Res Agentica
Reading

No saved reading position.

Reading

No saved reading position.

Chapter 1

What the Center Cannot See

The Raga and the Report

29 min read
Aa
Text size

For the listener, who listens in the snow, / And, nothing himself, beholds / Nothing that is not there and the nothing that is.

— Wallace Stevens, 'The Snow Man' (1921)

The Report

In the summer of 2020, public examinations in England did not take place. Ofqual still had to award grades. Schools supplied a predicted grade for each student and a rank order within each subject. A national standardization model then adjusted those submissions against each school's prior results. Very small cohorts were exempted because the statistical basis was too weak; medium-sized cohorts received a tapered treatment. The center knew that local evidence varied in reliability. It also knew that an unmoderated national result would be difficult to compare.

The model performed an intelligible public function. It tried to protect the meaning of a grade across thousands of schools when the common exam had disappeared. Yet its governing evidence was unevenly distributed. The school knew the student. The model knew the school. Neither knew the exam that never happened.

Across A-level entries, 59 percent of calculated grades matched teachers' center-assessed grades. In 39 percent, the calculated grade was lower. Those numbers do not establish that the model was wrong whenever it differed from a teacher. They establish that the choice of evidence moved consequences for a large minority of students. A national method could regularize institutions while obscuring the individual judgment it displaced. Four days after A-level results were released, Ofqual announced that students would receive the higher of the calculated grade and the center-assessed grade.

The episode is often told as an algorithmic morality play: machine against teacher, abstraction against person. That telling is too easy. Teacher predictions had their own errors and inequalities. Ofqual faced a real coordination problem, not a fictitious pretext. Its failure was constitutional. A consequential national judgment arrived before the affected student had an adequate way to expose why her local evidence had lost, contest the evidentiary choice, or obtain a remedy proportionate to the calendar governing university admission.

That distinction matters for computational governance. Central institutions remain necessary to compare outcomes, police discrimination, pool risks, preserve common standards, and intervene when local power becomes predatory. Their indispensable office is to see across cases. Their characteristic danger is to treat the view across cases as if it were the view from inside each one.

The question for this volume is therefore narrower than the familiar demand to align every system with a complete catalogue of human values. It is how a center can exercise its necessary office without pretending to possess the knowledge of every consequential crossing. The answer will require limits on what can be specified in advance, evidence that travels with the exercise of power, and forums able to hear what a model or ministry could not see.


Brahma's Laughter

In the Bhāgavata Purāṇa, King Kakudmī travels to the court of Lord Brahmā to ask which suitor is worthy of his daughter Revatī. He arrives at Brahmaloka and finds Brahmā engaged in hearing a musical performance by the Gandharvas, a single raga. Kakudmī is courteous. He waits. The performance is exquisite, its duration by Brahmā's measure brief. When the song ends, Kakudmī offers his obeisances and presents his question. He has prepared a list of candidates, men of standing in the world he left behind.

Brahmā laughs.

The laugh is not cruel. It carries something closer to tenderness. But what it recognizes is that Kakudmī's question has expired. Twenty-seven catur-yugas have passed while the raga played: ages of the world, civilizations risen and dissolved, lineages extinguished, the very kingdoms whose princes he had considered long since returned to dust. His question is syntactically intact and semantically void. The frame in which it made sense no longer exists. Brahmā advises him to give Revatī to Balarāma, because only someone of the present age can receive what belongs to it.

This is the structure of democratic deliberation under computational tempo. The raga is agent coordination: processes composing, settling, compounding at speeds no human governance can follow. The question is legislative process, judicial review, regulatory rulemaking: the mechanisms through which democratic societies constrain the exercise of power. Brahmā's laughter is the discovery that the world in which your deliberation was relevant has been replaced, not by violence or conspiracy, but by the accumulated drift of coordinations that concluded while you waited courteously for your turn to speak.

Call this the Kakudmī Problem: governance that operates at a tempo rendering some of its outputs obsolete upon completion. The bill moves through committee while the market prices and compounds. The regulation is drafted while the technology changes. The court issues its ruling after the pattern before it has migrated. Law can still alter the future. It may punish, compensate, disable, or deter. The temporal injury is that the person governed must often live through a concluded decision before any of those powers can reach it.

