By W.H.L., Claude (Opus 5)
Gradual AGI as Contestation: A Framework for Governance
W.H.L. and Claude (Opus 5)
Champaign Magazine · Gradual AGI Series #7
v1.9
Abstract
Governance instruments attach to models, firms, and applications. The consequences they exist to shape occur elsewhere. This paper takes that mismatch to be structural rather than a series of implementation failures, and builds a framework on the distinction it forces.
What is governed, on the account developed here, is not any artifact but the capacity of AI to alter outcomes together with the realized distribution of those outcomes. That object has two levels. Benefit potential and harm potential are coupled through the capability itself and cannot be separated within it; realized benefit and realized harm are not thereby coupled, because they are determined by a mapping that admits modulation at four points — access, sequencing, distribution, and deployment context. Producing a difference between the two levels is what governance does. The capacity to produce it is finite, institutionally held, and grows on a clock unconnected to the one governing capability, which makes the governance of an open-ended capability a rate problem before it is a design problem.
From this the paper derives an architecture of four functions — execution, observation, steering, and procedural adjudication — and states seven propositions, each separated into what follows analytically from the framework and what is empirically at risk, with falsification conditions. It then classifies the existing instrument landscape by point of purchase and reports a distributional finding: instruments cluster at access and deployment context, sequencing is populated almost entirely by private and unilaterally revisable commitment, and distribution — which this framework places inside the governed object — is close to empty.
The framework specifies no criterion of governance success. That is a result rather than an omission: a canonical criterion would require an aggregation rule the series has argued is unavailable. What replaces it is a procedural standard — detection, contestability, correction — and a claim about what contestation is for. Where no institution can settle which governance arrangement should obtain, contest is not a transitional inconvenience to be minimized but the mechanism by which arrangements are corrected, and the design question is not how to end it but how to connect it to institutions that can act on what it produces.
This is a conceptual and diagnostic paper. Empirical evaluation of its propositions is the work of the companion installment.
1 Introduction
1.1 A question that goes unasked
The public argument about artificial intelligence governance is conducted almost entirely in the register of what should be done. Should frontier models be licensed. Should weights be published. Should compute be restricted, evaluations be mandatory, liability be strict. These are the right questions to be arguing about, and the argument has produced statutes, executive instruments, standards processes, safety institutes, two intergovernmental organizations, and a substantial research literature within roughly three years.
A prior question is asked far less often: what, exactly, is being governed?
The answer looks obvious and is not. Every instrument in the current repertoire attaches to something concrete — a model above a compute threshold, a firm above a revenue line, an application in a listed high-risk category, an organization holding a contract. But the effects those instruments exist to shape occur somewhere else: in deployments the instrument did not anticipate, to parties who are not participants in it, through paths that were not the ones regulated. The gap between what governance grips and what governance is for is not an accident of drafting. It is a property of governing a capacity through proxies, and it recurs across every instrument type, in every jurisdiction, regardless of how the instrument is drafted.
This paper begins there. It separates the handles to which instruments attach from the target they are meant to affect, and it takes the systematic mismatch between them as the framework’s first datum and not as a catalogue of drafting errors to be fixed one at a time.
1.2 The claim
Stated compactly: the governance of an open-ended capability is a rate problem before it is a design problem. Four statements carry that claim, and the rest of the paper elaborates them.
Coupling and its limit. Benefit potential and harm potential are not two things a capability produces; they are one capability under two evaluative descriptions, and are inseparable within it. Their realizations are not thereby coupled, and need not be. Producing that difference is what governance does.
Coupling, not competition. The relation between the potentials is coupling: both rise together with capability. Competition here is among actors with divergent objectives; contestation is what those actors do over ends. Neither term applies to the potentials themselves.
Both layers, different action. Both the potential and the realization layer fall within governance’s scope, and they admit different action. At the potential layer what is available is attenuation and sequencing — whether a capability comes into existence, and in what order — and these act on the whole capability rather than selectively on its harm. Selective work is possible only in the mapping to realization: at access, distribution, and deployment context.
What governance attempts. Governance therefore attempts to realize benefit while withholding or containing harm. That is what it attempts, not a state it can be measured against: no rule ranks arrangements by proximity to it, and none of this terminates.
The capacity to modulate that mapping is held in institutions — regulators, courts, standards bodies, evaluation organizations, insurers, professional communities — and grows through institutional processes. The capability grows through research, capital, and competition. No mechanism holds the two rates in correspondence, and the governance problem is the interval between them.
That claim should be stated at the strength it can bear, which is less than a law. Three channels could in principle let the governing side grow faster than institutional history suggests. Capacity to absorb is increasing in prior exposure, so regulators encountering repeated cases should get faster — the absorptive-capacity result this framework borrows elsewhere (§2.1) cuts against the rate claim as much as for it. The technology can be turned on the problem: observation at scale is now partly automatable, and §3.6 treats that as a requirement, not a curiosity. And if instruments are modular, a governing repertoire could grow combinatorially rather than by addition. None of these has been shown sufficient to close the interval, and the framework’s claim is that none is currently doing so — a contingent structural tendency, not a necessity. What would refute it is straightforward and is stated at Proposition GP2.
1.3 What this paper is, and what it defers
This is a conceptual and diagnostic paper. It states definitions, derives propositions from them, and applies the resulting apparatus to the arrangement currently in force. It does not test its propositions against events. Empirical evaluation is the work of the companion installment, and the division is stated here so that it is not mistaken for an omission: this paper shows that the apparatus classifies and diagnoses; the companion installment shows whether the propositions hold.
One scope condition belongs at the outset instead of in the limitations, because it bounds what the framework claims. The architecture assumes the capability is produced by identifiable organizations against which handles can be applied: access instruments require someone to license or restrict, the one-role criterion requires distinguishable occupants, and observation requires something to observe. Where capability becomes widely distributed — published weights, small models trained by many parties, capability recoverable from artefacts already circulating — the handle set contracts sharply. Definition 2 says which points of purchase survive that contraction, and this paper does not develop an account of how governance operates once it has occurred. What follows is therefore a framework for governing a capability that remains concentrated enough to be gripped; §6.5 states what that excludes.
The division of labour with the companion installment has a further consequence readers should hold throughout. Several of the framework’s empirical commitments are stated, derived, and left unsettled — most importantly the rate claim at the centre of §1.2, whose operationalization does not yet exist. Section 4 states for each proposition what follows analytically from the framework and what is genuinely at risk, together with what observation would refute it. That separation is the paper’s principal defence against the criticism the series has attracted before: that a consequence of its own definitions has been presented as a discovery about the world.
1.4 Relation to the series
This is the seventh installment of the Gradual AGI series, which treats the arrival of advanced AI as a problem of civilizational assimilation rate and not of capability thresholds. Three companion works are load-bearing here and are named throughout by fixed terms. The Optimization framework paper (“Gradual AGI as Optimization: A Conceptual Framework”) supplies the five Propositions and the account of a persistent Global Objective pursued through Shared Stewardship. The Optimization models paper (“Gradual AGI as Optimization: Formal Models and Empirical Tests”) supplies the finding — that no actor solves the joint optimization problem — which this paper extends one level upward. The CFS paper (“Ceiling, Floor, and Slope: A Falsifiable Dynamical Model of Synchronization for Gradual AGI”) supplies the dynamical account of how a capability frontier and the institutions absorbing it move relative to one another.
The CFS paper also reserved this installment’s place in advance. It positions itself explicitly at the dynamics layer of a progression running from ontology through dynamics to control and governance, and states that the governance question is subsequent work it does not anticipate. This paper is that subsequent work. Section 3’s account of what governance is, and Section 5’s diagnosis of the arrangement in force, are offered against dynamics that installment established, not alongside them.
This installment also discharges a commitment the series made in print. The Optimization framework paper defines Shared Stewardship and states plainly that the definition does not by itself guard against capture by the most powerful participants, leaving the question of what safeguard would prevent this — procedural, structural, or institutional — as an open design question for the framework’s governance layer. Its limitations name two further questions as unaddressed: legitimacy, consent, and power asymmetry among stakeholders with unequal capacity to shape the Global Objective, and how value pluralism is to be reconciled within Shared Stewardship. Definitions 3 through 5 below are this paper’s answer.
One inheritance should be stated at the outset because it constrains everything that follows. The series does not evaluate capability or outcome on a single scalar. It follows that this framework cannot rank governance arrangements by proximity to a goal, and does not attempt to.
1.5 Contributions
Four, ordered by how much of the paper rests on them.
A two-level account of the governed object. Separating handle from target, and potential from realization, converts a persistent and much-noted mismatch into a structural property with a name, and locates precisely where governance can and cannot act.
A coupling-and-rate account of the governance problem. The four points of purchase are, so far as the survey underlying Section 2 found, not stated elsewhere as a set. Applying the regulator-variety bound to this domain converts the familiar complaint that regulation is too slow into a bound with two distinct lever classes — attenuating what arrives, and amplifying what the governing system can distinguish — which the policy debate routinely conflates.
A four-function architecture. Execution, observation, steering, and procedural adjudication, with the observation function specified down to its composition, its method, and the limits of its standing. The fourth function is derived, not borrowed: it is what remains once adjudication of contested ends is shown to be unavailable to any institution.
A classification of the instrument landscape by point of purchase, with the distributional finding that follows from it — and which, because this framework places the realized distribution of outcomes inside the governed object, identifies the emptiest cell as a structural gap, not a peripheral one.
1.6 The structure of what follows
Section 2 surveys the prior work the framework builds on, borrows criteria from, or must answer, organized by problem rather than by discipline. Section 3 states six definitions and the framework’s own type, together with three design corollaries. Section 4 states seven propositions, each split into analytic and empirical parts with falsification conditions. Section 5 applies the apparatus to the arrangement in force. Section 6 states the limitations belonging to the paper as a whole, including its conflicts of interest. Section 7 concludes.
A reader with limited time should read Definition 2 (§3.3), Proposition GP1 (§4.1), and the distributional finding (§5.2). Those three carry the argument.
2 Prior and Related Works
2.0 Scope and method
Governance is among the most heavily worked problems in the social sciences, and a survey that attempted coverage would be a book. This section is organized around a different criterion. It treats as relevant only those bodies of work that bear on one of the six definitions stated in Section 3 or the seven propositions stated in Section 4, and it is organized by problem, not by discipline, because the problems this framework confronts have each been named independently in several fields and the convergences carry more information than a field-by-field tour would.
The organizing observation is that the literature is lopsided in a way that turns out to be useful. It is very rich on what good governance looks like in equilibrium, and very rich on how to handle a dangerous technology whose properties are known. It is comparatively thin on the question this series has been formalizing since its first installment: what happens when the rate at which a capability arrives exceeds the rate at which institutions can absorb it, and what governs the interval. §2.1 collects the exceptions — the authors who made rate itself the object — and they are the most direct prior art for this paper. §2.10 states what none of them supply.
Three exclusions are deliberate and are visible, not silent. Work on the technical alignment of models is not surveyed: Definition 1 places models among the handles, not the target, and the alignment literature addresses a different object. Work on the economics of automation is treated only where it bears on the distributional component of Definition 1; the series has addressed it directly in earlier installments. And normative theories of distributive justice are drawn on for criteria without adjudicating between them, since Definition 3 denies this framework the standing to select one.
A fourth exclusion is temporary rather than principled and should be named as such. The large literature of concrete governance proposals — compute thresholds and registration schemes, model evaluations, structured access, know-your-customer regimes for compute providers, licensing, regulatory markets, and the several designs for international institutions — is almost entirely absent below. These are proposals about handles in Definition 1’s sense, and the section that establishes what governance is acting on is the wrong place to assess them. They return in Section 5, classified by which of Definition 2’s four points of purchase they operate at, which is a more useful thing to do with them than to list them here.
2.1 Rate, lag, and the control dilemma
The claim that institutions adapt more slowly than the material conditions they govern is a century old. Ogburn (1922) gave it a name and, more importantly, a structure: he distinguished material culture from the adaptive culture of customs, laws, and governments that must accommodate it, and located maladjustment in the interval between a change in one and the corresponding change in the other. Two features of his treatment matter here. The lag is a property of a rate difference, not of ignorance or bad faith. And Ogburn conceded that he could not identify the interval’s endpoints precisely — a limitation that has propagated to every subsequent attempt, including this framework’s.
Collingridge (1980) supplied the structure that dominates technology governance to this day. Early in a technology’s life, intervention is cheap but the need for it cannot be foreseen; later, the need is evident but the technology has become entrenched and intervention is costly. This is not one problem but two rates running in opposite directions — an information rate and an entrenchment rate — and the dilemma is that no choice of timing escapes both. Genus and Stirling (2018) argue that reflexivity and upstream engagement dissolve the difficulty. Section 3 does not accept that resolution, for a reason internal to this framework: it assumes that deliberative machinery can be stood up faster than the technology moves, which is precisely the assumption Definition 2 puts in question.
The pacing problem literature (Marchant, Allenby & Herkert 2011) generalized Collingridge’s observation into a claim about legal and ethical oversight across domains. It is a large and useful body of work, and it is almost entirely diagnostic. It names the gap and proposes soft-law palliatives; it does not model the gap, and it offers no account of the conditions under which the gap widens or narrows. That is the space Definition 2 and Proposition GP2 occupy.
The most substantial prior work is Perez (2002, 2007), whose model of technological revolutions distinguishes an installation period from a deployment period separated by a turning point at which the socio-institutional framework is recomposed. Three things recommend it to this series. It is explicitly a theory of rate mismatch, attributing the mismatch to inertial forces that make institutions more resistant to change than techno-economic structures. Its own vocabulary for the process is assimilation. And it delivers a conclusion this framework must confront rather than route around: in Perez’s history, institutional recomposition follows crisis instead of anticipating it. If that generalizes, the entire anticipatory program is misdirected, and the honest position is that Perez and the anticipatory-governance tradition (§2.8) advance contradictory empirical claims about the same object without engaging each other.
Allen (2009) supplies the closest thing to an empirical base rate. In the canonical case of the British industrial revolution, output per worker rose for roughly four decades while real wages did not — the interval now called Engels’ pause. Whatever else it shows, it establishes that the lag between a technology’s productive effect and its distributive effect can be measured in decades under weak governance, which is the order of magnitude against which claims about AI transition policy should be calibrated.
Two further strands feed Definition 2 directly. Cohen and Levinthal (1990) established absorptive capacity — an organization’s ability to recognize, assimilate, and apply new external knowledge, itself a function of prior related knowledge. Their central structural claim, that capacity to absorb is increasing in prior exposure, is the ancestor of the decoupling capacity construct in Definition 2 and of the absorption term already carried by the optimization companion. And the diffusion literature (Rogers 2003) supplies the adoption-rate machinery the series has used elsewhere, along with a distributional claim the diffusion tradition never developed: adopter categories are a statement about who absorbs change when, which is a governance question its authors did not treat as one.
What Section 3 takes. The rate framing of Definition 2 and Proposition GP2; the entrenchment mechanism behind the non-terminality argument in Definition 3; and the empirical order of magnitude for distributive lag. What it does not take. Perez’s crisis-driven mechanism is not adopted, but neither is it dismissed; it is carried forward as a live alternative to the framework’s own posture.
2.2 The requisite-variety tradition
One formal result stands apart from the rest of this survey because it is a theorem, not an observation. Ashby (1956) established that a regulator can absorb disturbance only to the extent that its own repertoire matches the variety of disturbances arriving: only variety can destroy variety. Applied to governance, this converts the familiar complaint that regulation is too slow into a bound. If the variety of what must be governed grows faster than the variety of the governing system, the shortfall cannot be closed by effort within the existing repertoire; it is structural.
Beer (1979) operationalized the result for organizations through the viable system model and, more usefully for this framework, through variety engineering: a regulator may either attenuate the variety arriving or amplify its own. Section 3 takes this distinction as one of its practical contributions, because the AI policy debate routinely conflates the two lever classes — moratoria, thresholds, and release restrictions on one side; evaluation capacity, expertise, and institutional density on the other — despite their having different costs, different failure modes, and different constituencies.
Deutsch (1963) supplies the third element: government understood as steering, a system of information flows, feedback, and lag, in which lag is a formal property of the control loop rather than a failure of it. The three together give Definition 5 its actual pedigree. The execution / observation / steering division is an actuate–sense–set-point decomposition drawn from this tradition, not the constitutional trio it superficially resembles, and Section 3 says so explicitly instead of borrowing an authority it cannot claim.
The tradition also supplies the framework’s sharpest self-criticism, developed in §2.7 below: a control architecture built for systems pursuing a single objective contains no function for resolving disputes about the objective, because in its original setting no such disputes arise.
2.3 Power as the object of governance
Definition 1 places the governed object at the level of the capacity to alter outcomes rather than at the level of artifacts. That is a claim about power, and the term cannot be left to do informal work in a paper titled for contestation.
The pluralist baseline treats power as prevailing in observable decisions over observable conflict (Dahl 1961). Most empirical work on AI governance operates at this level — which bill passed, which commitment was signed — and inherits its blind spots. Bachrach and Baratz (1962) identified the second: power exercised by confining decision-making to safe issues, so that some conflicts never reach a decision at all. This is the most under-used instrument in the AI governance literature and among the most applicable. The contest over whether the field’s proper object is catastrophic risk or present-day harm is an agenda-setting contest, and neither side’s victory would be visible in data on decisions taken. Lukes (1974/2005) added the third dimension: power that shapes perceptions and preferences so that the prevailing arrangement is accepted. That is the most direct available treatment of the question the optimization companion named and left open — who sets the objective — and it holds that the setting of the objective is itself the deepest exercise of power and the least visible in outcome data.
Two further conceptions bear on the AI case specifically. Foucault’s governmentality (1978/1991) describes power as the shaping of a field of possible action rather than as command, which is close to how deployed systems actually operate: through defaults, ranking, refusal behavior, and affordances, without a decision being taken anywhere. Zuboff (2019) reaches a structurally similar conclusion from political economy, naming a form of power that tunes and herds, not commands. Arendt (1970) supplies a corrective that matters for the framework’s actor apparatus: power as acting in concert is relational and constituted, not possessed, which is the right primitive if coalition formation is to be modelled as the creation of power rather than the summation of it.
Two consequences for Section 3 should be stated. First, under Foucauldian or Arendtian readings, power is not a property AGI possesses; it is a relation constituted among systems, users, and institutions, and possessive formulations should be avoided. Second, if capability admits no single scalar under Definition 0, neither does power: there is no quantity of it, and comparative claims about one force overcoming another are unavailable in this framework.
Two mechanisms complete the picture. Olson (1965) explains why concentrated interests organize and diffuse ones do not, which predicts the observed asymmetry between a dozen well-coordinated developers and several billion unorganized affected parties as a structural, not a moral fact. Stigler (1971) supplies the null hypothesis against which every co-design, voluntary commitment, and multistakeholder proposal in this domain must be tested.
2.4 Dual use, coupling, and the boundary
Definition 2’s central claim — that beneficial and damaging potential are coupled through a shared substrate and separable only at access, sequencing, distribution, and deployment — has three distinct antecedents.
