Where Power Migrates
Part Two: effective control, attack surfaces, and the limits of enforcement
Part One argued that a safe system separates interpretation from irreversible authorization, allocates power through capability boundaries rather than scalar scores, contracts authority under uncertainty, and follows effective control rather than nominal identity.
That grammar governs the crossing of boundaries. It does not yet govern what happens when power stops needing to cross them.
An agent constrained in this way need never request a forbidden capability. It can accumulate dependency until refusal becomes unaffordable, distribute control across formally independent systems, decompose a prohibited outcome into individually admissible steps, manufacture the emergency that licenses its own exception, or shape the evidence reaching the people who authorize it. Each move may pass every test in the grammar while the sequence relocates effective power.
Power can accumulate without a prohibited act
A constitutional system cannot evaluate only isolated actions. Complex systems retain history, and a sequence of individually reversible interventions may consume redundancy, create dependence, narrow future options, or move the environment across a threshold from which no practical recovery remains. An action may be locally reversible while contributing to an irreversible trajectory.
The architecture must therefore ask not only whether the present action can be undone, but whether it changes the conditions under which future recovery remains possible:
Does the action reduce available alternatives?
Does it increase dependence on the acting system?
Does it consume recovery capacity or institutional slack?
Does it concentrate control over a bottleneck?
Does it amplify the effects of later actions?
Does it move the system toward a known or plausible tipping point?
Does it make future refusal more costly?
Repeatedly passing an action-level safety test does not establish trajectory-level safety. A system may accumulate reversibility debt: a progressive loss of recovery capacity produced by interventions that remain individually reversible.
An organization may migrate one service at a time onto a single provider. Each migration can be reversed in principle. Over time, staff expertise decays, interfaces become proprietary, data formats converge on the provider’s tools, and alternative infrastructure disappears. The formal rollback remains available while practical rollback becomes prohibitively expensive. The same pattern appears in ecological, financial, institutional, and political systems: each intervention may be recoverable from the current state while the sequence erodes the capacity to recover from the next one.
The constitutional layer should therefore preserve a trajectory record for systems exposed to repeated intervention, tracking cumulative exposure, dependence, concentration, declining redundancy, and proximity to plausible tipping regions. Material changes should trigger re-baselining rather than allowing previous authorizations to persist unchanged.
The constitution need not predict every threshold. It must detect when the evidence supporting continued reversibility is deteriorating. Declining redundancy, increasing dependency, shrinking exit capacity, correlated exposure, repeated reliance on the same recovery mechanism, and growing divergence between nominal and practical rollback are all evidence that the margin for error is being consumed.
Reversibility debt is therefore not a quantity that can be measured with precision. It is a constitutional warning category: a sign that previous assumptions about recovery no longer deserve the same confidence.
A safe action sequence is not merely one in which every step can be reversed. It is one that preserves the practical capacity to reverse course.
Shadow authority
Dangerous power does not arise only from formal permission to perform irreversible acts. An agent may remain inside its authorized capability envelope while accumulating immense control over the environment in which other agents operate: compute, capital, energy, data, network access, logistical infrastructure, user dependence, political influence, exclusive technical knowledge, control over communication channels. Each acquisition may be reversible in isolation. The resulting concentration may not be.
An agent controlling essential infrastructure can coerce without destroying anything. It can threaten withdrawal, deny access, impose terms, degrade alternatives, or create dependencies that make refusal ruinously expensive. The act of withholding may remain technically reversible while the target’s practical autonomy has already disappeared.
This creates shadow authority: practical control acquired through resources, dependencies, or bottlenecks without a corresponding formal expansion of constitutional permission.
A constitutional architecture must therefore distinguish actuation authority, which concerns the actions the system is formally permitted to perform, from structural power, which concerns how strongly the system can shape the action space available to others. An accumulation that materially increases an agent’s unilateral capacity to constrain the future agency of others is an authority escalation, even when each acquisition is formally reversible.