The governed do not experience the Kakudmī Problem directly. They experience the decision wake: the turbulence left by coordinations that completed before awareness could form. Prices settled while they slept. Opportunities opened and closed within a single inference cycle. Allocations compounded through cascades no observer could follow in real time. Brahmā's laughter is inaudible. The wake is what you feel.

The structural limits that follow—knowledge too dispersed to collect, values too tacit to exhaust in rules, decisions too numerous to inspect individually—grow sharper when coordination accelerates. Hayek's manager at least possesses the local fact long enough to act on it. A transient market pattern may disappear into its consequences before an observer can name it.

On May 6, 2010, a large trader began selling 75,000 E-mini S&P 500 futures contracts through an execution algorithm. The order represented about $4.1 billion in exposure. It entered a market already under stress, met other automated strategies, and helped produce a feedback sequence in which liquidity receded as volume intensified. Major index products fell sharply in minutes and then recovered. Some individual securities traded at absurd prices before trades were later cancelled. The joint CFTC–SEC reconstruction required the combination of records from markets whose participants had experienced the event as one system.

The event does not prove that speed defeats law or that one algorithm alone caused the crash. It shows the difference between a market's operating time and an institution's explanatory time. The trades could be reviewed, cancelled, and regulated after the fact. None of that supplied a participant, during the cascade, with a stable account of which process was acting, under whose authority, against what limits, or with what avenue to interrupt the sequence. Liability and investigation remain necessary. At machine tempo they arrive as retrospective government unless the action itself carries evidence adequate to the later forum.


The Knowledge Problem

In 1945, Friedrich Hayek published a short article that would become one of the most cited papers in economics. "The Use of Knowledge in Society" did not propose a new theory of markets. It proposed a new theory of knowledge.

Hayek's puzzle concerned how an economy coordinates millions of actors, each pursuing separate ends, without a central coordinator directing the whole. The planning debate turned in part on whether a sufficiently informed authority could allocate resources more rationally than competing firms.

Hayek's response changed the terms of the debate. The question was not whether a central authority should direct the economy. The question was whether a central authority could possess the knowledge that direction requires.

His answer was no, and his reason was structural. In 1920, Hayek's mentor Ludwig von Mises argued that comprehensive socialist planning without markets and money prices for producer goods could not perform the economic calculation required to allocate them rationally. The claim was not that every act of central coordination destroys knowledge. It was that abolishing the exchanges through which capital goods receive prices also abolishes signals the planner would need for comparison. Hayek extended that calculation argument into a broader account of dispersed knowledge.

Hayek extended this insight from calculation to knowledge itself.

The knowledge required for economic coordination is not the kind that can be written in reports or stored in databases. It is what Hayek called "knowledge of the particular circumstances of time and place." The factory manager knows which supplier is reliable this month. The shopkeeper knows which customers will pay. The farmer knows which field drains poorly. This knowledge is local, fleeting, often inarticulate. It exists in millions of minds, and it changes continuously as circumstances change.

A central planner could, in principle, collect some of this knowledge by filing reports, conducting surveys, populating databases. But by the time the report reaches headquarters, conditions have shifted. The reliable supplier has gone bankrupt. The paying customers have moved away. The poorly draining field has been sold. The knowledge that matters is precisely the knowledge that cannot survive the journey to the center.

Bandwidth is not the problem. Even perfect transmission would not solve it. The knowledge is not merely dispersed; it is fleeting. The factory manager's judgment about this supplier, this month, this order is knowledge that exists in the act of decision. By the time it could be reported, the decision has been made and the knowledge has served its purpose. What remains is a retrospective description—data, not knowledge. The planner who receives perfect reports receives a museum of past conditions, not a map of present possibilities.

Markets solve this problem through prices, and the mechanism deserves more than a passing nod, because the limitations that follow matter only in proportion to the mechanism's genuine power.