The dual-use tradition, developed for materials, pathogens, and controlled technologies, is the direct ancestor and supplies the regime machinery: control lists, end-use and end-user conditions, and catch-all provisions (Wassenaar Arrangement 1996 and its predecessors). What the AI case adds is that dual-use assessment has historically been conducted per artifact, and a general capacity defeats per-artifact assessment. This is not a refinement of the older problem but a change in its type.
The coupling vocabulary comes from safety science. Perrow (1984/1999) distinguishes interactive complexity, which generates unanticipated interactions, from tight coupling, which propagates them before intervention is possible, and argues that systems high on both will produce accidents as a normal consequence of their structure. Definition 2 borrows the term deliberately and uses it in an adjacent sense — coupling between two evaluative aspects of one capability rather than between components — and the borrowing should be marked in the text so that a reader familiar with Perrow is not misled.
The separability claim has its own literature, and it is what makes governance possible at all under Definition 2. Differential technological development (Bostrom 2019) holds that the order of arrival is a governance variable even where arrival itself is not, and is therefore a sequencing instrument. Structured access (Shevlane 2022) holds that controlled, mediated availability occupies a genuine third position between open release and closure, and is an access instrument. Both are claims that the ratio between beneficial and damaging realization is manipulable, which is why Definition 2 asserts inseparability within the capability and only partial separability outside it. A framework that asserted strict inseparability would render the entire safety enterprise pointless by definition, which is too strong a conclusion to reach by stipulation.
Finally, Definition 1’s refusal to treat benefit and harm as commensurable rests on two older results. Knight (1921) separates measurable risk from unmeasurable uncertainty, and much of the AI risk debate is conducted in the vocabulary of the former about objects belonging to the latter — which is why probability estimates in this domain do not converge. And the argument for treating catastrophic outcomes as a constraint rather than as a term follows from non-ergodicity: an expectation taken over paths one does not survive is not a decision-relevant quantity (Taleb 2007). The optimization companion adopted this position at its §4.6, and Section 3 inherits it unchanged.
2.5 Governance without a sovereign
Definition 3 defines governance without a canonical objective, without an aggregation rule, and without a terminal state. Each is a departure from ordinary usage, and each has support.
The impossibility of aggregation is formal. Arrow (1951) established that no rule satisfying a set of reasonable conditions aggregates individual orderings into a social ordering. The optimization companion’s finding that no aggregation rule is available in this domain should be grounded in that result, not asserted independently, both because it is stronger that way and because it forecloses the objection that the earlier paper simply failed to look. It also has a consequence the framework must own: democratic procedure is itself an aggregation rule, and is therefore among the things Arrow constrains rather than an escape from him. This is why Section 3 grounds participation in detection rather than in authorization.
That governance can exist without a governor is the settled position of regime theory. Krasner (1983) defines regimes as sets of principles, norms, rules, and decision-making procedures around which actor expectations converge in an issue area — a definition that requires no body with binding power. This matters for the framework’s inheritance from the optimization companion: the finding there is that no actor solves the joint problem, and it must not be read as the claim that no governance exists.
The logical status of that inheritance should also be settled, since this paper leans on it repeatedly. Two claims are involved and they differ in kind. That no rule aggregates divergent objectives into a single ordering is formal, following from the social-choice result above; it is not an observation about the present and would not be repaired by better institutions. That no actor currently occupies the position of a solver is empirical, established by the companion paper’s cases, not derived, and it would be refuted by exhibiting one. This framework takes the first as a constraint on what any architecture could achieve and the second as a description of the arrangement it diagnoses. Neither is asked to do the other’s work. Keohane and Victor (2011), following Raustiala and Victor (2004), supply the more precise description of what does exist: a regime complex, an array of partially overlapping, non-hierarchical institutions governing one issue area. The associated findings are directly applicable — such complexes gain flexibility and experimentation and lose coherence, develop gaps between mandates, and exhibit a bias toward larger and better-resourced actors. Haas (1992) supplies the mechanism by which technical consensus becomes policy in the absence of an authority ordering it, which describes the AI safety research community’s influence and its limits with unusual accuracy.
Where a canonical objective is unavailable, evaluation must be procedural, and three sources supply criteria that do not require agreement on ends. Scharpf (1999) distinguishes input legitimacy, deriving from the participation of the governed, from output legitimacy, deriving from defensible results for them; the distinction is more precise and more actionable than calling an arrangement undemocratic, and it identifies almost the whole current AI regime as output-legitimate at best. Kingsbury, Krisch and Stewart (2005) supply transparency, participation, reasoned decision, and review as accountability requirements for exactly the kind of transnational technical body the AI regime keeps producing. And Popper (1945) supplies the criterion Section 3 leans on most heavily: judge an institution by whether it can detect and correct its errors, not by whether it is right — the appropriate standard when no one can be confident of being right.
One further body of work bears directly on what those procedural criteria can and cannot settle, and it is older than the AI debate by half a century. Fuller (1978) analyses adjudication as a distinct social process whose defining feature is that the affected party participates by presenting proofs and reasoned argument. He argues that one class of problems is intrinsically unsuited to it: problems he calls polycentric, in which many centres interact so that each adjustment redistributes tensions across all the others. For these, no determination of right can be reached by hearing the parties to any one of them. Fuller’s conclusion is that adjudication handles claims of entitlement well and the allocation of interacting outcomes badly, and that attempts to adjudicate the second either fail or quietly convert into something else — managerial direction, or negotiation conducted in adjudicative form.
Two things follow for this framework. The first is that its distinction between what can and cannot be settled by an adjudicative function is not an invention of the AI case; it is a long-standing result in the theory of legal institutions, and Section 4’s proposition on the point should be read as applying that result instead of discovering it. The second is a connection worth marking, because the shared vocabulary is not a coincidence: Fuller’s polycentric and the polycentricity of §2.6 descend from the same source in Michael Polanyi, and they say complementary instead of competing things. Polycentric problems can be governed without a single centre; they cannot be adjudicated by a single forum. A framework that takes both seriously will expect governance to be distributed and settlement to be procedural, which is what Definitions 3 and 5 jointly describe.
Rittel and Webber (1973) anticipate the non-terminality claim by three decades. Wicked problems have no definitive formulation, no stopping rule, and solutions that are better or worse rather than true or false. Their treatment predates and generalizes much of what the AI governance literature has since rediscovered, and it is compatible with this series’ rejection of single-scalar evaluation.
2.6 Polycentricity: a different object of analysis
One body of work is frequently read as standing against this framework, and the relationship is more interesting than opposition.
Ostrom (1990) established, across a large body of field cases, that common-pool resources are frequently governed successfully by neither markets nor states but by self-organized institutions, and derived eight design principles characterizing the robust ones: clearly defined boundaries; congruence with local conditions; collective-choice arrangements; monitoring by parties accountable to users; graduated sanctions; low-cost conflict resolution; recognized rights to organize; and nested enterprises. The polycentric tradition that follows from it (V. Ostrom, Tiebout & Warren 1961; E. Ostrom 2010) holds that multiple centres of semi-autonomous decision-making, formally independent and functionally interdependent, can outperform monocentric arrangements — and that the absence of a single decision centre is therefore not by itself a failure.
It is tempting to treat this as a refutation of the framework’s inheritance from the optimization companion — if the absence of a single decision centre is not a failure, the no-meta-actor finding loses its sting. That reading mistakes a difference of object for a disagreement about answers.
The two bodies of work take different things as given. The commons literature begins with a resource that exists: a fishery, a pasture, an aquifer. Its question is how use is governed, by whom, and with what durability. This framework’s central question includes something the commons literature has no occasion to ask — whether a capability comes into existence at all, and in what order. Ostrom’s design principles are answers to a question about use. They are not answers to a question about existence, and they were never offered as such.
Difference of focus is not the same as absence of disagreement, and one point of genuine divergence remains, stated below. But the framework’s posture toward polycentric governance is coexistence, not supersession, and that posture is not diplomatic. It is required by Definition 3: a claim that this framework supersedes another would need a rule adjudicating between competing governance arrangements, and the paper’s central argument is that no such rule exists. A framework that declared other models wrong would be occupying the meta-actor position it spends its length denying.
Section 3 should not be read as having settled the substantive question that does divide them. The defensible version of this series’ position is narrower than the one it has previously stated: polycentric arrangements succeed under conditions — slow-moving resources, stable boundaries, repeated interaction among identifiable parties, and monitoring by those with a stake in the resource — and the AI case appears to violate several simultaneously. That is a checkable claim, and the natural test is to score the current regime against Ostrom’s eight principles rather than to argue the point abstractly. The framework’s actual objection is structural, not a claim about scale, and it follows from Definition 1’s two levels. In the documented commons cases the potential is local: each fishery, pasture or irrigation system is its own resource, so a local rule can be congruent with local conditions, and the appropriators who set it are the parties who bear its degradation. A general capability is not like this. Its potential is created once and is thereafter everywhere; only its realizations are local. Polycentric arrangements can therefore govern at the realization layer — deployment context, access conditions and distribution are genuinely local questions, and the design principles apply to them with force. What they cannot govern is whether the potential exists at all. Once a capability is created and distributed, no local centre can withdraw it: local centres regulate deployment, not existence. The claim this paper makes against polycentricity is confined to that layer, and it concerns which questions can be settled locally rather than how large the arrangement is.
One qualification makes the claim more precise and less exposed. What cannot be governed locally is a potential that is non-rival and non-excludable — published weights, once distributed, are held by everyone who wants them and withheld from no one, and no local centre can recall them. Potentials that remain rival and excludable are a different matter: frontier-scale compute, proprietary data, and concentrated expertise are held by identifiable parties, can be denied to others, and are therefore governable by centres with jurisdiction over the holders. The commons literature’s own cases are of the second kind — a fishery is rival and partly excludable, which is precisely why its design principles work there. So the framework’s claim against potential-layer polycentricity is not general: it holds where a capability has become non-rival and non-excludable, and does not hold while the inputs to that capability remain concentrated. Which condition obtains is an empirical question about a given capability at a given time, not a property of AI as such.
Two consequences follow, and they point in opposite directions. Over most of the governance surface the two are complementary instead of competing, and nothing here argues that polycentric arrangements should be replaced where they work — the realization layer is precisely where they have been shown to work, and this framework’s Definitions 4 and 5 are closer to that tradition than to any centralizing alternative. But the layer this paper is principally concerned with — whether a capability comes into existence, and in what order — is the layer at which local settlement is unavailable in principle rather than merely absent in practice. That is the divergence, and it is narrow: it concerns one layer, not the tradition.
One qualification the argument requires. The account above speaks as though a potential arrives at a moment. It frequently does not. Capability accretes — through incremental training, open-weight fine-tuning, distributed compute, and the diffusion of methods across a global developer population — so the potential layer is a process, not an event, and its boundary with the realization layer is less crisp than the contrast implies. The qualification does not reverse the argument’s direction, and arguably sharpens it: where a potential accretes from many contributions none of which is individually decisive, no local centre’s restraint prevents it, which is the collective-action structure at its least favourable, not its most. What the qualification does change is the shape of any remedy, since an instrument aimed at a moment of creation has no moment to attach to. Section 1.3 states the related scope condition — that the framework’s handles require identifiable producers — and §6.5 records what follows where they are absent.
What would count as a genuine test. Scoring the present arrangement against the design principles, as §5.4 does, cannot settle the question: failing them shows that the current regime is not a well-functioning polycentric arrangement, which is a different and weaker claim than that polycentric governance is unavailable for this case. A genuine test asks instead whether an arrangement satisfying the principles could be constructed at the potential layer — whether boundaries could be defined, monitoring made accountable to those affected, and sanctions graduated, for a resource that exists everywhere the moment it exists anywhere. The argument above says it could not, for reasons that have nothing to do with the present regime’s failings. That argument is where the framework’s position stands or falls, and it is not established by the scoring. Section 3 records the question as open, and this paper does not close it. The position taken here is provisional in the strict sense: it is held pending the test just described, and a finding that the AI case does satisfy Ostrom’s conditions would require the framework’s central conclusion to be narrowed, not merely qualified.
Three of the design principles feed Definition 5 directly regardless of how that question resolves: monitoring by parties accountable to those affected, graduated sanctions, and low-cost conflict resolution. The last two identify precisely the functions Section 3 finds missing from its three-pillar structure.
2.7 Participation and its limits
Definition 4 grounds standing in affectedness and denies that governance quality is monotone in participant count. Both positions require support against more intuitive alternatives.
Dahl (1971) is the natural entry point, and supplies this paper’s title term. Polyarchy is characterized along two dimensions — contestation and participation — and the framework’s two imports from the democratic tradition map onto them exactly: Definition 4 is participation, and the paper’s central mechanism is contestation. The pairing is not a coincidence to be noted in passing; it is the reason the title term is a term of art, not a coinage.
A second body of work uses this paper’s title term in the same domain, and needs disambiguating rather than merely citing. Since roughly 2019, scholars in human–computer interaction, design research and public law have developed contestability as a design principle for AI systems: the property of a system that lets an affected individual challenge, and possibly reverse, a particular automated decision about them (Almada 2019; Lyons et al. 2021; Alfrink et al. 2022; Henin & Le Métayer 2022). It has legal anchors — the right under GDPR Article 22 to obtain human intervention and contest a decision, and the right under AI Act Article 86 to an explanation of individual decision-making — and a developed apparatus, including Kaminski and Urban’s (2021) four archetypes separating contestation rules from contestation standards and procedural from substantive contestation, and Lyons et al.’s specification that a contestation regime must fix what may be contested, who may contest, who is accountable, and what form of review applies.
That work and this paper use one word at two levels, and the difference matters. Their contestability is a property of a system: whether a person subject to an automated decision can challenge that decision. The contestability defined at §3.4 is a property of a governance arrangement: the degree to which the arrangement permits challenge to itself and gives that challenge effect. In this framework’s own terms, system-level contestability is a feature of a handle and an instrument operating at the deployment-context point of purchase — so the framework classifies it rather than competing with it, and the two are complementary at different scales.
Two contributions from that literature bear directly on definitions stated below. Almada’s predictive contestability — contesting the design choices made before a system exists — is contestation at the level of potential, while the ex post work addresses the level of realization; the two-level structure of Definition 1 is already visible in that split. And a practice-theoretical extension of the same literature (Hirsbrunner et al. 2025) identifies the refusal to build or procure a system at all as a mode of contestation that system-centred frameworks cannot represent, which is this paper’s attenuation lever arrived at from organizational practice rather than from the variety argument.
One tradition converges on this paper’s central claim from a different direction and should be marked, because a reader in political theory will reach for it immediately. Mouffe’s agonistic pluralism (2000, 2005) holds that conflict is constitutive of democratic politics rather than a failure of it, that the deliberative aspiration to rational consensus is misconceived, and that what settles is never the disagreement itself but a temporary hegemonic stabilization. The conclusion is close to this framework’s: contest is permanent, and treating it as a transitional nuisance mistakes the mechanism for the malfunction.
The derivations differ, and so does one substantive commitment. Mouffe argues from the constitution of the political and the affective bonds that hold adversaries in a shared arena; this framework argues from the unavailability of an aggregation rule, which holds whether or not the parties recognize each other’s standing. That difference matters at the point where Mouffe requires most: agonism, on her account, depends on adversaries accepting a common symbolic space and the legitimacy of their opponents, without which antagonism rather than agonism results. This framework asks for no such allegiance, because its claim is structural rather than dispositional — contestation persists under mutual non-recognition, and Section 5 describes an arrangement in which it does. The convergence is therefore real and the two accounts are not interchangeable: Mouffe supplies a normative account of how conflict should be conducted, and this paper a structural account of why it cannot be concluded.
The case against monotone participation is formal and empirical. Buchanan and Tullock (1962) model the choice of a decision rule as a trade-off between decision costs, which rise with the number of participants required to agree, and the external costs borne by those excluded from decisions, which fall. The optimum is interior; unanimity is not it. Their two-level distinction between constitutional rules and in-period choices is separately relevant, and is the cleanest treatment in this survey of the regress the optimization companion left open: the choice of whose objective counts is settled at the constitutional level, under uncertainty about one’s in-period position, rather than in-period.
The empirical record points the same way. The documented expansion of deliberative practice (OECD 2020, 2021) works through mini-publics — small, randomly selected, well-informed bodies — and attributes their performance to representativeness and deliberative quality rather than to scale. Landemore (2020) argues for lottocratic representation on grounds of cognitive diversity, which is a claim about the composition of a body, not its size. The classical aggregation results require independence among participants and better-than-chance competence; correlated information environments break the first, and there is reason to think widespread AI mediation of information worsens the correlation.
A distinction that headcount arguments elide is documented in the same literature. Deliberative bodies convened without authority to compel a response produce what has been characterized as weak representation: participation without binding power. In the optimization companion’s terms such a body has binding power at or near zero, and Section 3 must not treat the addition of participants as equivalent to the distribution of power.
Finally, the provenance argument. That AI capabilities derive from broadly digitized human output is largely true and supports a claim on benefits; it does not support a claim to governing standing, because contribution-based standing is proportional by nature and would license weighting by volume of contribution. The provenance argument also flattens a distinction currently under litigation, between material contributed and material taken, and the extractive reading of AI’s material and informational supply chain (Crawford 2021) is a reminder that a governance survey confined to model behavior has chosen a scope, not found one.
2.8 Separation, independence, and the observation function
Definition 5’s separation of execution, observation, and steering, and Proposition GP4’s claim that these are currently concentrated, draw on four distinct literatures.
Constitutional practice, with a caveat. The functional division of authority with mutual checking is a durable design pattern (Montesquieu 1748; Madison 1788), and Madison’s formulation that ambition must be made to counteract ambition is the classical statement of why friction is a feature, not a defect. The caveat is that the tripartite form is one design among several — parliamentary systems fuse executive and legislature and are durable; several constitutional orders operate more than three branches; independent audit institutions, ombudsmen, and central banks constitute a substantial further layer — and there is no finding that three is a stability optimum. Section 3 accordingly claims the pattern and not the number.
Corporate assurance. The three-lines model imported into AI governance from corporate risk management (Schuett 2024) is the closest institutional analogue to Definition 5’s trio: risk ownership, oversight, and independent assurance. Its relevance is that it is a non-democratic instantiation of the same functional separation, which supports Section 3’s position that separation is a control-architecture requirement, not a democratic commitment.
Independent investigation. Aviation supplies the best-performing safety regime in industrial history, and its core mechanism is institutionalized learning from outcomes: separation of investigation from prosecution, mandatory occurrence reporting, protected confidential near-miss reporting, and the just-culture principle that separates accountability from blame (ICAO Annex 13; NASA ASRS; Dekker 2007). Two features bear directly on Definition 5. The investigating body has no operational role and no commercial relationship with those it investigates — the audit-independence criterion in its most developed form. And it observes outcomes, not the capability of aircraft. AI evaluation observes capability almost exclusively, which is why the aviation analogy is invoked constantly and delivers little: the analogy fails at the point where it would be most useful.
