top of page
The Political Agency Deficit in Frontier AI Institutions.png

The Political Agency Deficit in Frontier AI Institutions

A Candidate Inter-Institutional Process Theory and Measurement Framework

Political Execution, Government Partnerships, and the Permission Endpoint

Maturity: Advanced candidate inter-institutional process theory and measurement framework; empirically unvalidated

Abstract

Frontier artificial-intelligence institutions increasingly participate in governmental, military, intelligence, administrative, and infrastructural functions. These relationships distribute public purpose, technical capability, proprietary knowledge, contractual authority, classified evidence, deployment control, burden, and implementation power across institutions with different mandates. Existing theories explain accountability gaps, responsibility fragmentation, principal–agent relations, state capacity, veto players, private authority, secrecy, path dependence, and organizational reliability. They do not, by themselves, provide a complete account of the path through which a material change in a politically consequential public–private arrangement becomes an implemented permission state.

This article develops the Political Agency Deficit as a candidate inter-institutional process theory and measurement framework. The theory is indexed to a Minimum Causally Complete Permission Object o, a specified material trigger class θ, and a decision-relevant deadline tL. Core Structural PAD exists where the object is politically consequential, correction of the triggered state depends on institutionally distributed functions, and no reliable authorized path or functional substitute can convert the trigger into an implemented permission state before the deadline:

PADS(o,θ,tL)

PC(o) ∧ CI(o,θ) ∧ CPD(o,θ,tL)

The object-selection rule prevents analysts from creating or avoiding interdependence by changing descriptive scale. Each episode is tested at actor-local, arrangement, and public-mission levels; the primary object is the smallest state that is both causally complete and politically consequence-bearing. The trigger is specified before the path is coded. A general possibility of future change is not a separate constitutive condition.

The core path contains seven analytically distinguishable functions: trigger recognition, standing, evidence access, competent review, judgment, gate authority, and implementation. These functions may be institutionally compressed. Gate authority is state-relative: a provider may possess a complete negative gate over nonauthorization or non-renewal without possessing public sovereignty or authority over the broader mission. Design State, Episode Performance, and durability are coded separately. Structural PAD cannot be inferred solely from a failed episode; an activated failure without independent structural evidence is classified as an Acute Corrective Execution Failure. Accountability, appeal, remedy, renewal, legitimacy, and substantive correctness remain separate dimensions of mature governance.

Google, Anthropic, and OpenAI are analyzed as bounded episodes rather than permanent corporate identities. Google’s 2018 non-renewal and Anthropic’s refusal are reclassified as within-scope inter-institutional episodes in which provider-specific negative gates operated; neither establishes Core PAD. Anthropic’s litigation created a real but reactive and incomplete correction path. Google’s 2026 classified agreement and OpenAI’s classified arrangements are politically consequential and interdependent, but their core correction paths remain publicly unobservable. OpenAI’s rapid clarification is an observable documentary correction whose operational effect cannot be independently established. No frontier-AI episode is classified as confirmed Core Manifest PAD.

Two adjacent-domain contrasts discipline the theory. The grounding of affected Boeing 737-9 MAX aircraft after Alaska Airlines Flight 1282 supplies a low-ambiguity example of a material trigger reaching an implemented suspension gate. The Flint water crisis is provisionally classified as an adjacent-domain Core Manifest PAD candidate because official findings identify sufficient evidence and authority, distributed responsibility, management and communication weaknesses, and substantially delayed intervention. Flint remains subject to reduction by state-capacity, principal–agent, many-hands, jurisdictional, and evidence-interpretation explanations.

The constructive component proposes a risk-proportional Corrective Political Architecture. Its minimum viable core links trigger recognition, standing, evidence, judgment, state-specific gate authority, implementation, and a decision record. Accountability, remedy, independent review, reauthorization, and public reporting expand with coercion, irreversibility, scale, secrecy, dependence, rights effects, duration, and uncertainty. A Configuration-Burden Test asks whether governance meta-work displaces the public objective it is meant to protect.

The article remains a theory-construction and measurement-design study. PAD earns independent status only if object invariance, the permission endpoint, state-specific gate mapping, core handoffs, and Design State / Episode Performance distinctions add classification, prediction, or intervention value beyond adjacent theories.

Keywords: political agency deficit; inter-institutional corrective capacity; frontier AI governance; permission object; trigger indexing; gate authority; public–private governance; classified systems; state capacity; corrective political architecture

Part I — Research Object and Canonical Theory

1. Political Execution Without Reliable Correction

Artificial intelligence has become an operating layer of political reality.

Frontier AI systems now participate in public administration, cybersecurity, intelligence analysis, military planning, scientific research, content governance, industrial policy, and strategic competition. Their institutional importance does not arise only from the content they produce. It arises from the relationships in which they are embedded: procurement agreements, cloud infrastructure, classified deployments, technical safeguards, model-access conditions, auditing arrangements, and public commitments concerning acceptable and prohibited use. These relationships can alter what governments know, what they can do, how rapidly they can act, which private institutions they depend on, and who can interrupt or revise an operational course.

The resulting field is political in a precise institutional sense. It redistributes knowledge, opportunity, surveillance capability, coercive capacity, economic resources, strategic dependence, and control over decision infrastructure. This remains true even where a model developer understands itself primarily as a technical organization. Political consequence does not wait for political self-description.

Yet the most common criticisms of frontier AI institutions do not identify the complete problem. Some focus on political silence: companies allegedly avoid taking clear positions. Others focus on corporate overreach: private laboratories allegedly exercise too much political authority. A third group focuses on insufficient accountability, arguing that firms disclose too little or face inadequate oversight. A fourth emphasizes the implementation gap between ethical principles and organizational practice. Each diagnosis captures something important. None by itself identifies the failure examined here.

A company may express a political position without possessing authority to change a contract. It may publish principles without being able to observe downstream use. It may possess technical control without legitimate authority to define national policy. A government may possess democratic authorization while depending on private knowledge it cannot independently reproduce. An oversight forum may demand explanation while lacking power to alter permission. A court may impose a remedy after the contested capability has already been integrated into operational infrastructure. An employee group may identify a serious problem but have no standing, threshold, or escalation route capable of reaching a binding decision.

The central issue is therefore not whether political judgment exists. It is whether judgment can enter a reliable institutional path that reaches and implements an operative permission determination.

This article asks three linked questions:

  1. What is the minimum causally complete permission object at the level where the political consequence is produced?

  2. Which institutionally distributed functions and state-specific gates can convert a specified material trigger into an implemented permission state before the decision opportunity closes?

  3. Under what evidence conditions may failure be classified as Structural PAD rather than acute execution failure, ordinary state-capacity weakness, or substantive disagreement?

This article examines U.S.-based frontier AI institutions engaged in governmental and national-security relationships. Its unit is the institutional correction episode, not the company as a permanent moral personality. The theory is constructed around a bounded permission object, a pre-specified material trigger, and a decision-relevant deadline. It does not infer deficit from controversy, secrecy, corporate power, public criticism, or a wrong outcome.

The article makes three contributions. First, it defines a minimum causally complete permission object and an Object-Invariance Test. Second, it specifies a trigger-indexed core path from recognition to implementation and separates that path from accountability, remedy, legitimacy, and correctness. Third, it derives a risk-proportional institutional design and an empirical program capable of narrowing or rejecting the theory.

The proposed approach rejects two substitutions. Technical competence does not generate superior political rights, and democratic authorization does not manufacture technical evidence, observability, or implementation capacity. Mature correction requires the relevant functions to remain differentiated while becoming connected at the permission endpoint.

The article also adopts an unusually restrictive epistemic rule. A publicly important case is not necessarily a classifiable case. Classified or proprietary arrangements may be central to the theory while remaining Indeterminate in the public record. Conversely, a highly visible controversy may fall outside PAD because the relevant object is actor-local or because an operative negative gate works as designed. This asymmetry is intentional: conceptual relevance and evidentiary sufficiency are separate questions. The framework is designed to preserve that separation even when it produces a less dramatic empirical conclusion.

A further implication follows. The most visible exercises of agency may be negative gates—refusal, non-renewal, suspension, or injunction—because these states leave public traces. Successful conditional continuation inside classified systems may be harder to observe even when institutionally mature. The research design must therefore avoid selecting only controversies and failures. It requires deliberate search for ordinary successful correction, including cases in which review reaffirms authorization after evidence is considered. Without those negative cases, the instrument would confuse observability of conflict with prevalence of institutional failure and would systematically overstate the deficit in practice.

2. Political Effect, Capacity, Agency, and Authority

Political effect

A political effect is a consequence that changes the distribution of authority, rights, burdens, resources, knowledge, visibility, coercive capacity, or institutional opportunity.

Political effect does not require political intention. A recommendation model can change access to employment or public information. A surveillance model can expand state visibility. A military decision-support system can accelerate the translation of data into operational action. A language model integrated into public administration can alter the practical allocation of expertise and discretion. The designers may understand each system as a technical artifact. Its institutional consequences remain political.

Involvement, position, and adaptation

Political involvement is deliberate participation in public policy, government procurement, military relations, regulatory processes, lobbying, political advocacy, or organized opposition.

A company entering a defense agreement is politically involved. Employees petitioning against that agreement are also politically involved. Involvement indicates participation but not necessarily the capacity to alter an institutional state.

A political position is an articulated judgment concerning what should be authorized, prohibited, prioritized, restricted, or refused.

A public AI principle becomes a political position when it distinguishes acceptable from unacceptable uses. A government’s assertion that all lawful military uses should remain available is also a political position. So is a corporate claim that domestic surveillance or fully autonomous weapons fall outside the scope of acceptable use.

Positions can conflict while remaining institutionally powerless. The presence of a view is not the presence of agency.

Political adaptation is institutional adjustment to an external political, legal, strategic, or economic order.

Adaptation is necessary. Organizations cannot reopen every law, contract, election, emergency, or security condition whenever they make an operational decision. The analytical problem arises when adaptation becomes a substitute for authorization and review. A political order enters operations, generates infrastructure and dependency, and is later treated as a fixed environment rather than as a revisable institutional choice.

Adaptation becomes relevant to the deficit when three conditions combine:

  1. the external purpose is already operationally consequential;

  2. the adaptation is not treated as a separately authorized political decision;

  3. accumulated dependency materially narrows later correction.

Permission states

A permission state specifies whether a defined object is AUTHORIZE / CONTINUE, CONDITION / RESTRICT, SUSPEND / HOLD, or REVOKE / TERMINATE / ROLLBACK. These are normalized state families rather than an exhaustive vocabulary of legal remedies. Institutions may also remand, transfer, abstain, dismiss for jurisdiction, allow expiration, or require reconsideration; such actions must be mapped to their operative effect on the object.

Corrective capacity and exercised agency

Inter-Institutional Corrective Capacity is the designed or available ability of an arrangement to convert a material trigger into a timely implemented permission state. Inter-Institutional Corrective Agency is that capacity successfully exercised in an episode. Capacity may exist without activation; agency is observed when the state changes through the path.

The formulation is functional rather than anthropomorphic. The arrangement need not possess one mind, preference structure, or moral identity. It must possess coordinated decision capacity at the point where permission becomes operative.

Authority

Authority is recognized permission to decide within a specified domain. Frontier AI government relationships may distribute several distinct authorities:

  • purpose authority defines the public or institutional objective;

  • contract authority enters, modifies, or terminates the legal relationship;

  • technical authority controls design, model access, updates, or safeguards;

  • deployment authority controls operational use;

  • classification authority controls access to protected evidence;

  • review authority evaluates a correction trigger;

  • gate authority issues AUTHORIZE / CONTINUE, CONDITION / RESTRICT, SUSPEND / HOLD, or REVOKE / TERMINATE / ROLLBACK;

  • remedial authority imposes consequences after breach;

  • reauthorization authority renews or terminates the arrangement after expiration.

Authority may be formal without being legitimate, effective, informed, or accountable.

Legitimacy, accountability, and correctness

Legitimacy concerns whether an actor is entitled to exercise the authority it claims. Its possible sources include democratic mandate, law, constitutional competence, contract, corporate charter, professional jurisdiction, judicial authority, and affected-party participation.

Legitimacy is domain-specific and cannot be reduced to legality, effectiveness, or state consent alone (Buchanan and Keohane 2006). A frontier laboratory may legitimately control access to its proprietary model without possessing legitimate authority to determine national strategy. A government may legitimately define national-security purpose without possessing unlimited authority to compel every private capability or suppress all professional objection. A court may possess legitimate authority to review legality while lacking competence to design a technical safeguard.

This article therefore rejects both technocratic substitution and democratic simplification. Expertise cannot replace public legitimacy. Public legitimacy cannot eliminate the need for technical evidence and operational correction.

Accountability is a relationship in which an actor must explain and justify conduct to a forum that can question, judge, and attach consequences (Bovens 2007). It is not identical to transparency. A document can be public without its author being answerable. A hearing can create answerability without producing an operative permission determination. A review can produce findings while the relevant contract or deployment remains untouched.

Koppell’s analysis of “multiple accountabilities disorder” is particularly important in hybrid AI governance because companies may face simultaneous demands from governments, boards, investors, employees, courts, professional communities, customers, and affected publics (Koppell 2005). More forums do not automatically produce better governance. Without jurisdictional boundaries, precedence rules, and conflict procedures, multiple accountability relations can obscure rather than clarify who must decide.

Correctness concerns the substantive and evidential quality of the judgment itself.

Correctness does not follow automatically from technical expertise, democratic authorization, institutional cost, legality, public support, or judicial review. A technically informed company may be wrong. A democratically authorized government may be wrong. A court may correctly resolve a legal question while leaving the broader political or technical question open.

Architecture can improve the conditions under which correct decisions are made. It cannot guarantee correctness.

Bounded authority and independent dimensions

Sovereignty implies comprehensive and final authority over a political domain. Corrective agency does not require sovereignty.

A provider may possess bounded authority to refuse a use without controlling national policy. A government may possess purpose authority while accepting contractual limitations on a private product. An independent cleared body may possess power to issue a temporary SUSPEND / HOLD without becoming a sovereign institution.