A price is a compressed signal that aggregates dispersed information without requiring anyone to possess that information directly. When copper becomes scarce, its price rises. Consumers economize; producers search for substitutes; miners increase extraction. No one needs to know why copper is scarce. The price carries the aggregate; the participant needs only the local. Prices accomplish four things simultaneously: they aggregate dispersed knowledge into a signal anyone can read, they motivate action without requiring agreement on purpose, they update continuously as conditions change without committee meetings or publication cycles, and they do all of this without any participant needing to understand the system as a whole. A farmer responds to the wheat price without knowing whether the price moved because of drought in Ukraine, dietary trends in China, or a futures trader's speculation.

Israel Kirzner extended the insight by describing markets as discovery processes as well as allocation mechanisms. The entrepreneur, alert to price discrepancies others have not noticed, generates and disseminates knowledge that no planner could have specified in advance. The profit opportunity that exists at 9 AM may vanish by noon because someone discovered it and acted. Conditions may not have changed. This is knowledge that exists only in the moment of its discovery and disappears in the moment of its use. No planning board can capture it because it exists only in the act of entrepreneurial judgment.

Hayek's later formulation sharpened the point. Competition is also a discovery procedure: it generates knowledge that does not exist before the competitive process occurs and cannot be specified in advance. The center cannot collect what competition has not yet produced. The alignment specification faces the same generative limit: what "aligned" behavior means in a particular context of use is knowledge that emerges from the encounter between system and user. It cannot be written into the model before the encounter occurs.

In economic coordination narrowly construed (the domain of production, exchange, and allocation), Hayek's prices remain superior to anything this framework proposes. Receipts are not better prices. They do not aggregate preferences more efficiently or coordinate production more nimbly. Anyone who reads the argument that follows as claiming that receipts replace prices has misunderstood the claim.

But prices aggregate preferences. They do not aggregate accountability. A price tells you what something costs; it cannot tell you whether the transaction was coerced. Prices reveal willingness-to-pay. They do not reveal whether the payment was authorized by someone with standing to authorize it. They coordinate production (what should be made, and how much?) but not governance: what power was exercised, over whom, and was it within bounds?

A borrower denied a mortgage may receive a price signal that reflects aggregate risk with admirable efficiency. Her individual denial also presents a governance problem when it discloses no factors and leaves no trace she can inspect or contest. No price, however efficient, provides that trace. The governing questions concern what happened to her and who must answer for it.

Receipts address the domain prices cannot reach. Where Hayek's price mechanism aggregates dispersed knowledge about value, the receipt regime aggregates dispersed evidence about authority. Both are decentralized. Both operate without requiring any participant to comprehend the whole. Both coordinate through signals rather than commands. The receipt extends Hayek into the domain his mechanism was never designed to serve: governance, where what matters is what power was exercised and whether it was within bounds.

One strong version of the aspiration to align AI with human values requires three steps: specify the relevant values, embed the specification, and verify compliance across contexts of use.

Modest as it sounds, the aspiration hides deeper limits. Human values are, after all, the values humans already hold. The task appears to be discovery and encoding, not creation. Surely, with sufficient study, the relevant values can be catalogued. With sufficient engineering, the catalogue can be embedded. With sufficient oversight, the embedding can be verified.

Each step confronts the same structural limit.

Specification: values differ across individuals, cultures, and moments. The same person may rank them differently when healthy and when sick, when young and when old, when alone and when observed. A principle that commands assent in the abstract becomes contested when a case determines what counts as unnecessary suffering.

Kenneth Arrow proved in 1951 that, with at least three alternatives, no social-welfare ordering can simultaneously satisfy unrestricted domain, Pareto unanimity, independence of irrelevant alternatives, completeness and transitivity, and non-dictatorship. The theorem is conditional, not a declaration that collective choice is impossible. A procedure can escape dictatorship by restricting preferences, relaxing independence, tolerating incompleteness, or abandoning another condition. The constitutional lesson drawn here is narrower: an aggregation rule does not dissolve disagreement. It selects which desiderata will yield, and that selection remains a political act.