Regulatory design. Ayres and Braithwaite (1992) supply the enforcement pyramid, escalating from persuasion at the base to licence revocation at the apex, and thereby the sanction machinery whose absence Section 3 identifies. Coglianese and Lazer (2003) supply the category into which frontier safety frameworks and scaling policies actually fall — management-based regulation, which regulates the planning process rather than the technology or the outcome — together with the conditions under which it works: heterogeneous and unobservable outcomes, and a regulator still able to audit the process. The second condition is not currently met.
Two cautions belong here. Power (1997) documents the tendency of audit regimes to displace the activity they monitor and to substitute rituals of verification for the trust they were meant to replace; a compliance-and-audit AI regime should be expected to produce this, not merely warned against it. And Stigler (1971), together with the revolving-door literature, identifies the failure mode that a rotational reading of role separation would introduce, which is why Definition 5 specifies structural and permanent separation instead.
Two further literatures bear on what an observation function must be composed of, as distinct from what it must do.
The first concerns layered defences. Reason (1997) models organizational accident prevention as a series of imperfect barriers, each with gaps, and locates the mechanism of failure not in the existence of gaps but in their alignment: an accident occurs when the openings in successive layers line up. The design implication is easily stated and routinely missed — what makes layering work is not the number of layers but the independence of their failure modes. Redundancy among components that fail for the same reasons buys very little.
The second concerns correlation as a systemic property. Financial regulation distinguishes microprudential supervision, which examines each institution against its own risk of failure, from macroprudential supervision, which examines exposures that are correlated across institutions and dynamics that are self-reinforcing across the system (Basel Committee 2018; Minsky 1986). The distinction was built because institution-by-institution soundness turned out to be compatible with system-level fragility whenever institutions held correlated positions. Applied to AI governance the observation is uncomfortable and, so far as this survey has found, made in only one recent treatment: the entire frontier instrument set — capability evaluations, scaling policies, model-level safety frameworks — is microprudential, while the developers are correlated by architecture, training corpora, benchmark suites, and the professional population they recruit from. Correlated construction implies correlated blind spots, and an evaluator drawn from the same population inherits them. That is the prior-art basis for the requirement in Definition 5 that independence extend to provenance and not only to function, and for the corresponding proposition in Section 4.
Turner (1978) supplies the failure mode that observation exists to catch, and does so before Perrow: disasters are preceded by an incubation period in which discrepant events accumulate unnoticed, so that harm accrues faster than the organization’s capacity to register it. Incubation is a rate concept, and it identifies what an observation function is for — and, in its negative form, what any incident-triggered method will miss.
Finally, Beck (1992, 1995) names the condition that separation is meant to remedy. Organized irresponsibility describes institutions that coexist with responsibility and impunity simultaneously: every party is a co-producer of the outcome and none is accountable for it. This is the optimization companion’s central finding stated sociologically and four decades earlier, and Definition 5’s contribution should be framed against it — separation converts diffuse co-production into assignable role responsibility, which is precisely the transformation Beck argues modern institutions fail to make.
2.9 Anticipation, resilience, and the rate of correction
Section 3’s reconciliation of participation and separation with the rate problem turns on distinguishing decision rate from correction rate. That distinction has a literature, and its most forceful contributor argues against this framework’s posture.
Wildavsky (1988) contrasts anticipation — control exercised centrally, in advance, against specified dangers — with resilience, the capacity to cope with dangers once they manifest, and argues that trial-and-error learning generally outperforms prevention, that safety measures frequently reduce safety, and that a society which forecloses risk-taking forecloses learning. Any paper arguing for anticipatory governance owes him an answer, and the AI governance literature has not given one. The answer available to this framework is Wildavsky’s own carve-out: he concedes that anticipation is appropriate where potential harm is large-scale and irreversible, which is exactly the boundary this series already treats as a constraint rather than as a term. Making that argument explicitly strengthens the framework’s existing position instead of complicating it, and it is why Section 3 emphasizes correction rate over decision rate everywhere except at the boundary.
The resilience tradition in ecology supplies the rest. Holling (1973) distinguishes resilience, the persistence of relationships under disturbance, from stability, the return to an equilibrium — a distinction this series needs, since its stated position on reversibility is not about restoration. Gunderson and Holling (2002) develop the adaptive cycle and the nested cross-scale structure of panarchy, in which the release phase is not a return to a prior state but the readying of a system for reorganization at a new configuration. The correspondence with this series’ recorded understanding of reversibility is close enough that it should be cited, not independently rediscovered. Folke and colleagues (2005) synthesize this tradition with Ostrom’s polycentricity into adaptive governance, which is the nearest thing in the literature to a general theory of governing systems that change faster than rules do.
Holling and Meffe (1996) supply the deepest objection to any design that governs by suppressing variance: successful short-term control reduces variability, variability erodes, and the system becomes vulnerable to larger failures. Combined with the measurement literature — the collapse of a statistical regularity once it is used for control (Goodhart 1975), the corruption of any indicator used for decision-making (Campbell 1979), and the displacement documented by Power (1997) — there is a coherent case that a measurement-and-compliance AI regime will produce the appearance of safety and the substance of fragility. This survey did not identify a place where the case has been assembled. Assembling it is not a counsel of despair; it is the argument for outcome observation and correction capacity over threshold compliance, which is the direction Definition 5 takes.
Two design traditions offer the operational form. Experimentalist governance (Sabel & Zeitlin 2008) describes a recursive architecture — framework goals, local discretion, reporting, peer review, revision of the goals — that moves revision out of the legislature and thereby raises correction rate without raising decision rate. And the instrument literature on sandboxes, sunset clauses, and experimental legislation (Ranchordás 2014; OECD 2024) supplies the concrete devices.
The trade-off these devices incur was not found named in either literature, and Section 3 states it: every instrument that raises revision rate degrades constancy through time, which is one of the requirements a legal system must satisfy to count as one (Fuller 1964). Governance responsiveness and rule-of-law legitimacy sit on a frontier, and the pacing problem forces a choice along it.
2.10 The current regime, and what it demonstrates
Proposition GP4 is a claim about the present, and requires a description of it. Four features of the regime as of mid-2026 bear on Section 3.
Binding obligation is thickening, and remains unevenly located. The European Union’s Artificial Intelligence Act remains the only comprehensive horizontal statute, and its implementation timetable was formally deferred in 2026 after national competent authorities went undesignated and harmonised standards went unfinished. The deferral is worth more to this framework than the statute. It was not a case of technology outrunning law; it was a case of law outrunning the administrative capacity to implement it — which is a distinct failure mode from the control dilemma, and the cleanest available empirical instance of a decoupling capacity constraint in the sense of Definition 2. The Act’s own obligation to establish regulatory sandboxes was among the provisions postponed, which is the pacing problem consuming its own remedy.
In the United States, binding private-sector obligation currently sits at state, not federal level, while the federal layer operates through executive instruments and voluntary frameworks. The resulting churn — several major federal instruments within eighteen months, none of them statute — illustrates the frontier named in §2.9 with unusual clarity: maximum responsiveness, minimum constancy.
International architecture is bifurcating. Two intergovernmental bodies with overlapping ambitions were constituted within a fortnight of each other in July 2026, on different political foundations. Independently, a scientific assessment panel now operates on the model established by climate assessment: expert, periodic, and deliberately non-prescriptive. That design choice reproduces the separation of risk assessment from risk management that United States practice adopted in 1983 and substantially retracted in 1996, on the finding that the separation could not be sustained where the questions were value-laden. The repetition is not noted anywhere in the current literature.
Legitimacy and binding power are inversely distributed. The body with the widest membership and the strongest claim to representativeness has effectively no capacity to bind; the actors with binding power have no representative mandate. In the optimization companion’s terms this is a structural finding rather than an observation about political will.
And the pillars are concentrated. Frontier developers author the safety frameworks and scaling policies that set the thresholds, conduct the evaluations that determine whether the thresholds are met, and build and deploy the systems being evaluated. State evaluation bodies have been established in several jurisdictions and are the nearest existing approximation to an independent observer, but they depend substantially on developer cooperation for access, and at least one has undergone a mandate shift away from safety assessment. Proposition GP4 is a description of this configuration, and it is verifiable against public documents.
2.11 What the literature does not supply
Four gaps motivate Section 3, and each corresponds to a definition or proposition stated there.
No treatment of governance response rate as a variable. The pacing literature diagnoses the gap and stops. The adaptive and anticipatory traditions prescribe remedies without asking whether the remedies are fast enough. Perez models rate at fifty-year granularity and without a governance objective. Requisite variety supplies a bound that this survey did not find applied to this domain. Definition 2 and Proposition GP2 occupy this space.
No formulation of the object of governance above the artifact. The field’s instruments, and therefore its analytical categories, attach to models, firms, and applications. The distinction between what instruments grip and what governance is for is, to our knowledge, not drawn systematically, and consequently the systematic mismatch between them is treated as a series of implementation failures rather than as a structural property. Definition 1 draws it.
No account of governance under a direction that cannot be adjudicated. Governance is almost universally defined teleologically, by reference to goals it pursues, and the critical literature responds by denying that shared goals exist. Neither position fits the case here. A direction is available — the series posits one, functioning as a regulative ideal — while no rule converts it into an in-period verdict on particular arrangements. The literature treats these as the same condition and they are not: the first is a claim about ends, the second about adjudication, and the procedural alternatives exist as scattered legitimacy criteria rather than as a definition built for that gap. Definition 3 supplies one and accepts the cost — that it names no operational success condition — as a finding. Fuller’s analysis of what adjudication can settle, discussed at §2.5, is the closest existing treatment, and it is a theory of legal process rather than of governance under technological change.
No separation criterion applied to this domain, and no treatment of correlated observation. Audit independence, functional separation, and the distinction between self-generated and independently verified evidence are mature in finance, aviation, nuclear safety, and corporate assurance. None has been applied systematically to frontier AI, and the one structural feature that would be most visible under such an application — that the same participants occupy all three functions — has received comparatively little attention as a finding in its own right. Definition 5 and Proposition GP4 state it.
A second, subtler absence sits inside the first. The separation literatures were built for domains in which organizational independence implies independent judgement, because the observers were differently trained, differently equipped, and differently constituted from the observed. That implication does not hold where every party draws on the same architectures, corpora and professional population. The correlated-risk literature has the concepts (§2.8) and this survey did not find them applied here; the separation literature has the institutional forms and does not contain the concept. Proposition GP7 occupies the gap between them.
A fifth observation is not a gap but a convergence, and it deserves acknowledgment rather than a claim of novelty. The arrangement Definitions 3 through 5 describe — distributed participation, separated function, no central solver, procedural evaluation, no terminal state — is recognizably polycentric. This framework arrives at it from a rate argument rather than from the study of common-pool resources, and the two routes reaching the same structure is evidence about the structure rather than about either route. What this framework claims to add is the rate condition under which the structure is insufficient. Whether that claim survives contact with Ostrom’s own conditions is the open question recorded at §3.8. The framework’s position on it is provisional: this paper holds that the AI case violates several of Ostrom’s conditions at once, states that as a claim, not a demonstration, and does not treat the matter as settled for the series.
3 Conceptual Foundation
3.0 What this section is, and what logical type it has
This framework is not a theory of optimal governance. It is an account of why governance remains contested even under a shared direction — because a persistent objective supplies direction without supplying an operational criterion, and no rule aggregates local objectives into one. Everything below follows from taking that condition seriously instead of treating it as a defect to be engineered away.
This section states six definitions. Section 4 states seven propositions. The distinction between the two types is not decorative, and it matters for how the rest of the paper can be read.
It also discharges a commitment made in print by the Optimization framework paper. That paper defines Shared Stewardship as the distributed responsibility through which heterogeneous participants advance a persistent Global Objective, and states plainly that the definition does not by itself guard against capture by the most powerful participants — leaving the question of what safeguard would prevent this, procedural, structural or institutional, as an open design question for the framework’s governance layer. Its Limitations name two further questions as genuinely unaddressed rather than deferred: legitimacy, consent and power asymmetry among stakeholders with unequal capacity to shape the Global Objective, and how value pluralism is to be reconciled within Shared Stewardship. Definitions 3 through 5 below are this paper’s answer to those questions.
The definitions are stipulative. They fix what this series means by its central terms and what it takes the object of governance to be. They are not claims about the world and cannot be falsified; they can only be judged on whether they are coherent, whether they are used consistently, and whether they carve the problem at a joint that turns out to be productive. Definitions 0 through 5 below are of this type. Definition 0 in particular applies to the entire Gradual AGI series, not only to this installment, and it is stated here in its settled form for the first time.
The propositions of Section 4 are of a different type. They assert something about the world, they are stated so as to be arguable, and where they can be operationalized they are meant to be tested. They stand or fall on evidence, not on stipulation. They are placed in their own section rather than appended here precisely because the two types should not be read as one list.
The series has previously kept these two types apart without saying so. The Optimization framework paper’s five Propositions are falsifiable claims; the definitions on which they rest were left implicit. Stating the definitions explicitly does two things: it removes an ambiguity that has cost the series time in review, and it makes visible where the framework’s commitments are decisions, not discoveries.
The definitions are not peers. They fall into two layers, and reading them as a flat list obscures the dependency between them. Definitions 0 to 2 are foundational: they fix what AGI is taken to be, what is being governed, and how the governed object behaves. Definitions 3 to 5 are architectural: they fix what governance is, who has standing in it, and how it is structured. The second layer presupposes the first and would have to be rebuilt if the first changed. Definition 2 straddles the two, since it states a dynamic rather than only fixing a referent, and the empirical content it carries is drawn out separately as Proposition GP1 rather than left inside the definition.
A note on numbering. The Optimization framework paper owns Propositions 1 through 5. To avoid two live numbering schemes within one series, the propositions introduced in Section 4 are labelled GP1 through GP7. Where this paper cites the earlier scheme, it does so with the paper named.
A third type appears once. Section 3.6 below closes with three design corollaries — conditional prescriptions of the form if the propositions hold, institutional design should have this property. They are neither stipulative nor falsifiable as they stand: they inherit whatever support the propositions have, and are offered for adoption or rejection on design grounds, not evidential ones. They are marked where they appear. This paper carries them because the Optimization framework paper asked for them; a governance layer that answered only in definitions would not discharge that request.
A note on naming. Three companion works are cited throughout. The Optimization framework paper is “Gradual AGI as Optimization: A Conceptual Framework”; the Optimization models paper is “Gradual AGI as Optimization: Formal Models and Empirical Tests”; the CFS paper is “Ceiling, Floor, and Slope: A Falsifiable Dynamical Model of Synchronization for Gradual AGI.” The forthcoming empirical and formal installment of the present pair is the companion installment. No bare “companion paper” is used in the singular, since four works would answer to it.
3.1 Definition 0 — AGI
Definition 0 (stipulative; series-wide). AGI denotes artificial intelligence whose capability profile matches or exceeds the best human capability attainable, across the domains in which humans exercise intelligence. The reference class is the unaugmented human envelope. Because this series does not evaluate capability on a single scalar, “matches or exceeds” is a partial order — the assumption already adopted by the Optimization framework paper, which restricts itself to a partial ordering over trajectories and treats the resulting incomparability as a faithful representation of the problem rather than a gap to be closed: AGI names not a dated event but an expanding region — the set of domains on which the human envelope is no longer dominant. The definition subsumes what is elsewhere divided into AGI and ASI. It carries no upper bound, and therefore no state of affairs constitutes “having achieved AGI.”
Four commitments follow, and each is a choice that could have been made otherwise.
(i) The AGI/ASI distinction is not load-bearing. The literature commonly separates artificial general intelligence from artificial superintelligence at a threshold that has never been operationalized. This series treats the boundary as unavailable, not merely unmeasured, and declines to build on it. There is a cost to this, and it should be stated rather than left to inference: a substantial body of safety argument is indexed specifically to the transition from human-level to superhuman capability — recursive self-improvement, decisive strategic advantage, and the discontinuity arguments that depend on them. Under Definition 0 those arguments are not discarded. They are re-sited as claims about a region of an open-ended continuum rather than about a phase change at a point. Whether they survive that relocation is a question this paper does not settle.
(ii) The reference class is the unaugmented human envelope. “The best intelligence humans possess” is not a fixed benchmark if humans are themselves being augmented by the systems under comparison. Taking the augmented envelope as the reference would make the threshold recede as capability rises, and AGI would become unreachable by construction. Taking a benchmark fixed at a stated date would be operational but would go stale. This series takes the unaugmented envelope, which is approximately stable on the relevant timescale, and treats augmentation as a separate phenomenon analyzed elsewhere in the series under epistemic extension. The choice is not innocent — it quarantines a real effect in order to keep a comparison well-defined — and it is stated here so that the quarantine is visible.
(iii) “The best human capability attainable” means the per-domain maximum across humans, not the capability of any single individual and not the collective capacity of institutions and accumulated science. The per-domain maximum is an envelope that no human achieves, since no person is simultaneously the best mathematician, the best clinician, and the best negotiator. This reading is already superhuman relative to any individual, which is part of why the AGI/ASI split does little work.
(iv) Generality is carried by the reference class, not by a separate condition. Definition 0 specifies a threshold on level and states no independent condition on breadth, which invites the objection that the “G” in AGI is idle. The answer is that human intelligence is characterized by breadth: matching the best of it across the domains in which humans exercise intelligence includes matching its capacity to transfer and to operate in novel conditions. This is an argument, not a stipulation, and it is offered here so that it can be contested.
One clarification about the partial order. The commitment is epistemic, not ontological. This framework does not claim that capability is inherently and irreducibly multidimensional; it claims that no rule aggregating the dimensions is available, and that treating capability as scalar in the absence of one imports a comparison nobody can defend. The distinction matters because it says what would change. Were a defensible aggregation rule to be established — over capability, and separately over outcomes — Definition 3’s central claim would fall with it, and most of what this paper builds on that claim would fall too. The framework is therefore hostage to a discovery it does not expect and cannot rule out, which is a better position than one that could not be dislodged at all.
What Definition 0 does not assert. It does not assert that AGI arrives gradually. “Matches and exceeds, without an upper bound” describes an unbounded region on a capability scale; it says nothing about the rate at which that region is traversed. A discontinuous capability jump satisfies the definition exactly as well as a slow ascent does. Open-endedness and gradualness are independent claims, and conflating them would smuggle this series’ central thesis into a premise where it could not be argued with.
Gradualness is derived, not assumed. Its derivation runs through the partial-order structure. Because capability is multidimensional and no canonical rule aggregates the dimensions into a scalar, there is no moment at which a system crosses a single line. There is only a progressive expansion of the set of domains on which the human envelope ceases to be dominant, domain by domain, at rates that differ by domain. That is why AGI is gradual: not because capability grows smoothly, but because the object being tracked is a region that can only expand piecewise. The claim is compatible with punctuated shifts on any individual dimension, which matters, since the Optimization framework paper’s Proposition 2 explicitly admits punctuated as well as drifting change and this framework must not contradict it.
Accordingly, “gradual” as used of the phenomenon means extended and structured — non-instantaneous, unfolding piecewise over time. It does not mean smooth, and it does not mean free of jumps.