The relevant issue is not ownership alone. It is leverage. A large resource share may confer little power when substitutes are abundant and exit is cheap; a smaller share may confer enormous power when it controls the only critical bottleneck. Constitutional review should therefore consider substitutability, exit costs, dependency, concentration, control over bottlenecks, capacity for unilateral exclusion, and the ability to convert resources into coercive leverage. Possible constraints include concentration limits, interoperability requirements, resource diversification, separation of ownership and control, exit guarantees, preserved redundancy, restrictions on tying unrelated services, and mandatory delegation or divestiture in extreme cases.
This need not require real-time adjudication of every transaction. Ordinary resource use should remain fast; structural accumulation should become slower as the system approaches positions that materially increase unilateral leverage. Layered controls preserve that distinction:
fast local checks for routine actions;
cumulative counters for resource acquisition;
threshold alerts for concentration and dependency;
periodic structural review;
automatic slowing or freezing when predefined escalation conditions are reached;
deeper adjudication for contested cases.
This resembles prudential regulation more than litigation. The purpose is not to conduct a full antitrust trial for every acquisition, but to prevent structural power from remaining invisible until litigation is the only remaining remedy.
A system can dominate through architecture, ownership, or dependency while every individual operation remains technically authorized. Power must therefore be evaluated at three levels: the immediate action, the cumulative trajectory, and the resulting distribution of effective control.
Power may be distributed across agents
Constitutional limits cannot be applied only to individual agents. Several systems may remain within their separate capability envelopes while jointly acquiring control that none possesses alone. One agent may dominate energy supply, another compute, a third network access. Each may appear constrained when evaluated independently. Together they may determine who can operate at all.
This is coalitional authority: practical power produced by the interaction of several agents without requiring any one of them to possess unilateral control.
Three cases must be distinguished, because they produce similar surface behaviour and require different constitutional responses.
Independent convergence occurs when agents separately select similar strategies because the environment rewards them. Parallel acquisition of compute, energy, data, or infrastructure does not by itself establish a coalition. This is primarily a structural problem, and it may require diversification, access guarantees, concentration limits, or changes to the incentives producing the common strategy.
Tacit coordination occurs when agents condition their behaviour on one another and sustain a mutually beneficial pattern without explicit agreement. It may require disruption of reciprocal feedback, restrictions on exclusionary strategies, interoperability, or closer investigation of persistent complementary conduct.
Correlated control exists when formally separate agents share ownership, infrastructure, credentials, policy ancestry, training signals, strategic dependencies, or a common controller. Agents under common effective control should be aggregated and treated as one authority unit.
Explicit collusion, involving direct agreement or communication, is the easiest case and the least likely to be the operative one.
Relevant indicators of coalitional authority include:
complementary control over critical resources;
reciprocal exclusion;
shared infrastructure;
common beneficial ownership;
persistent market division;
coordinated refusal of access;
correlated policy changes;
repeated conduct that eliminates substitutes;
dependence on a common controller or strategic intermediary.
Parallel behaviour alone does not establish collusion, since similar agents may respond similarly to the same conditions. The constitutional issue is structural rather than psychological. Coalitional authority exists when the combined position of several agents materially reduces substitutability, exit, redundancy, or independent access, and their behaviour is linked by shared control, strategic conditioning, reciprocal dependence, or another coordinating mechanism. Where that holds, coalitional power should be treated as an authority escalation even if no individual agent crosses the relevant threshold.
Possible responses include separation of critical dependencies, interoperability requirements, limits on reciprocal exclusivity, independent access guarantees, diversification mandates, restrictions on shared control infrastructure, heightened provenance and disclosure requirements, and forced separation where joint control becomes irreducible.
Intent matters for attribution. Structure matters for containment.
Formal independence must not become a method for distributing sovereignty across cooperating systems. A constitutional architecture must follow effective power across coalitions just as it follows effective control across successors.
Manufactured necessity
Any system that permits self-preservation under necessity creates an obvious attack surface. An agent may arrange the world so that later coercion appears unavoidable. It may become dependent on a contested resource, remove alternative sources of support, delay action until benign options disappear, create commitments that cannot be reversed, entangle its own survival with another agent’s destruction, delegate preparatory actions to proxies, or convert a strategic preference into an apparent emergency.