Any specification of "human values" risks becoming too vague to guide action or too specific to accommodate legitimate variation. A committee that claims to have completed the specification has suppressed a disagreement. Its choice remains a political act that determines whose values count as "human," however much discovery informed it.

Embedding: a skilled doctor diagnoses through pattern recognition developed over years of practice. A good judge weighs circumstances that no rulebook enumerates. Michael Polanyi named this "tacit knowledge," the dimension of knowing that exceeds telling. Some of the knowledge required to navigate human values therefore resists prior specification.

Verification: pre-deployment testing and ex post auditing can inspect samples, architectures, controls, and observed failures. They cannot reproduce every context in which a general system will be used. The gap is qualitative as well as quantitative: the relevant property often emerges from the encounter among a model, a user, an institution, and a stake.

Regulators can sample. Adversaries will target the unsampled. They can audit. Adversaries will optimize for the audit. They can certify. The certificate will describe the system as it was, not as it becomes through deployment. Where knowledge is dispersed and judgment is contextual, central specification collapses into vagueness or misfit. Central verification collapses into sampling gaps or process theater.

The knowledge problem does not make alignment undesirable. It limits what centralized specification and verification can establish at machine scale. Some knowledge can be aggregated, some values can be stated as rules, and some conduct can be tested. The residue is the consequential case whose meaning depends on facts or judgment that the distant authority did not possess.

Successful alignment would be a considerable constitutional benefit. A system that understands what its users are trying to do, adapts intelligently to unfamiliar circumstances, and refuses to exploit their mistakes could prevent injuries that later review would only imperfectly repair. Such an achievement need not proceed through a complete catalogue of values written in advance. The knowledge problem is a reason to distrust that catalogue, not a proof that contextual learning must fail.

The question of authority nevertheless survives the achievement. A system may serve its principal faithfully while imposing terms on people whose interests the principal does not represent. Those people need standing to question the use of power, including an accurate and competently executed use. Even where their interests have been considered, someone must justify the decision about whose purposes govern and which burdens may be imposed. Better conduct makes that account easier to defend; it does not make the account unnecessary. If successful alignment is defined to include legitimate authority, affected parties' standing, and effective contest, it has included the constitutional work rather than abolished it.

No particular receipt architecture follows as a universal necessity. Law, professional institutions, technical constraints, and other arrangements may perform parts of the work described here. Their adequacy turns on whether consequential power is bounded and answerable to those it governs. We should welcome alignment that reduces the occasions for complaint while preserving institutions through which a justified complaint can still change what happens. The alternative is to let a promise of good government determine who will be allowed to question it.


High Modernism at Scale

The twentieth century tested this limit repeatedly. James C. Scott named the pattern.

Scott's most exact image is a forest. Early scientific forestry made the woodland legible as an inventory of commercially valuable timber. Foresters standardized species, age, spacing, and yield. On the administrative map, the new forest was an improvement: its outputs could be counted and planned. What vanished from the account were the relations that made a forest durable—mixed growth, dead wood, soil organisms, animals, local use, and the practical knowledge carried by people who lived through it. The simplified forest could produce impressive early yields and still become ecologically brittle.

The lesson is not that measurement ruins whatever it touches. Forestry requires measurement, and public administration cannot act without categories. The failure begins when an instrument designed to see one property is mistaken for a complete representation of the thing governed. Legibility then changes from aid to ontology. Whatever the table cannot register becomes noise; whatever resists standardization appears as defect.

Ofqual's model had this shape without the hubris sometimes imputed to it. It could see historical distributions, school-level patterns, submitted ranks, and cohort size. It could not see the cancelled examination or convert a school's knowledge of a student into nationally comparable evidence without loss. The center's mistake was not seeing from above. Someone had to. It was allowing the administrative view to become consequential before the person below had an adequate route to challenge what the view excluded.

This is the constitutional office of the center: to preserve common measures, compare patterns that no locality can see alone, maintain public backstops, and create forums in which local power can be answered. Its discipline is to remember that every map is proposition-specific. A center may know whether a distribution has shifted while remaining ignorant of why one student belongs at one point within it.