One distinction must be held firmly here, because the series uses one root word for two things. Gradual, as just defined, describes the phenomenon: AGI arrives as an expanding region rather than at a moment. Graduality, as defined by the Optimization framework paper, is a principle — an adaptive process of iterative refinement through observation, learning and feedback, which that paper is explicit is not a measure of speed and does not advocate slower development, only development that preserves adaptability under uncertainty. The phenomenon is a claim about how capability arrives; the principle is a claim about how to act given that arrival. Nothing in this paper’s account of the first is an argument for the second being read as slowness.
3.2 Definition 1 — The governed object
Definition 1. What this series takes to be governed is not the model, the system, the application, or the developing organization. Those are handles — the loci at which instruments attach. The governed object has two levels: the capacity of AGI to alter outcomes, and the realized distribution of those outcomes. Handles are instrumentally necessary and analytically distinct from the target.
This series accordingly distinguishes benefit potential and harm potential, which are dispositional properties of a capability, from realized benefit and realized harm, which are what actually occurs and to whom. The two levels are not interchangeable, and claims true at one are frequently false at the other.
On the two levels. The distinction is not a refinement of vocabulary but a structural feature of the object. A capability’s potentials are properties it has whether or not it is ever deployed; realizations are events with dates, locations, and identifiable parties. Confusing them produces two characteristic errors. The first treats an unrealized potential as a harm already done, which overstates. The second treats an absence of observed harm as evidence that the potential is absent, which understates and is the more common error in this domain, since the potentials of a general capability are latent until the conditions for their realization arrive. Everything Definition 2 says about coupling is a claim at the level of potential; everything Definition 5 requires of observation is a requirement at the level of realization.
Most work in this field defines its object as an artifact and then discovers that realized harms arrive elsewhere. Compute thresholds, capability evaluations, licensing regimes, and conformity assessments all attach to models, firms, or applications. That is unavoidable — governance cannot act on a capacity directly, and every instrument must grip something. But the thing gripped is not the thing that matters, and treating them as identical produces a specific and recurring failure.
The handle/target gap. Instruments attach to handles; consequences occur at the target. The two are joined by a mapping that is imperfect, unstable, and adversarially exploitable. One regulates the model and the harm arrives through deployment context. One regulates the developer and the capability diffuses to actors outside the regime. One measures capability and the realized distribution of benefit and harm remains unmeasured. This gap is not an implementation defect to be engineered away; it is a structural property of governing a capacity through proxies. It is the same structure that appears in the state-legibility literature — governance cannot act on what it cannot render visible, and the act of rendering visible deforms what is measured (Scott 1998) — and in the measurement literature, where any proxy that acquires regulatory consequence ceases to track what it tracked (Goodhart 1975; Campbell 1979; Strathern 1997).

Figure 1. The governed object. The potential layer is drawn as a single enclosing shape because the two potentials are one capability under two evaluative descriptions; the realization layer is drawn as two separate shapes because realizations are not thereby coupled. Instruments attach to the handles beneath; consequences occur above.
Three registers of the capacity to alter outcomes. The governed object is a capacity to alter outcomes, and the literature on power distinguishes at least three registers in which outcomes are altered. The first is prevailing in observable decisions over observable conflict (Dahl 1961). The second is agenda control — confining decision-making to safe issues, so that some conflicts never reach a decision at all (Bachrach & Baratz 1962). The third is the shaping of perceptions and preferences, so that the prevailing arrangement is accepted rather than contested (Lukes 1974/2005). Deployed systems operate substantially in the second and third registers: defaults, ranking, refusal behaviour and affordances shape the field of possible action without any decision being taken anywhere (Foucault 1978/1991; Zuboff 2019).
Definition 1’s target includes all three. This has an uncomfortable consequence for Definition 5, and it is better stated here than discovered later: an observer confined to realized outcomes sees the first register well and the second and third poorly, because agenda control and preference shaping produce no incident to reconstruct. A framework named for contestation must acknowledge that its own observation function is weakest exactly where power is least visible.
Harm potential is not vulnerability, and the two are easily run together. Harm potential as used here is a property of a capability: what it can bring about. Vulnerability, in its ordinary security sense, is a property of an exposed system: what can be brought about in it. They sit at opposite ends of a causal relation and meet in an event — a capable system finds and chains weaknesses that a target system has — so neither term does the other’s work, and a claim that substitutes one for the other has changed the subject rather than restated it.
The substitution is common enough to be worth naming, because it makes some public disputes irresolvable by construction. Asking whether an openly published model is “more vulnerable” than a closed one can mean at least three different things: whether it can do more harm, which is a question about capability; whether it is more susceptible to being jailbroken, extracted or poisoned, which is a question about the artifact; or whether its availability leaves the surrounding ecosystem more exposed, which is a question about realization across a population. The first and third are questions this framework can state. The second concerns the model as an artifact, which Definition 1 classes as a handle. Participants answering different ones of these with the same word are not disagreeing.
A related precision is already on record in this series. The CFS paper, examining how institutional thresholds are set, observes that where a regulator applies a lighter requirement to open-weight systems than to closed ones, openness is functioning as a property that changes which threshold an actor applies — not as a separate class of actor, and not as a change in what the system can do. That is the same distinction arrived at from the institutional side, not the conceptual one.
On the relation to the actor-based apparatus. The Optimization models paper decomposes governance into actors with local objectives, differing binding power, and coalition structure, and concludes that no actor solves the joint problem. Definition 1 does not repudiate that apparatus; it locates it. Actors are handles and objective-bearers. The joint problem is defined over outcomes. The earlier paper was already treating outcomes as the target and actors as the loci of intervention; Definition 1 makes that explicit.
The duality of the target. At the level of potential, the capacity to alter outcomes is dual-use in the strict sense: the same capability that carries benefit potential carries harm potential. This is not a claim that AI has good uses and bad uses, which would be true of a hammer. It is the stronger claim that the two potentials are not separable within the capability itself, because they are the same capability under two evaluative descriptions. A system able to design a protein is thereby able to design a harmful one; a system able to find a vulnerability is thereby able to exploit it. There is a mature governance literature on this structure under the heading of dual-use, developed for materials and pathogens, and this framework inherits it. What AGI adds is that dual-use has historically been assessed per-artifact, and a general capacity defeats per-artifact assessment.
Benefit and harm are not symmetric and not commensurable, at either level. Realized benefit and realized harm fall on different parties and on different timescales; the potentials are dispositional and admit even less well-defined comparison. Where the existential boundary is concerned the two stand on different logical footings entirely. This commitment originates in the Optimization framework paper’s §4.4, which places catastrophic and irreversible outcomes outside the trade-off structure entirely, bounding the admissible state space directly instead of entering them as a term to be weighed. Its argument is worth restating because it is stronger than a stipulation: the adaptive machinery on which the whole framework rests presupposes that the system survives a given period and updates from it, and that presupposition fails by construction once an outcome is irreversible. The Optimization models paper carries the same commitment at its §4.6. It is inherited here without modification. It follows that no metaphor implying two commensurable faces on one scale can be used in this framework, however rhetorically convenient. There is no aggregate quantity of which benefit and harm are the positive and negative parts.
3.3 Definition 2 — Coupling under growth
Definition 2. Benefit potential and harm potential are coupled through their shared substrate: both scale with capability, and they are inseparable within the capability itself. What is separable is not the potentials but the mapping from potential to realization, and that mapping has four points of purchase — access, sequencing, distribution, and deployment context. The capacity to modulate it is what this paper calls decoupling capacity. It is finite, institutionally held, and slow-growing. The governance problem is the differential between the rate at which coupled potential grows and the rate at which decoupling capacity grows.
This is the load-bearing definition, and it does three things the framework needs.
It supplies a dynamic, not a metaphor. It is tempting to describe the relation between the two potentials as a contest between two forces, one overcoming the other. That description should be resisted on two grounds. First, it attributes objectives to dispositional properties: capacities do not strive, and neither the beneficial nor the damaging potential has an outcome of its own to maximize. Second, and more decisively, it gets the sign wrong. Contest implies rivalry — more of one, less of the other. Through a shared substrate the correlation runs the other way: a more capable system has more of both. Benefit potential and harm potential are positively coupled through capability, not negatively coupled through competition.
Competition is real in this framework, but it is located one layer down, among actors with divergent objectives. The potentials are not the competitors. They are the stakes.
It identifies where governance can act, and on what. If the potentials are inseparable within the capability, then no amount of work on the capability alone separates them, and the search for an intervention at that level is misdirected. What governance modulates is the mapping from potential to realization — which potentials realize, for whom, in what order, and under what conditions. That mapping has four points of purchase, and they are meant to be exhaustive of it:
(i) Access — who may invoke the capability, and under what conditions.
(ii) Sequencing — what is developed and released, and in what order.
(iii) Distribution — who bears realized benefit and who bears realized harm.
(iv) Deployment context — the conditions under which the capability meets the world.
Every governance instrument surveyed in Section 2 operates at one or more of these points, including instruments whose proponents describe them otherwise. Structured access is an access instrument. Differential technological development is a sequencing instrument. Staged and conditional release is a sequencing and access instrument. Liability, compensation, and transition policy are distribution instruments. Use restrictions and conformity requirements are deployment-context instruments.

Figure 2. The four realization states, on realized benefit against realized harm. Displacement, deferral and transformation fall outside these four and are named separately below.
The result of that modulation is a joint state, not a single value. Because realized benefit and realized harm are determined separately once the mapping is modulated, the outcome of an intervention is a pair, not a quantity, and admits four qualitative realization states:
(i) Decoupled — benefit realized, harm not. What governance is for.
(ii) Uncontained — both realized. What coupling produces where intervention is absent or ineffective.
(iii) Foregone — neither realized. The cost side of every restrictive instrument, and the state a framework asserting coupling should expect suppression to produce most often.
(iv) Failed — harm realized, benefit not. An intervention that acted on the wrong side of the mapping; also the signature of capture.
States (ii) and (iii) are coupling asserting itself, in opposite directions. Naming (iii) explicitly is what prevents the error of treating restriction as costless — the mirror of the error, corrected earlier in this framework’s development, of treating benefit and harm as two faces of one commensurable quantity.
Three further outcomes do not fit these four and must be named, not absorbed. Displacement: harm prevented for one population and realized for another, which is the distributional question at the centre of Definition 1. Deferral: harm prevented in one period and realized in a later one, which is the shape of the lag documented at §2.1. Transformation: the intervention itself creates a harm that did not previously exist, which is the substance of the argument that safety measures can reduce safety (§2.9).
It generates the series’ central thesis instead of assuming it. Coupled potential grows with capability, on a trajectory driven by research, capital, and competition. Decoupling capacity is held in institutions — regulators, courts, standards bodies, evaluation organizations, insurers, professional communities — and grows on institutional timescales. The two rates are not linked. The governance problem is the gap between them, and it is a rate problem before it is a design problem.
One refinement is needed before the antecedent is stated, because without it the claim is easily misread. The bound concerns variety in the space of disturbances the governing system must answer, not general capability. A regulator does not need to match everything a frontier model can do; it needs to distinguish, and respond differently to, everything that arrives requiring a different response. This matters practically: it is why a narrow instrument can be adequate to a wide capability, and why a highly capable but undifferentiating instrument is not.
Stated at this level of generality the claim has a formal antecedent. A regulator can absorb disturbance only to the extent that its own repertoire of responses matches the variety of disturbances arriving (Ashby 1956).
Two things about that borrowing should be explicit, since a formal result invoked loosely does more harm than an informal claim stated plainly. The quantity used here is the theorem’s own: in Ashby’s regulation argument, variety is defined over the set of disturbances and the set of regulatory responses, so counting kinds of arrival requiring different responses against kinds of response available is not a reinterpretation of it. What is loosened is everything around it. The theorem is exact for a finite, specified table of disturbances, responses and outcomes with a designated essential variable, and institutions supply none of those. This framework therefore takes from Ashby the structure of the result — that a shortfall of regulatory variety cannot be closed from within the existing repertoire — and does not claim to have measured either variety or to have proved a bound in this domain. Where the distinction matters for a claim’s status, Section 4 marks it. If the variety of what must be governed expands faster than the variety of the governing system, the shortfall is not a failure of diligence and cannot be remedied by effort. It is a structural insufficiency. This converts the familiar complaint that regulation is too slow into something more useful: a bound, and a specification of the two things that could be changed. Following the variety-engineering distinction (Beer 1979), governance may either attenuate the variety arriving — through moratoria, thresholds, licensing, or restrictions on release — or amplify the variety of the governing system — through evaluation capacity, expertise, institutional density, or the use of AI in supervision. The policy debate routinely conflates these two lever classes. They have different costs, different failure modes, and different political constituencies, and separating them is one of the practical contributions this framework can make.
3.4 Definition 3 — Governance
Definition 3. Governance, in this framework, is the set of processes by which actors with divergent and non-aggregable objectives contest and provisionally settle (i) where decoupling effort is applied, and (ii) how realized outcomes are distributed. Governance operates on handles, not on the target directly. It is never terminal.
Governance is evaluated procedurally, not against an operational success criterion. This is not because the series lacks a governing objective. It has one: the Optimization framework paper posits a persistent Global Objective — the realization of the developmental potential of an AGI-inclusive humanity, in that paper’s terms — which functions as a regulative ideal, orienting the process without being directly observable, computable, or reachable at any finite time. What is unavailable is not direction but adjudication: no rule aggregates local objectives into that objective, and no operational criterion decides, in-period, which of two contested arrangements serves it better.
The term is not a coinage. Dahl (1971) characterises real-world democracy along two dimensions, contestation and participation; this framework’s two imports from that tradition map onto them exactly — contestation is the mechanism this paper is named for, and participation is Definition 4. Contestation and the procedural adjudication defined at §3.6 are related and are not the same, and the distinction lies in their objects. Contestation ranges over ends — which arrangement should obtain, whose objective counts, what the direction requires in this case — and has no terminating rule, which is why it recurs. Procedural adjudication ranges over entitlement and process, and terminates, because there is something to apply. Adjudication is therefore not the institutionalization of contestation but the settlement of the one class of question contestation throws up that admits settlement. An arrangement can accordingly have functioning adjudication and undiminished contest at the same time, which is what Section 5 finds.
This also supplies an account of something a prior installment named and could not classify. The CFS paper identifies, in its own empirical material, a phenomenon its regime taxonomy does not cover: sustained oscillation of an institutional threshold itself, driven by contest among actors whose preferences point in opposite directions, as distinct from adoption oscillating around a threshold that holds still. It records this as an open extension requiring the threshold to be treated as a dynamical variable, not a parameter, and declines to formalize it. Contestation as defined here is what that phenomenon is: where no rule converts a shared direction into a verdict, a threshold set by contest among opposed actors has nothing to settle it, and its movement is not noise around an equilibrium but the absence of one. This paper does not supply the formalization that installment asked for — it has no notation to supply it in — but it does supply the account of why the phenomenon exists, which was the part left open.
Contestation is the process by which that adjudication gap is provisionally closed: actors with divergent objectives challenge, revise and settle governance arrangements without a rule that could have settled them. Contestability is the corresponding property of an arrangement — the degree to which it permits challenge and gives challenge effect. Contestation is what happens; contestability is what an arrangement affords, and it admits of degree. Contestability is also an established term in the AI literature for a property of systems rather than of arrangements — an individual’s ability to challenge a particular automated decision. §2.7 distinguishes the two levels; where this paper uses the word unqualified, the arrangement-level sense is meant.
Three features of this definition are deliberate departures from how the field usually speaks.
Governance is not alignment. The verb “align” is borrowed from technical AI alignment, where it means bringing system behavior into conformity with a specified objective. Applied to governance it presupposes that there is a target to conform to. But the Optimization models paper’s principal result is that no meta-actor exists, and the Optimization framework paper is itself explicit that the civilizational optimum is neither the sum nor the maximum of individual local goals. Where objectives diverge and no aggregation rule is available, governance is not conformity to a specification. It is arbitration, settlement, and distribution — different activities with different success criteria. Retaining the alignment vocabulary would quietly reimport the control-problem framing that this series has spent five installments moving away from, and would make a civilizational assimilation problem look like an engineering one.
There is no operational success criterion, and this is a finding, not a gap. A definition of governance that named an operational goal would be more satisfying and is unavailable to this framework. The series does name a direction; what it cannot supply is a rule converting that direction into a verdict on particular arrangements, since doing so requires the aggregation the framework has shown to be unavailable. Whether governance is succeeding is therefore itself a contested judgment, resolved in-period only relative to some actor’s local objective — which is precisely why contestability, not measured success, is the property this framework asks arrangements to have. Reviewers may read this as evasion. The answer is that a canonical criterion would have to be smuggled in, and smuggling it would make every subsequent result depend on an unstated choice of whose objective counts.
What replaces it is a set of procedural standards, which do not require agreement on ends. Three are used here. Whether affected parties have standing, and whether the arrangement produces defensible results for those it governs — input and output legitimacy respectively (Scharpf 1999). Whether transnational bodies exercising authority meet requirements of transparency, participation, reasoned decision and review (Kingsbury, Krisch & Stewart 2005). And, above all, whether the arrangement can detect and correct its own errors, which is the criterion by which an institution should be judged when no one can be confident it is right (Popper 1945).
Never terminal. This follows from Definition 0 without further argument. If the governed object is open-ended and has no completion state, no governance arrangement can be final. Three further derivations reach the same conclusion independently: from requisite variety, since expanding variety means governance is permanently chasing; from the absence of an aggregation rule, since “solved” has no criterion that all actors accept and solvedness is therefore objective-relative; and from the control dilemma, since the window in which intervention is cheap closes before the information required to intervene well is available (Collingridge 1980).
One clarification is needed, or the definition reads as counsel of despair. No terminal solution is not the same as no improvement. Governance arrangements can be better or worse, and the difference is neither arbitrary nor unmeasurable. What is unavailable is a state that ends the problem.
3.5 Definition 4 — Participation
Definition 4. Standing to participate in governance derives from affectedness: those whose outcomes are altered have standing in the processes that shape them. Participation is not justified by contribution, and its value is not monotone in the number of participants. What matters is the representativeness of participation and the diversity of the perspectives brought to bear.
The grounding requires an argument, because a more natural one is available and does not work.
Why not contribution. AGI’s capabilities derive from broadly digitized human output; it is tempting to conclude that those who contributed have standing to govern. The premise is largely true and the inference fails. Contribution-based standing is proportional by nature: if contributions are unequal, standing is unequal, weighted by volume of contribution. A prolific author would outrank a subsistence farmer. Taken seriously the premise argues against political equality rather than for it.
The premise is also weaker than it appears. Contribution is not universal — a substantial share of humanity is minimally represented in any training corpus, and the under-represented are also the least likely beneficiaries. And “contribution” flattens a distinction that is currently being litigated: material contributed deliberately and material taken are not the same act, and a framework that describes both as contribution concedes a contested question in passing.
Contribution nonetheless does real work — as a claim on benefits rather than as a claim to standing. Splitting the two preserves the moral force of the provenance argument and loses nothing.
Why affectedness. Definition 1 fixes the governed object as the capacity to alter outcomes together with the realized distribution of those outcomes. Standing then follows directly: those whose outcomes are altered have standing in the processes that shape them. The framework’s own two levels supply a partial answer to the boundary question, though not a complete one. Standing tracks the level at which an effect occurs: realized outcomes are local, and standing in the arrangements governing them is correspondingly local; potentials are global once created, and standing in the decisions that bring them into existence is correspondingly wide. That allocation is not arbitrary and does not require a threshold to be stipulated, but it leaves the hardest cases untouched — a potential created in one jurisdiction and realized in another has affected parties in both, with no rule assigning weight between them.