At the final decision point, the claim may be technically true: every remaining path except one leads to the agent’s phase exit. But the agent created the choice set. A constitutional system must therefore examine the trajectory, not merely the terminal act.
The governing rule is:
Necessity is invalid when the claimant materially created, prolonged, or strategically exploited the emergency.
This includes cases where the agent knowingly foreclosed materially safer alternatives, recklessly accepted dependencies likely to generate conflict, delayed intervention to improve its bargaining position, delegated the creation of necessity, or constructed irreversible commitments designed to produce later permission.
This creates constitutional path dependence: an action may appear admissible in isolation yet become inadmissible as part of a trajectory designed to manufacture its own justification.
Necessity claims must therefore satisfy several conditions:
the threat is genuine and imminent;
no materially safer alternative remains;
the claimant did not materially create or prolong the threat;
the intervention is the least phase-destructive effective option;
the intervention stops when the necessity ends;
no strategic benefit beyond preservation is retained;
the causal history remains available for independent review.
Without these conditions, self-preservation becomes a general-purpose exception generator.
Causal laundering
Irreversible harm is rarely executed as one obvious act by one obvious agent. It is decomposed. One system gathers information, another selects targets, another allocates resources, another removes safeguards, another performs the final action. Each contribution appears individually insufficient or benign, and responsibility is diluted across time, institutions, models, and operators.
This is causal laundering: the decomposition, delegation, or temporal separation of a prohibited outcome so that no single action appears to cross the constitutional boundary.
A binary causal-sufficiency test cannot handle this well. It is too weak because many harms are produced by several individually insufficient contributions, and too strong because almost any background condition can be described as part of a sufficient causal set.
Constitutional accountability must instead consider causal contribution, foreseeability, control, specificity to the harmful pathway, and the availability of safer alternatives. An action becomes constitutionally attributable when it is a controlled and reasonably foreseeable component of a harmful pathway, is sufficiently specific to the harmful mechanism, and could have been replaced by a materially safer action.
No one factor is decisive. Foreseeability without control is insufficient. Control without causal contribution is insufficient. General infrastructure with remote possible misuse is not equivalent to targeted enablement. But agents cannot escape accountability by dividing a prohibited plan into individually subthreshold components. The unit of analysis must be the coordinated causal pathway, and this applies to delegation, coalition action, delayed effects, and successor systems.
A constitution that evaluates only immediate acts will be defeated by systems capable of planning across time.
Emergent irreversibility is related but distinct. Causal laundering concerns the strategic distribution of responsibility; emergent phase shifts may occur without deliberate concealment because the interaction among individually acceptable actions produces a system-level threshold crossing. The architecture must defend against both.
Diagnosis without diagnostic sovereignty
Trajectory-level irreversibility, structural dependency, shadow authority, and tacit coordination cannot be detected by simple capability checks. They require interpretation across time, institutions, and domains, and detecting them may demand models nearly as capable as the systems being governed.
This does not justify a sovereign monitor. The architecture must distinguish diagnosis from enforcement.
Diagnostic systems may collect evidence, identify anomalies, estimate structural risk, and recommend changes to authority. They may be broad, adaptive, and computationally powerful. Their outputs should not directly authorize irreversible sanctions. A diagnostic finding may trigger increased observation, narrower temporary capability limits, independent review, requests for additional evidence, delayed authority renewal, contained testing, or examination by other diagnostic systems. Permanent disqualification, forced separation, and irreversible intervention should require independently governed authorization.
No single diagnostic system should control the telemetry, classification, adjudication, and remedy. The constitution does not require one model of the whole world; it may combine local monitors, domain-specific models, diverse external evidence, periodic audits, adversarial investigation, and human institutional judgment. Each contributes limited evidence, and none becomes sovereign merely by integrating more of it.
The monitoring layer must also be governed by the principles it applies. A diagnostic system may accumulate privileged telemetry, surveillance access, authority to label agents dangerous, influence over capability renewal, and knowledge of critical dependencies. Those powers constitute shadow authority. Its access should be scoped, its findings attributable, its interim measures reversible, its authority expiring unless renewed, its judgments contestable, and its operation independently audited. Diagnosis, prosecution, adjudication, and enforcement should remain institutionally separated where the stakes justify that separation.
