How this was made. The version number counts drafts of the text. It does not measure the inquiry behind it, which has run over days and across several AI systems, with argument between those systems and within them, directed, refused and repeatedly redirected by the author. The source material was AI-generated, and then adversarially and iteratively refined across a range of tools — systems built by different companies in different jurisdictions, set against each other and against the author. No one of them produced this text, and no one of them reviewed it alone. The plurality is deliberate rather than incidental. A single model carries a single set of priors about which sources are authoritative, and this series argues that an evidence base narrowed in exactly that way is how a contested question comes to look settled. Using one model to investigate that claim would have been the claim refuting itself. To name a single model on it would credit that model with work that was neither its own nor done in a single pass. The plurality was also necessary, and the record should say why. In drafting, the assisting model repeatedly led with United States institutional sources — a national laboratory, an industry association, a market study nineteen years old — and presented conclusions drawn from them as the state of knowledge. On one occasion European measured data contradicting those conclusions was present in the same research return and was placed below them. Framings were proposed that would have argued against this series’ own position using that evidence base, and offered as rigour. Each was refused by the author and the material rebuilt. That is the mechanism these documents describe, occurring in their own making, and it is recorded because a series arguing that evidence bases narrow without anyone deciding to narrow them cannot credibly claim its own production was exempt. The framing, the corrections and the judgements are the author’s, and so are the errors. How this site is written sets out what is declared on every piece, who checks it, and where the per-piece record lives.
That is not the claim. A great deal of help is available — on whether a model is accurate on a benchmark, whether a system is robust to a class of input, whether a process discriminates on a measure somebody has defined. All of that is real work and the piece says so.
What nobody else can supply is the content of the words. Safe against which harms, to whose tolerance, at what cost to what else. Those are judgements about a particular organisation’s obligations, and they are made by whoever will answer for the result. A supplier who has filled those blanks for you has not answered your question; they have answered their own and handed you the paperwork.
No. Nothing here says an institution must own its models, run its own hardware, or write its own software. Several of the requirements later in the series are satisfied perfectly well by arrangements with an outside supplier.
The claim is about which party holds which control, not about where the machine sits. An institution can rent every processor it uses and still hold the authority to set a limit, inspect what happened, change the arrangement and stop it. It can also own the building and hold none of those.
Nothing, as a way to learn what a tool does. The problem is what it becomes when it is also the measure of whether the tool was worth adopting.
Adoption rates measure how many people used something. They do not measure whether the uses were good ones, whether the failures were visible, or whether anybody could have refused. A programme judged on adoption has an interest in every number except the ones that would show it going wrong — and the fastest way to raise the number is to remove the friction that makes refusal possible.
The trap is not that the metric is useless. It is that it is the only one that gets easier to report as the situation gets worse.
The common form puts technical controls at the centre and rings them with process, operating model, governance and culture, with ethical judgement somewhere on the outside.
Read as a picture of an organisation, it is unobjectionable. Read as a picture of how a request is stopped, it is misleading, because the rings do not stop anything. A request that reaches the technical layer is refused or permitted there; culture is not standing in the path. Drawing judgement as an outer ring suggests it wraps the machinery, when what the piece argues is that judgement only reaches the machinery if somebody has built a place for it to act.
The diagram is not wrong about what matters. It is wrong about what is load-bearing, and it is used to argue that the documentary layers are doing work the technical layer is actually doing alone.
Norm Hardy described the confused deputy in ACM SIGOPS Operating Systems Review in 1988: a program holding authority of its own, asked by a caller to act, unable to keep the caller’s authority and its own apart. His sentence was “It has no way to keep them apart.”
The Model Context Protocol authorization specification dated 2025-06-18 contains a section headed “Confused Deputy Problem”, and requires that a server must not pass through the token it received. The failure is named, thirty-seven years later, in the specification of a protocol written for exactly this class of system. That is not a historical curiosity; it is a defect recognised as current by the people building the current thing.
An instrument that closes the prior questions without the institution answering them — a standard that specifies safety in terms an outside body can certify, for a class of use broad enough to be useful, without the deploying organisation filling in any blank.
Something close to that exists in narrow domains. If it generalised, the argument here would be overtaken by events, and the series says so rather than treating its own case as unfalsifiable.
What this publication does not claim, and what is outstanding against it in the register.
A question this rests on is parked: How is the aggregation ceiling actually enforced?
We claim that we do not compose and retain no capability to compose. We do not claim that composition by others is impossible.
Alongside: the publication · sources and provenance