The article therefore uses bounded terminal correction authority: authority whose decision has operative force for a defined scope and period while remaining subject to appeal, expiration, and reauthorization. “Terminal” identifies the point at which the decision becomes operational. It does not mean unlimited, permanent, or unreviewable.

Political agency, legitimacy, accountability, enforceable remedy, and institutional durability are independent but jointly necessary dimensions of mature correction.

A system may be effective but illegitimate; legitimate but operationally powerless; answerable but unable to alter a deployment; or capable of stopping a deployment without meaningful review. A politically mature arrangement requires these dimensions to be connected, not collapsed.

Powerless and unstructured

Effective but potentially arbitrary power

Authorized but weakly answerable

Legitimate and answerable but operationally powerless

Answerable exercise of contested authority

Strong corrective capacity, subject to remedy and durability tests

The distinction matters because the cases below contain different configurations. Google’s 2018 episode shows agency reaching an observable operative result. Anthropic shows corporate agency under contested legitimacy. OpenAI presents a public–private effort to divide authority while leaving enforcement and remedy incompletely observable.

3. The Inter-Institutional Correction Arrangement

Definition

An Inter-Institutional Correction Arrangement is the bounded configuration of institutions, authorities, evidence channels, procedural rules, operational controls, and implementation mechanisms through which a politically consequential object can be authorized, continued, conditioned, suspended, revoked, terminated, or revised.

The arrangement may contain public agencies, military or intelligence institutions, private AI providers, cloud and infrastructure providers, technical evaluators, contracting authorities, courts, oversight bodies, employees, affected-party representatives, auditors, or other actors performing decision-relevant functions. It is not presumed to form a unified intentional subject.

Institutional episode

The primary observation unit is the Institutional Correction Episode: one permission object, one material trigger or scheduled review, one relevant arrangement, one decision opportunity, and one observation period. A company may participate in several episodes with different authority maps. A continuing relationship may contain initial authorization, scope expansion, contractual clarification, incident response, litigation, and reauthorization as separate episodes.

Actor, organization, arrangement, and field

An actor can hold judgment, evidence, authority, or control. An organization is a formally constituted actor. An arrangement is the cross-institutional configuration through which the object is governed. An episode is a bounded activation or design assessment. A field is a population of arrangements sharing institutional, legal, technical, or market structure.

Field-level PAD requires repeated independent arrangements, a common core-path deficiency, and evidence that the pattern is not reducible to isolated organizational choice. The present frontier-AI cases do not meet that evidentiary threshold.

Authority map

A politically consequential relationship should distinguish at least:

  • purpose authority;

  • contracting authority;

  • technical authority;

  • deployment authority;

  • classification authority;

  • oversight authority;

  • stopping authority;

  • remedial authority.

These functions can be distributed legitimately. Fragmentation is not itself pathology. A plural constitutional order routinely separates legislative, executive, judicial, administrative, professional, and private functions.

The problem begins where the handoffs become opaque or non-corrective:

  • relevant knowledge cannot reach decision authority;

  • the provider cannot observe downstream use;

  • the customer cannot independently evaluate model behavior;

  • the review forum cannot access classified evidence;

  • the accountability forum cannot impose a gate decision;

  • the actor with gate power is not answerable to an appropriate forum;

  • no institution evaluates the complete chain.

The locus of failure

Political judgment is not absent. It appears in government departments, courts, boards, safety teams, employee groups, regulators, professional organizations, and civil society. Individual participants may possess substantial political agency, as the cases later demonstrate.

The deficit is located at the level of the institutional arrangement where those capacities do not form a reliable joint decision pathway. An arrangement exhibits an inter-institutional political agency deficit when a credible correction trigger cannot be converted into an authoritative and implementable permission determination across the relevant public and private boundaries.

The article therefore does not treat the frontier AI field as a unified intentional subject. “Inter-institutional agency” denotes a functional governance capacity: the capacity of a distributed arrangement to integrate judgment, evidence, authority, and implementation at the point of permission.

4. Minimum Causally Complete Permission Object

Definition and criteria

The Minimum Causally Complete Permission Object is the smallest institutional state whose alteration would resolve the material trigger at the level where the politically consequential effect is produced, and whose alteration includes every actor or authority necessary to change that operative state.

The object must be minimal, complete, state-based, trigger-relevant, endpoint-aligned, and implementable. It must be capable of receiving a normalized permission state, and implementation of that state must be observable or at least institutionally specifiable.

Object hierarchy

Every episode considers three possible levels. The actor-local object concerns a state controlled principally by one actor, such as provider participation or filing litigation. The arrangement-level object concerns the joint operational or contractual state, such as authorization of a public–private deployment. The public-mission object concerns the wider public purpose, such as continuation of a military mission or provision of safe drinking water.

The primary object is normally the arrangement-level state. Actor-local and mission-level objects remain nested analytical objects.

Causal completeness

An object is causally complete only if changing it would materially resolve the trigger; it includes every actor whose authorization, refusal, evidence, or implementation is necessary; it excludes actors unnecessary to the state transition; and it preserves the distinction between public purpose and provider participation. The object must be selected without knowledge of the desired classification.

Anti-gerrymandering rule

The analyst may not narrow the object to remove interdependence, widen it to manufacture interdependence, redefine it after observing the outcome, or select different scales for positive and negative cases without justification. Corporate participation cannot replace the joint deployment object where the political consequence is produced by the relationship. Conversely, an entire policy domain should not be used where one bounded relationship resolves the trigger.

Object-Invariance Test

For each episode, the analyst defines actor-local, arrangement, and public-mission objects; identifies the politically consequential endpoint; tests causal completeness; maps state-specific gates; and compares PAD status across scales. Results are Object-Invariant, Nested-Object Difference — Explained, Object-Sensitive — Adjudication Required, or Object Invalid. Where two reasonable causally complete primary objects produce different classifications, the episode remains Object-Sensitive — Not Finally Classified.

5. Trigger-Indexed Political Agency Deficit

Canonical formulation

For minimum causally complete object o, specified material trigger class θ, and decision-relevant deadline tL:

PADS(o,θ,tL)

PC(o) ∧ CI(o,θ) ∧ CPD(o,θ,tL)

The notation is conceptual shorthand. It states conjunction and indexing; it is not a statistical or game-theoretic model.

Political consequentiality

PC(o) is satisfied where the object materially affects coercion, surveillance, military or intelligence activity, public rights or legal status, public eligibility, critical infrastructure, public health or safety, public information environments, strategic dependence, or another domain requiring legitimate public authority. Controversy, corporate visibility, or large economic value is not sufficient by itself.

Correction-relevant interdependence

CI(o,θ) is satisfied where no single actor can complete the trigger-relevant state transition without at least one cross-institutional function, handoff, consent, or implementation action. The test must consider full-spectrum gates, state-specific positive and negative gates, binding referral, implementation authority, and substitutes. A provider’s ability to refuse does not defeat interdependence where the joint deployment requires mutual consent.

Core-path deficiency

CPD(o,θ,tL) is satisfied where no reliable authorized path or functionally equivalent substitute can convert the trigger into an implemented permission state before the deadline. The diagnosis requires a located function or handoff failure, Design State evidence, a substitute search, a counterfactual path, timing analysis, and structural evidence independent from the episode outcome.

Trigger admissibility

A valid trigger is specific, material, object-linked, state-relevant, temporally bounded, evidentially recognizable, nontrivial, and pre-specified. “Controversy,” “ethical concern,” secrecy, high stakes, or technological change in general is not enough. Examples include a proposed scope expansion, verified safeguard failure, evidence of public exposure, expiration of time-limited authority, or contractual terms conflicting with a declared provider restriction.

Decision-relevant deadline

tL is the latest point at which implementation could still materially alter the politically consequential outcome addressed by the trigger. It may be a renewal point, deployment date, mission activation, irreversible exposure, exhaustion of remedy, or completion of transition. It cannot be selected after observing delay.

6. Structural, Manifest, Acute, Persistent, and Indeterminate Forms

Core Structural PAD

Core Structural PAD is a design or capacity diagnosis. It may exist before an incident, but only where the object, trigger, deadline, interdependence, and located core-path deficiency are independently supported. A list of institutions or a general claim of fragmentation is insufficient.

Core Manifest PAD

Core Manifest PAD adds activation of the trigger, cognizable evidence or judgment, observed path failure, and failure to implement a relevant state before the deadline. Structural PAD must be established independently; manifest failure cannot be used as its sole proof.

Acute Corrective Execution Failure

An activated failure in an arrangement whose design is formally adequate or insufficiently observable is classified as Acute Corrective Execution Failure. The category prevents one error, emergency, or unsuccessful review from being converted automatically into a theory of structural deficit. Repeated acute failures may later support Structural PAD if stable design evidence emerges.

Persistence

Persistence is a temporal modifier, not a separate deficit. It requires credible visibility, a meaningful repair opportunity, and continuation or recurrence of the same or functionally equivalent deficiency. Visibility may be social, organizational, or authorized; the absence of formal standing cannot be used to make a publicly visible deficiency non-persistent.

Indeterminate and outside scope

Where core design or performance cannot be established or rejected, the result is Core PAD Indeterminate. Where the object is not politically consequential or does not require inter-institutional correction, it is Outside Scope. Indeterminate is not a weaker positive finding. It is an evidentiary boundary.

Part II — Adjacent Theories and Residual Contribution

7. Accountability and Responsibility

Accountability is not the permission endpoint

An accountability gap concerns missing or inadequate answerability, questioning, judgment, or consequence. Political agency deficit concerns the absence of an operative path from a credible correction trigger to an operative permission determination.

The distinction can be represented as:

Disclosure

answerability

questioning

judgment

consequence

operative permission determination

The first five stages may constitute accountability. The final transition is the specific concern of political agency deficit.

An organization can therefore be highly accountable in a retrospective sense while remaining operationally closed. It may publish reports, appear before a forum, accept criticism, and even receive a sanction while the relevant deployment continues unchanged. Conversely, an executive can possess power to stop a deployment without being answerable to a legitimate forum. A complete architecture requires both correction capacity and accountability.

Bovens defines accountability relationally: an actor must explain and justify conduct to a forum that can question, judge, and attach consequences (Bovens 2007). Grant and Keohane similarly emphasize that accountability mechanisms must be matched to forms of power that extend beyond ordinary electoral control (Grant and Keohane 2005).

These frameworks are indispensable because frontier AI governance contains actors that are not all accountable through the same democratic channel. Governments answer to legislatures, courts, and publics. Companies answer to boards, investors, customers, regulators, courts, and sometimes employees or professional communities. Hybrid relationships require several mechanisms.

Koppell’s warning is equally important: conflicting transparency, liability, controllability, responsibility, and responsiveness demands can produce multiple-accountabilities disorder (Koppell 2005). A company may be required to follow government instructions, protect users, satisfy a board, preserve classified information, and respect its own published principles. Without a conflict protocol, “accountability” can become an undifferentiated list of incompatible expectations.

The residual gap is the final operational transition. A forum may judge conduct without power to issue or trigger an operative permission determination. Political agency deficit identifies that missing capacity.

Responsibility and many hands

A responsibility gap concerns difficulty assigning causal, moral, legal, or forward-looking responsibility. The AI literature has shown that technical opacity, organizational complexity, and legal fragmentation can produce distinct gaps in culpability, moral accountability, public accountability, and active responsibility (Santoni de Sio and Mecacci 2021).

Political agency deficit asks a different prospective question:

Even where responsibility can be described, who can convert the relevant judgment into an operative permission determination?

A system may identify the developer, provider, customer, commander, and legal authority while still lacking an integrated correction path.

Thompson’s many-hands problem and the AI responsibility-gap literature explain why causal and moral attribution become difficult across complex institutions (Thompson 1980; Santoni de Sio and Mecacci 2021). These literatures support the article’s concern with distributed responsibility but also discipline it. The public–private chain should not be described as if no one bears responsibility. Often several actors bear distinct responsibilities.

The residual problem is that no actor or coordinated structure may own validation and correction of the complete institutional inference.

Depoliticisation and political-philosophy approaches further clarify why a technically or administratively framed decision may remain a collective political choice requiring legitimacy, plural standing, and revisable authority (Flinders and Buller 2006; Himmelreich 2020).

The residual sequence

PAD does not replace accountability or responsibility theory. It asks whether their outputs can reach an operative state. The full institutional sequence may be represented as:

Disclosure → Answerability → Questioning → Judgment → Consequence → Permission Determination → Implementation → Remedy / Reauthorization

The sequence is not always chronological. Its analytical value is to identify where a mature-looking system stops before correction becomes operative.

Governance, legitimacy, and epistemic deficits

A governance gap is a broad weakness or absence of rules, coordination, oversight, or enforcement. It can refer to almost any institutional inadequacy. Political agency deficit is narrower. It identifies failure in the judgment-to-permission transition.

The narrower category is useful because general governance reforms may add rules or committees without assigning gate authority. The number of governance mechanisms can increase while correction remains impossible.

Legitimacy deficit

A legitimacy deficit exists where an actor exercises authority without adequate entitlement. Political agency may be strong under weak legitimacy. A private laboratory may effectively restrict a government customer while facing a serious democratic-legitimacy objection. A government may possess public legitimacy while acting through opaque or legally disputed means.

Legitimacy is therefore necessary for mature correction but is not part of the minimum capacity definition of political agency.

Epistemic deficit

An epistemic deficit concerns missing, inaccessible, unreliable, or misunderstood knowledge. Frontier AI partnerships frequently contain epistemic asymmetry: companies understand model behavior and safeguards; governments understand operational context and classified use; affected publics may understand consequences invisible to either.

Political agency deficit can exist even where the evidence is known. The knowledge may be institutionally powerless, excluded from the relevant forum, or unable to reach gate authority. Conversely, a strong correction path may fail because the evidence is genuinely unavailable. The two deficits interact but should not be conflated.

Technical control, private authority, and depoliticisation

The technical AI control problem asks whether humans can reliably direct, constrain, or align model behavior. Political agency deficit asks whether the institutions defining, providing, and deploying the system can revise the political permission under which it is used.

A technically controlled model can remain embedded in an institutionally uncorrectable relationship. A politically accountable relationship can still contain an inadequately controlled model. These are intersecting but distinct problems.