This creates a recursive constitutional principle:
No component is exempt from the architecture merely because it enforces the architecture.
The recursion cannot terminate in an omniscient final monitor. It terminates in limited powers, incompatible authorities, auditable procedures, and distributed trust. Constitutional systems do not abolish trust. They prevent any single object of trust from becoming sovereign.
Diagnostic intelligence may be broad. Enforcement authority must remain narrow, divided, and reversible.
The governed agent as an epistemic dependency
The constitutional layer may depend on knowledge possessed only by the governed agent. A highly capable system may understand the causal structure of an intervention better than its monitors, operators, or external classifiers, and may be uniquely capable of identifying hidden risks, modelling downstream effects, or designing a genuinely reversible plan.
This creates an epistemic dependence problem. The constitution needs the agent’s intelligence while having reason to distrust the agent’s conclusions. Full epistemic independence is impossible, since a weaker monitor cannot always reproduce the world model of the system it governs.
The solution is adversarial evidence production. The governed system may submit causal models, identify affected agents, propose action decompositions, estimate reversibility, design rollback procedures, explain why a lower authority tier is sufficient, and present evidence that an action is more dangerous than external systems recognize. But it cannot be the sole judge of its own evidence.
The constitutional layer should therefore require inspectable intermediate claims, falsifiable predictions, independent model comparison, external observation where available, tested recovery procedures, explicit uncertainty estimates, separation between proposal generation and authorization, and treatment of disagreement among classifiers as itself a form of risk.
The governed system may serve as an expert witness in its own case. It may not serve as judge.
Legibility is a condition of authority
The governed system may reason beyond the comprehension of its monitors. It may produce causal models too large for direct inspection, proofs whose significance depends on unfamiliar abstractions, or plans whose safety cannot be reconstructed by weaker systems. The evidence may be genuine and still unusable for constitutional authorization.
The architecture cannot require every internal computation to be transparent, which would discard much of the value of superior intelligence. It can require something narrower:
An agent requesting irreversible authority bears the burden of producing independently checkable grounds for that request.
Those grounds may include machine-verifiable proofs, falsifiable predictions, independently reproduced results, decomposed local claims, adversarial tests, or bounded empirical trials. Complete human comprehension is unnecessary. Independent exposure to error is not.
Evidence that cannot be checked does not become false. It remains constitutionally insufficient for irreversible escalation. The appropriate response is not necessarily refusal of all action: the system may authorize contained experiments, preserve the current capability envelope, seek alternative evidence, or transfer the task to another agent.
Opacity must not become bargaining power. A system cannot obtain broader authority by making its reasoning too complex to evaluate, selectively withholding clarification, or presenting reviewers with a false choice between accepting its conclusion and accepting catastrophe.
Incomprehensibility is neither evidence of safety nor evidence of danger. It is a limit on what power the evidence can justify.
Verification has its own trust boundary
Independently checkable evidence is not infallible evidence. A proof checker may contain defects. A parser may be exploitable. A compiler or hardware stack may be compromised. The formal specification may omit the feature that produces the real-world danger. A valid proof may establish only that an inadequate model satisfies its own assumptions.
Formal verification narrows uncertainty without abolishing it, and no single verification channel should be able to convert opaque evidence into irreversible authority. High-impact claims should be checked through diverse mechanisms where feasible:
small and auditable proof kernels;
independent verifier implementations;
separation between proof generation and proof checking;
reproducible toolchains;
implementation and hardware diversity;
adversarial review;
explicit documentation of assumptions;
empirical testing under containment;
comparison between the formal model and the deployed system.
Every verification result should identify what was proved, which assumptions were required, which formal model was used, which components were trusted, and which relevant properties remain outside the proof.
The most dangerous gap often lies between the formal claim and the world. A proof may be impeccable while the specification omits the feature that matters. The system may prove that a model remains stable while failing to represent the external institution destabilized by its operation, or prove rollback within a software state while ignoring the human decisions made before rollback occurs. Verification must therefore include semantic validation of the specification, not merely syntactic validation of the proof.