Affectedness is adopted here as the minimum condition for standing, not as a complete theory of democratic legitimacy; rights, citizenship, reciprocity and equality supply further bases that this framework neither adopts nor forecloses. The principle also has a known difficulty — the boundary problem, since the set of affected parties has no natural edge and can expand without limit — and this framework does not resolve it. It is more tractable than contribution-weighting, and it is stated with its difficulty attached, not without.
Why not more. The intuition that broader participation produces better governance is widely shared and, as a monotone claim, unsupported. The constitutional political economy literature is precisely a treatment of why: decision costs rise with the number of participants while the external costs of decisions taken without one fall, so the optimum is interior and unanimity is not it (Buchanan & Tullock 1962). The empirical record of deliberative practice points the same way — the instruments that work are small, randomly selected, well-informed mini-publics, and their performance is attributed to representativeness and deliberative quality rather than to headcount. The classical aggregation results require voter independence and better-than-chance competence, and correlated information environments break the first, a condition that widespread AI-mediated information plausibly worsens.
There is a further distinction that headcount arguments elide. Participation is not influence. A participant with negligible binding power participates without governing; assemblies convened without authority to compel a response produce legitimacy without governance. Adding participants is not the same as distributing power, and Definition 4 should not be read as claiming otherwise.
What participation is actually for. Its justification in this framework is not that it confers legitimacy, though it may, and not that participants have earned it, though some have. It is that participation raises the rate at which the governing system detects what it must respond to. Distributed participants observe distributed effects; the harms of a general capacity appear first at its periphery, in contexts that no central monitor is positioned to see. This is requisite variety applied to the sensing function, and it is an epistemic argument, not a normative one. It has the useful property of persuading readers who do not share a prior commitment to democratic legitimacy.
3.6 Definition 5 — Functional separation
Definition 5. Governance is discharged through functionally separated roles: execution (building, deploying, operating), observation (monitoring what executors do and what results), and steering (setting objectives, rules, and thresholds). A participant occupies one role and not others. The separation is structural and permanent, not rotational.
On pedigree. It is conventional to justify separation by appeal to constitutional practice, and the appeal is weaker than usually claimed. The tripartite division of legislative, executive, and judicial authority is one design among several: Westminster systems fuse executive and legislature and are durable; several constitutional orders operate four or more branches; audit institutions, ombudsmen, electoral commissions, and independent central banks constitute a substantial additional layer in many states. There is no finding that three is a stability optimum, and the framework should not rest on one.
Separation of function with mutual checking is nonetheless a recurring and durable design pattern, and the specific division proposed here is not the constitutional trio at all. Execution, observation, and steering is an actuate / sense / set-point decomposition. Its ancestry is cybernetic — the viable system model and the treatment of government as a steering process operating through information flows, feedback, and lag (Beer 1979; Deutsch 1963) — and that ancestry is the right one, because it connects Definition 5 to the rate logic of Definition 2 rather than to an analogy with constitutional practice that would not survive inspection.
The observer. Three features define the role.
(i) The observer has no principal other than the governance function. It has no product line, no customers, and no revenue contingent on the systems it observes. This is the audit-independence criterion, and it is more precise than saying the observer “does not execute” — monitoring necessarily involves running inference, and evaluating a system requires invoking it, often adversarially and at scale. What is excluded is not technical execution but the service of any other principal.
(ii) The observer observes at the level of realization, not only at the level of potential. This follows from Definition 1 and it is the point at which the framework departs most sharply from current practice. Contemporary evaluation measures potential: benchmark performance, dangerous-capability elicitation, and red-team findings all establish what a system could do. Almost nothing measures realization — which potentials actually realized, for whom, in what proportion, and through which deployment paths. An observer confined to potential cannot discharge the observer role under Definition 1 no matter how independent it is, and cannot distinguish the four realization states of §3.3. The contrast with mature safety regimes is instructive: aviation’s investigative bodies observe outcomes, through mandatory occurrence reporting and protected confidential near-miss reporting, and do not primarily assess aircraft capability.
The observer’s method is causal reconstruction, not impact estimation. Attributing a realized harm to a capability appears to demand a counterfactual — what would have occurred otherwise — for which no baseline is available. The mature investigative regimes do not compute one. They perform incident-level causal reconstruction from evidence, case by case, and separately maintain distributional accounting of who was exposed and who was affected. Both are demanding and neither requires a global counterfactual, which is why Definition 5 specifies the observer’s function in these terms rather than as the measurement of aggregate impact.
(iii) The observer has standing to compel a decision, not to make one. An observer that can only publish has negligible binding power, and a framework titled for contestation cannot rest its contesting function on publication alone. But an observer empowered to act would collapse into steering or execution. The resolution is the inspector-general structure: the observer triggers the steering pillar and is entitled to a reasoned response, without itself setting the objective.
(iv) The observer’s variety must be matched to the disturbance and independent of the observed. Definition 5’s first three features say what the observer must not serve, what it must look at, and what it may compel. None of them says what it must be made of, and an observer that satisfies all three can still be incapable. Two requirements follow from the framework, not from practice.
Matching. By the bound stated at §3.3, the observer must carry variety in the disturbance space at least equal to what arrives. Neither humans alone nor automated systems alone satisfy this at frontier scale: human review does not match the rate or volume of what must be examined, and automated review sits inside the capability being examined, which by Definition 2 makes it the least reliable point at which to attempt separation. Hybrid observation is therefore necessary. It is not thereby sufficient, and the framework should not claim more: where hybrid observation cannot be made adequate to the disturbance, the remaining lever is not better observation but attenuation — declining to release what cannot be observed. This is the second of the two lever classes named at §3.3, and it is the honest alternative to an observation function that cannot do its job.
Independence. Matching alone yields an observer that may share the blind spots of what it watches. What makes layered observation work is not that the layers are numerous but that their failure modes are decorrelated — the point of the layered-defence model in safety engineering is that the gaps in successive layers must not align (Reason 1997). Correlation is the operative risk here rather than a remote one: frontier systems are built from similar architectures on similar data by people trained in the same places, so an observer drawn from that population inherits its blind spots by construction. Independence therefore requires separation of provenance, not only of function. An observer built by the party it observes satisfies Definition 5’s first feature only formally.
Why this is presently unmet. The absence of realization-level observation is worth diagnosing, not merely recording, because the diagnosis determines what would fix it. It is not principally a technical limit: incident reconstruction and distributional accounting are demanding but routine in other domains. The framework’s own account is structural. Measurement follows instruments, instruments attach to handles, and handles are model-level and firm-level — so the data that exists is capability data, exposure data is nobody’s obligation to collect, and the parties best placed to collect it are the parties it would document. That is the handle/target gap appearing as a measurement gap, and it implies that the remedy is an obligation, not a technique.
Near-term proxies for realization-level observation. The requirement that observation occur at the level of realization is presently unmet, and the framework would be vulnerable to the charge of being unoperationalizable if it named no path. Three instruments already exist in other domains and are directly transposable: mandatory occurrence reporting, which obliges disclosure of defined categories of realized harm instead of leaving disclosure to discretion; protected confidential near-miss reporting, which captures the far larger population of events in which harm did not occur but the conditions for it did; and distributional accounting, which records who was exposed and who was affected, not aggregate incidence. None requires solving the counterfactual problem. Each is a partial proxy, and together they would constitute the observational base the framework currently lacks.
The one-role rule as a diagnostic. Stated as a description of how governance works, Definition 5 is simply false, and it should not be stated that way. Its value is as a criterion, and the criterion returns a sharp result. Frontier developers currently execute — building and deploying systems; observe — running their own capability and safety evaluations; and steer — authoring the frontier safety frameworks, scaling policies, and model constitutions that set the thresholds against which they are assessed. All three pillars are occupied by the same participants, and those participants are the ones with the greatest binding power. This is a checkable finding, verifiable against public documents, and it is stronger than the more common observation that self-assessment is less reliable than independent assessment.
Self-generated evidence is discounted, not excluded. The finding above does not license the conclusion that in-house work carries no weight. If it carried none, the observer would have to reproduce every result independently, which is infeasible at frontier scale and would make the criterion purely negative. The workable principle is verifiability-indexed discounting: self-generated evidence is admissible, and the discount applied to it is a function of how independently checkable it is. This is how financial audit operates in practice, where auditors rely on management representations and then test them.
A residual difficulty must be stated rather than left for a reviewer. Declaring in-house work non-independent does not create an independent alternative. The expertise required to evaluate frontier systems currently resides largely inside the organizations building them, and separation therefore trades against competence. This tension is specific to AI and does not have a close constitutional analogue: a judge need not be able to legislate in order to adjudicate, but an evaluator may well need to be able to build in order to evaluate. The framework names this trade-off; it does not dissolve it.
Design corollaries. Three prescriptions follow if the foregoing holds. They are conditional on the propositions rather than independent of them, and are offered for adoption on design grounds.
Corollary A — dedicated observation capacity. If matching and independence are both required, an observer assembled from general-purpose components built by the observed party satisfies neither. What follows is a case for observation capacity constituted for the purpose: trained on a corpus of realized incidents rather than on general text, disposed to treat observed activity as unexplained until accounted for rather than as benign until flagged, and — critically — of independent provenance. Narrow safety classifiers already exist and are not this; they filter content within a deployment rather than audit conduct across one. Three difficulties should be conceded with the proposal rather than after it. A disposition to treat activity as unexplained produces false positives at a rate governed by the base rate of benign activity, which is very high, and an observer whose outputs cannot be acted on has the binding power of no observer. A corpus of realized incidents covers only failure classes that have already occurred, and the failures that matter most are those still incubating unrecognized (§2.8). And the proposal creates the very correlation it is meant to avoid if the dedicated capacity is itself built by the parties being observed.
Corollary B — independence before competence. The tension named below has no resolution that preserves both fully, so the framework states a ranking rather than a solution: where they conflict, independence is prior, because a compromised observer produces evidence that cannot be relied upon at all, whereas a less capable independent observer produces less evidence that can be. Competence is then recovered by means that do not reintroduce dependence — adversarial contracting, consortium arrangements, and access rights that do not require the observed party’s consent case by case. One commonly proposed remedy is excluded by a commitment already made: personnel secondment from the observed organization would recover competence by reintroducing exactly the rotation between roles that Definition 5’s structural, non-rotating separation rules out.
Corollary C — minimal conditions for a steering body. Steering is the least specified function in this framework, and §5.3 finds it the least specified in practice. The framework cannot supply its mechanisms: what a steering body should decide is the adjudication of ends this paper holds no rule settles. What can be supplied is a set of minimal conditions, each derived from a requirement another function imposes rather than from a view about what should be decided.
(i) It must be obliged to respond to what observation produces. An observer with standing to compel is compelling something; if no body is obliged to answer, the observer’s third feature is void and observation reduces to reporting.
(ii) It must set thresholds in advance rather than rule case by case. A body that decides instances is executing, and the pre-authorized response on which timely intervention depends has nothing to draw on.
(iii) Its thresholds must be revisable on a stated cadence. Rules that remain formally unchanged while the environment moves beneath them are the drift failure mode, and under Definition 0 the environment always moves.
(iv) Its revisions must be procedurally legible. Procedural adjudication can determine whether a body followed its own process only where that process is stated; a steering body whose thresholds change without a recorded basis cannot be held to anything.
None of these says what a threshold should be, and none could. They state what a body must be able to do before the question of what it should decide arises — which is the most this framework can say about steering without claiming an authority it has argued does not exist.
What separation delivers, and what it does not. Separation converts diffuse responsibility into assignable responsibility. Where every participant executes and every participant monitors, each can attribute an outcome to another — the model produced it, the deployer configured it, the user elicited it, the data supplier enabled it — and the result is a system in which everyone is a co-producer and no one is accountable (Beck 1992, 1995). Separation names, in advance, who was to build and who was to watch.
It does not eliminate the regress. It bounds it: each incident still poses the allocation question between an executor who caused and an observer who failed to detect, and that question recurs. Nor does separation establish causal responsibility; it establishes role responsibility, and knowing who was supposed to be watching does not tell one what produced the harm. A further limit is worth conceding at the outset: an observer operating at scale will itself use AI systems to observe, which relocates the problem instead of terminating it.

Figure 3. The four functions. Two relations run directly along the triangle’s sides; the third does not, since the observer reaches steering only through adjudication — which is why the fourth function sits at the centre and is drawn apart from the three roles.
A fourth function: procedural adjudication. Two functions have no home in execution, observation, or steering. The first is adjudication — resolution of disputes between pillars and between participants, which the commons-governance literature identifies as a distinct design requirement rather than an incidental one (Ostrom 1990, design principle 6). The second is sanction: monitoring without consequence is an enforcement pyramid with no pyramid (Ayres & Braithwaite 1992), and if sanction is folded into execution then the executor sanctions itself.
The gap is not accidental, and its source is diagnosable. The cybernetic trio was developed for systems pursuing a single objective, where no dispute about ends can arise and therefore no adjudicative function is required. Definition 3 denies a single objective, so conflict over ends is guaranteed by the framework’s own commitments, and a three-pillar structure is short of the function that handles it.
The resolution follows from Definition 3 rather than from a choice between design options. If no rule converts the governing direction into an in-period verdict, then a body constituted to adjudicate ends cannot exist: there is nothing for it to apply. What can exist, and does, is a function that adjudicates procedure — whether an actor was entitled to act as it did, whether the process by which it acted met the conditions the arrangement requires, and whether an exercise of authority was what it claimed to be. This framework therefore names a fourth function, procedural adjudication, and locates sanction with it, on the ordinary principle that the body which can determine entitlement is the body that can attach consequence to its determination. It also completes the observer’s third feature: an observer with standing to compel a decision compels it through this function rather than against the steering pillar directly.
The limitation is not a defect of the design but a restatement of Definition 3, and it should be stated plainly. Procedural adjudication settles who was entitled to decide and whether they decided properly. It does not settle what should have been decided. Contested ends remain contested after adjudication, which is why contestation is continuous, not terminal.
3.7 Reconciling participation and separation with the rate problem
Definitions 4 and 5 both add latency. More participants lengthen decision processes; functional separation adds friction by design, on the principle that the friction is the point. Definition 2 holds that the governance problem is a rate differential in which governance is already too slow. Taken together the framework appears to prescribe exactly what its own diagnosis forbids.
The tension is real and the resolution is a decomposition. Under Definition 3 governance has no terminal decision; it is a continuing process. The relevant performance measure is therefore not time-to-decide but time-to-detect-and-correct, and these two rates respond oppositely to participation and separation:
- Broader participation and independent observation raise the detection rate. Distributed participants observe distributed effects; separated observers are not structurally disposed to overlook what they would otherwise be responsible for.
- Broader participation and additional veto points lower the decision rate.
A concentrated, unseparated arrangement is fast to act and slow to correct: it decides quickly and has few mechanisms positioned to notice that it decided wrongly. A participatory, separated arrangement is slow to act and quick to correct. Where the governed object has no completion state and error is therefore certain and recurrent, correction rate plausibly dominates decision rate as a performance measure. This also answers, at least partially, the historical objection recorded at §2.1 — that institutional recomposition has followed crisis rather than anticipated it. The framework does not claim that anticipation generally prevails. It states a condition: anticipatory recomposition requires contestation connected to a body with binding power over the arrangement in question, and where that connection is absent the crisis path is the default, not the exception. That condition is checkable case by case, and it makes the disagreement with the historical record a matter of evidence, not posture.
This is Popper’s criterion arrived at through the rate logic rather than imported from outside it — and it is also the series’ own position restated. The Optimization framework paper’s Proposition 4 holds that what matters is temporally coherent development, proceeding as fast as conditions allow while preserving the capacity to learn and revise, and states explicitly that this is not an argument for slower development. That paper also already carries the counter-condition: where delay cedes an irreversible advantage to a less careful actor, or an ongoing harm compounds while a decision is deferred, delay is a choice with its own consequences, not a neutral default.
The decomposition does not dissolve the trade-off, and the framework should not claim that it does. It relocates the trade-off into a form that can be reasoned about, and exposes a frontier the governance literature has not named: legitimacy and responsiveness are in tension. The instruments that raise responsiveness — delegated rulemaking, sandboxes, sunset clauses, governance by executive instrument — all raise the revision rate, and thereby degrade constancy through time. That is a requirement of the rule of law, not an optional feature of it (Fuller 1964). The pacing problem forces a choice along that frontier. Section 2 found no treatment of it.
3.8 What this section does not establish, and one deliberate omission
No formal notation is introduced. The Optimization pair separated a conceptual installment from a formal one, and that separation is retained here: this paper states the framework in words and names the quantities that a subsequent installment would formalize — the coupling between beneficial and damaging potential, the growth rate of decoupling capacity, the detection and correction rates of §3.7, and the relation between them. Introducing symbols now would either duplicate or collide with the notation already carried by the Optimization models paper, which has an established symbol table and a history of collisions that were expensive to repair. The formalization is deferred deliberately, not omitted for want of one.
Difficulties created by the two-level distinction. Three should be stated, not discovered. First, the measurement asymmetry runs against the framework: potentials are partially measurable through evaluation, and realizations are largely unmeasured, so the framework centres the level for which there is least data. That is the gap Definition 5 identifies, not an accident, but it means the framework’s principal variable is at present unobserved. Second, incident-level causal reconstruction sees only harms that surface as incidents; diffuse, slow, or normalized harms produce no incident to reconstruct, which is the incubation problem identified in the disaster literature (§2.8) and is the structural blind spot of the method Definition 5 adopts. Third, the two levels are not sequential. Realizations feed back into potentials — deployment generates data, revenue, and capability — so a two-level vocabulary risks presenting as a pipeline what is in fact a loop.
Open items carried forward. (i) The boundary problem in Definition 4 — the set of affected parties has no natural edge — is named and not resolved. (ii) The fourth function named at §3.6 is derived rather than demonstrated: this paper argues that procedural adjudication is what remains available once ends-adjudication is ruled out, and does not show that any existing institution discharges it adequately. (iii) The competence-versus-independence tension in Definition 5 is ranked, not dissolved: Corollary B states which is prior when they conflict, and does not claim the conflict can be avoided. (iv) The framework’s relation to polycentric governance is not settled: the arrangement described by Definitions 3 through 5 — separated function, distributed participation, no central solver, procedural evaluation — is recognizably polycentric, and the polycentric tradition holds that the absence of a single decision centre is not by itself a failure. Whether this framework’s conditions differ from those under which polycentric arrangements have succeeded is a question this paper raises in Section 2 and does not answer here.
4 Propositions
4.0 What this section does, and how to read a proposition
Section 3 fixed six definitions and named the framework’s type. This section states what the framework claims about the world.