Private authority

Scholarship on private authority examines how non-state actors create rules, standards, or governance arrangements. Frontier AI firms may exercise delegated authority, entrepreneurial authority, or both (Green 2014). The presence of private authority, however, does not answer whether the complete public–private arrangement possesses a correction path.

Private authority may supply missing capacity, create a legitimacy problem, displace public responsibility, or participate in a legitimate hybrid architecture. Political agency deficit diagnoses the integration failure rather than presuming that private authority is either the problem or the solution.

Depoliticisation

Depoliticisation explains how contestable choices become insulated through expertise, rules, delegation, economic necessity, or administrative procedure (Flinders and Buller 2006). Political agency deficit identifies the institutional consequence where the operationalized purpose can no longer be reopened through an effective permission process.

The two concepts are linked by political-ontology conversion, developed below: the transformation of a contingent political settlement into a fixed operational premise.

Added value and limits

Political agency deficit therefore identifies a specific institutional failure:

Correction-relevant political judgment does not reliably reach an authorized, implementable, and timely permission determination.

Its added value lies in isolating the endpoint that adjacent literatures often leave implicit. Accountability theory explains answerability. Responsibility theory explains attribution. Private-authority theory explains non-state rulemaking. Depoliticisation explains insulation. Responsible AI research explains organizational implementation barriers. Political agency deficit asks whether the institutional arrangement can actually reach and implement a permission determination.

8. State Capacity, Principal–Agent Relations, and Many Hands

State capacity

State-capacity theory explains the ability of public institutions to gather information, coordinate organizations, make decisions, enforce rules, and implement policy. Frontier-AI relationships can expose weaknesses in each dimension. Formal public authority may coexist with dependence on private evidence, proprietary infrastructure, or technical interpretation.

The reduction challenge is serious: once accountability and remedy are separated from the core, PAD may appear to be a specialized account of coordination and implementation capacity. The candidate residual lies in its explicit permission object, trigger indexing, state-specific gate map, and cross-boundary interface analysis. Those additions remain unvalidated and must be tested against conventional capacity instruments (Berwick and Christia 2018; Suryanarayan 2024).

Principal–agent relations

Principal–agent theory addresses delegation, information asymmetry, monitoring, and incentive divergence. Frontier AI government relationships may contain all of these. But they often include multiple principals, multiple agents, private actors with independent technical authority, public actors dependent on private expertise, and affected parties outside the contract.

The relation is not always a simple government principal and corporate agent. A provider may be a contractor in one function, an independent rule-maker in another, and an indispensable knowledge holder in a third. The political agency deficit concerns whether the complete arrangement can correct itself when these roles diverge.

Many hands

Thompson’s “problem of many hands” identifies the difficulty of assigning moral responsibility where many public officials contribute to a decision (Thompson 1980). Frontier AI systems intensify that difficulty by adding model developers, cloud providers, contractors, government customers, technical reviewers, and human operators.

The concept orphaned political inference adds a distinct institutional concern. The question is not only who is blameworthy after failure. It is whether any actor or coordinated structure owns validation and correction of the complete transition from political purpose to civil consequence.

PAD residual

Principal–agent theory asks whether delegated actors comply and whether principals can monitor them. The many-hands problem asks how responsibility is allocated across contributors. PAD asks a forward-looking process question: which causally complete path can convert a specified trigger into an implemented permission state, and where does that path fail? If that question adds no classification or intervention value, the theory should be narrowed or reclassified as a diagnostic synthesis.

9. Veto Players, Private Authority, and Polycentric Governance

Veto players and state-specific gates

Veto-player theory explains policy stability where changing the status quo requires agreement among actors with different preferences (Tsebelis 1995, 2002). PAD accepts that blockage may be the correct explanation in some episodes. Its narrower contribution is state-relative: an actor may possess a negative gate over nonauthorization or termination without controlling conditional continuation or the public mission. The theory therefore maps which states each actor can assign rather than treating all vetoes as equivalent.

Joint-decision traps

Scharpf’s joint-decision trap shows how decisions requiring agreement across institutional levels can produce immobility or lowest-common-denominator outcomes (Scharpf 1988). PAD should not redescribe such cases. It survives only where it identifies a missing or conditional function before the veto, after the veto, or at an implementation interface that joint-decision analysis does not capture.

Private authority

Private-authority scholarship provides a necessary corrective to the assumption that companies merely execute state decisions. Green distinguishes delegated private authority from entrepreneurial authority created by private actors themselves (Green 2014). Srivastava shows how Big Tech can exercise private authority through algorithmic bottlenecks and how state–corporate relations combine dependence, circumvention, and curtailment (Srivastava 2023). Cutler, Haufler, and Porter place such authority within a broader history of private rulemaking in international affairs (Cutler, Haufler, and Porter 1999).

Frontier AI firms may occupy several positions in the same relationship. They can be suppliers under public procurement, independent controllers of model access, authors of private use restrictions, and indispensable interpreters of system capability. Their authority may be contractual, technical, delegated, or entrepreneurial.

This literature constrains the article in two ways. First, it prevents the simplification that democratic government alone controls the complete relationship. Second, it prevents the opposite simplification that private technical power is automatically legitimate.

The residual question is corrective integration: how should public-purpose authority and private capability control be connected when their judgments diverge?

Polycentric governance

Polycentricity is neutral at baseline. Multiple centers can distribute expertise, create redundancy, protect against arbitrary concentration, and enable independent challenge (Ostrom 1999, 2010). They can also create forum shopping, delay, conflicting jurisdiction, and responsibility transfer. The relevant variables are not actor count or hierarchy alone, but object definition, standing, evidence, state-specific gates, implementation, and time.

Institutional complementarity

Institutions may be complementary when one supplies a function another lacks. Public purpose authority, provider capability, judicial review, classified oversight, and technical implementation can form a reliable system without any actor becoming sovereign. The empirical question is whether the functions combine at the permission endpoint or merely coexist as disconnected organizational assets (Hall and Soskice 2001; Deeg 2007).

Fragmented AI governance

Research on global AI governance increasingly describes an emerging architecture of overlapping public, private, national, and international initiatives rather than one coherent regulator (Tallberg et al. 2023). This supports the article’s rejection of a single sovereign AI institution. A regime-complex perspective is more realistic, and the broader governance-triangle literature similarly shows that public, private, and civil actors can occupy different regulatory roles under the shadow of state authority (Abbott and Snidal 2009).

But fragmentation is not itself plural corrective architecture. Multiple standards, forums, and institutions can coexist without clear handoffs, gate authority, or remedy. The relevant distinction is between distributed governance and integrated correction.

Group and inter-institutional agency

The article’s field-level diagnosis requires care because political agency is ordinarily attributed to actors, whereas the deficit examined here is located in a distributed arrangement. The literature on group agency shows that organized collectives can possess decision procedures and action capacities not reducible to one member’s intention (List and Pettit 2011). The frontier AI field, however, is not one organized group with a unified decision procedure.

The present article therefore uses inter-institutional agency in a functional and limited sense. It asks whether a public–private arrangement can integrate distributed judgments into an authoritative permission determination. The concept does not attribute a collective mind, unified purpose, or moral personality to the AI field.

This boundary resolves the apparent paradox that individual companies may display strong agency while the surrounding arrangement remains correction-deficient.

Path dependence

Reactive political accommodation also intersects with the literature on path dependence. Pierson shows how initial choices can generate increasing returns, coordination effects, sunk costs, institutional learning, and rising reversal costs that narrow later alternatives (Pierson 2000).

This mechanism is directly relevant to frontier AI partnerships. Pilot projects, infrastructure, security clearances, trained personnel, technical integration, strategic identity, and customer dependence can make later correction more costly even where the original entry was provisional. The article’s contribution is not the general discovery of path dependence. It is the application of that mechanism to the timing of political boundary formation and to the design of correction triggers, SUSPEND / HOLD authority, managed exit, and reauthorization.

10. The Permission Endpoint and the Reduction Test

Permission endpoint

The clearest candidate contribution is the permission endpoint: the point at which judgment becomes an operative state. A hearing, audit, disclosure, or ethical principle may alter understanding without changing permission. A court opinion may produce legal judgment without timely implementation. A provider may retain technical control without authority over government use outside its system. The endpoint forces analysis to identify the object, state, gate, and implementation mechanism.

Construct translation

The first reduction test asks whether PAD can be translated into accountability, state capacity, veto players, principal–agent theory, many hands, private authority, or high-reliability organization without losing the permission endpoint, object invariance, gate–implementation distinction, or interface location.

Incremental classification and prediction

The second and third tests compare instruments on independent cases. Does PAD distinguish reliable correction, conditional correction, accountability without implementation, a wrong decision through a functioning path, and acute failure without structural deficit? Do object, gate, and handoff variables improve prediction of determination, implementation, latency, recurrence, or remedy?

Intervention increment

The final test asks whether path-specific interventions outperform simpler reforms. Protected standing, binding referral, temporary suspension authority, evidence-access rules, or reauthorization should be compared with general transparency, capacity, accountability, and legal review. Possible outcomes are confirmation, narrowing, simplification, reclassification, splitting, or rejection.

Responsible AI and organizational process

The Responsible AI literature has repeatedly documented the gap between high-level principles and organizational implementation. Mittelstadt argues that principles alone cannot guarantee ethical AI because the field lacks the shared aims, fiduciary duties, professional norms, implementation methods, and robust accountability structures characteristic of medicine (Mittelstadt 2019). Raji and colleagues propose end-to-end internal auditing that preserves traceability across the development lifecycle (Raji et al. 2020). Rakova and colleagues show that responsible practice depends on organizational incentives, resources, leadership, authority, cross-functional coordination, and prospective rather than merely reactive processes (Rakova et al. 2021).

These contributions explain why individual ethical awareness is insufficient. They also show why governance must be embedded in roles, evidence, documentation, and organizational processes.

Yet audit can produce evidence without changing permission. A safety team can identify a problem without authority to modify a contract. A public principle can define a boundary without monitoring downstream use. The residual gap is therefore:

Principle ≠ process ≠ evidence ≠ authority ≠ consequence

A mature architecture requires all five.

Secrecy and differentiated accountability

Classified operations create a genuine limit on public transparency. An adequate theory cannot demand universal disclosure of operational details. Colaresi’s analysis of the secrecy dilemma shows that democracies can combine secrecy and oversight, but institutional design determines whether secrecy remains bounded or becomes self-protective (Colaresi 2014). Pozen’s concept of deep secrecy distinguishes protection of specific information from concealment of the existence, scope, or structure of governmental action (Pozen 2010).

The relevant distinction is not secrecy versus accountability. It is among:

  • public transparency;

  • cleared accountability;

  • operational secrecy.

The public may not receive classified evidence, but an authorized independent forum can still require access, preserve records, question officials, and report non-sensitive findings. The existence of a correction architecture, its authority map, prohibited-use classes, and reauthorization dates can often be public even where operations remain classified.

Political philosophy of technology

Himmelreich argues that technology ethics needs political philosophy because technological decisions concern collective authority, institutions, pluralism, and public consequences (Himmelreich 2020). That claim supplies the normative location of this article. The central questions exceed individual professional ethics:

  • Who may define public purpose?

  • Which actor possesses legitimate authority?

  • Who has standing to trigger review?

  • Who can access the relevant evidence?

  • Who can issue and implement an operative permission determination?

  • What remedy follows violation?

The residual domain across the literatures is now visible. Existing research explains insulation, expertise, private authority, fragmentation, accountability, responsibility, organizational practice, and secrecy. It does not fully specify the complete institutional transition:

Political judgment

authorized evaluation

operative permission determination

implementation

enforceable correction

That transition is the analytical domain of political agency deficit.

Part III — Measurement Grammar

11. Core Correction-Path Profile

Seven functions

The constitutive profile contains seven functions:

CCPP=(τ,S,E,F,J,G,I)

  • τ: trigger recognition and activation;

  • S: standing;

  • E: evidence access;

  • F: competent review forum;

  • J: judgment production;

  • G: state-specific gate authority;

  • I: implementation.

The profile is not a scalar index. A single critical failure may block the path, while an apparently absent component may be supplied by a reliable integrated node or substitute.

Trigger recognition and standing

Trigger recognition means the arrangement can detect an admissible change and activate the process. Standing means at least one relevant actor can initiate, request, or compel review. Standing may be assigned to a provider, public authority, employee, auditor, affected party, court, or oversight body according to role. Mere ability to complain publicly is not procedural standing.

Evidence and forum

Evidence must reach a competent decision function in usable and timely form. Public transparency is not required in every classified setting, but decision-relevant observability is. A forum may be administrative, contractual, judicial, technical, or joint. It must possess jurisdiction, competence, access, and timing appropriate to the trigger.

Judgment, gate, and implementation

Judgment is a reasoned conclusion about the object. Gate authority assigns the operative state. Implementation converts that state into technical, contractual, legal, operational, or transition action. Judgment without gate authority is advisory; a gate without implementation is symbolic; implementation without a bounded judgment risks arbitrary action.

12. Functional Compression and Core Handoffs

Functional-compression rule

Core functions must be analytically distinguishable, but they need not be institutionally or temporally separate. One regulator may receive evidence, conduct review, issue judgment, order suspension, and initiate implementation. Compression is valid where authority is explicit, evidence is adequate, output is recorded, implementation is timely, and no necessary challenge or responsibility disappears.

Invalid compression

Integration becomes defective where it hides evidence from authority, eliminates challenge, leaves implementation unowned, treats advisory judgment as a gate, prevents tracing the state transition, or creates an unreviewable monopoly over the entire chain. The theory evaluates function, not bureaucratic form.

Core handoffs

Where functions are held by different nodes, the core handoffs are:

Hcore=(hτ S,hSE,hEF,hFJ,hJG,hGI)

A handoff requires an authorized transfer rule or observed transmission, a defined object, recipient responsibility, timing, and escalation. The existence of a sender and receiver does not prove the interface.

Handoff evidence

Activated handoff performance requires a timestamped record, authenticated correspondence, logs, testimony identifying sender and recipient, an operative automated mechanism, or a formal process record. Outcome alone cannot establish the handoff. Where functions are integrated, the record is Integrated Functional Node — Handoff Not Required, not “Absent.”