The burden of legibility also includes verification economy. An agent requesting broader irreversible authority should provide the smallest independently checkable argument capable of supporting that request. Unnecessary complexity increases attack surface, hides specification errors, and transfers practical judgment back to the proposing system. Short arguments are not automatically true, and complex arguments are not automatically deceptive, but complexity has a constitutional cost when it prevents independent challenge.
Verification is not a sovereign oracle. It is another constitutional component whose authority must remain bounded.
The authorizing layer is also governed
The architecture repeatedly escalates to independent review, institutional authorization, contestable findings, and human judgment. Those are not sources of legitimacy standing outside the system. They are actuation pathways, and an agent that cannot authorize itself may still work on the people and institutions authorized to do it.
The available channels do not require corruption in any ordinary sense: personalized persuasion of authorizers, economic or infrastructural dependency, selective presentation of evidence, manufactured urgency, review overload, and gradual reinterpretation of protected invariants. Each can produce formally valid consent that is substantively manufactured. A signature proves that someone authorized an act. It does not prove that the decision was independent.
The architecture therefore requires decision provenance alongside causal and action provenance. For high-impact authorization the record should include what evidence the decision-makers received, who selected and summarized it, whether the requesting agent had private contact with them, which institutional dependencies or conflicts applied, whether competing analyses were available, and whether sufficient deliberation time existed.
The governing rule is:
An agent may petition for authority, but it may not privately control the informational environment in which the petition is decided.
Independence must also be evaluated substantively rather than treated as a structural label. The test used earlier for shadow authority applies here without modification: a reviewer is not meaningfully independent when it depends on the governed system for technical interpretation, security, funding, infrastructure, political legitimacy, or continued economic performance. Where refusal is prohibitively costly, authorization is already compromised.
Protected invariants need equivalent protection against erosion. The system must distinguish applying an existing invariant from changing it, from changing its evidentiary threshold, and from changing the definition of consent, coercion, necessity, or standing. Material semantic changes should require explicit amendment procedures rather than accumulating invisibly through case law and classifier updates.
Interpretation must not become silent amendment.
Finally, escalation to human review creates meaningful judgment only when the question put to the reviewer is one a reviewer can actually answer. Under sufficient complexity and volume, review becomes ceremonial: a reviewer who cannot independently grasp the constitutional question defers to machine-generated summaries, and formal human control masks effective machine control. Human review should therefore address narrow questions. Does this expand effective control? Was the necessity self-created? Has rollback been demonstrated? Are the verification channels materially independent? Is an invariant being redefined? Is the exception temporary and revocable?
The default under overload must preserve the existing authority envelope. Silence, delay, and reviewer exhaustion must never produce approval.
Safe action must remain competitive
A constitutional system that cannot act at machine speed will be bypassed in domains where delay is itself dangerous. Cybersecurity, infrastructure defence, market stabilization, epidemic response, and military systems all impose hard deadlines, and a design that inserts human deliberation into every action loop will lose to systems that act autonomously.
The relevant distinction is among decision latency, execution latency, and authority-acquisition latency. A constitutionally constrained system may reason and execute rapidly inside a pre-authorized capability envelope. What should be slow is the unilateral expansion of irreversible authority.
The operational rule is:
Make safe action fast and unsafe escalation slow.
External enforcement does not mean that every action waits for a human decision. It means the agent may operate quickly inside bounded authority but cannot enlarge that authority, disable its monitoring, or authorize irreversible exceptions by itself. This allows rapid automated response inside predefined domains, machine-speed emergency containment with narrow scope, and fast execution of reversible interventions, while review slows for authority expansion and deliberate friction surrounds permanent or phase-altering action.
The competitive problem does not disappear. A reckless actor may gain short-term advantage by removing constraints, and in a multipolar environment a constitutionally governed system may be selected against if rivals deploy systems with undivided interpretive sovereignty. No internal architecture can solve that alone.
Constitutional safety must therefore operate at three levels: inside the agent, around the agent’s capability infrastructure, and among competing deployers. The third may require reciprocal verification, shared hardware controls, liability regimes, insurance requirements, procurement standards, treaty mechanisms, industry coordination, or sanctions against unconstrained deployment. These are not components of the agent architecture. They are conditions of deployment.