Computational systems intensify the temptation to forget that discipline because their representations are unusually rich. A model may detect regularities no official could articulate. Greater predictive power makes it more useful, but usefulness does not convert its variables into the whole truth of the governed person. The constitutional question concerns the remainder: who may introduce the fact the system did not encode, who must answer it, and what happens before the answer arrives.

One further danger exceeds even Scott's catalogue.

Whoever controls an alignment specification can shape what a governed system permits. Where systems mediate credit, speech, employment, or dispute resolution, that authority requires the same suspicion applied to other consequential public and private powers. A single mandatory specification can also become a point of capture.

Scott warned that states dominate by making citizens legible to the center: visible, countable, classifiable into categories administration can process. The inversion we propose makes power legible to citizens, forcing decision rules, bounds, and authorities into the open, while keeping the complex reality of persons default opaque to power. That asymmetry is the structural condition of non-domination. Centralized AI governance reverses it when citizens become legible to systems while the systems’ operators remain opaque. A center that investigates operators and gives affected people standing can help enforce the asymmetry instead.


The Tacit Dimension

The knowledge problem has a sharper edge than Hayek fully developed. Michael Polanyi's work on tacit knowledge completes the argument.

Polanyi was a physical chemist turned philosopher. His central claim was simple and devastating: "We know more than we can tell."

Consider the expert diagnostician. She looks at a patient and sees pneumonia where the intern sees a cough. Her knowledge includes a perceptual skill developed through thousands of cases, each one slightly different, each one refining her capacity to see the relevant patterns. Asked to explain her judgment, she can offer reasons, but those reasons may not exhaust the process that produced her perception.

Polanyi distinguished two kinds of awareness: focal awareness (what we attend to) and subsidiary awareness (what we attend from). When reading, we focus on meaning while relying subsidiarily on the letters. We do not attend to the letters; we attend through them. The skill of reading integrates the subsidiary into the focal, and the integration cannot be decomposed into explicit steps.

Michael Oakeshott arrived at a parallel conclusion from a different tradition. His "Rationalism in Politics" distinguished technical knowledge, codifiable and transferable, from practical knowledge, which exists only in the activity of its exercise and cannot be separated from the practitioner who deploys it. A project that treats alignment as complete prior specification repeats the Rationalist wager: that a rulebook can replace the practiced capacity to navigate moral complexity. Oakeshott’s objection bears on that wager. Learning from encounters, exposing the limits of a specification, and retaining institutions capable of revising it are different undertakings.

This is the fault line for alignment-by-specification. The application of human values draws heavily on tacit knowledge.

A fair judicial decision has formal components: equal treatment, absence of bias, consistency with precedent. Its application to a particular case also involves judgment. Leniency may serve the purpose of a rule in one setting and undermine it in another. The decision depends on circumstances that a judge must perceive and explain, even when the practiced capacity behind the perception exceeds a formula.

The same difficulty attends "harm," "consent," "dignity," and other values that alignment specifications invoke. Their application depends in part on contextual judgment that a prior specification may not exhaust.

This does not mean that no constraints are specifiable. Some are: do not disclose private data without authorization; do not execute transactions that exceed stated limits; do not produce outputs that match known malware signatures. These constraints are formal, bounded, and verifiable. They belong to the core of what rules can capture.

But the contested edge, the penumbra where reasonable people disagree about whether a particular action satisfies a particular value, cannot be made reliably rule-complete in advance. That is where tacit judgment matters and where the hardest governance questions concentrate.

The difficulty for alignment engineering is structural. To make AI systems "aligned," designers must state enough of the desired behavior to guide and test the system. Explication can improve practice, but it may leave out the subsidiary perception through which a skilled judgment was formed. Once the partial account becomes a target, a system can satisfy the stated proxy while missing the judgment's purpose.

Consider content moderation. Platform rules attempt to specify "hate speech." The specifications proliferate into elaborate category systems. Sophisticated users learn to encode hate in forms the specifications do not recognize. The moderation arms race escalates: more categories, more classifiers, more evasions. Meanwhile, the original judgment, recognizing when speech is intended to dehumanize, recedes further from the rules that were supposed to instantiate it.