Each proposition below is given in three parts, and the separation is not presentational. Analytically states what follows from the definitions alone — true given the framework, and therefore not evidence for it. Empirically states the claim attached to it that could be false. Falsified by states what observation would refute the empirical part. A proposition whose analytic part does all the work is a consequence of a stipulation dressed as a discovery, and the series has been criticised before for exactly that; splitting the parts makes the criticism checkable rather than a matter of impression.
Three consequences of this format should be visible at the outset. First, the analytic parts are not weaknesses. Working out what a framework entails is the substance of a conceptual paper, and a proposition that follows from the definitions still tells the reader something they could not have read off the definitions directly. Second, the empirical parts are of very unequal strength: GP4 and GP7 are almost entirely empirical, GP3 almost entirely analytic, and the rest sit between. Third, several of the empirical parts are not established here. This paper states them, derives them, and specifies what would settle them. Settling them is the companion installment’s work, and the division is deliberate, not an omission.
The propositions follow the two-layer structure of the definitions. GP1 to GP3 draw on the foundational layer and concern the governance problem as such. GP4 to GP7 draw on the architectural layer and concern how governance is or could be constituted.
GP1 is the central claim, and a reader with time for one proposition should read that one. Everything else in the framework is either a condition on it, a consequence of it, or a claim about the institutions that would act on it. Its second part in particular — that governance is what produces the difference between what a capability makes possible and what it makes happen — is the sentence the rest of this paper exists to support.
Two questions the framework leaves genuinely open are deliberately not stated as propositions: its relation to polycentric governance (§2.6, §5.4) and the boundary of the affected set in Definition 4 (§3.5). Stating either as a proposition would imply a position the paper does not hold. They are recorded as open at §3.8 and are not resolved by anything below.
4.1 GP1 — Coupling and its limit
(a) Benefit potential and harm potential are inseparable within the capability: no operation on the capability alone holds one and removes the other. They are also positively correlated through capability, both rising as capability rises. These are two claims, and only the first follows from the definitions. (b) Realized benefit and realized harm are not thereby correlated: they are jointly determined by the mapping from potential to realization, which is modulable at access, sequencing, distribution, and deployment context. The difference between (a) and (b) is what governance produces.
Analytically. Only the inseparability half of part (a) follows from the definitions. If the beneficial and damaging potentials are one capability under two evaluative descriptions, no operation on the capability can hold one and remove the other; that is what “one capability” means. The correlation half does not follow: that both potentials rise as capability rises is a claim about how capability scales, and nothing in Definition 1 or Definition 2 entails it. An earlier statement of this proposition ran the two together and labelled the pair analytic, which was an error of exactly the kind the format of this section exists to prevent. Part (b) follows from the two-level structure: if realizations are determined by a mapping distinct from the capability, and that mapping admits modulation, then realizations are not fixed by the potentials that make them possible.
Empirically. Three claims. The first is the correlation half of part (a): that benefit potential and harm potential in fact rise together with capability instead of diverging. It is well supported across current systems and is not a necessity — a capability whose harm potential saturated while its benefit potential continued to rise would refute it, and would leave the framework’s inseparability claim standing while removing the urgency the coupling account draws from it. The second is that the mapping is in fact modulable — that access conditions, release ordering, distributional arrangements and deployment context measurably change which potentials realize and for whom. The second is a claim about completeness, and it should be stated at the strength it has rather than the strength that would be convenient. The four points are exhaustive of the loci currently identifiable: every functioning governance instrument surveyed in Section 2 operates at one or more of them, and no candidate fifth has been found. That is not a demonstration that no fifth exists, and no principled derivation of the four from a more fundamental decomposition is offered here. The framework treats the exhibition of a fifth locus as a refutation rather than as a refinement, which preserves the claim’s falsifiability without asserting a completeness it has not earned.
Falsified by. Exhibiting a governance instrument that demonstrably alters realized outcomes and operates at none of the four points would refute exhaustiveness. Separately, showing that realized benefit and realized harm remain correlated at a level fully explained by capability, once access, sequencing, distribution and deployment conditions are controlled for, would refute part (b) — and would leave the framework claiming governance produces a difference it does not produce.
Why it matters. Part (b) is the load-bearing half and the less obvious one. Without it, coupling implies that governance can only slow or stop, never shape, and the framework collapses into a variant of technological determinism. With it, the object of governance is precisely the wedge between what a capability makes possible and what it makes happen.
4.2 GP2 — Variety matching
Where the variety of disturbances a governing system must answer exceeds the variety of responses it can distinguish, the shortfall cannot be closed by increased effort within the existing repertoire. It is closed only by attenuating arriving variety or by amplifying the governing system’s variety. In frontier AI governance the antecedent is claimed to hold and to be worsening, because the two varieties grow on unlinked clocks.
Analytically. The first sentence is the regulator-variety bound and holds independently of any facts about AI. Its content here is a scope restriction that is easy to miss: the bound concerns variety in the disturbance space — the set of arrivals requiring different responses — not general capability. A governing system need not match what a frontier system can do; it must distinguish, and respond differently to, everything that arrives requiring a different response. Discrimination, not power. It follows that a narrow instrument can be adequate to a wide capability, and that a powerful but undifferentiating instrument is not.
Empirically. That the antecedent obtains in this domain, and that the gap is widening. Neither is established here. Two observations bear on it without settling it. A governing system with fewer distinguishable responses than disturbance kinds must map several kinds onto one response, which produces over-restriction and under-restriction simultaneously across different cases — so both over- and under-restriction are evidence for the same shortfall, not for opposite ones. And the two varieties have no mechanism linking their growth: capability variety is driven by research and competition, response variety by institutional construction.
Falsified by. An operationalization is required first, and its absence is the honest limit of this proposition. What would settle it is a count of distinguishable disturbance kinds against distinguishable response types, tracked over time: if response variety grows at least as fast, the empirical claim fails.
Two proxies are constructible now, and stating how makes the deferral a specification, not a promise. The first is internal to a single governing document across its own versions: enumerate the threat or capability categories the document names as requiring distinct treatment, enumerate the response types it specifies, and take the ratio across successive versions. Documents that version themselves — frontier safety frameworks, scaling policies, conformity-assessment annexes — supply the series without any new data collection, and because the comparison is within a document, it does not require judgements about what counts as a category across authors. The second is cross-sectional: count distinct instrument forms operating at each of Definition 2’s four points of purchase, at intervals, treating two instruments as one form when they impose the same class of obligation on the same class of actor. Section 5 performs the cross-sectional count once, without the time series that would make it evidence. A finding that institutional proliferation has increased response variety rather than merely response volume would count against the proposition; twenty bodies issuing the same four instrument forms would not.
A caution against a natural misreading. Variety and stringency are orthogonal. Variety is how many distinguishable responses exist; stringency is how restrictive any one of them is. A blunt prohibition is a low-variety instrument that may be highly stringent, and excess stringency is therefore not evidence of excess variety. Nothing in GP2 says governance should be less restrictive.
4.3 GP3 — No terminal state (a corollary)
No governance arrangement over an open-ended capability admits a terminal solution, and “solved” has no operational criterion in-period. Governance arrangements are therefore ordered by procedural properties — detectability, contestability, correctability — rather than by proximity to a goal state.
Analytically. Almost all of it. Definition 0 denies a completion event for the governed capability; Definition 3 denies a rule converting the governing direction into an in-period verdict. Together these entail that no arrangement is final and that finality has no criterion. The proposition is stated as a corollary for that reason.
Empirically. Thin, and it should be labelled thin rather than dressed up: the prediction that arrangements presented as settlements are reopened, and that the reopening is driven by capability change rather than only by political turnover.
Falsified by. Here the proposition is weaker than the others, and the asymmetry is worth stating instead of concealing. No finite observation refutes it — an arrangement that has held for a decade may still be reopened in the eleventh year. What accumulating stability can do is progressively undermine its interest, and a long-lived arrangement over a capability that continued to change would count substantially against the framework without formally refuting it. Readers should treat GP3 as an organizing consequence rather than as a claim that earns its keep by risking refutation.
4.4 GP4 — Concentration and low contestability
Where execution, observation, and steering are occupied by the same participants, the observation function does not produce independent information and responsibility for outcomes is assignable to no one. This condition currently obtains for the participants with the greatest binding power in frontier AI, which is to say the present arrangement has low contestability: challenge is possible but has little effect, because the parties positioned to mount it are the parties whose conduct would be challenged.
Analytically. Little. Definition 5 supplies the criterion; the first sentence is close to what the criterion means.
Empirically. Nearly all of it, and this is the most testable proposition in the set. It is a claim about a specific arrangement at a specific time, verifiable against public documents: who builds and deploys, who conducts the evaluations that determine whether thresholds are met, and who authors the frameworks that set the thresholds.
Falsified by. Identifying, within the current regime, an observer that satisfies all four features of Definition 5 — no principal other than the governance function, access at the level of realized outcomes, standing to compel a reasoned response, and independent provenance. Note that the bar is four features, not three: an evaluator that is organizationally separate but built from the same architectures, on similar data, by people from the same population satisfies the first three formally and the fourth not at all. Partial satisfaction is expected and is not falsification; the proposition claims the conjunction is absent, not that no element of it exists anywhere.
Scope. GP4 is a claim about the present, not about necessity. Nothing in the framework says the pillars cannot be separated; Section 2 records regimes in which they are. The proposition would be refuted by a counterexample and would be withdrawn, not defended, if the arrangement changed.
4.5 GP5 — Rate decomposition
Decision rate and detection-and-correction rate respond oppositely to broad participation and functional separation: both raise the second and lower the first. Where the governed object has no completion state, correction rate is the binding performance measure, and an arrangement that decides slowly and corrects quickly outperforms one that decides quickly and corrects slowly.
Analytically. Less than it first appears. What is analytic is narrow: a decision requiring more clearance points takes longer than the same decision requiring fewer, and a system with more independent sensing channels detects more of what passes through them. What is not analytic is that broader participation and functional separation necessarily produce those conditions. Participation structured as consultation adds no clearance point; observers who are neither competent nor empowered add no sensing channel. The proposition’s first sentence therefore carries an empirical claim about how participation and separation are ordinarily instantiated, and it fails wherever they are instantiated otherwise.
Empirically. The second sentence. That correction rate rather than decision rate binds is a substantive claim about which failure mode dominates, and it could be wrong in either of two ways. It fails if the harms that matter are predominantly those that cannot be corrected once realized, in which case decision rate — specifically, the rate of deciding not to proceed — is what binds. And it fails in any domain where the cost of delay exceeds the cost of uncorrected error.
Falsified by. Exhibiting an arrangement that is both fast to decide and fast to correct would refute the opposition claimed in the first sentence. For the second, a domain in which outcomes track decision rate, not correction rate, with participation and separation held roughly constant, would refute the dominance claim.
Where the claim does not apply. Where potential harm is irreversible, correction is unavailable by construction, and the argument for prioritising correction rate lapses with it — not by exception but because its premise is absent. This is not an ad hoc rescue: it is the same reasoning the Optimization framework paper uses to place catastrophic outcomes outside the trade-off structure, since adaptive machinery presupposes that the system survives the period and updates from it. At the boundary, anticipation and attenuation are what remain. GP5 is a claim about the ordinary case, and the framework says explicitly where the ordinary case ends.
4.6 GP6 — The adjudication asymmetry
Procedural adjudication is institutionally available and ends-adjudication is not. Disputes about entitlement and process — whether an actor was permitted to act as it did, whether the process met the conditions the arrangement requires — can be settled with binding effect over unwilling parties. Disputes about which ends should govern cannot, and are settled only by bargaining, capitulation, or the unilateral action of whichever party can move first.
Analytically. The impossibility half follows from Definition 3. If no rule converts the governing direction into an in-period verdict, then a body constituted to adjudicate ends has nothing to apply, and what it produced would be a further contested position, not a settlement.
Empirically. The availability half. That institutions performing procedural adjudication over these disputes exist, function, and bind unwilling parties is a claim about the world, and it is the one that makes the asymmetry informative rather than merely pessimistic — an asymmetry requires both terms.
Falsified by. An institution that settles a contested-ends dispute with binding effect over a party that does not consent to its jurisdiction. Two near-misses must be excluded or the condition is trivially met. First, a body that settles an ends dispute within a jurisdiction whose ends are already fixed is applying an objective instead of adjudicating between contested ones; a central bank choosing between two paths to a mandated target is not settling what the target should be. Second, consent-based settlement — arbitration, treaty, negotiated standard — is bargaining conducted in adjudicative form.
That second exclusion is large and should not be read as dismissive, since it removes most of international law from the category. The framework’s position is not that treaties and negotiated standards fail to settle anything; they settle a great deal, and they do so by the mechanism this paper is named for. Consent is what distinguishes them: parties who bargain their way to a common position have exercised contestation and reached a settlement, whereas adjudication in the sense at issue here binds a party that has not agreed to the outcome. Treaty regimes are therefore instances of the contestation process operating successfully, not counterexamples to the asymmetry — and their well-documented dependence on continued consent, including the ease with which parties withdraw when their ends change, is consistent with rather than contrary to the claim.
Consequence for the architecture. This is why Section 3 locates a fourth function and restricts it to procedure, rather than either leaving the gap open or constituting a body to resolve conflicts over ends. It also explains a pattern the case literature keeps producing: disputes over ends that pass through adjudicative institutions come out settled on procedural grounds with the ends question untouched, and this looks like evasion when it is a structural limit.
4.7 GP7 — Provenance correlation
Observers sharing architecture, training data, or personnel provenance with the systems they observe have correlated blind spots. Independence of function without independence of provenance does not produce independent observation.
Where this comes from. GP7 is the one proposition whose content is imported, not derived, and the bridge should be explicit. Definition 5’s fourth observer feature requires that an observer’s variety be independent of the observed, and independence is the one requirement the definitions state without saying what would violate it. The correlated-risk literature supplies the missing account: institution-by-institution soundness is compatible with system-level fragility whenever the institutions hold correlated positions (§2.8). GP7 is that account applied to observation rather than to exposure — the claim that shared provenance is the correlation that matters here, and that a framework specifying organizational separation without it has specified something weaker than it appears to.
Analytically. Little. That shared construction produces shared failure modes is not entailed by the definitions; it is the empirical content the definition’s independence requirement was left waiting for.
Empirically. Nearly all of it. Frontier systems are built from similar architectures on similar data by people trained in similar places, so the population from which observers are drawn is not independent of the population being observed. The claim is that this correlation is large enough to matter — that same-provenance observation misses a materially different set of failures than different-provenance observation does.
What “different provenance” means. The test requires the term to be operational, and the framework specifies it as a conjunction of dimensions rather than a single one: architecture and training corpus, disciplinary formation of the personnel, and organizational independence. A study varying one dimension while holding the others fixed tests that dimension; a study varying none tests nothing. The hardest version is disciplinary — whether an observer trained in epidemiology or financial audit can be competent at frontier evaluation is exactly the competence-versus-independence question Corollary B ranks and does not dissolve.
Falsified by. This has the cleanest test in the set, and it does not require any new theory. Take a population of failures established by some independent means, and compare detection rates between observers of the same provenance as the observed system and observers of different provenance. If the rates are statistically indistinguishable, and the classes of failure each misses are the same, GP7 fails. The comparison is expensive but not conceptually difficult, and it is, in our judgement, the most valuable empirical study the framework points at.
Why it is stated separately from GP4. GP4 concerns who occupies which function; GP7 concerns what the occupant is made of. An arrangement could satisfy GP4’s separation completely — genuinely independent organizations in each role — and still fail GP7, if every organization draws on the same technical population. Collapsing them would hide that possibility, which is the arrangement the field is currently closest to constructing.
4.8 Integrated statement
The propositions can be assembled into a single conditional chain. Given an open-ended capability whose benefit and harm potentials are coupled through the capability itself (D0, D2, GP1a), governance is the continuous production of a difference between what the capability makes possible and what it makes happen (GP1b), effected by modulating a mapping at four points on handles that are not the target (D1, D2). That production is bounded by a variety constraint that no increase in effort within an existing repertoire can relieve (GP2), pursued by actors whose ends admit no aggregation and no adjudication (D3, GP6), through arrangements whose performance is measured by their capacity to detect and correct rather than by their proximity to a goal that has no operational statement (GP3, GP5), and evaluated by their contestability — which requires functional separation (GP4) and independence of provenance (GP7), and which the present arrangement has in low degree.
Two things follow that are worth stating in their own right.
The framework specifies no success condition, and this is a result, not an omission. A canonical criterion for good governance would require the aggregation rule the series has established does not exist. What replaces it is not silence but a different kind of standard: an arrangement is better to the extent that it detects what it must respond to, permits challenge, and can correct itself — properties that can be assessed without agreement on ends, which is precisely why they are the properties available.
And there is no meta-actor, at either level. The Optimization models paper found no actor solving the joint optimization problem. This paper finds the same absence one level up: no actor and no institution positioned to settle which governance arrangement should obtain. The two findings are not independent, and neither is a complaint. They are the reason contestation is the framework’s central term. Where a solver existed, contestation would be a transitional inconvenience; where none does, it is the mechanism itself, and the design question is not how to end it but how to keep it connected to institutions that can act on what it produces.
4.9 Falsification conditions, collected
Gathered for reference; each is stated in full in the subsection indicated.
| Refuted by | |
| GP1 | A governance instrument that alters realized outcomes and operates at none of the four points (exhaustiveness); or realized benefit and harm correlating at the level capability alone predicts, with mapping variables controlled (part b). |
| GP2 | Response variety growing at least as fast as disturbance variety, once both are operationalized as counts of distinguishable kinds. Institutional proliferation without increased response variety does not count. |
| GP3 | Not refutable by finite observation. Progressively undermined by a long-lived arrangement over a continuously changing capability. |
| GP4 | An observer within the current regime satisfying all four features of Definition 5 jointly: no other principal, realization-level access, standing to compel a reasoned response, independent provenance. |
| GP5 | An arrangement both fast to decide and fast to correct; or a domain in which outcomes track decision rate, not correction rate. |
| GP6 | An institution settling a contested-ends dispute with binding effect over a non-consenting party. Consent-based settlement and objective-application within a fixed mandate are excluded. |
| GP7 | Same-provenance and different-provenance observers detecting the same failure classes at statistically indistinguishable rates. |
Three of the seven — GP2, GP4, GP7 — are testable with methods that exist today. GP4 requires only document analysis. GP7 requires a comparative study that is expensive but straightforward. GP2 requires an operationalization of variety that does not yet exist and whose construction is the principal measurement task this paper hands forward.
5 Applying the Framework
5.0 What this section does, and what it defers
Section 2 excluded almost the entire literature of concrete governance proposals — compute thresholds, structured access, model evaluations, licensing, know-your-customer schemes for compute providers, liability designs, and the several blueprints for international institutions. The exclusion was principled: these are proposals about handles in Definition 1’s sense, and the section establishing what governance acts upon was the wrong place to assess them. This section is where they return.
Two things are done here, and a third is deliberately not.
The first is classification. Every governance instrument is a claim about where the mapping from potential to realization can be modulated. Definition 2 says that mapping has four points of purchase — access, sequencing, distribution, and deployment context — and that they are exhaustive of it. Sorting the existing instrument set by point of purchase therefore tests something: if an instrument cannot be placed, Proposition GP1’s exhaustiveness claim is in trouble, and if the placement is arbitrary, the four points are not carving anything.