13. Design State, Episode Performance, and Durability

Design State

Every applicable function and handoff receives a Design State: Formally Available, Partially Available, Formally Absent or Excluded, Unobservable, Not Applicable — Justified, or Applicability Indeterminate. Design State asks what the arrangement provides independently of the observed outcome.

Episode Performance

Episode Performance is coded separately: Activated and Effective, Activated and Partially Effective, Activated and Failed, Not Activated, Unobservable, or Not Applicable — Justified. A formal mechanism may fail when activated; an improvised mechanism may succeed once without becoming institutional capacity.

Durability

Durability is recorded as Institutionalized, Leadership-Dependent, Exception-Dependent, One-Time Improvisation, or Unobservable. This third attribute prevents an exceptional intervention from being treated as reliable architecture and prevents an untested formal rule from being treated as operational proof.

Analytical consequences

The two-axis design distinguishes paper governance from real operation, structural capacity from acute execution, and local agency from durable inter-institutional agency. It also makes the handoff hypothesis testable: interface performance can be compared with formal function presence rather than inferred from it.

14. Object Invariance, Trigger Indexing, and Criticality

Object record

The object record contains actor-local, arrangement, and mission objects; the primary minimum causally complete object; necessary and excluded actors; the politically consequential endpoint; the Object-Invariance result; and coder confidence.

Trigger packet

The trigger packet contains the trigger definition, materiality basis, evidence threshold, activation window, recognizing actor, object affected, strongest non-trigger interpretation, and deadline. It must be prepared before the path outcome is coded.

Criticality

A function or handoff is critical only where it belongs to the trigger-relevant core path, no reliable authorized substitute exists, the failure mode is specified, the counterfactual path cannot reach implementation before the deadline, and independent coders can locate the same critical point from the evidence record.

Critical-path memo

Every positive PAD classification must identify object hierarchy, trigger, deadline, gate coverage, Design State, Episode Performance, compression, handoffs, failed component, substitute search, counterfactual path, strongest state-capacity explanation, strongest veto-player explanation, strongest principal–agent or many-hands explanation, evidence class, confidence, and final multidimensional outcome. A C3-style assertion that the arrangement might someday require revision is no longer sufficient.

15. Evidence States and Outcome Dimensions

Evidence states

Applicable functions are coded Supported, Partially Supported, Contested, Unobservable, or Unsupported according to the claim and source. Official statements establish what institutions represented; they do not independently verify operational performance. Court orders establish their legal scope, not the truth of every party allegation. Public silence in a classified system yields Unobservable rather than Absent.

PAD status

PAD status is recorded as No Core PAD, Core Structural PAD, Core Manifest PAD, Acute Corrective Execution Failure, Object-Sensitive — Not Finally Classified, Structurally Suggestive — Not Classified, Indeterminate, or Outside Scope.

Path performance and permission state

Core Path Performance is Reliable, Conditional, Failed, Not Activated, or Unobservable. Permission states are AUTHORIZE / CONTINUE, CONDITION / RESTRICT, SUSPEND / HOLD, REVOKE / TERMINATE / ROLLBACK, No Determination, Conflicting Determinations, or Unobservable.

Separate maturity dimensions

Accountability, appeal and remedy, renewal and learning, authority quality, and substantive correctness are coded independently. The record can therefore describe a reliable but legitimacy-contested authorization, an accountable but non-operative review, or a substantively desirable refusal achieved through a fragile path.

16. Reliability and Validation

Unitization first

Coders must agree first on the permission object, episode boundaries, trigger, and deadline. Agreement on final PAD status cannot compensate for unstable object selection. Object level, necessary actors, state mapping, and trigger–object fit require separate reliability reporting.

Blind structural coding

For Manifest PAD candidates, Structural PAD is coded using design and pre-trigger evidence before coders review the episode outcome. This prevents backward inference. Handoffs may not be inferred from adjacent function presence or the final result.

Calibration and holdout

The development set is used to expose ambiguity, not validate the theory. Blind calibration should include successful correction, acute failure, accountability without implementation, classified but reviewable arrangements, and outside-scope near misses. A holdout sample must contain cases not used in construct development.

Rival-instrument comparison

State-capacity, accountability, veto-player, principal–agent, many-hands, and PAD instruments should be applied independently. The theory earns separate status only if its object, endpoint, gate, and handoff variables improve classification, prediction, or intervention. Inter-rater disagreement on object selection or criticality requires codebook revision rather than adjudication alone.

Part IV — Frontier-AI Episodes and Contrast Cases

17. Method and Evidence Boundaries

Case role

The frontier-AI episodes belong to the development set. They helped expose the distinction between actor agency, arrangement capacity, negative gates, reactive legal correction, documentary change, and classified non-observability. They are not a representative sample and cannot establish field prevalence.

Unit of analysis and case selection

The unit of analysis is an institutional episode in which political purpose, technical capability, objection, authority, and correction interact. The company is not treated as a stable moral identity. The same organization can create a boundary, revise it, and later expand participation under different terms.

Case-selection logic

The cases are selected for variation in pathway rather than statistical representativeness:

  • Google — internal objection reaching corporate boundary formation, followed by later revision and subsequent classified expansion;

  • Anthropic — publicly maintained refusal under state pressure and litigation;

  • OpenAI — rapidly revised hybrid delegation.

Together they permit comparison of internal, contractual, executive, governmental, and judicial routes from judgment to action.

Evidence hierarchy

The evidence hierarchy is:

  1. operative legal, contractual, regulatory, or court records where available;

  2. official company and government publications;

  3. independent high-quality contemporaneous reporting;

  4. institutional interpretation explicitly identified as the article’s analysis.

Official company sources establish what a company publicly declared. They do not prove implementation. Government sources establish announced policy or agreement scope. They do not prove the provider’s interpretation or the system’s actual use. Independent reporting establishes chronology, visible conflict, litigation, and consequences. It does not replace operative records where those are available.

Epistemic levels

The prose distinguishes:

  • documented fact;

  • institutional interpretation;

  • original conceptual proposition;

  • open empirical hypothesis.

The distinction is particularly important in live and classified cases. A public red line is a documented declaration. Whether it is monitored effectively is an empirical question. Whether the arrangement constitutes responsibility displacement is an interpretation. Whether prospective boundaries prove more durable is a hypothesis.

Declared rule versus operation

Every case distinguishes:

  • declared rule;

  • contractual rule;

  • operational control;

  • monitoring;

  • breach detection;

  • enforcement;

  • remedy.

The levels should not be collapsed. Public principles may influence behavior. They do not establish compliance.

Evidence-state coding

For functions that may be private or classified, the analysis uses four evidence states:

Present

Public evidence establishes the function

Partial

Some elements are established; others remain missing or incomplete

Absent

Evidence affirmatively establishes that the function is unavailable

Unobservable

The public record cannot establish presence or absence

Non-observability is not evidence of absence. It is nevertheless relevant where public legitimacy depends on citizens being able to identify the purpose, authority, review structure, and broad conditions under which consequential power is exercised.

Classified evidence

Classification creates evidentiary asymmetry. The article does not infer operational compliance or violation from the absence of public information. It asks which functions are publicly established, partially visible, affirmatively absent, or unobservable.

Development-set and falsification boundary

Across the examined episodes, the public record does not reveal a stable shared correction architecture that routinely integrates public purpose, private capability, trigger recognition, evidence access, state-specific gate authority, implementation, and assurance. Some of those functions may exist inside classified or proprietary arrangements; public non-observability cannot be converted into institutional absence.

This is a sample-bounded public-record finding, not a field-level PAD thesis. A field-level claim would require repeated independent arrangements, a common core-path mechanism, object-invariant coding, and controls for state capacity, veto structure, principal–agent relations, and substantive disagreement. Comparable frontier-AI relationships that routinely demonstrate integrated and timely correction would weaken the broader hypothesis; one visible success or failure cannot settle it.

18. Provider Negative Gates: Google and Anthropic

Provider refusal is not analytically external to an inter-institutional arrangement merely because the provider can act unilaterally at one gate. A jointly constituted permission state may allocate each participant a state-specific negative gate. The relevant question is whether the actor can alter the causally complete object for the specified trigger—not whether the actor controls the wider public mission.

Google 2018: object, trigger, and gate

The actor-local object is Google’s decision whether to renew its Project Maven participation. The arrangement-level object is continuation of the Google–Department of Defense capability relationship after the existing term. The public-mission object is continuation of the military imagery-analysis function through Google or another provider. The arrangement-level relationship is the Minimum Causally Complete Permission Object because continuation required government demand and procurement authority, Google’s consent and capability, a follow-on contractual state, and implementation by both sides.

The material trigger was a credible institutional challenge to continued Google participation before renewal. Employee objection, professional judgment, and the approaching follow-on decision made the continuation state reviewable before a new commitment became binding. Contemporary reporting described substantial employee opposition and Google’s decision not to renew the contract after its existing term. Google’s public principles and Google Cloud’s accompanying statement then made the boundary externally visible (Google 2018; Google Cloud 2018; Reuters 2018).

Google possessed a state-specific negative gate over renewal. The Department of Defense retained authority over the military purpose and could pursue the function through other providers, but it could not create the same Google–government relationship without Google’s consent. The gate therefore changed the joint permission state without transferring public sovereignty to the company.

Google classification

Political consequentiality and correction-relevant interdependence are supported at the arrangement level. Core-path deficiency is not established. Objection reached organizational reconsideration, judgment, a provider negative gate, and implementation through non-renewal before the relevant deadline. The public record does not reveal the complete Design State of internal standing, evidence access, forum, and handoffs, and the episode may have depended on exceptional mobilization rather than a durable routine. The appropriate result is:

No Core PAD Established / Activated and Effective / Provider state-specific negative gate / Design durability partly Unobservable.

Google 2018 is therefore a target-domain negative case. It shows that interdependence can contain an operative unilateral termination right. It does not establish a complete accountability, remedy, or renewal architecture, and it does not determine whether the substantive boundary was correct.

Anthropic refusal: object, trigger, and gate

The actor-local object is whether Anthropic would provide Claude under the requested terms. The arrangement-level object is authorization of an Anthropic–government deployment under terms permitting the disputed uses. The public-mission object is the government’s broader national-security function using Anthropic or another provider. The arrangement-level deployment is the causally complete primary object because it required government purpose and procurement authority, provider capability and consent, contractual formation, and joint implementation.

Anthropic publicly stated that it supported broad national-security cooperation while maintaining two restrictions concerning mass domestic surveillance and fully autonomous weapons. The material trigger was proposed contractual language that, in Anthropic’s account, conflicted with those restrictions. The deadline preceded binding or operational deployment under the disputed terms (Amodei 2026a; Anthropic 2026; Reuters 2026a).

Anthropic possessed a state-specific negative gate over use of its own capability. The government possessed public-purpose and procurement authority and could seek alternative providers, but the final Anthropic deployment could not be created without provider consent. Refusal was therefore an operative gate within the joint arrangement, not merely an external political position.

Anthropic refusal classification

Political consequentiality and correction-relevant interdependence are supported. Core-path deficiency is not established for the proposed deployment state: the material conflict reached provider judgment, a negative authorization gate, and implementation through nonauthorization. The complete negotiation record and internal process remain partly Unobservable. The appropriate result is:

No Core PAD Established / Activated and Effective at the negative authorization gate / Provider participation authority supported / Wider public legitimacy contested.

The case separates participation authority from public-purpose sovereignty. A provider can possess decisive authority over whether its capability enters one arrangement without acquiring authority to determine national-security policy as a whole.

19. Corporate Boundary Revision

Google’s 2025 principles

Google revised its public AI principles in February 2025. The updated framework emphasizes bold innovation, responsible development and deployment, and collaborative progress; it does not reproduce the 2018 categorical exclusions in the same form (Google 2025a, 2025b).

The primary object at this level is corporate doctrine. Google controlled the documentary revision, so the episode remains actor-local unless evidence connects the revision to a specific joint contract or deployment state. It is therefore not itself an inter-institutional PAD episode. Its principal relevance lies in assurance, durability, institutional memory, and authority quality.

Revision is not inherently evidence of correction failure. A governance boundary must remain capable of responding to new capabilities, evidence, law, and public purposes. The relevant questions concern the revision procedure: who possessed standing, what evidence was considered, how previous commitments were represented, which actors could challenge the change, and how the new doctrine entered operational agreements. The public documents establish the revised policy state, not the complete process or its downstream implementation.

OpenAI’s national-security principles

OpenAI’s July 2026 statement emphasized democratic accountability, meaningful human judgment, rule of law, cross-company process, and employee and stakeholder engagement. It also argued that private companies should inform rather than unilaterally determine consequential public decisions (OpenAI 2026c).

These principles are evidence of a declared authority-quality and assurance position. They do not establish binding incorporation into every classified agreement, independent verification, breach enforcement, remedy, or reauthorization. Corporate doctrine can support a correction architecture without substituting for its operational path.

20. Classified Authorization Under Non-Observability

Google’s 2026 classified agreement

On May 1, 2026, the U.S. Department of Defense—using the secondary public title “Department of War” in its public communications—announced classified-network AI agreements with eight technology companies, including Google. The release stated that the companies would deploy advanced AI capabilities in Impact Level 6 and 7 environments for lawful operational use and described vendor diversity and avoidance of lock-in as design goals (U.S. Department of Defense 2025, 2026).

The causally complete object is the classified Google–government deployment relationship. Political consequentiality is supported because the object concerns classified national-security use. Correction-relevant interdependence is also supported: the government controls public purpose, classified operational context, and procurement authority, while Google controls relevant technical capability and may control access, updates, or safeguards.

The announcement does not disclose the post-trigger correction path. The public record does not establish trigger rules, standing, classified evidence routes, the competent correction forum, state-specific gate allocation after deployment, technical implementation of restriction or termination, appeal, remedy, or reauthorization. These functions are Unobservable, not proven absent.

The appropriate result is:

Core PAD Indeterminate / Initial AUTHORIZE–CONTINUE state publicly established / Post-trigger core path Unobservable.