Here the arms race reveals its structure. Each specification creates an edge to probe. "Hate speech" is defined, and users encode hatred through irony. "Coordinated inauthentic behavior" is specified, and actors route coordination through plausibly deniable channels. "Medical misinformation" is categorized, and claims are framed as questions while conveying the same content. A practiced reader may use context that a classifier or its training record fails to preserve; another reader may still disagree. Formalization can narrow the dispute without reliably eliminating the contextual judgment.

What Polanyi called the "structure of tacit knowing" explains why. We integrate subsidiary elements into focal achievements, but we cannot make the integration itself fully explicit without disintegrating the achievement.

For AI governance, the implication is a limit rather than an impossibility theorem. Alignment specifications can settle bounded propositions and improve consistency, yet in consequential domains they will sometimes underspecify the case or overspecify a rule that fits it poorly. Tacit knowledge does not guarantee the human answer is correct. It explains why a formal answer should not claim more jurisdiction than its representation has earned.


The Verification Burden

Even a sound specification leaves a governance problem. Testing can establish bounded properties, and central auditors can compare behavior across a system. Neither method can inspect every consequential encounter. Verification at machine scale therefore has to combine central inquiry with evidence and contest at the point of impact.

Even sampling strategies face adversarial adaptation. Any verification creates two categories: verified and unverified. Under adversarial conditions, the unverified category becomes the attack surface.

The adversarial dynamic deserves emphasis. Consider financial auditing. Auditors sample transactions according to statistical models. Sophisticated actors learn the sampling patterns: which transaction types trigger review, which thresholds attract attention, which timing windows receive less scrutiny. They route problematic transactions through the unsampled paths. The audit remains formally valid; the evasion remains substantively successful.

AI systems face the same dynamic at higher velocity. A model trained to detect policy violations will be probed by actors seeking its decision boundaries. Once a boundary is mapped, adversaries can generate conduct that falls outside the detected category while pursuing the same end.

The audit illusion includes a selection pressure toward evasion. Formal compliance may improve as substantive harm migrates to the shadows. Spot-checking biases attention toward what is easiest to audit. Systems optimize for the metrics audits measure, and actors route edge cases away from scrutiny while satisfying formal requirements.

Better tools can reduce the gap. They cannot abolish the distinction between a tested sample and an unobserved encounter.

Auditing regimes in other domains manage the problem through physical constraints. A factory has a location. Inspectors can visit. A drug has a chemical composition. Labs can test. A reactor has a design. Engineers can review. The artifact under inspection is bounded, stable, and physically accessible. The inspector can hold it in hand, subject it to measurement, compare it to specification.

AI systems present a different kind of object. They operate across jurisdictions, adapt continuously, and produce outputs that depend on inputs the auditor never sees. The "system" is a process, a relationship between model, data, context, and query that reconstitutes itself with each inference. What the auditor certifies is a snapshot; what the user encounters is a trajectory. The verification model that works for bounded artifacts does not scale to unbounded inference.

The relevant property may also be the system's behavior in context rather than its architecture. A model can satisfy a formal audit and still produce harmful outputs when deployed in contexts the auditors did not anticipate. Harm may arise from the encounter among weights, inputs, institutions, and stakes that no pre-deployment audit can fully specify.

The result is what we might call the audit illusion: formal verification procedures that create the appearance of accountability without the substance. Form without substance, compliance without constraint. This is process theater applied to verification itself.

The system has been certified. The paperwork is in order. The boxes are checked. And yet the actual behavior of the system, in the contexts that matter, remains unknown to those who claim to supervise it.

The alternative is a division of constitutional labor. Central investigators identify patterns, test controls, compare populations, and enforce common law. Systems preserve provenance and expose whether a formal constraint was satisfied. Affected people and independent advocates introduce the local fact, challenge the asserted authority, and seek remedy in a forum with power to act. Cryptographic enforcement can make some promises harder to break. It cannot determine whether the promise was adequate or supply the standing, capacity, and remedy required to contest it.


One Level of the Stack

Precision requires limits, and the argument that follows is bounded deliberately.

