrational when buyers cannot check), a search component (the brand as attention heuristic), and a taste-and-status component. Machine verification attacks only the first. Where quality becomes cheaply and credibly verifiable, the sustainable assurance premium compresses toward the cost of credibly attested verification — and high-quality entrants can substitute evidence for accumulated reputation at a minimum scale that falls with K.
What part of a brand does verification actually attack?
Something like this has already run once at partial scale, and it provides a suggestive historical analogue, consistent with the model's direction. Online reviews are a crowd-sourced, noisy, partial verification technology — and their diffusion coincided with the hotel chain-affiliation premium falling by more than half between 2000 and 2015, concentrated among low-quality and small-market properties (the assurance-heavy cells), while premia at the high end, where taste and status dominate, largely persisted. A one-star Yelp increase raises independent-restaurant revenue five to nine percent; chains — whose brand was the assurance — gained nothing.Hollenbeck (2018); Luca (2016). Gill (2026b), Section 6, treats the review era as the closest historical analogue: same sign, lower evidentiary quality, narrower attribute reach than machine verification. The prediction is not that brands die. It is that brand capital migrates toward what remains intrinsically unverifiable — identity, taste, status, attention — while the assurance function moves to whoever bears liability for the attestation.
The optimality layer: repricing before switching
Everything so far concerns conformity: was the bill computed per the contract? There is a second, quieter layer. A contract can be perfectly performed and still be the wrong contract — the wrong tariff structure, the wrong term, the wrong risk allocation for this relationship's realized data. Nothing is misstated; nothing is illegal; no court could touch it. The mismatch survives because constructing and validating the counterfactual — repricing the customer's actual data against the obtainable menu — was itself expensive analysis. A €300-a-year mismatch rationally survived a €1,000 benchmarking study. The comparison never happened, so the rent never appeared as one.
When the counterfactual becomes cheap, the minimum mismatch worth acting on falls with it. And the enforcement mechanism needs no adjudication at all: the customer says an equivalent contract exists at lower cost — match it or I leave. An incumbent who can profitably match will reprice rather than lose the relationship, so the equilibrium response is repricing first, switching second — gaps compress without switching statistics moving, deterrence's twin in the pricing domain.Gill (2026b), Proposition 4. Compression stops at switching friction s, not zero — which is where policy lives, since s is partly regulatory (notice periods, exit fees, portability) while the computation cost is not a policy variable at all. Because an optimality mismatch is a flow that no restitution reaches backward, the value of checking lies in its frequency: the layer's limit is continuous verification, contract choice becoming continuous re-optimization.
And when the incumbent reprices, who captures the identified gap — the customer, the supplier, or the auditor in between? That pass-through share is, to my knowledge, unmeasured anywhere; the implementation in commercial energy contracting logs it as a primary outcome, client by client, as the ratio of realized concession to identified gap.
The rebuttal asymmetry: the transition's dark corner
The same technology that checks claims cheaply generates accusations cheaply. The cost of proving innocence — document assembly, legal process, management time — is human and procedural, and falls far more slowly. A compliant target facing demand σ settles whenever σ is below its rebuttal cost, so nuisance challenge against the honest is profitable exactly when accusation cost is below rebuttal cost — and an asymmetric collapse expands that region even as it improves true deterrence.
When does cheap accusation pay?
The welfare economics of the whole transition turn on this asymmetry more than on anything else: cheap verification is welfare-improving where rebuttal costs fall in step, and can be welfare-destroying where compliant parties become extortable at scale.Gill (2026b), Proposition 5, machine-age descendant of Rosenberg and Shavell (1985) and Bebchuk (1988). The Google Fonts wave displayed both halves at once: a genuine compliance response, and judicial abuse-of-rights pushback against the challenge flood. Fee-shifting, pleading standards, and cheap rebuttal technology are the instruments that restore symmetry. Expect them to be the most contested policy territory of the transition.
And opacity relocates
One honest boundary on all of it: opacity is not eliminated. Sellers allocate effort across attributes, and when the verifiable ones get priced accurately, distortion and marketing migrate toward judgment, ambiguity, and whatever machines cannot yet measure. The economy does not become transparent. Its opacity moves — from syntax to substance, from formula-governed claims to unverifiable attributes — and the next round of every result above will be fought there.Gill (2026b), Proposition 6, on Holmström–Milgrom multitask logic; the within-attribute version is the obfuscation contest of Gill (2026a), Section 6.3. Documented at national scale in tax: when one margin became verifiable, firms substituted almost fully toward harder-to-verify margins (Carrillo, Pomeranz, and Singhal 2017).