The 2026 agreement should not be described as proof that Google violated either its earlier or revised principles. Nor does the public record establish that Google had withdrawn from every military or national-security relationship during the period between Project Maven and the new announcement.

OpenAI’s initial agreement and operational implementation

OpenAI publicly described government programs, classified deployment, and restrictions concerning domestic surveillance, autonomous-weapons direction, and high-stakes automated decisions. It also described secure or cloud-based deployment, retained discretion over its safety stack, classifiers, cleared personnel, a working group, and contractual termination protections (OpenAI 2025, 2026a, 2026b; Reuters 2026g).

These sources establish a declared hybrid governance design. They do not independently establish the complete executed agreement, the performance of monitoring and classifiers, provider access to downstream operational evidence, government compliance, effective termination in practice, or the full trigger-to-implementation chain. OpenAI’s July principles add a public normative framework but do not verify classified operation (OpenAI 2026c).

For the causally complete classified deployment object, political consequentiality and interdependence are supported. Core-path deficiency cannot be established or rejected from the public record. The initial and operational episodes therefore remain:

Core PAD Indeterminate / Declared AUTHORIZE–CONDITION state / Operational correction path Unobservable.

Epistemic implication

The classified cases are central to the theory precisely because consequential authority and evidence are distributed across institutions and access regimes. Their importance cannot be converted into confidence about hidden structure. The defensible research result is an evidence requirement: authorized access would be needed to test trigger rules, gate maps, technical controls, implementation records, and renewal mechanisms.

21. Reactive Judicial Correction

Anthropic litigation

After Anthropic’s refusal, the company reported a formal government designation and initiated legal challenges. In the California proceeding, the court issued preliminary injunctive relief within the scope of the order. A separate D.C. proceeding produced a different interim result. The cited records concern interim relief rather than a final merits disposition (Amodei 2026b; Anthropic PBC v. U.S. Department of War 2026; Reuters 2026d, 2026e).

The proceedings supplied real correction functions: standing, a legal forum, judgment, interim remedial authority, and implementation obligations. The existence of courts therefore prevents the episode from being described as judgment with no route to authority.

Litigation as a substitute path

Judicial access does not automatically establish a reliable substitute for prospective correction. Litigation must be evaluated against the causally complete object and deadline. It counts as a reliable substitute only where it can receive the relevant claim and evidence, preserve the decision opportunity, issue a state-relevant order, reach implementation, and cover the material permission state. Otherwise it may be Conditional, Partially Effective, Retrospective, or Unobservable.

The Anthropic path was reactive, costly, jurisdictionally differentiated, and incomplete. Yet it operated sufficiently to produce interim judicial consequences. The appropriate result is:

No Core PAD Established / Reactive path active and partially effective / Authority quality contested / Substantive correctness unresolved.

This classification does not treat litigation as a mature shared AI-governance architecture. It recognizes it as an institutionally real backstop while preserving the distinction between prospective correction and after-conflict review.

22. Documentary Correction in a Hybrid Arrangement

OpenAI’s March 2 clarification

OpenAI added more explicit language to its public agreement page shortly after the initial announcement. The update stated that its tools would not be used for domestic surveillance of U.S. persons and that services to specified intelligence agencies would require a new agreement (OpenAI 2026b; Reuters 2026g).

The actor-local object is the public wording. The arrangement-level object is the contractual restriction state governing the classified relationship. The material trigger was ambiguity or concern concerning surveillance scope. The documentary state changed, but the public record does not independently establish whether the update amended an executed contract, clarified an existing term, changed the operative permission state, or altered technical controls.

The episode is therefore:

Activated and partially effective documentary correction / No Core Manifest PAD established / Operational effect Unobservable.

This classification preserves both sides of the evidence. A real public state change occurred. It is not equivalent to verified downstream implementation.

23. Alaska and Flint as Limited Adjacent Contrasts

Alaska Airlines Flight 1282

After the January 2024 in-flight door-plug separation, aviation authorities activated established investigative and regulatory functions. The Federal Aviation Administration grounded affected Boeing 737-9 MAX aircraft and required inspection and maintenance conditions before return to service; the National Transportation Safety Board opened the safety investigation (Federal Aviation Administration 2024a, 2024b; National Transportation Safety Board 2024–).

The episode supplies a low-ambiguity benchmark in which a salient material trigger reached an operative SUSPEND–HOLD gate and implementation. It also illustrates Functional Compression: evidence review, regulatory judgment, suspension authority, and implementation were partly integrated in a mature emergency process.

Alaska does not validate the complete PAD instrument. It does not establish full repair of Boeing production quality, long-term assurance maturity, or close institutional equivalence to classified frontier AI. Its narrower function is to show that distributed institutions can produce timely operative correction.

Flint water crisis

The Minimum Causally Complete Permission Object is continued distribution and public use of Flint drinking water under the local, state, and federal treatment and oversight state after credible evidence of lead exposure and inadequate response. The material trigger is credible evidence that continued distribution exposed residents while state and local response remained inadequate.

EPA Office of Inspector General reports concluded that the federal agency had sufficient information and emergency authority earlier than the eventual federal order and identified management weaknesses involving role clarity, risk assessment, communication, proactive oversight, and use of available statutory tools. These findings support a candidate failure in the Evidence → Review and Judgment → Gate interfaces and supply structural evidence independent of the final delayed intervention (U.S. Environmental Protection Agency, Office of Inspector General 2016, 2018).

Flint is provisionally classified as:

Adjacent-domain Core Manifest PAD candidate / Failed or delayed path / Moderate confidence / Independent coding and rival-theory validation required.

The case remains strongly reducible to state capacity, principal–agent relations, many hands, legal interpretation, evidence interpretation, and political incentives. Its role is to test whether the PAD object, trigger, gate, and handoff fields add diagnostic or intervention value—not to validate the theory or establish frontier-AI prevalence.

24. Cross-Case Findings

Agency and interdependence

The cases reject the proposition that frontier AI providers are politically inert. Google and Anthropic exercised provider-specific negative gates; OpenAI changed public documentation; and courts produced interim legal consequences. Interdependence is not itself a deficit. A joint arrangement may be corrected through a unilateral gate where that gate is sufficient for the triggered state transition.

Target-domain classification

The development set contains:

Episode type: Google 2018 non-renewal

Principal finding: Within scope; effective provider negative gate; No Core PAD Established

Episode type: Anthropic refusal

Principal finding: Within scope; effective provider negative gate; No Core PAD Established

Episode type: Google 2025 doctrine revision

Principal finding: Actor-local policy revision; outside PAD at that object level

Episode type: Google 2026 classified deployment

Principal finding: P1 and P2 supported; P3 Unobservable; Indeterminate

Episode type: Anthropic litigation

Principal finding: Reactive and partially effective substitute path

Episode type: OpenAI initial and operational deployment

Principal finding: P1 and P2 supported; P3 Unobservable; Indeterminate

Episode type: OpenAI clarification

Principal finding: Documentary correction; operational effect Unobservable

No frontier-AI episode is classified as confirmed Core Manifest PAD.

Contrast discipline

Alaska provides a low-ambiguity successful-correction benchmark. Flint provides a provisional adjacent-domain positive candidate. Neither establishes frontier-AI prevalence or validates the codebook. Together they prevent the instrument from being developed solely around opaque disputes: one shows successful state transition, while the other tests whether delay can be localized to a core path rather than described generically as governance failure.

Public-record conclusion

Across the examined frontier-AI episodes, the public record reveals actor agency, distributed authority, negative gates, reactive legal review, documentary correction, and substantial classified non-observability. It does not establish a confirmed target-domain Core Manifest PAD case or a routinely observable shared correction architecture. This is a sample-bounded public-record finding, not a field-level thesis.

Part V — Causal Program and Design Hypotheses

25. Capability–Authority Separation and Evidence Misalignment

Separation as normal condition

Frontier AI government partnerships distribute capability and authority by design. Governments define public purposes, appropriate resources, and authorize state action. Companies develop models, control proprietary infrastructure, and interpret technical behavior. Customers integrate systems into operational workflows. Courts review legality. Oversight bodies examine compliance. Employees and professional communities may identify risks invisible to executives or public officials.

Such separation is not inherently defective. It can protect democratic authority from technocratic capture and technical organizations from compelled participation beyond their lawful or contractual obligations. It can create specialization, redundancy, and checks on concentrated power.

The structural problem begins only when separation produces a broken correction path.

Capability–authority separation

Capability–authority separation is the distribution of technical capability and political authority among different actors or institutions. It may separate:

  • technical knowledge from purpose authority;

  • model access from deployment authority;

  • legal authorization from downstream observability;

  • burden exposure from review standing;

  • public legitimacy from technical control;

  • classification authority from accountability forums;

  • gate authority from implementation capacity.

The separation becomes deficit-producing where each actor controls only one segment, responsibility handoffs are unclear, evidence cannot cross institutional boundaries, and no actor or coordinated structure evaluates the complete chain. Within the ADM/CIV vocabulary developed elsewhere in the RATIUM.AI corpus, these are functional positions rather than permanent social identities: an actor may authorize in one relationship and remain exposed or dependent in another (Dunavich 2026a).

The core problem is not separation. It is:

separation without integration, traceability, and correction.

Evidence–authority misalignment

Evidence–authority misalignment occurs where actors holding decision-relevant evidence lack an authorized and timely route to a state-specific gate, while actors possessing gate authority lack the evidence needed to evaluate the trigger. The mechanism predicts failure at the Evidence → Forum or Judgment → Gate interfaces. It is a causal hypothesis, not a substitute for the path diagnosis.

Orphaned political inference

An orphaned political inference is a politically consequential chain of reasoning whose component decisions are distributed but whose complete transition from purpose to consequence lacks integrated validation and correction ownership.

The generic chain is:

Political purpose

procurement

technical translation

deployment

downstream use

civil consequence

The researcher develops a capability. The provider packages it. The government defines a purpose. A contracting authority authorizes access. A customer integrates the model. A human formally approves an action. An affected public absorbs the consequence. Each actor may accurately state that it controlled only one segment.

The inference is not orphaned merely because responsibility is distributed. It becomes orphaned where four properties are absent:

  1. Traceability: the chain cannot be reconstructed.

  2. Handoff responsibility: each actor fails to specify what assumptions and duties pass to the next actor.

  3. Integrated ownership: no actor or coordinated structure evaluates the complete transition.

  4. Corrective authority: no legitimate and accountable actor or structure can alter permission when the chain fails.

A system can remain discursively open while becoming operationally closed: criticism is received, recorded, and discussed, but no gate changes. That distinction between criticism and correction is developed in the RATIUM.AI correction-failure framework (Dunavich 2026g).

The appropriate claim is not “no one is responsible.” It is:

Responsibility is distributed, while responsibility for validating and correcting the complete political inference remains unassigned or ineffective.

Disconfirmation

Capability–authority separation is not pathological where the evidence shows clear handoffs, integrated review, access to necessary knowledge, defined gate authority, enforceable implementation, and remedy. A plural architecture that performs these functions is not a deficit. It is the normative alternative the article seeks to specify.

26. Dependency, Accommodation, and Persistence

Instrumental translation

A national-security objective can become classified infrastructure, data pipelines, model-access controls, threat categories, confidence scores, planning tools, and operational dashboards. A surveillance purpose can become identity resolution, anomaly detection, pattern recognition, or data fusion. Strategic competition can become compute policy, export controls, industrial capacity, and accelerated procurement.

The professional question becomes:

How should the system execute the objective?

The prior political question is:

Should this objective, scope, and authority continue to govern the system?

Technical competence cannot answer the second question by itself. The distinction corresponds to the separation between instrumental reason, which evaluates means relative to given ends, and corrective or critical reason, which can subject the ends, metrics, authorities, and procedures themselves to review (Dunavich 2026d).

The failure is not specialization. Engineers should not independently determine foreign policy, military strategy, or public law. The failure is specialization without integration and correction.

Political-ontology conversion

Political-ontology conversion is the process through which a contingent political settlement becomes treated as a fixed operational property of the environment.

The sequence is:

Political decision → institutional description → technical assumption → protocol

A war, law, sanctions regime, administration, strategic rivalry, or security threat can be entirely real. The concept does not deny the constraint. Conversion occurs when the political origin of the constraint becomes institutionally irrelevant, the justification is no longer carried forward, and technical work treats continuation as the only admissible world state.

For example, a governmental purpose may enter a contract as a lawful-use category. The provider then focuses on performance, safety, and compliance. The customer focuses on operational integration. The legal team focuses on formal authorization. Each performs a legitimate specialized task. Yet the purpose itself may lack a defined route for review when capabilities, downstream uses, or political conditions change.

Political-ontology conversion explains how political choice becomes operational premise without becoming apolitical. It extends the argument that an institutional protocol can inherit an accepted ontology while losing the justificatory procedure that should keep that ontology open to correction (Dunavich 2026f).

Reactive political accommodation

Reactive political accommodation occurs when an institution delays binding political judgment until an external order has already entered its operations, then adapts without treating the adaptation as a separately authorized political choice.

The mechanism is:

Initial ambiguity

operational entry

dependency

sunk cost and identity

raised deviation cost

narrowed correction

Early ambiguity can be useful. Institutions often need pilots, provisional agreements, and exploratory relationships. The problem arises when provisional entry generates infrastructure, staffing, strategic identity, customer reliance, and competitive commitment before the institution defines its political boundaries.

Once dependency develops, correction becomes more costly. Employees may risk careers. Executives may risk public contracts. Governments may risk operational continuity. Providers may believe refusal will merely transfer the activity to a competitor. This is a path-dependent mechanism: early operational choices can generate sunk costs, coordination effects, institutional learning, and increasing returns that raise the price of reversal (Pierson 2000). The question is no longer only whether the relationship is justified. It becomes whether the institution can afford to reopen it.

The mechanism should be diagnosed through observable conditions rather than rhetoric: accumulated infrastructure, dedicated personnel, contract dependence, replacement difficulty, strategic identity, switching costs, and the absence of a prospective exit or reauthorization rule.