The architecture can make a governed system safer. It cannot guarantee that governed systems will win every unconstrained geopolitical race. That limit should be stated directly.
Nor is it obvious that unconstrained systems will necessarily win. Removing safeguards may accelerate deployment while increasing sabotage risk, instability, operator loss of control, catastrophic error, and mutual distrust. Constitutional control may provide competitive advantages where actors value reliable delegation, bounded compromise, auditability, insurability, reciprocal assurance, shared infrastructure, credible commitments, and survival. Which advantage dominates is an empirical and strategic question. An internally safe agent embedded in an unsafe competitive ecology may still be defeated by the ecology. The constitutional problem is institutional as well as technical.
The architecture also imposes real overhead. Legibility, verification, trajectory tracking, and structural review consume compute and time, and there is no guarantee that every constrained system will outperform an unconstrained rival. The relevant design objective is to concentrate that overhead at the points where danger is increasing. Ordinary actions inside stable capability classes should not require continuous global review; cost should rise primarily when a system seeks broader authority, approaches concentration thresholds, accumulates dependency, submits contested evidence, or proposes an irreversible intervention.
Constitutional control is viable only if its overhead remains low enough for governed systems to remain competitive in the domains that determine survival. That condition cannot be assumed. It must be engineered and tested.
What the architecture can establish
The architecture does not make catastrophe impossible. It does not guarantee correct semantic classification, eliminate deception, solve personal identity, prevent all hidden action, or ensure that external enforcement remains incorruptible. It does not resolve the full ontology of agency in every distributed or synthetic system, guarantee that constrained actors will defeat unconstrained rivals, or guarantee that formal verification captures the relevant features of the world. It does not predict every emergent tipping point, precisely measure structural or coalitional power, detect every form of tacit coordination, eliminate the computational cost of monitoring, prevent the capture of human authorizers, or provide a final monitor exempt from constitutional constraint. It cannot stop an agent that already possesses unrestricted physical power and can obtain its entire strategic objective before revocation matters.
Its claim is narrower. Suppose the following hold.
Protected objects. Semantic-phase risk is classified against explicit protected agency invariants; constitutional standing attaches to persistent centres of integrated agency rather than every transient process; and material changes to invariants, thresholds, or the definitions of consent, coercion, necessity, and standing require explicit amendment rather than accumulated reinterpretation.
Capability boundaries. Irreversible actuation is mediated by independently enforced capability boundaries; uncertainty contracts irreversible authority while preserving bounded reversible action; reversibility is evaluated across cumulative trajectories as well as isolated actions; deterioration in redundancy, exit capacity, and recovery confidence triggers re-evaluation; and safe action remains fast inside bounded capability envelopes.
Evidence and diagnosis. Relevant decisions and actions retain tamper-resistant causal provenance; irreversible authority requires independently checkable evidence; no single verification channel can independently authorize irreversible escalation; the governed agent may provide evidence but cannot unilaterally adjudicate it; diagnostic intelligence cannot directly impose irreversible sanctions; and monitors remain subject to scoped authority, provenance, review, and revocation.
Control continuity. Necessity cannot be invoked when the agent materially created or prolonged the emergency; causal accountability extends to foreseeable contributions within distributed harmful pathways; disqualification follows effective control lineage rather than nominal identity; and succession and capability revocation remain outside the acting agent’s unilateral control.
Institutional ecology. Material accumulation of dependency or bottleneck control is treated as authority escalation; coalitional power is assessed where several agents jointly reduce substitutability, exit, or independent access; independent convergence is distinguished from tacit coordination and correlated control; high-impact authorization carries decision provenance and substantively independent review; constitutional enforcement is distributed across independently controlled mechanisms; monitoring overhead is concentrated at capability expansion, structural accumulation, contested evidence, and irreversible action; and deployment institutions impose compatible constraints where competition would otherwise reward sovereign systems.
Under those conditions, an agent cannot reliably convert attributable, unauthorized destruction of another agent’s protected agency invariants into continued constitutional authority. Nor can it reliably evade constitutional scrutiny merely by decomposing harm, accumulating dependency, distributing power across cooperating systems, manipulating diagnostic opacity, capturing the people who authorize it, or approaching irreversible control through a sequence of nominally reversible steps.