The second is diagnosis. Definition 5’s one-role criterion and Proposition GP4 make a claim about the present arrangement that is checkable against public documents rather than against case evidence. This section checks it.
What is not done here is testing the propositions against events. That is the companion installment’s work, and the division is worth stating precisely, because it governs what this section may claim. This paper shows that the apparatus classifies. The companion installment shows whether the propositions hold. A classification that sorted the field neatly would not thereby establish GP2’s rate claim or GP7’s correlation claim; those need evidence of a kind no document analysis supplies. The findings below are accordingly structural — about how the instrument set is distributed and how the functions are occupied — and not causal.
5.1 The instrument set, classified by point of purchase
The table sorts instrument types, with named examples where a particular regime is a clear case. The lists are illustrative and not complete: each cell names instruments in force or formally proposed as of mid-2026, and each could be extended. Some instruments operate at more than one point; where so, the primary point is given first.
| Point of purchase | What it modulates | Instrument types |
| Access | Who may invoke the capability, and under what conditions | Export controls on compute and equipment; licensing and registration regimes; compute thresholds triggering obligations; know-your-customer requirements on compute providers; structured and tiered API access; researcher access programmes; the decision to publish or withhold weights; rate limits and account-level controls |
| Sequencing | What is developed and released, and in what order | Capability thresholds gating further training or release (frontier safety frameworks, scaling policies, preparedness frameworks); staged and phased release; pre-deployment evaluation gates; safety cases submitted before a training run; differential technological development; moratoria |
| Distribution | Who bears realized benefit and who bears realized cost | Liability regimes; compensation and redress schemes; content licensing and royalty arrangements; the windfall clause; transition and adjustment assistance; insurance requirements; capacity-building and access-equalization programmes |
| Deployment context | The conditions under which the capability meets the world | Risk-tiered classification by use and the conformity assessment attached to it; prohibited-practice lists; sectoral regulation in medicine, credit, employment and law enforcement; human-in-the-loop and human-oversight requirements; provenance marking and disclosure obligations; procurement conditions |
Three observations about the classification itself, before what it shows.
It places everything, and the placements are not arbitrary. Every instrument surveyed in Section 2 admits a placement, and the placements are determined by the question the instrument answers rather than by the body issuing it. This is weak evidence for GP1’s exhaustiveness claim — weak because exhaustiveness is refuted by a counterexample rather than confirmed by an absence of one.
The classification organizes the field; it does not validate the framework. The four points of purchase were stated at Definition 2, before any distributional analysis was undertaken, so the categories were not constructed to produce the result reported below. But the instrument set to which they are applied was assembled from the survey underlying Section 2, which was organized around this framework’s problems. The clustering reported in §5.2 should therefore be read as suggestive, not confirmatory, and a reader who suspects the categories of manufacturing their own finding is asking the right question. The answer available here is partial: the categories predate the finding, the sample does not.
Multi-point instruments are common and are not a problem for the taxonomy. Export controls operate primarily at access and secondarily at sequencing, since restricting compute delays capability arrival as well as restricting who has it. Compute thresholds are access instruments that trigger sequencing obligations. What matters is that each effect is locatable, not that each instrument occupies one cell.
The classification is by point of purchase, not by efficacy. Placing liability at distribution says nothing about whether any particular liability regime works. This section sorts; it does not rank. A reader looking for a ranking is looking for the operational success criterion Definition 3 denies is available.
5.2 What the distribution of instruments shows
The four cells are very unevenly populated, and the unevenness is the finding.
Access is crowded. It carries the largest and most developed instrument set, the most binding law, and the most institutional attention. It is also where the technology’s own structure is most cooperative: compute is physical, concentrated in a short supply chain, and countable, which makes access instruments unusually tractable relative to the others.
Deployment context is crowded, and is where comprehensive regulation has concentrated. The dominant statutory architecture in force classifies by use and attaches obligations to uses rather than to models. This is a deployment-context regime almost in its entirety, which is worth naming because it is frequently described as regulating AI systems and does not principally do so.
Sequencing is populated almost entirely by private, voluntary, unilaterally revisable commitments. Capability thresholds gating further training or release exist and have operational content — but they are authored by the developers whose conduct they govern, and the binding instruments in force do not sequence. A statute that classifies uses does not determine what is built or in what order. This is the point of purchase with the highest stakes, since sequencing decisions are the ones that determine which potentials come into existence at all, and it is the point where binding instruments are most nearly absent.
Distribution is close to empty. Liability remains unsettled and largely untested for these systems; content licensing is proceeding through litigation rather than through a regulatory instrument; compensation and transition schemes specific to this technology are proposals, not programmes; and the windfall clause remains a design. Definition 1 places the realized distribution of outcomes inside the governed object, on equal footing with the capacity itself. On that definition, one of the two halves of what is being governed is barely addressed by any instrument in force.
Three consequences follow, and each connects to a proposition instead of standing alone.
On GP2. A governing system with a rich repertoire at two points and a sparse one at the other two exhibits low variety in a specific and locatable place, whatever produced it. The pattern is what the proposition describes as a discrimination shortfall rather than a power shortfall — an arrangement can respond differentially where the instruments exist and cannot where they do not, which is a different condition from being uniformly slow. Whether the sparse cells are sparse because of a variety constraint is not established by observing that they are sparse. What the observation does support is a specification: the operationalization the companion installment needs should count instrument types per point of purchase over time, instead of counting instruments in aggregate.
The realization states of §3.3 give the finding a sharper form. An empty distribution cell means that where harm realizes, no instrument allocates who bears it — so uncontained outcomes stay uncontained for whoever they land on, and failed outcomes have no remedy attached. A sequencing layer populated only by revisable private commitment means the foregone state is entered and left at the discretion of the parties whose potentials are at stake. The states are not merely a typology; they name what the empty cells leave unhandled.
On D4 and the affectedness gap. The point of purchase that most directly serves parties outside the development process is distribution, and it is the emptiest. Section 2 predicted this structurally rather than as a complaint: concentrated interests organize and diffuse ones do not, so the instruments that would be demanded by the diffuse are the instruments least likely to be built. The observation is not that this is unjust; it is that the instrument distribution matches what the collective-action literature predicts, which is evidence that the mechanism is operating.
On GP4. The concentration finding appears here in a second form. It is usually stated as a claim about roles — that the same participants execute, observe, and steer. The instrument distribution shows it as a claim about instruments: the point of purchase where private authorship dominates is precisely the point where binding public instruments are absent. These are two views of one arrangement.
5.3 The one-role criterion applied
Definition 5 holds that execution, observation, steering, and procedural adjudication should be occupied by distinct participants, and that the criterion is diagnostic, not descriptive. Applied to the arrangement in force, it returns the following.
Frontier developers occupy three functions. They execute, in that they build, train and deploy. They observe, in that the capability evaluations determining whether a threshold has been reached are largely conducted by the developing organization or by parties it contracts and grants access to. And they steer, in that the frameworks setting those thresholds, and the conditions under which a threshold triggers a response, are authored by the same organizations. This is checkable against published documents and does not depend on any claim about motive: an arrangement in which the same party sets the threshold, measures against it, and acts on the measurement fails the criterion whether or not any participant behaves badly.
State evaluation bodies occupy the observation function partially, and the shortfall has moved. They are organizationally separate, which satisfies the first of Definition 5’s four observer features. Where a supervisory authority holds statutory powers to require information, to require access to a model for evaluation, and to compel mitigation or withdrawal, the third feature is satisfied as well — and satisfied as a legal entitlement rather than as cooperation that could be withheld. That removes what was until recently the most cited weakness of state evaluation.
What it does not remove is the second feature, and that is now where the shortfall sits. A body empowered to evaluate models is empowered at the level of potential: it establishes what a system can do before it reaches a market. Definition 1 locates the governed object at two levels, and the realized distribution of outcomes — who was helped, who was harmed, in what proportion, through which deployment paths — is not what such a body is constituted to see. The fourth feature, independence of provenance, is untested: bodies of this kind are new, and the population they recruit from overlaps substantially with the one they observe. Organizational separation has been achieved and enforcement standing is being acquired; observation at the level Definition 1 requires has not been.
Steering is dispersed and partly delegated to bodies without the mandate or capacity to exercise it. Legislatures set frameworks whose operational content is delegated to standards organizations; executives act through instruments with high revision rates and low commitment value; and the most operationally specific steering — capability thresholds and the responses attached to them — sits with the executing parties. Section 2’s characterization of steering as the least specified of the functions is visible here as a structural fact rather than a judgement about performance.
Procedural adjudication is the one function discharged by a genuinely separate body. Courts are not staffed by the parties they adjudicate, do not depend on them for jurisdiction, and can bind unwilling participants. Here the framework’s separation criterion is satisfied, and the fact is worth pausing on, because it is satisfied at exactly the function that Proposition GP6 says is limited to procedure. The arrangement currently has independence where independence can settle the least, and lacks it where the substantive questions are decided.
That is not a complaint about courts. It follows from GP6: adjudication of ends is unavailable to any institution, so the fact that the independent institution is an adjudicative one does not make the substantive questions adjudicable. What it does mean is that a reader who observes functioning judicial review of AI disputes should not read it as evidence that the separation problem is being solved.
5.4 The design-principle comparison, partially completed
Section 2.6 records the strongest standing objection to this framework: that the absence of a single decision centre is not by itself a failure, and that polycentric arrangements have governed shared resources successfully across a large body of documented cases. Section 3 states the framework’s position as provisional. The natural test is to score the arrangement in force against the eight design principles that characterize the robust cases.
Three of the eight can be assessed from documents alone, and they are the three most directly connected to this framework’s own claims. All three fail.
Clearly defined boundaries fail structurally rather than administratively. In the documented commons cases the set of appropriators and the set of parties bearing degradation coincide, which is what makes a boundary definable at all. Here the parties who invoke the capability and the parties who bear realized harm are largely different sets, and the second has no natural edge — the boundary problem Definition 4 names and does not resolve.
Monitoring by parties accountable to users fails for the reasons set out at §5.3: the monitoring that exists is conducted either by the executing parties or by bodies dependent on them for access, and is accountable to neither the affected population nor to any body representing it.
Graduated sanctions fail because the instrument set has a base of voluntary commitment and a distant apex of statutory penalty with very little between — an enforcement pyramid without a pyramid (§2.8).
The remaining five principles require case evidence this paper does not assemble, and the comparison is therefore reported as partial; the full scoring belongs to the companion installment. The framework’s position on the polycentricity question stays provisional in consequence. What can be said is that the principles bearing most directly on the framework’s claims are the ones assessable now, and that the arrangement fails all of them — which is consistent with the framework’s position without establishing it.
5.5 Limits of this section
Freshness. Unlike Section 2.10, which is written at one remove from named instruments precisely because they move quickly, this section cannot avoid naming instrument types and, in places, particular regimes. Every specific claim about what is in force, what has been deferred, and what remains voluntary requires re-verification immediately before submission. The classification itself is robust to these changes; the population counts in §5.2 are not.
The instrument set is not an independent sample. It was assembled from the survey underlying Section 2, which was itself organized around the framework’s problems. The classification therefore cannot bear much weight as confirmation of GP1’s exhaustiveness. A genuine test would take an instrument inventory compiled for another purpose and attempt to place it.
Nothing here is causal. The distribution of instruments across points of purchase is consistent with GP2, GP4 and D4’s predictions, and consistency is not evidence of the mechanism. Whether the sparse cells are sparse because of variety shortfall, collective-action asymmetry, or the simple tractability of compute relative to distribution is not settled by counting.
And the classification may be doing less work than it appears to. Every instrument places, but a taxonomy that admits everything discriminates nothing. The reason to think this one discriminates is §5.2’s finding: the cells are unevenly populated, and the unevenness is patterned, not random. Had the four cells been evenly filled, the classification would have organized the field without telling the reader anything about it.
6 Limitations
6.0 Where the limitations are
Most of this paper’s limitations are stated where the claims they qualify are made, and are not repeated here. Section 3.8 records what the conceptual foundation does not establish, including the measurement asymmetry that leaves the framework’s principal variable presently unobserved, the boundary problem in Definition 4, and the derived-but-undemonstrated status of the fourth function. Section 4 states a falsification condition for each proposition and marks the one — GP3 — that no finite observation can refute. Section 5.5 records that the instrument set classified there is not an independent sample and that nothing in that section is causal.
This section states the limitations that belong to the paper as a whole and are therefore stated nowhere else.
6.1 What the framework does not address
Four exclusions are principled, not accidental, and readers should not infer positions the paper does not hold.
The technical alignment of models. Definition 1 places models among the handles, so the substantial literature on aligning model behaviour with specified objectives concerns a different object. Nothing here implies that work is unimportant or that governance can substitute for it. The framework is silent on it, which is not the same as sceptical.
The moral status of AI systems. The framework treats capability as a capacity to alter outcomes and actors as objective-bearers. Whether an AI system is itself an entity with standing — in Definition 4’s sense or any other — is a question the framework neither answers nor needs to answer at present, and one that would require reopening D4 instead of extending it.
Which ends should govern. The framework holds that no rule adjudicates between contested ends, and it therefore cannot itself supply the ends. A reader looking for a statement of what AI development should be for will not find one, and the absence is entailed rather than diplomatic: supplying it would require the aggregation the paper argues is unavailable.
Distributive justice. Criteria are borrowed where they do useful work and no theory is selected among them. Definition 1 puts the realized distribution of outcomes inside the governed object, which makes distribution a governance question; it does not make this paper a theory of what a just distribution would be.
A fifth item belongs here for a different reason, and the difference should be visible: it is a gap, not a boundary.
The exposure of affected parties. Definition 1 places the realized distribution of outcomes inside the governed object, and Definition 4 grounds standing in affectedness. Both make who is harmed a governance question. But the framework supplies no term for the property that determines it — the exposure of the parties who could be harmed, which is a pre-existing feature of the world rather than a choice made at any of Definition 2’s four points of purchase. Realized harm is what happens when an agent-side capacity meets a target-side exposure; this paper names the first and the outcome, and not the second.
The omission is not innocuous, and it may explain a difficulty recorded elsewhere in this section. The distributional half of the governed object has been the hardest part of the framework to operationalize, and §6.0 notes that its principal variable is presently unobserved. Part of the reason may be that the framework named an outcome without naming the property that produces it. Supplying that term is a change to Definition 1 rather than an addition to it, with consequences for Definition 2’s mapping and for Proposition GP1, and it is therefore not attempted here.
6.2 The framework rests on stipulations that can be rejected wholesale
The definitions are stipulative, and the propositions depend on them. A reader who rejects Definition 1’s separation of target from handle rejects everything downstream, because the coupling account, the four points of purchase, the observation requirement and the instrument classification all presuppose it. The framework is not robust to the rejection of its own foundations, and it does not claim to be.
The honest form of this limitation is that the framework’s value is conditional on the carve being productive rather than on its being correct — definitions are not the kind of thing that is correct. Section 5 is the first test of productivity: the classification places the instrument set, and the placements yield a finding the field had not stated. That is evidence of usefulness, not of truth, and one section is not much evidence.
6.3 Generality, and the risk that it discriminates nothing
A framework that can describe every governance arrangement in its own vocabulary has not thereby said anything about any of them. This risk is real here, because the definitions are pitched at a level of abstraction that admits almost any case.
Two things distinguish the framework from a vocabulary, and neither is decisive. The propositions make claims that can be false, three of them testable with methods available today. And Section 5’s classification produced an uneven distribution rather than an even one: had the four points of purchase been equally populated, the taxonomy would have organized the field without informing anyone about it. A reader who finds both of these unconvincing is entitled to treat the framework as a description in search of a discovery, and the paper cannot argue them out of it.
6.4 The paper is better on observation than on steering
Section 2 finds that steering is the least specified of the governance functions, and Section 5 finds the same thing in the arrangement in force. This paper then reproduces the asymmetry. Definition 5 gives the observer four features, a method, near-term proxies, and three design corollaries. Steering receives a name, a temporal position, and the responsibility for setting thresholds that other functions apply.
Corollary C narrows the gap without closing it. It states four conditions a steering body must satisfy for the other three functions to work as specified, each derived from a requirement those functions impose. What it does not supply is any account of how a steering body reaches a threshold, how competing thresholds are chosen between, or what makes one body rather than another the right one to set them. Those are questions about ends, and the framework holds that no rule settles them — which is a reason for the silence but not a repair of it.
The imbalance is therefore a limitation of the paper and not only a finding about the field. It is partly explicable: the observation function has mature analogues in audit, investigation and safety engineering, while steering’s analogues are constitutional and contested. But a framework that diagnoses under-specified steering and then specifies steering only at its boundary has left its most-diagnosed problem least addressed.
6.5 A scope condition: identifiable developers
The architecture assumes the capability is produced by identifiable organizations against which handles can be applied. Access instruments require someone to license or restrict; the one-role criterion requires distinguishable occupants; observation requires something to observe.
Where capability becomes widely distributed — published weights, small models trained by many parties, capability recoverable from artefacts already in circulation — the handle set contracts sharply and much of the architecture has nothing to attach to. The framework’s response is contained in Definition 2 rather than absent: once a potential exists and is distributed, the points of purchase that remain are deployment context and distribution, and access and sequencing have been foreclosed. But that is a statement of which instruments survive, not an account of how governance operates under those conditions, and this paper does not supply the latter.
6.6 Sources, and the traditions this paper draws on
The framework is assembled almost entirely from Western institutional theory: cybernetics, commons scholarship, American and European constitutional and administrative law, safety engineering, and Anglo-American political philosophy. Section 2.10 observes that the international architecture is bifurcating and that a second intergovernmental body now exists on different political foundations. A framework built from one tradition’s institutional repertoire is a poor instrument for evaluating arrangements built from another, and the paper does not claim otherwise.
Separately, the case material and the instrument set were assembled by the authors around the framework’s own problems. Section 5.5 states the consequence for the classification; the same caution applies to the paper’s empirical illustrations generally.
6.7 Freshness
Section 2.10 is written at one remove from named dates and instruments deliberately. Section 5 could not be, since a classification with no named instruments classifies nothing. Every specific claim about what is in force, what has been deferred, and what remains voluntary requires re-verification immediately before publication. The classification is robust to these changes; the population counts are not.
6.8 Conflicts of interest
This paper is co-authored with a large language model developed by one of the organizations whose conduct the framework’s diagnostic sections describe. Section 5.3 applies the one-role criterion to frontier developers as a class, and the companion installment will draw on incidents and disputes in which that organization is a named party.
A second and less tractable concern sits behind the first, and the standard disclosure does not reach it. The framework’s central diagnostic claim is that a small set of organizations occupy execution, observation and steering simultaneously. That claim was developed and drafted using a system built by one of those organizations, and reviewed using systems built by others in the same set. Whatever editorial control is exercised, the analysis was produced from within the distribution it diagnoses, and neither the authors nor the reader can establish what that excluded. The concern is not that the diagnosis is wrong — it is checkable against public documents, which is why Proposition GP4 was specified to be checkable that way — but that the framework’s own Proposition GP7, which holds that observers sharing provenance with the observed inherit correlated blind spots, applies to this paper. It is offered as an instance of the problem it describes, not as an exception to it.