Section 5A post-opacity scenario: 2026–2032
The papers derive orderings — which claim classes cross first, which institutions move before which. Orderings imply a sequence the way a phase diagram implies a melting sequence. What follows attaches dates to that sequence, and the two layers should not be confused: the orderings are model predictions; the dates are scenario conjecture. Each entry's tag names the derived result it instantiates — that part is falsifiable theory. Each entry's date is a guess about when it becomes visible — that part is conditional extrapolation, not prophecy. If the pipeline fails to clear somewhere, that entry stalls; that, too, is the theory speaking.
2026 · now
The volume-first beachhead
Contract-to-invoice reconciliation, utility and telecom billing, procurement, and standardized claims processing cross the frontier first: formula-governed, high-volume, individually small — the €2 × 2,000,000 region where marginal cost was the binding constraint and checkers already exist. Automated private enforcement of adjudicated digital rules (the Google Fonts pattern) recurs in new domains. Recovery numbers look spectacular; this is the stock being harvested.
2027
The bespoke tail opens
Model-assisted construction turns bespoke parsers and single-counterparty audit tools into configuration. Verification reaches contracts and counterparties no institution could previously afford to check — the territory where reputation premia and tolerated opacity were largest. First-wave adopters are intermediaries (brokers, recovery-audit firms) amortizing the tooling across client books: the migration observed from inside.
2027–2028
Deterrence becomes visible as absence
In the beachhead classes, error rates fall economy-wide while realized enforcement stays flat: counterparties clean up claims because checking is now credible, not because they were caught. Early vendor dashboards start showing declining recoveries; the sophisticated read it as success, procurement reads it as a reason to churn. Evaluation frameworks begin shifting to coverage and avoided loss.
2028
Repricing waves without switching waves
Continuous counterfactual engines — is this still the right contract for this relationship's realized data? — reach commercial energy, insurance, telecom, freight, and banking fees. Incumbents facing systematically informed customers reprice before customers exit; measured switching barely moves while realized margins on inertia compress toward switching friction. Suppliers' visible response: menu simplification in some markets, differentiation on incomparable dimensions in others.
2028–2029
Fee escalation, then the first tippings
Certification-shaped businesses — recovery-audit firms, benchmarking consultancies, inspection regimes on standardized claims — see their bespoke fringes leave first. Per-client fees escalate as shrinking books carry fixed cost recovery; then individual segments collapse abruptly rather than eroding. Survivors reprice around recognition and liability — attestation, standing, insurance — not amortization.
2029
The nuisance wave and the counter-reformation
Mechanized challenge generation, profit-financed, is pointed at imperfect precision and asymmetric dispute costs: automated demand letters against parties for whom settlement is cheaper than defense. Courts, regulators, and platforms respond — fee-shifting, heightened pleading, abuse-of-rights doctrine, bulk-filing friction. Jurisdictions diverge measurably: symmetric-cost regimes get the deterrence gains without the extraction.
2029–2030
Contracts learn they are being read
New contract vintages are drafted machine-readable: explicit data provenance, calculation formulas, structured evidence fields, audit rights, escalation rules. Ambiguity becomes a priced instrument — unverifiable claims trade at a visible discount. Semantic standards (shared identifiers, definitions, provenance conventions) spread as complements to verification, even as pressure for uniform formats fades. The cleanest leading indicator, visible in contract language before any dispute occurs.
2030–2031
Brand premia compress where they were assurance
In categories where the premium was mostly assurance on verifiable attributes — specification compliance, provenance, billing accuracy, durability — verified small entrants gain share against incumbent names, repeating the review-era hotel pattern with better evidence. Premia hold, and in attention-flooded categories strengthen, where brand value is taste, identity, and status. Assurance spending migrates from advertising toward attested evidence and liability-bearing certification of the un-amortized kind.
2031–2032
Voluntary verifiability, and the residue
Where being checkable is now cheaper than being challenged, honest parties pre-certify and non-certification becomes informative — partial unraveling, the benign equilibrium. Materiality thresholds, sampling conventions, and episodic audit are renegotiated against near-zero checking costs. What remains opaque is what machines cannot yet measure — judgment, tacit quality, radically incomplete states — plus every domain where the enforcement pipeline never cleared. The frontier stops moving where the institutions stop, which is the definition of post-opacity.
This scenario will be publicly re-graded here every August, entry by entry, including the misses. Dated predictions earn their credibility on the second date, not the first.
Section 6What stops it, where, and why
A claim this large earns credibility from its failure modes, so here they are, stated as sharply as the successes.
The pipeline gates everything. Where evidence standards reject machine output, where enforcement is congested, where remedies are weak, the frontier stays at infinity no matter how good detection gets. The prediction is testable at the pipeline-stage level: when machine verification disappoints somewhere, you should be able to name the stage that failed.