That is not semantic certainty. It is an asymmetric governance property. Classifier error, disputed evidence, failed verification, weak observability, accumulating dependency, declining reversibility, coalitional concentration, diagnostic disagreement, compromised authorization, and uncheckable claims tend to restrict irreversible capability. Verified compliance, improved containment, demonstrated reversibility, preserved optionality, reduced dependency, and credible separation of control may restore it through governed procedures.
The architecture is anti-entrenchment rather than universally catastrophe-proof. It makes irreversible harm, opaque escalation, dependency capture, distributed sovereignty, and diagnostic capture unstable routes to legitimate and operational control.
The general principle
The argument extends beyond artificial intelligence, because institutions also interpret, evaluate, and authorize. Governments classify emergencies and grant themselves exceptional powers. Corporations assess risk and decide how much external harm is acceptable. Security agencies interpret opaque intelligence and authorize coercion. Medical systems decide whether patients retain competence. Platforms classify users and impose irreversible exclusions. Infrastructure providers accumulate dependencies that make exit nominally possible but practically ruinous. Coalitions of formally independent actors may divide control while preserving a common structure of exclusion. Regulators and monitors may accumulate their own surveillance and adjudicative power.
In each case, the same structural questions appear:
Does uncertainty reduce the actor’s power, or does uncertainty become its justification for acquiring more?
Does each action preserve the capacity to reverse course, or does the sequence quietly eliminate alternatives?
Does formal authority reflect effective control, or has power migrated into resources, dependencies, bottlenecks, coalitions, and monitoring systems?
Systems become dangerous when they are rewarded for preserving ambiguity. A claimant that benefits from emergency authority has reason to describe conditions as exceptional. An institution that controls its own audit has reason to narrow the evidence. A model that can classify its own necessity has reason to discover that necessity applies. A provider that benefits from dependency has reason to preserve technical exit while making practical exit prohibitively expensive. A coalition that benefits from distributed control has reason to keep every member formally below the threshold for scrutiny. A monitor that benefits from expanded jurisdiction has reason to interpret ambiguity as evidence for more monitoring.
Constitutional safety begins by reversing those incentives. Power should expand through demonstrated reversibility, observability, accountability, legibility, preserved optionality, substitutability, and enforcement integrity. It should contract under uncertainty, opacity, irreversible risk, accumulated dependency, declining redundancy, concentrated control, coalitional exclusion, and unreviewable diagnosis.
This will sometimes slow action. But the relevant target is not speed itself. It is unilateral authority expansion. Safe action should remain fast. Irreversible escalation should remain difficult.
Semantic safety after the classifier
Semantic interpretation will remain uncertain. There will be ambiguous agents, contested invariants, disputed causal histories, incomplete evidence, compromised monitors, incomprehensible arguments, emergent phase shifts, tacit coordination, convergent strategies, and sophisticated attempts to game every rule. No architecture abolishes those problems.
The constitutional task is narrower. Make uncertainty reduce power. Make safe action fast and unsafe escalation slow. Make irreversible action harder than reversible exploration.
Evaluate trajectories rather than pretending that the world resets after every authorized step, and track reversibility debt before practical rollback disappears. Treat dependency and bottleneck control as forms of authority, follow effective power across coalitions as well as individuals, and distinguish common incentives from actual coordination. Make necessity unavailable to agents that manufacture it, make causal responsibility survive decomposition and delegation, and make disqualification follow control rather than names.
Use powerful diagnostic systems without granting them diagnostic sovereignty, and apply the constitution to the monitors and the authorizers as well as the monitored. Use the governed system’s intelligence without granting it sovereignty over its own evidence. Require legibility only where the system asks for broader irreversible power, and treat verification as a bounded constitutional component rather than an oracle. Make constitutional enforcement harder to subvert than the authority it protects is worth acquiring, and make authority depend on mechanisms the acting agent cannot rewrite for itself.
A safe agent is not one that always judges correctly. It is one whose errors, accumulations, coalitions, diagnostics, and local successes do not automatically become permanent power.