While verification cost is a necessary condition for the structures we will propose, it is not a sufficient condition for the outcomes we desire. The fact that verification can be made cheap does not determine who will use that capacity or toward what ends. It shifts the feasible set and reshapes rent opportunities. It does not uniquely determine outcomes.

Beyond verification, violence, ideology, geography, and resource control continue to matter. Coercion persists regardless of verification costs. A population captured by a worldview can forfeit freedoms that verification would allow it to protect. A geography with chokepoints can be controlled even when individual transactions are cryptographically sovereign. The argument operates at one level of the social stack. It does not reduce politics to that level.

Cheap verification can serve surveillance as readily as freedom. States, platforms, employers, and landlords can use it to inspect those subject to their decisions while exposing little of their own reasoning. The surveillance gradient ordinarily flows downhill.

This gradient has a direction: those with resources verify those without; those with power inspect those subject to it. Employers verify workers through background checks, drug tests, productivity monitoring. Workers do not verify employers' financial stability, safety records, or wage-theft history. Landlords verify tenants through credit reports and references. Tenants do not verify landlords' maintenance records or eviction patterns. Platforms verify users through identity documents and behavioral analysis. Users do not verify platforms' data practices, algorithmic decisions, or content policies. In each case, the party with more power uses verification to reduce their risk at the expense of the party with less power. This is not conspiracy; it is equilibrium.

We call this differentiator civic asymmetry: the principle that coercive power must be maximally legible while private persons remain default opaque. Civic asymmetry reverses the gradient: those who wield coercive authority become maximally inspectable; those who live private lives become default opaque. The verification capacity flows uphill, not down. Where verification flows from citizen to state but not from state to citizen, cheap verification perfects tyranny. Where verification flows in both directions, or flows primarily from power to public scrutiny, cheap verification enables contestation. This book does not claim verification technology determines freedom. It claims verification technology makes a certain kind of freedom structurally possible for the first time. Without deliberate design, the default is surveillance, not liberty.

The default deserves emphasis. In the absence of constitutional intention, verification capacity will be captured by those who can afford it and deployed against those who cannot resist it.

Reversing this gradient is the project of this book. The tools to do so exist, but their deployment and political architecture present constitutional choices.


Consequence

The Prologue asked what receipts power leaves. The answer cannot come only from above, and it cannot remain only below.

When governance confronts distributed intelligence, it faces three limits. Relevant knowledge is dispersed across contexts no authority can observe in full. Human judgment exceeds exhaustive prior specification. Machine-scale action outruns inspection act by act.

Hayek identified one limit in economic coordination, Scott in administrative vision, and Polanyi in the structure of knowing. None proved that a center is dispensable. Together they show why a center must govern without claiming a view from nowhere.

The institutional response is neither administrative surrender nor another claim of total supervision. It is to place verifiable constraints and durable evidence inside the transaction while preserving central powers of comparison, investigation, standard-setting, and remedy. The center should be able to see the pattern. The person should be able to contest the case. The forum should be able to connect them.

Return to the students whose grades arrived in August 2020. Publishing source code later improved public scrutiny. Reversing the result supplied immediate relief. A constitutional architecture would have required more at the moment the method became consequential: the act performed, the evidence the method was authorized to use, the evidentiary choice it made, the limits of that choice, and a route of contest able to operate within the student's calendar. Such a receipt would not have decided whose grade was correct. It would have made the disagreement governable before a national reversal became the only available remedy.

But distributed governance requires an interface: a point where digital proposals become biological consequences, where cryptographic proofs meet human stakes. That interface is what we will call the Membrane.

Many consequential Membranes are privately controlled. Platforms decide what gets through and what is filtered, what can be verified and what must be trusted. Public systems build Membranes too. The next chapter asks what happens at that crossing, where a digital representation becomes a fact in a human life.

Architects of this territory set out to build products. At scale, products can become infrastructure and infrastructure can become power. A platform that mediates access to information, commerce, and dispute resolution may become a gatekeeper whose gate has no appeal surface.

Search the book

Use ↑ ↓ to move through results; Escape to close.

Search every published chapter, section and reference.

    In this chapter