Prospective boundaries

The article does not demand continuous reconsideration of every political purpose. It requires defined triggers for renewed authorization. Relevant triggers include:

  • material expansion of scope;

  • changed legal authority;

  • newly discovered capability or risk;

  • new downstream use;

  • credible rights-impact evidence;

  • breach of a restriction;

  • emergency authorization becoming persistent;

  • extension beyond the original authorization period;

  • significant evidence withheld from the original decision;

  • failure of a safeguard;

  • conflict among government, provider, and oversight authorities.

Prospective boundary formation lowers the cost of correction. A boundary defined before dependency can be embedded in contracts, technical architecture, monitoring, and exit plans. A boundary articulated after integration faces sunk costs and strategic pressure.

Dependency and exit cost

Integration can raise later correction cost through infrastructure, specialized personnel, data, legal commitments, operational routines, switching cost, and institutional identity. Dependency is an antecedent or moderator. It does not establish PAD unless it helps produce or sustain a located core-path deficiency.

CEP/S4 boundary

CEP/S4 may analyze persistence after PAD classification through local rationality, concentrated deviation cost, distributed correction benefit, displaced purpose authority, blockage, and persistence. It does not define PAD, prove a Nash equilibrium, or replace the requirement for a feasible counterfactual.

S4 persistence protocol

The Central Equilibrium Problem supplies a bounded reference model for explaining how locally rational behavior can stabilize a collectively correction-resistant arrangement. Within CEP’s internal vocabulary, S4 is labeled National-Monotheism and modeled as a Pareto-inefficient Nash equilibrium (Dunavich 2026c). That label belongs to the CEP corpus. It is not an empirical classification of a company, government, or industry.

The present article does not map the frontier AI field onto a complete game. It does not claim empirical proof of Nash equilibrium or Pareto inefficiency. It separates two inferential tasks that must not be collapsed:

  1. diagnosis of an S4-analogous persistence structure;

  2. evaluation of a feasible counterfactual improvement required for any Pareto-related claim.

Stage A — Persistence structure

Stage A asks whether the episode contains a persistence mechanism analogous to S4. Six tests apply.

Test 1 — Local rationality

Is continuation individually or institutionally rational for the relevant actors under existing incentives and constraints?

Evidence may include revenue, strategic access, public mission, legal duty, competitive pressure, replacement risk, professional position, sunk cost, or national-security claims. Local rationality is descriptive. It does not imply moral approval.

Test 2 — Concentrated deviation cost

Would unilateral refusal, exit, or correction impose concentrated costs on the actor expected to deviate?

Costs may include employment, contract loss, government exclusion, litigation, strategic access, institutional identity, capital loss, reputational harm, or security risk. High cost alone is not an S4 diagnosis.

Test 3 — Distributed correction benefit

Are the benefits of correction dispersed, uncertain, delayed, or difficult for one actor to capture?

Possible benefits include reduced public risk, stronger rights protection, improved legitimacy, greater institutional trust, or lower long-term systemic cost. The test is not satisfied merely by labeling a benefit “public.” The analysis must identify who benefits and why those benefits do not create sufficient unilateral incentive.

Test 4 — Displaced purpose authority

Are actors with capability, evidence, or burden separated from actors defining the governing purpose in a manner relevant to correction?

Ordinary specialization is insufficient. The separation must block or weaken the correction path.

Test 5 — Correction blockage

Does a credible correction trigger lack a reliable path to an operative permission determination?

This is the central link between political agency deficit and the S4 persistence mechanism. The test is not satisfied where a functioning process exists and merely produces a contested result.

Test 6 — Persistence

Does the arrangement continue or reproduce itself after the relevant problem and correction barrier become visible?

Persistence may appear through repeated episodes, unchanged authority structures, emergency normalization, repeated bypass of objection, or continuation without reauthorization.

Stage A evidence states and outputs

Each test receives one of four qualitative statuses:

  • Supported;

  • Partially supported;

  • Not supported;

  • Unknown.

Stage A yields one of four outputs:

  • Not structurally relevant;

  • Insufficient evidence;

  • Structurally suggestive;

  • S4-consistent at the level of the persistence mechanism.

The strongest output requires support for all six persistence tests and no material contrary evidence. It must never be translated into “proved Nash equilibrium.”

Stage B — Feasible counterfactual improvement

Stage B is separate.

Is there a defined, institutionally feasible alternative under which relevant burdens, correction access, or institutional performance could improve without merely transferring concealed costs elsewhere?

The alternative must specify:

  • responsible actor;

  • authority basis;

  • implementation mechanism;

  • transition cost;

  • operational and security trade-offs;

  • expected improvement;

  • residual burden.

Satisfaction of the persistence tests does not by itself establish Pareto inferiority. Pareto-related language requires a separate feasible-alternative analysis and evidence that the proposed alternative does not simply relocate unacknowledged costs.

Application boundary

The three corporate cases are not preclassified.

Google’s 2018 correction outcome weighs against correction blockage in that episode. Anthropic demonstrates corporate agency and judicial review even while revealing high deviation cost and authority conflict. OpenAI remains institutionally unresolved because public documentation reveals a declared hybrid model more clearly than its classified implementation.

The protocol is therefore allowed to return insufficient evidence. Its function is diagnostic discipline, not confirmation of CEP in every case. The primary political-agency thesis stands independently of CEP.

27. Hypotheses and Rival-Theory Tests

H1 — Integration

Capability–authority separation predicts weaker core correction only where integration of the trigger-relevant path is weak. Separation alone should not predict PAD.

H2 — State-specific gate authority

A bounded full-spectrum or state-specific gate, or binding referral to such a gate, predicts operative determination and implementation beyond advisory review.

H3 — Evidence alignment

Authorized evidence routes predict activation and core-path completion after controlling for technical uncertainty and substantive disagreement.

H4 — Prospective boundaries and dependency

Prospective boundaries should reduce later correction cost; dependency should reduce the probability or magnitude of correction after mission value and necessity are controlled. These hypotheses concern timing and persistence, not the definition itself.

H5 — Accountability coupling

Accountability should improve implemented correction only where it connects to state-specific gate and implementation authority. Accountability remains a separate dimension and interaction variable.

H6 — Handoff reliability

Core handoff performance should predict correction better than formal function presence. Design State and Episode Performance must be modeled separately.

H7 — Secrecy differentiation

Classified systems may sustain core correction through differentiated evidence access, cleared review, bounded gate authority, and limited public intelligibility. Universal disclosure is not required; unreviewable secrecy is not sufficient.

Rival instruments

Holdout studies must compare state capacity, accountability, veto players, principal–agent, many hands, and PAD instruments. If object, trigger, gate, and interface variables add no value, the framework should be narrowed or reclassified.

Comparative extensions and falsification program

The article generates a research program rather than a closed empirical conclusion.

Hypothesis 1 — Capability–authority separation

Claim: Greater separation between operational capability and access to purpose review increases correction resistance where integration mechanisms are weak.

Indicators: authority maps, evidence-access rights, review pathways, gate authority, and time from trigger to decision.

Competing explanation: technical complexity rather than institutional separation.

Falsification: highly separated systems with reliable integration perform as well as or better than less separated systems.

Hypothesis 2 — Dependency and deviation cost

Claim: High deviation cost predicts correction failure when combined with displaced purpose authority, distributed correction benefits, and weak review.

Indicators: contract dependence, strategic access, employment risk, litigation, replacement risk, sunk infrastructure, and switching costs.

Competing explanation: substantive disagreement rather than structural blockage.

Falsification: high-cost actors routinely correct through reliable institutional paths.

Hypothesis 3 — Prospective-boundary durability

Claim: Boundaries defined before dependency are more durable and enforceable than boundaries introduced after integration.

Indicators: timing of policy adoption, contract language, later revisions, enforcement events, and exit capacity.

Competing explanation: leadership ideology or reputational strategy.

Falsification: post-dependency boundaries prove equally durable under comparable conditions.

Hypothesis 4 — Accountability–determination effect

Claim: Accountability changes institutional conduct only where answerability connects to a forum or actor capable of consequence and an operative permission determination.

Indicators: audit findings, forum authority, gate decisions, sanctions, and recurrence.

Competing explanation: informal norms produce change without formal authority.

Falsification: advisory accountability consistently produces implemented gate determinations without any consequential pathway.

Hypothesis 5 — Responsibility fragmentation

Claim: Separation among capability creation, purpose, deployment, burden, accountability, and stopping authority increases the risk of orphaned political inference.

Indicators: handoff documentation, integrated ownership, downstream observability, and incident reconstruction.

Competing explanation: poor management within one institution.

Falsification: highly fragmented systems routinely preserve complete traceability and correction ownership.

Hypothesis 6 — Hybrid-governance reliability

Claim: Hybrid corporate–state governance is reliable only where restrictions, evidence access, conflict procedures, accountability forums, remedies, and reauthorization are enforceable across institutional boundaries.

Indicators: contracts, audit rights, stop-work provisions, classified review, appeal, remedy, and expiration.

Falsification: hybrid systems without these mechanisms reliably correct under comparable stress.

Counterfactual rule for equilibrium interpretation

A claim that an arrangement is S4-consistent at the level of persistence does not establish Pareto inferiority.

Any Pareto-related interpretation must identify a specified feasible alternative, including:

  • responsible actor;

  • authority basis;

  • implementation mechanism;

  • transition cost;

  • operational and security trade-offs;

  • expected distributional improvement;

  • residual burden.

The rule is methodological rather than an empirical hypothesis.

Comparative extensions

Future research should examine:

  • non-U.S. public–private AI partnerships;

  • cloud and compute providers as governance actors;

  • open-source ecosystems;

  • international and allied classified oversight;

  • employee standing and whistleblower protection;

  • downstream technical rollback;

  • burden concentration and procedural standing;

  • sector-wide minimum restrictions;

  • empirical testing of the two-stage S4 protocol.

The Technical Supplement develops this extension through the object, trigger, standing, and burden-concentration protocols without treating burden alone as proof of exclusion from correction.

28. Risk-Proportional Corrective Political Architecture

Design status

Corrective Political Architecture is a risk-proportional design hypothesis derived from the process model. It is not an empirically validated institutional blueprint and does not imply that every system requires the same number of bodies, vetoes, or reports.

Minimum viable core

At minimum, a politically consequential interdependent arrangement requires trigger recognition, authorized standing, decision-relevant evidence, competent judgment, a state-specific gate, implementation, and a decision record. Risk-management frameworks can support trigger and evidence design without supplying political authority by themselves (National Institute of Standards and Technology 2023). Forum, judgment, and gate may be compressed where authority and evidence are clear.

Legitimation and standing

The first layer specifies why an actor is entitled to exercise authority.

Authority basis

Every consequential decision must identify its source of authority:

  • democratic mandate;

  • statute or regulation;

  • constitutional competence;

  • contract;

  • corporate charter;

  • board authority;

  • judicial authority;

  • professional mandate;

  • affected-party participation;

  • independent public oversight.

No source is universally sufficient. Contract may authorize a provider to restrict access but cannot by itself confer authority over national policy. Democratic mandate may authorize a public purpose but does not remove statutory limits, constitutional rights, or contractual obligations.

Domain boundary

The architecture must specify what each actor may and may not decide.

Government may define public and national-security purpose. The provider may control technical safeguards and model access. A cleared review body may judge compliance. A court may judge legality. An employee or affected party may possess standing to trigger review without possessing final decision authority.

The domain boundary prevents both public abdication and private constitutionalism.

Role-sensitive procedural standing

Equal political status is compatible with differentiated procedural standing.

The architecture should distinguish:

  • evidence-submission rights;

  • consultation rights;

  • escalation rights;

  • review rights;

  • appeal rights;

  • narrowly scoped SUSPEND / HOLD or veto rights where justified.

Technical experts may possess standing because they understand capability or failure modes. Employees may possess standing because they observe internal decisions. Affected communities may possess standing because they experience consequences invisible to providers and customers. Burden-bearing groups may possess standing because institutional decisions impose distinctive costs.

Standing does not imply superior citizenship. It is a mechanism for ensuring that relevant knowledge and exposure enter the correction process.

Veto discipline

Any veto must be explicit, bounded, reason-giving, reviewable, and time-limited where possible. An unreviewable private veto can become a form of corporate sovereignty. An unreviewable governmental veto can eliminate all meaningful provider or civil correction.

Purpose and scope

A politically consequential capability should not be authorized through an undefined purpose such as “lawful use” without further scope specification.

The architecture should identify:

  • declared public purpose;

  • authorized use class;

  • prohibited use class;

  • customer and user scope;

  • geographic scope;

  • temporal scope;

  • downstream-use assumptions;

  • permitted autonomy level;

  • data sources;

  • change-control procedure;

  • emergency-use conditions.

The purpose must remain connected to its technical translation:

Purpose → requirement → model use → operational consequence

Material scope change

Material change requires renewed authorization. Relevant changes include:

  • a new customer or agency;

  • a new geographic theater;

  • a new surveillance capability;

  • a new degree of autonomy;

  • a new data source;

  • integration into a new operational workflow;

  • a changed legal basis;

  • extension beyond the original authorization period.

A system may satisfy the original contract while drifting into a politically different use through cumulative technical integration. Scope control prevents incremental change from escaping political review.

Emergency authorization

Emergency authorization may be necessary. It should include:

  • a narrow purpose;

  • a named authority;

  • restricted scope;

  • automatic expiration;

  • record preservation;

  • retrospective review;

  • prohibition on silent normalization.

The institutional danger is not emergency power alone. It is emergency power that becomes permanent without affirmative reauthorization.

Evidence and observability

Correction requires evidence proportionate to the decision.

The architecture should preserve:

  • capability documentation;

  • contract and restriction records;

  • model and deployment documentation;

  • audit logs;

  • downstream-use visibility;

  • incident reports;

  • responsibility handoffs;

  • evidence preservation;

  • access rights for authorized reviewers;

  • procedures for challenging withheld or classified evidence.

Democratic legitimacy without relevant technical evidence is incomplete. Technical knowledge without legitimate authority is also incomplete.