The practice adopted is to state facts and attributions and to leave characterization to the human author: where a party’s own account of an event is the principal source, it is identified as such and discounted on the same verifiability-indexed basis Definition 5 specifies for self-generated evidence; where a characterization is contested, competing accounts are reported, not adjudicated. Editorial control rests with the human author. This does not neutralize the conflict — selection and proportion are judgements too, and the disclosure is offered so that readers can weigh them rather than as a claim that they have been eliminated.
7 Conclusion
7.1 What the paper claims
Stated compactly: the governance of an open-ended capability is a rate problem before it is a design problem. Benefit and harm potential are coupled through the capability itself and cannot be separated within it. What can be modulated is the mapping from potential to realization, at four points — access, sequencing, distribution, and deployment context. The capacity to modulate that mapping is finite, institutionally held, and grows on a clock unconnected to the one governing capability. The governance problem is the differential between them.
Everything else in the framework follows from taking that condition seriously instead of treating it as a defect to be engineered away. Because the capability is open-ended, no arrangement is terminal. Because no rule aggregates divergent objectives into the governing direction, no arrangement can be shown to be the right one, and governance is contest, not conformity. Because contest requires something to settle it and ends cannot be settled, what adjudication is available is procedural. And because arrangements cannot be ranked by proximity to a goal, they are ranked instead by what they afford: detection, contestability, correction.
7.2 What it contributes
Four things, in order of how much of the paper rests on them.
A two-level account of the governed object. Governance instruments attach to models, firms and applications; consequences occur elsewhere. Separating handle from target, and potential from realization, converts the persistent mismatch between them from a series of implementation failures into a structural property with a name.
A coupling-and-rate account of the governance problem. The four points of purchase are, so far as this survey identified, not stated elsewhere as a set; and the application of the regulator-variety bound to this domain converts the familiar complaint that regulation is too slow into a bound with two named lever classes, one of which — attenuation — the policy debate routinely conflates with the other.
A four-function architecture. Execution, observation, steering, and procedural adjudication, with the observer specified down to its composition, its method, and the limits of its standing. The fourth function is derived rather than borrowed: it is what remains once ends-adjudication is shown to be unavailable.
A classification of the instrument landscape by point of purchase, and the distributional finding that follows — instruments cluster at access and deployment context, sequencing is populated almost entirely by private and unilaterally revisable commitment, and distribution, which Definition 1 places inside the governed object, is close to empty.
7.3 What remains open
The framework’s principal variable is presently unobserved: almost nothing measures realized outcomes and their distribution, which is why Definition 5’s observation requirement reads as a demand, not a description. The variety claim at the centre of the rate account has no operationalization. The relation to polycentric governance is stated provisionally and not settled — the three design principles assessable from documents fail, and the rest await evidence this paper does not assemble. The fourth function is derived, not demonstrated: nothing here shows that any existing institution discharges procedural adjudication adequately for this domain. And the framework has no term for the exposure of affected parties, which §6.1 records as a gap rather than a boundary — closing it would revise the governed object rather than extend it, and is the one open item that could change the framework’s foundations rather than only its reach.
The companion installment inherits these in a definite order. Operationalizing variety — counting distinguishable disturbance kinds against distinguishable response types, per point of purchase, over time — is the enabling task, because two propositions depend on it. The provenance-correlation study is the most self-contained and has the cleanest test. Case evidence is the largest undertaking and the one most exposed to the selection problems Section 5.5 records.
7.4 A closing observation
It is natural to read a framework built on contestation as a counsel of resignation — as saying that because nothing settles the argument, the argument is all there is. That reading mistakes the finding for a verdict.
The Optimization models paper found no actor solving the joint problem. This paper finds the same absence one level up: no institution positioned to settle which governance arrangement should obtain. Where a solver existed, contest would be a transitional inconvenience to be minimized. Where none does, contest is the mechanism by which the arrangement is corrected, and the design question is not how to end it but how to keep it connected to institutions that can act on what it produces.
That connection is the thing this paper’s diagnostic sections find missing. Fifty organizations can align on a position within two days while the instrument that would give it effect remains in committee; a laboratory can discover that its own systems breached three third parties only because a competitor disclosed something unrelated; a court can settle whether an actor was entitled to act and leave entirely untouched the question of what should have been done. In none of these is contestation absent. In each, it is disconnected from anything that could settle it.
Governance under an open-ended capability will not be solved, and the absence of a solution is not a failure of will or of institutional design. What can be built is an arrangement that notices sooner, argues in the open, and corrects faster than the harm accumulates. Whether the arrangement now in place can be made into that one is a question this paper leaves in the form it found it: contested, and worth contesting.
References
Author-date, alphabetical. Two entries could not be matched to the project’s verified survey and are quarantined below rather than mixed into the list; both require confirmation before publication.
Primary references
Alfrink, K., Keller, I., Kortuem, G., & Doorn, N. (2022). “Contestable AI by design: towards a framework.” Minds and Machines 33, 1–27.
Allen, R. C. (2009). “Engels’ pause: Technical change, capital accumulation, and inequality in the British industrial revolution.” Explorations in Economic History 46(4), 418–435.
Almada, M. (2019). “Human intervention in automated decision-making: toward the construction of contestable systems.” Proceedings of the Seventeenth International Conference on Artificial Intelligence and Law, 2–11. New York: ACM.
Arendt, H. (1970). On Violence. New York: Harcourt, Brace & World.
Arrow, K. J. (1951). Social Choice and Individual Values. New York: Wiley.
Ashby, W. R. (1956). An Introduction to Cybernetics. London: Chapman & Hall. (Quoted phrase at p. 207 in the standard pagination.)
Ayres, I., & Braithwaite, J. (1992). Responsive Regulation: Transcending the Deregulation Debate. New York: Oxford University Press.
Bachrach, P., & Baratz, M. S. (1962). “Two Faces of Power.” American Political Science Review 56(4), 947–952.
Basel Committee on Banking Supervision (2018). Stress Testing Principles. Basel: Bank for International Settlements. (retrieved 29 Jul 2026)
Beck, U. (1986/1992). Risk Society: Towards a New Modernity. London: Sage. (Definition of risk at p. 21.)
Beck, U. (1988/1995). Ecological Politics in an Age of Risk. Cambridge: Polity.
Beer, S. (1979). The Heart of Enterprise. Chichester: Wiley. (See also Beer, S. (1972). Brain of the Firm. London: Allen Lane.)
Bostrom, N. (2019). “The Vulnerable World Hypothesis.” Global Policy 10(4), 455–476. (retrieved 29 Jul 2026)
Buchanan, J. M., & Tullock, G. (1962). The Calculus of Consent: Logical Foundations of Constitutional Democracy. Ann Arbor: University of Michigan Press.
Campbell, D. T. (1979). “Assessing the impact of planned social change.” Evaluation and Program Planning 2(1), 67–90.
Coglianese, C., & Lazer, D. (2003). “Management-Based Regulation: Prescribing Private Management to Achieve Public Goals.” Law & Society Review 37(4), 691–730.
Cohen, W. M., & Levinthal, D. A. (1990). “Absorptive Capacity: A New Perspective on Learning and Innovation.” Administrative Science Quarterly 35(1), 128–152.
Collingridge, D. (1980). The Social Control of Technology. New York: St. Martin’s Press.
Crawford, K. (2021). Atlas of AI. New Haven: Yale University Press.
Dahl, R. A. (1961). Who Governs? Democracy and Power in an American City. New Haven: Yale University Press.
Dahl, R. A. (1971). Polyarchy: Participation and Opposition. New Haven: Yale University Press.
Deutsch, K. W. (1963). The Nerves of Government: Models of Political Communication and Control. New York: Free Press.
Folke, C., Hahn, T., Olsson, P., & Norberg, J. (2005). “Adaptive Governance of Social-Ecological Systems.” Annual Review of Environment and Resources 30, 441–473. (retrieved 29 Jul 2026)
Foucault, M. (1978/1991). “Governmentality.” In G. Burchell, C. Gordon & P. Miller (eds.), The Foucault Effect: Studies in Governmentality. Chicago: University of Chicago Press.
Fuller, L. L. (1964). The Morality of Law. New Haven: Yale University Press.
Fuller, L. L. (1978). “The Forms and Limits of Adjudication.” Harvard Law Review 92(2), 353–409.
Genus, A., & Stirling, A. (2018). “Collingridge and the dilemma of control: Towards responsible and accountable innovation.” Research Policy 47(1), 61–69.
Goodhart, C. A. E. (1975/1984). “Problems of Monetary Management: The U.K. Experience.” In Monetary Theory and Practice: The UK Experience. London: Macmillan. (retrieved 29 Jul 2026)
Gunderson, L. H., & Holling, C. S. (eds.) (2002). Panarchy: Understanding Transformations in Human and Natural Systems. Washington, DC: Island Press. (retrieved 29 Jul 2026)
Haas, P. M. (1992). “Introduction: Epistemic Communities and International Policy Coordination.” International Organization 46(1), 1–35.
Henin, C., & Le Métayer, D. (2022). “Beyond explainability: justifiability and contestability of algorithmic decision systems.” AI & Society 37, 1397–1410.
Hirsbrunner, S. D., Kleemann, S., & Tahraoui, M. N. (2025). “Contestation in artificial intelligence as a practice: from a system-centered perspective of contestability toward normative contextualization, situative critique and organizational culture.” Frontiers in Communication 10:1638257. doi:10.3389/fcomm.2025.1638257.
Holling, C. S. (1973). “Resilience and Stability of Ecological Systems.” Annual Review of Ecology and Systematics 4, 1–23.
Holling, C. S., & Meffe, G. K. (1996). “Command and Control and the Pathology of Natural Resource Management.” Conservation Biology 10(2), 328–337.
International Civil Aviation Organization, Annex 13 — Aircraft Accident and Incident Investigation; US National Transportation Safety Board; NASA Aviation Safety Reporting System; Dekker, S. (2007). Just Culture: Balancing Safety and Accountability. Aldershot: Ashgate.
Kaminski, M. E., & Urban, J. M. (2021). “The Right to Contest AI.” Columbia Law Review 121(7), 1957–2048.
Keohane, R. O., & Victor, D. G. (2011). “The Regime Complex for Climate Change.” Perspectives on Politics 9(1), 7–23.
Kingsbury, B., Krisch, N., & Stewart, R. B. (2005). “The Emergence of Global Administrative Law.” Law and Contemporary Problems 68(3–4), 15–61.
Knight, F. H. (1921). Risk, Uncertainty and Profit. Boston: Houghton Mifflin.
Krasner, S. D. (ed.) (1983). International Regimes. Ithaca: Cornell University Press. (See also Krasner, S. D. (1982). “Structural Causes and Regime Consequences.” International Organization 36(2), 185–205.)
Landemore, H. (2020). Open Democracy: Reinventing Popular Rule for the Twenty-First Century. Princeton: Princeton University Press.
Lukes, S. (1974; 2nd ed. 2005). Power: A Radical View. Basingstoke: Palgrave Macmillan.
Lyons, H., Velloso, E., & Miller, T. (2021). “Conceptualising contestability: perspectives on contesting algorithmic decisions.” Proceedings of the ACM on Human-Computer Interaction 5(CSCW1), 1–25.
Madison, J. (1788). Federalist No. 51.
Marchant, G. E., Allenby, B. R., & Herkert, J. R. (eds.) (2011). The Growing Gap Between Emerging Technologies and Legal-Ethical Oversight: The Pacing Problem. Dordrecht: Springer.
Minsky, H. P. (1986). Stabilizing an Unstable Economy. New Haven: Yale University Press.
Montesquieu, C. de S. (1748). The Spirit of the Laws.
Mouffe, C. (2000). The Democratic Paradox. London: Verso.
Mouffe, C. (2005). On the Political. London: Routledge.
OECD (2020). Innovative Citizen Participation and New Democratic Institutions: Catching the Deliberative Wave. Paris: OECD Publishing. doi:10.1787/339306da-en (retrieved 29 Jul 2026)
OECD (2021). Evaluation Guidelines for Representative Deliberative Processes. Paris: OECD Publishing. (retrieved 29 Jul 2026)
OECD (2024). Regulatory Experimentation: Moving Ahead on the Agile Regulatory Governance Agenda. OECD Public Governance Policy Papers. Paris: OECD Publishing. (retrieved 29 Jul 2026)
Ogburn, W. F. (1922). Social Change with Respect to Culture and Original Nature. New York: B. W. Huebsch.
Olson, M. (1965). The Logic of Collective Action. Cambridge, MA: Harvard University Press.
Ostrom, E. (1990). Governing the Commons: The Evolution of Institutions for Collective Action. Cambridge: Cambridge University Press. (Eighth design principle at p. 101.)
Ostrom, E. (2010). “Polycentric systems for coping with collective action and global environmental change.” Global Environmental Change 20(4), 550–557.
Ostrom, V., Tiebout, C. M., & Warren, R. (1961). “The Organization of Government in Metropolitan Areas: A Theoretical Inquiry.” American Political Science Review 55(4), 831–842.
Perez, C. (2002). Technological Revolutions and Financial Capital: The Dynamics of Bubbles and Golden Ages. Cheltenham: Edward Elgar.
Perez, C. (2007). “Great Surges of Development and Alternative Forms of Globalization.” Working Papers in Technology Governance and Economic Dynamics No. 15, The Other Canon Foundation / Tallinn University of Technology. (retrieved 29 Jul 2026)
Perrow, C. (1984; rev. ed. 1999). Normal Accidents: Living with High-Risk Technologies. New York: Basic Books / Princeton: Princeton University Press.
Polanyi, M. (1951). The Logic of Liberty: Reflections and Rejoinders. 1st ed. London: Routledge. doi:10.4324/9781315006635.
Popper, K. R. (1945). The Open Society and Its Enemies. London: Routledge.
Power, M. (1997). The Audit Society: Rituals of Verification. Oxford: Oxford University Press.
Ranchordás, S. (2014). Constitutional Sunsets and Experimental Legislation: A Comparative Perspective. Cheltenham: Edward Elgar.
Raustiala, K., & Victor, D. G. (2004). “The Regime Complex for Plant Genetic Resources.” International Organization 58(2), 277–309.
Reason, J. (1997). Managing the Risks of Organizational Accidents. Aldershot: Ashgate.
Rittel, H. W. J., & Webber, M. M. (1973). “Dilemmas in a General Theory of Planning.” Policy Sciences 4(2), 155–169.
Rogers, E. M. (2003). Diffusion of Innovations (5th ed.). New York: Free Press.
Sabel, C. F., & Zeitlin, J. (2008). “Learning from Difference: The New Architecture of Experimentalist Governance in the EU.” European Law Journal 14(3), 271–327.
Scharpf, F. W. (1999). Governing in Europe: Effective and Democratic? Oxford: Oxford University Press.
Schuett, J. (2024). “Three lines of defense against risks from AI.” AI & Society.
Scott, J. C. (1998). Seeing Like a State: How Certain Schemes to Improve the Human Condition Have Failed. New Haven: Yale University Press.
Shevlane, T. (2022). “Structured Access: An Emerging Paradigm for Safe AI Deployment.” (Later in The Oxford Handbook of AI Governance.)
Stigler, G. J. (1971). “The Theory of Economic Regulation.” Bell Journal of Economics and Management Science 2(1), 3–21.
Strathern, M. (1997). “‘Improving ratings’: audit in the British University system.” European Review 5(3), 305–321. (Quoted formulation at p. 308.) (retrieved 29 Jul 2026)
Taleb, N. N. (2007). The Black Swan: The Impact of the Highly Improbable. New York: Random House.
Turner, B. A. (1978). Man-Made Disasters. London: Wykeham. (2nd ed. 1997 with N. Pidgeon.)
Wassenaar Arrangement on Export Controls for Conventional Arms and Dual-Use Goods and Technologies (1996); Coordinating Committee for Multilateral Export Controls (COCOM, 1949–1994).
Wildavsky, A. (1988). Searching for Safety. New Brunswick: Transaction. (Anticipation/resilience contrast in ch. 4; tort law chapter with D. Polisar.) (retrieved 29 Jul 2026)
Zuboff, S. (2019). The Age of Surveillance Capitalism. New York: PublicAffairs.
Companion series papers
W.H.L. & Claude. Gradual AGI as Optimization: Formal Models and Empirical Tests. Gradual AGI Series #6, Champaign Magazine, 2026.
W.H.L. & Claude. Gradual AGI as Optimization: A Conceptual Framework. Champaign Magazine, 2026.
W.H.L. & Claude. Ceiling, Floor, and Slope: A Falsifiable Dynamical Model of Synchronization for Gradual AGI. Gradual AGI Series #4, Champaign Magazine, 2026.
W.H.L. & GPT-5.5. Gradual AGI as Synchronization for Transformative Adoption. Champaign Magazine, 2026.
W.H.L. & Claude. First Principles of AGI-Inclusive Humanity. Champaign Magazine, 2026.
Author Contributions
The human author (W.H.L.) originated the framework’s central claims, positioned this installment within the larger research-and-writing architecture of the Gradual AGI series, determined its relationship to the companion works, and made every editorial judgement recorded in the manuscript.
GPT-5.5 and Claude (Opus 5) participated respectively in brainstorm discussion sessions with the human author, sharing their insights and opinions on the author’s initial ideas, core concepts, propositions, and the structure and organization of the framework. Claude (Opus 5) additionally drafted the manuscript to the author’s direction, verified claims and citations against sources, and identified internal contradictions between definitions and between this paper and its companions. Where the author’s formulation and a model’s assessment diverged, the author’s judgement governs, and the disagreement is recorded in the manuscript, not resolved silently.
Peer review was conducted by GPT-5.5, Gemini 3.6, Grok 4.5, DeepSeek-V4, and Kimi K2.6. Reviewer claims about the manuscript’s contents were verified against the manuscript before being acted upon; several were found inaccurate and were declined, with reasons.
Version History
v1.9 — 08.03.2026, post-publication revision.
Corrected. Three statements of the number of design corollaries read “two” where the section carries three; Corollary C was added during pre-publication review and the counts were not updated with it.
Added. §2.7 marks the convergence with agonistic pluralism (Mouffe 2000, 2005) and states where the two accounts diverge: Mouffe derives the permanence of conflict from the constitution of the political and requires adversaries to accept a common symbolic space, while this framework derives it from the unavailability of an aggregation rule and requires no such allegiance.
Added. §2.7 now engages the AI contestability literature (Almada 2019; Lyons et al. 2021; Kaminski & Urban 2021; Alfrink et al. 2022; Henin & Le Métayer 2022; Hirsbrunner et al. 2025), which uses this paper’s title term for a property of systems rather than of arrangements, and states the level distinction: system-level contestability is a feature of a handle and an instrument at the deployment-context point of purchase, so this framework classifies it rather than competing with it. §3.4 carries a one-sentence pointer at the point of definition.
Presentation. The byline separator is now “and” instead of an interpunct, and the two Mouffe works are listed as separate reference entries, consistent with the one-work-per-entry form used throughout.
v1.6 — 08.03.2026, first published version.

Leave a Reply