The frontier fights back. Obfuscation is an investment: fragmented data, contractual complexity, rebundling, plausible-but-noisy documentation. Near the frontier there is a discrete motive to buy just enough complexity to push a claim class back below it. The empirical signature is substitution, not disappearance — and post-shock, complexity migrates from syntax (which machine verifiers now read) to substance (which they cannot).Gill (2026a), Section 6.3; Gill (2026b), Section 9.1. On complexity chosen because it generates agency rents, Biais and Landier (2020); on strategic price complexity preserving rents in retail financial markets, Carlin (2009); on sellers raising search costs to protect pricing rents, Ellison and Wolitzky (2012).
Not everything is verifiable. Preferences, long-horizon strategy, artistic value, much medical and legal judgment resist cheap verification under any technology. The frontier moves within the set of formal, data-represented claims — and that set is not everything, which is precisely why opacity relocates rather than dies.
And the market will not find the right frontier on its own. Much of what verification prevents is a transfer, part of dispute costs falls on the challenged party, and deterrence spills over to relationships the verifier doesn't own. Private verification therefore races past the social optimum where transfers dominate — privately profitable, socially wasteful verification races — and stalls short of it where deterrence is a public good no individual victim will finance.Gill (2026a), Proposition 5, inheriting Landes and Posner (1975) and Shavell (1982, 1997); the over-investment corner is Hirshleifer (1971), machine-financed. Both corners are already observable in the Google Fonts episode alone. Materiality thresholds, fee-shifting, evidence standards, and safe harbors for certified claims are the levers — post-frontier economies will need all of them.
Section 7The research agenda
The program reduces to one measurable quantity:
Every parameter of the answer — c, K, f, the pipeline reliabilities, the density of claim classes near the frontier — is estimable in real transactional domains, and the papers specify the designs: randomized or staggered rollout of verification across comparable claim classes, pre-registered outcomes, disclosed false-positive and dispute results, with the construction-cost series K(t) — the cost to stand up verification for each new counterparty format, quarter by quarter — as the novel measured object.Gill (2026a), Section 8; Gill (2026b), Section 10. An implementation is in progress in commercial energy contracting — chosen because bills are generated from explicit contracts, tariff formulas, metered consumption, and regulated network components, so claims are formula-governed, high-volume, and individually small: the region the theory says moves first. Commercial-interest disclosure on the title pages.
The theory sticks its neck out. Eight predictions, compressed from the papers, each falsifiable:
- Ordering. Verification adoption grows fastest in bespoke, previously reputation-governed relationships as K falls; amortization intermediaries lose share before liability-bearing ones.
- Tipping. Certification-shaped markets end with rising per-client fees and abrupt segment collapse, not gradual fee erosion.
- Brand migration. Premium compression concentrates in assurance-heavy, verifiable categories; taste- and status-heavy premia persist.
- Recovery hump. Under systematic verification, measured recoveries rise then fall while error incidence declines throughout.
- Optimality compression. Identified contract mismatches shrink over time under continuous counterfactual auditing, with repricing outrunning switching.
- Repricing before switching. Incumbents facing informed customers change offers before switching statistics move.
- Nuisance divergence. Challenge volume against compliant parties rises where rebuttal costs stay high; fee-shifting jurisdictions capture deterrence without extraction.
- Relocation. Post-verification, misconduct and marketing effort shift measurably toward unverifiable attributes within the same relationships.
If you work on auditing, enforcement, contract theory, market design, or the economics of AI: these are stated precisely enough to be wrong. Test them.
Section 8Cite this work
For the formal results, cite the working papers — the economics paper is on SSRN with a DOI; the institutions paper is hosted here while its repository posting completes. For the definition and public exposition of post-opacity, cite this essay.
@techreport{gill2026economics,
author = {Gill, Amrit},
title = {The Economics of Machine Verification: Verification-Cost Shocks and the Extensive Margin of Monitoring},
year = {2026},
month = {August},
type = {SSRN Working Paper},
number = {7307578},
doi = {10.2139/ssrn.7307578},
url = {https://ssrn.com/abstract=7307578}
}
@techreport{gill2026institutions,
author = {Gill, Amrit},
title = {Machine Verification and the Institutions of Trust: Reputation, Certification, and Contract when Checking Becomes Cheap},
year = {2026},
month = {August},
type = {Working paper},
url = {https://post-opacity.com/papers/institutions-of-trust.pdf}
}
@misc{gill2026postopacity,
author = {Gill, Amrit},
title = {Post-Opacity: What Happens When Checking Becomes Cheap},
year = {2026},
howpublished = {\url{https://post-opacity.com}}
}Comments, counter-analysis, and measurement collaborations are welcome: amritbir1@gmail.com.