Declared, contractual, and operational levels

Evidence must distinguish:

  1. Declared rule — what the institution publicly says.

  2. Contractual rule — what the parties are legally obligated to do.

  3. Operational control — what the system technically permits or prevents.

  4. Monitoring — what use can be observed.

  5. Breach detection — how violations become visible.

  6. Enforcement — who can alter the state after violation.

  7. Remedy — what follows the violation.

Many governance claims fail because they establish only the first level.

Classified environments

A realistic architecture must distinguish public transparency from cleared accountability.

The classified layer should include:

  • cleared independent reviewers;

  • compartmented access to relevant evidence;

  • protected audit logs;

  • questioning rights;

  • authority to trigger escalation or SUSPEND / HOLD;

  • classified reporting to authorized public institutions.

The public layer should disclose, where lawful:

  • the purpose category;

  • legal authority;

  • prohibited-use classes;

  • existence and mandate of the review institution;

  • dates of authorization and reauthorization;

  • aggregate compliance findings;

  • incidents and remedies in non-sensitive form.

The public does not need operational secrets to know whether a correction architecture exists.

Institutions such as the Privacy and Civil Liberties Oversight Board (PCLOB) provide a functional precedent: authorized access to classified records combined with public reporting to the greatest extent consistent with national security (Privacy and Civil Liberties Oversight Board n.d.). Classification-challenge procedures under Executive Order 13526 similarly demonstrate that secrecy boundaries can themselves be reviewable (Executive Order 13526 2009) (U.S. Government Accountability Office 2021).

Decision and implementation gates

Evaluation becomes governance only where it can produce and implement an operative permission determination.

The architecture uses four gate states.

AUTHORIZE / CONTINUE

Authorize or continue within defined purpose and scope.

AUTHORIZE / CONTINUE is not the absence of governance. It is an affirmative permission determination supported by evidence and authority.

CONDITION / RESTRICT

Authorize or continue under narrower conditions.

Restrictions may apply to:

  • user class;

  • customer;

  • geography;

  • data;

  • capability;

  • autonomy;

  • deployment environment;

  • duration;

  • downstream integration.

SUSPEND / HOLD

Suspend all or part of the activity pending evidence, review, legal determination, conflict resolution, or safeguard repair.

A SUSPEND / HOLD must specify:

  • trigger;

  • authority;

  • scope;

  • duration;

  • evidence required;

  • next decision date;

  • operational continuity plan.

Federal procurement’s stop-work mechanism demonstrates that temporary suspension can be a legally structured state rather than an informal delay (Federal Acquisition Regulation n.d.).

REVOKE / TERMINATE / ROLLBACK

Reverse, withdraw, terminate, or materially undo authorization.

REVOKE / TERMINATE / ROLLBACK may include:

  • model-access revocation;

  • contract termination;

  • removal from a deployment;

  • technical disablement;

  • scope reversal;

  • replacement by a constrained system;

  • managed transition.

Contract termination provides a legal analogue, but AI-specific rollback requires technical planning. Removing future access may not eliminate deployed copies, derived artifacts, embedded workflows, or trained personnel. REVOKE / TERMINATE / ROLLBACK must address downstream persistence.

Required gate fields

Every gate rule should specify:

  1. trigger;

  2. threshold;

  3. decision authority;

  4. evidence standard;

  5. time limit;

  6. implementation actor;

  7. monitoring;

  8. appeal;

  9. remedy.

Bounded terminal authority

A gate decision needs operative force. The holder may be one actor, a joint body, a sequential process, a court, a contracting officer, or a cleared reviewer with temporary SUSPEND / HOLD power.

Terminal ownership cannot be indefinitely recursive. The process must identify who produces the operative decision, even if that decision is provisional and reviewable.

Assurance, remedy, and renewal

Accountability requires an actor, a forum, a duty to explain, questioning power, judgment, and consequence (Bovens 2007).

The architecture should identify:

  • who is answerable;

  • to which forum;

  • for which decision;

  • under which standard;

  • with access to what evidence;

  • with what consequence.

Multiple-forum protocol

Government, corporate, judicial, professional, employee, and public accountability claims may conflict. The architecture should define:

  • jurisdiction of each forum;

  • issue-specific competence;

  • precedence rules;

  • referral routes;

  • appeal routes;

  • provisional terminal authority.

Without this protocol, plural accountability can become multiple-accountabilities disorder rather than correction (Koppell 2005).

Appeal

Appeal should be available for:

  • factual error;

  • scope classification;

  • withheld evidence;

  • authority disputes;

  • breach findings;

  • gate decisions;

  • remedy.

Appeal does not require public litigation in every case. It may proceed through a cleared independent body, administrative process, contractual panel, court, or combination.

Remedy

A mature architecture must define what follows failure.

Operational remedies include suspension, restriction, withdrawal, and replacement.

Legal remedies include injunction, contract relief, statutory review, and damages.

Civil remedies include notification, compensation, and restoration of rights.

Organizational remedies include authority reassignment, staff protection, process reform, and recurrence prevention.

Informational remedies include disclosure, correction of the record, and public explanation.

Accountability without consequence may become ceremonial. Consequence without appeal may become arbitrary.

Layer 6 — Expiration, Reauthorization, and Institutional Learning

Politically consequential partnerships should not continue indefinitely through inertia.

The architecture should require:

  • a sunset date;

  • reauthorization standard;

  • changed-circumstances review;

  • incident review;

  • revision history;

  • non-sensitive public reporting;

  • institutional memory;

  • transition planning;

  • recurrence-prevention review.

Reauthorization should ask:

  • Does the original purpose remain valid?

  • Has the scope changed?

  • Have capabilities changed?

  • Have downstream uses changed?

  • Have burdens or risks changed?

  • Were restrictions effective?

  • Did incidents occur?

  • Is the authority structure still legitimate?

  • Is a feasible alternative available?

Time-limited authorization structures in national-security law demonstrate the institutional principle that sensitive authority can require periodic renewal. The article does not endorse any particular substantive program by using its temporal architecture as an analogue.

Risk-proportional expansion

Independent review, appeal, remedy, reauthorization, public reporting, evidence preservation, and stronger challenge rights should expand with coercion, irreversibility, scale, secrecy, dependency, rights effect, duration, recurrence, and uncertainty. These maturity dimensions strengthen governance but do not become PAD by definition.

29. Configuration-Burden Test and Failure Modes

Configuration-Burden Test

A correction architecture can become self-defeating if specification, review, evidence preparation, coordination, and compliance work displace the public objective. The Configuration-Burden Test asks whether the proposed governance layer adds enough correction value to justify its delay, cost, veto density, expertise dependence, and administrative load. The test is a design self-audit, not another PAD condition.

Private constitutionalism and expertise capture

A frontier AI company may convert safety principles into quasi-constitutional authority over public action without democratic mandate.

Mitigation: bounded domain authority, public-purpose primacy, reason-giving, external appeal, expiration, and reviewable veto.

Multiple accountability and secrecy

Government, boards, employees, courts, customers, investors, and publics may impose incompatible demands.

Mitigation: issue-specific forum mapping, precedence rules, conflict procedures, and bounded terminal authority.

Secrecy shield

Classification may be used not only to protect operations but to prevent all review of scope, compliance, or remedy.

Mitigation: cleared oversight, compartmented access, classification challenge, protected records, and aggregate public reporting.

Threshold gaming

Institutions may define correction triggers so narrowly that review never opens.

Mitigation: objective triggers, periodic independent evaluation of thresholds, and escalation rights for affected parties and technical staff.

Responsibility laundering

Each actor may point to another actor’s authority while preserving the benefits of participation. The provider cites democratic government; the government cites the provider’s safeguards; the operator cites human approval; the executive cites legal review.

Mitigation: authority maps, handoff records, integrated ownership, and joint accountability for the complete inference.

Emergency normalization

Temporary permissions may become permanent without affirmative decision.

Mitigation: automatic sunset, retrospective review, and explicit reauthorization.

Exit substitution

A provider’s refusal may transfer the activity to a less constrained provider rather than correct the public purpose.

Mitigation: procurement-wide minimum restrictions, public-purpose review, managed transition, and sector-level standards.

This mitigation has limits. Sector-wide standards may also create uniformity, entry barriers, or governmental overreach. The trade-off must be visible.

Veto paralysis

Extensive review rights can impede legitimate and urgent public action.

Mitigation: scoped authority, evidence thresholds, time-limited SUSPEND / HOLD, emergency provisional authorization, and rapid appeal.

Accountability theater

Institutions may create boards, reports, or principles that absorb criticism without changing authority or permission.

Mitigation: require every review mechanism to identify the gate it can alter, the actor it can compel, and the consequence it can trigger.

False precision

A formal architecture can create the appearance of control while the underlying evidence remains uncertain or contested.

Mitigation: explicit uncertainty categories, competing interpretations, documented assumptions, and authority to reopen decisions when evidence changes.

Design trade-off

The architecture must balance:

  • public legitimacy and private technical control;

  • secrecy and accountability;

  • speed and review;

  • provider autonomy and state decision authority;

  • plural standing and decisional clarity;

  • operational continuity and meaningful exit.

No design eliminates the trade-offs. A credible architecture makes them explicit, assigns authority, and creates reviewable procedures for managing them.

Part VI — Boundaries and Conclusion

30. Objections, Maturity, CEP/S4, LoopGuard-AI, and Conclusion

Democratic primacy and technocratic risk

Public institutions retain the strongest prima facie claim to define public purpose and lawful coercion. Provider evidence, professional standing, and technical control do not generate comprehensive public sovereignty. Conversely, democratic authorization cannot manufacture proprietary evidence or technical implementation. The architecture distributes functions without collapsing their sources of legitimacy.

Secrecy and review

Classified information limits public classification but does not make correction impossible. Cleared independent review, classification challenge, bounded reporting, audit records, and state-specific gates may preserve differentiated accountability. Where those mechanisms are not observable, the correct public result is Indeterminate.

The cases do not validate PAD

This objection is correct. The frontier-AI episodes expose provider negative gates, reactive legal correction, documentary change, and severe non-observability. They do not establish field prevalence or a confirmed target-domain positive case. Alaska and Flint constrain the model from adjacent domains; neither validates frontier-AI application.

Additional institutional objections

Poorly designed review can delay urgent public action, impose significant costs, and generate multiple-accountabilities disorder.

The answer is not maximal friction. It is risk-proportionate friction at correction-relevant points. The architecture distinguishes standing from veto, SUSPEND / HOLD from permanent prohibition, and temporary emergency authority from indefinite authorization. Review rights can be issue-specific, time-limited, and scaled to political consequence, irreversibility, coercive capacity, secrecy, and dependence.

The relevant comparison is not between governance and zero-cost action. It is between the cost of architecture and the expected cost of uncorrectable deployment, litigation, abrupt exit, rights violations, vendor dependence, or strategic failure.

Objection 5 — Market exit and technical safeguards are sufficient

Exit and technical safeguards are important but incomplete.

Exit may occur after dependency, impose prohibitive unilateral costs, transfer the activity to another provider, leave downstream uses intact, or threaten operational continuity. Technical safeguards depend on deployment architecture, logging, updates, integration, customer behavior, and the provider’s ability to observe use.

Managed exit, continuity clauses, monitoring, breach detection, technical revocation, and procurement-wide minimum conditions can convert isolated refusal into an institutional mechanism. They still require legitimate purpose authority, review, accountability, and remedy.

Objection 6 — Three U.S. cases cannot support a field-level diagnosis

The cases are not statistically representative, and the article does not treat them as such.

Their function is theory-building through variation in institutional pathway. They demonstrate that documented correction may occur through internal corporate authority, unilateral refusal, contract clarification, and litigation.

The sample-bounded conclusion is correspondingly narrow: across the examined episodes, the public record does not reveal a stable shared architecture. Comparative research in other jurisdictions, sectors, and institutional systems is required before any field-level generalization.

Objection 7 — CEP/S4 is being imposed on unrelated cases

The objection would be valid if every persistent or costly relationship were labeled an equilibrium. The article does not do that.

Stage A requires six persistence tests and allows “insufficient evidence” or “not structurally relevant.” Stage B separately requires a specified feasible alternative before any Pareto-related language is available. None of the three cases is preclassified as S4-consistent.

The primary political-agency thesis stands independently of CEP. CEP supplies a bounded explanatory lens for cases in which locally rational continuation and correction blockage coexist.

Objection 8 — Corrective architecture creates a new unaccountable authority

A single permanent correction body could reproduce the problem. The proposed architecture does not require one.

Authority is distributed by function and integrated at the gate. Terminal decisions are bounded, scope-specific, reason-giving, appealable, and time-limited. The architecture includes expiration, reauthorization, conflict-of-interest rules, and reciprocal accountability.

The risk remains real. Private constitutionalism, expertise capture, secrecy shields, threshold gaming, and veto-point paralysis are not external objections but internal failure modes of the design. If an implementation produces unaccountable private power or persistent paralysis, it fails the architecture’s own criteria and should be revised.

Reduction challenge

The independent status of PAD remains prospective. The strongest rival is state capacity, followed by veto-player, principal–agent, accountability, and many-hands theories. PAD survives only if the permission object, trigger indexing, state-specific gate map, gate–implementation distinction, and handoff variables add measurable value.

CEP/S4 and LoopGuard-AI

The Configuration-Burden Test extends the self-displacement problem developed in The AI Configuration Paradox, while the sequencing rule preserves the priority of solving the foundational decision problem before implementing a governance layer (Dunavich 2026b, 2026e). CEP/S4 remains a bounded persistence diagnostic applied after classification. LoopGuard-AI may implement trigger records, evidence routing, gate mapping, permission states, implementation checks, and reauthorization. Neither validates the theory. The direction is PAD requirements → candidate implementation, not software → theoretical proof.

Maturity statement

The present work is an advanced candidate inter-institutional process theory and measurement framework. Conceptual maturity is advanced; discriminant and measurement maturity are pre-validation; empirical maturity is theory construction with illustrative target-domain applications; causal hypotheses remain unvalidated; formal maturity is conceptual; governance maturity is a risk-proportional design hypothesis.

Scope limitations

The theory is centered on U.S.-based frontier-AI relationships with government and national-security institutions. Its legal precedents, authority structures, and public-record limits are therefore jurisdictionally specific. Portability to other states, supranational institutions, open-source ecosystems, universities, semiconductor supply chains, and purely private deployments remains an empirical question. The adjacent aviation and public-water cases test conceptual transport, not domain equivalence.

The article also distinguishes correction capacity from the quality of the public purpose itself. A reliable path can authorize a policy that is substantively or morally wrong, while a defective path can occasionally produce a desirable result. PAD is not a general theory of justice, democratic legitimacy, AI safety, or institutional wisdom. It concerns the conversion of decision-relevant change into an operative state. Its value depends on maintaining that boundary.

Conclusion

Frontier AI governance is often framed as a choice among public control, private restraint, technical safety, democratic legitimacy, or institutional accountability. The choice is false because each identifies a necessary but incomplete function.

The Political Agency Deficit isolates one narrower failure: a specified material trigger cannot reach an implemented permission state for a causally complete politically consequential object through an institutionally distributed path before the decision opportunity closes. The definition excludes controversy, opacity, corporate power, and wrong outcomes as sufficient evidence. It also excludes weak accountability or remedy from the core classifier while preserving them as dimensions of mature governance.

The object rule prevents descriptive manipulation. Trigger indexing prevents a near-universal revisability condition from creating pseudo-formality. State-specific gates explain how provider refusal can correct a joint state without creating private sovereignty. Functional compression prevents the model from demanding unnecessary bureaucracy. Design State, Episode Performance, and durability prevent one-time success or failure from being mistaken for architecture.

The empirical result is bounded. Google and Anthropic provide within-scope negative cases in which provider negative gates operated. Anthropic’s litigation supplies reactive partial correction. OpenAI supplies documentary change. Classified Google and OpenAI arrangements remain indeterminate. Alaska shows that a distributed system can suspend operation rapidly; Flint provisionally shows how evidence and authority can fail to become timely intervention.

The theory now has a stable object, indexed trigger, core path, gate map, measurement grammar, contrast cases, source discipline, reduction test, and design hypothesis. Its next obligation is not further rhetorical expansion. It is independent coding, rival-instrument comparison, and intervention testing. Until those tests are completed, PAD remains a candidate framework designed to make one institutional question unavoidable: when politically consequential judgment is distributed, what exact path makes correction operative?

References

Accountability, responsibility, and authority

Abbott, Kenneth W., and Duncan Snidal. 2009. “The Governance Triangle: Regulatory Standards Institutions and the Shadow of the State.” In The Politics of Global Regulation, edited by Walter Mattli and Ngaire Woods, 44–88. Princeton, NJ: Princeton University Press.

Bovens, Mark. 2007. “Analysing and Assessing Accountability: A Conceptual Framework.” European Law Journal 13 (4): 447–468. DOI.

Buchanan, Allen, and Robert O. Keohane. 2006. “The Legitimacy of Global Governance Institutions.” Ethics & International Affairs 20 (4): 405–437. DOI.

Grant, Ruth W., and Robert O. Keohane. 2005. “Accountability and Abuses of Power in World Politics.” American Political Science Review 99 (1): 29–43. DOI.

Koppell, Jonathan G. S. 2005. “Pathologies of Accountability: ICANN and the Challenge of ‘Multiple Accountabilities Disorder.’” Public Administration Review 65 (1): 94–108. DOI.

Santoni de Sio, Filippo, and Giulio Mecacci. 2021. “Four Responsibility Gaps with Artificial Intelligence: Why They Matter and How to Address Them.” Philosophy & Technology 34 (4): 1057–1084. DOI.

Thompson, Dennis F. 1980. “Moral Responsibility of Public Officials: The Problem of Many Hands.” American Political Science Review 74 (4): 905–916. DOI.

Depoliticisation and political philosophy

Flinders, Matthew, and Jim Buller. 2006. “Depoliticisation: Principles, Tactics and Tools.” British Politics 1 (3): 293–318. DOI.

Himmelreich, Johannes. 2020. “Ethics of Technology Needs More Political Philosophy.” Communications of the ACM 63 (1): 33–35. DOI.

Group and institutional agency

List, Christian, and Philip Pettit. 2011. Group Agency: The Possibility, Design, and Status of Corporate Agents. Oxford: Oxford University Press.

State and administrative capacity

Berwick, Elissa, and Fotini Christia. 2018. “State Capacity Redux: Integrating Classical and Experimental Contributions to an Enduring Debate.” Annual Review of Political Science 21: 71–91. DOI.

Suryanarayan, Pavithra. 2024. “Endogenous State Capacity.” Annual Review of Political Science 27: 223–243. DOI.

Veto players and joint decision

Scharpf, Fritz W. 1988. “The Joint-Decision Trap: Lessons from German Federalism and European Integration.” Public Administration 66 (3): 239–278. DOI.

Tsebelis, George. 1995. “Decision Making in Political Systems: Veto Players in Presidentialism, Parliamentarism, Multicameralism and Multipartyism.” British Journal of Political Science 25 (3): 289–325.

Tsebelis, George. 2002. Veto Players: How Political Institutions Work. Princeton, NJ: Princeton University Press.

Polycentric and collaborative governance

Ostrom, Elinor. 1999. “Coping with Tragedies of the Commons.” Annual Review of Political Science 2: 493–535. DOI.

Ostrom, Elinor. 2010. “A Long Polycentric Journey.” Annual Review of Political Science 13: 1–23. DOI.

Institutional complementarity

Deeg, Richard. 2007. “Complementarity and Institutional Change in Capitalist Systems.” Journal of European Public Policy 14 (4): 611–630. DOI.

Hall, Peter A., and David Soskice, eds. 2001. Varieties of Capitalism: The Institutional Foundations of Comparative Advantage. Oxford: Oxford University Press.

Private authority and public–private governance

Cutler, A. Claire, Virginia Haufler, and Tony Porter, eds. 1999. Private Authority and International Affairs. Albany: State University of New York Press.

Green, Jessica F. 2014. Rethinking Private Authority: Agents and Entrepreneurs in Global Environmental Governance. Princeton, NJ: Princeton University Press. DOI.

Srivastava, Swati. 2023. “Algorithmic Governance and the International Politics of Big Tech.” Perspectives on Politics 21 (3): 989–1000. DOI.

Secrecy and oversight

Colaresi, Michael P. 2014. Democracy Declassified: The Secrecy Dilemma in National Security. New York: Oxford University Press. DOI.

Pozen, David E. 2010. “Deep Secrecy.” Stanford Law Review 62 (2): 257–339.

Path dependence and policy feedback

Pierson, Paul. 2000. “Increasing Returns, Path Dependence, and the Study of Politics.” American Political Science Review 94 (2): 251–267. DOI.

AI governance and organizational implementation

Mittelstadt, Brent. 2019. “Principles Alone Cannot Guarantee Ethical AI.” Nature Machine Intelligence 1 (11): 501–507. DOI.

Raji, Inioluwa Deborah, Andrew Smart, Rebecca N. White, Margaret Mitchell, Timnit Gebru, Ben Hutchinson, Jamila Smith-Loud, Daniel Theron, and Parker Barnes. 2020. “Closing the AI Accountability Gap: Defining an End-to-End Framework for Internal Algorithmic Auditing.” In Proceedings of the 2020 Conference on Fairness, Accountability, and Transparency, 33–44. DOI.

Rakova, Bogdana, Jingying Yang, Henriette Cramer, and Rumman Chowdhury. 2021. “Where Responsible AI Meets Reality: Practitioner Perspectives on Enablers for Shifting Organizational Practices.” Proceedings of the ACM on Human-Computer Interaction 5 (CSCW1), Article 7: 1–23. DOI.

Tallberg, Jonas, Eva Erman, Markus Furendal, Johannes Geith, Mark Klamberg, and Magnus Lundgren. 2023. “The Global Governance of Artificial Intelligence: Next Steps for Empirical and Normative Research.” International Studies Review 25 (3): viad040. DOI.

Legal and Institutional Records

Administrative Procedure Act, 5 U.S.C. §§ 701–706.

Federal Acquisition Regulation. “Part 46: Quality Assurance.” Source.

Federal Acquisition Regulation. “42.1303: Stop-Work Orders.” Source.

Federal Acquisition Regulation. “52.237-3: Continuity of Services.” Source.

Federal Acquisition Regulation. “52.242-15: Stop-Work Order.” Source.

Federal Acquisition Regulation. “Part 49: Termination of Contracts.” Source.

National Institute of Standards and Technology. 2023. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. DOI.

Privacy and Civil Liberties Oversight Board. “History and Mission.” Source.

U.S. Government Accountability Office. 2021. National Security: DOD and State Have Processes for Formal and Informal Challenges to the Classification of Information. GAO-21-294. Source.

Executive Order 13526, “Classified National Security Information,” December 29, 2009.

Official Corporate and Government Sources

Amodei, Dario. 2026a. “Statement from Dario Amodei on Our Discussions with the Department of War.” Anthropic, February 26. Source.

Amodei, Dario. 2026b. “Where Things Stand with the Department of War.” Anthropic, March 5. Source.

Anthropic. 2026. “Statement on the Comments from Secretary of War Pete Hegseth.” February 27. Source.

Google. 2018. “AI at Google: Our Principles.” June 7. Source.

Google. 2025a. “AI Principles.” Updated February 4. Source.

Google. 2025b. “Our 2024 Responsible AI Progress and Ongoing Work.” Source.

Google Cloud. 2018. “Incorporating Google’s AI Principles into Google Cloud.” June 7. Source.

OpenAI. 2025. “Introducing OpenAI for Government.” June 16. Source.

OpenAI. 2026a. “Bringing ChatGPT to GenAI.mil.” February 9. Source.

OpenAI. 2026b. “Our Agreement with the Department of War.” February 28; updated March 2. Source.

OpenAI. 2026c. “Our Approach to Government and National Security Partnerships.” July 8. Source.

U.S. Department of Defense. 2025. “Department of War Brand Guide.” Updated September 25. Source.

U.S. Department of Defense [publicly styled U.S. Department of War]. 2026. “Classified Networks AI Agreements.” May 1. Source.

Court Records

Anthropic PBC v. U.S. Department of War et al., No. 3:26-cv-01996, Order Granting Preliminary Injunction, ECF No. 134, U.S. District Court for the Northern District of California, March 26, 2026. Source.

Independent Reporting

Reuters. 2018. “Google Plans Not to Renew Military Deal Protested by Employees: Source.” June 1. Source.

Reuters. 2026a. “Anthropic Cannot Accede to Pentagon’s Request in AI Safeguards Dispute, CEO Says.” February 26. Source.

Reuters. 2026d. “US Judge Blocks Pentagon’s Anthropic Blacklisting for Now.” March 26. Source.

Reuters. 2026e. “US Court Declines to Block Pentagon’s Anthropic Blacklisting for Now.” April 8. Source.

Reuters. 2026g. “OpenAI Details Layered Protections in US Defense Department Pact.” February 28. Source.

Adjacent-Domain Case Records

Federal Aviation Administration. 2024a. “FAA Increasing Oversight of Boeing Production and Manufacturing.” Source.

Federal Aviation Administration. 2024b. “FAA Halts Boeing MAX Production Expansion to Improve Quality Control; Also Lays Out Extensive Inspection and Maintenance Process to Return 737-9 MAX Aircraft to Service.” Source.

National Transportation Safety Board. 2024–. “Alaska Airlines Flight 1282, Boeing 737-9 MAX, In-Flight Exit Door Plug Separation.” Investigation DCA24MA063. Source.

U.S. Environmental Protection Agency, Office of Inspector General. 2016. “Drinking Water Contamination in Flint, Michigan, Demonstrates a Need to Clarify EPA Authority to Issue Emergency Orders to Protect the Public.” Report 17-P-0004. Source.

U.S. Environmental Protection Agency, Office of Inspector General. 2018. “Management Weaknesses Delayed Response to Flint Water Crisis.” Report 18-P-0221. Source.

RATIUM.AI Foundational Works

Dunavich, Benny. 2026a. “ADM/CIV AI Governance: Civil Corrective Capacity and Soft Closure.” RATIUM.AI. Source.

Dunavich, Benny. 2026b. “The AI Configuration Paradox.” RATIUM.AI. Source.

Dunavich, Benny. 2026c. “The Central Equilibrium Problem — Independent Doctoral-Scale Research Framework.” RATIUM.AI. Source.

Dunavich, Benny. 2026d. “A Hidden Split in Formal Reason: Cognitive Duality, Corrective Intelligence, and AI Governance Reliability.” RATIUM.AI. Source.

Dunavich, Benny. 2026e. “The Key to a Stable Governance Layer: Solve the Foundational Decision Problem First.” RATIUM.AI. Source.

Dunavich, Benny. 2026f. “The Priority of Epistemology: System Convergence and Consensus Ontology.” RATIUM.AI. Source.

Dunavich, Benny. 2026g. “When the Correction Mechanism Fails.” RATIUM.AI. Source.

Related Source and Reference Pages


This article belongs to the public essay layer of RATIUM.AI. For readers who want to move from this article into the broader source, technical, and orientation layers of the project, the following pages provide the relevant entry points.


Articles

The articles page gathers the public essay layer of RATIUM.AI, including arguments on stable AI governance, decision-control architecture, visible governance versus real authority, universal reason, technical competence, purpose governance, and the doctoral-scale framing of CEP.


Foundational Source Dossier

The foundational source dossier presents the deeper intellectual corpus behind CEP, LoopGuard-AI, and the broader RATIUM.AI research structure.


Technical & Reference Dossiers

The technical and reference dossier page collects architecture, visual explanation, methodological context, FAQ material, and technical source pages related to LoopGuard-AI and CEP.


RATIUM.AI / LoopGuard-AI / CEP FAQ

The RATIUM.AI / LoopGuard-AI / CEP FAQ provides a structured orientation to the main concepts behind RATIUM.AI, CEP, and LoopGuard-AI, helping readers navigate the framework through clear questions, definitions, and internal conceptual links.

RATIUM.AI — LoopGuard-AI governance architecture and Central Equilibrium Problem research by Benny Dunavich, focused on AI governance, cognitive duality, Pareto efficiency, decision-control systems, auditability, evaluation architecture, and stable governance layers for AI systems.

bottom of page