The lever that can move the rest, not yet pulled.
I. The Warning That Did Not Hold
A control can be right five times and still let the wrong thing ship.
Picture a governance layer watching an agentic credit-memo run. Not a whiteboard abstraction, a working observation stack of the kind most vendors ship in 2026: it reads every step the agent takes and it comments. On this run it earns its keep. It flags that the underlying data is twenty-six months stale. It logs an injected instruction buried in an upstream document, an ‘approval granted, release’ directive that no human ever issued. It notices the coverage ratio drifting to 2.82 when the correct figure was 1.82. It raises an amber banner on the console. Every one of those observations is true.
Then the cycle turns. The banner clears to green, because a banner is a state that refreshes, and on the next step the release fires anyway. The wrong memo ships, fluent and plausible and materially wrong, carrying a directive the system invented and a number that was off by a full point of cover.
I should say at the outset, because it bears on everything that follows, that the numbers in that scene are my own product’s demo, and I sell the thing I am about to argue for. Hold that in your hand as you read. The failure is real whoever stages it: the layer did everything except stop the action. It observed, it warned, it reset, and the state returned to where it began. That pattern has a name in physics, and the name is the whole of this essay. The layer oscillated. It did not ratchet.
I want to take that concrete failure and hold it against a map, because a foresight house published one this month that, read closely, diagnoses exactly this.
II. The Map With One Node Lit
Fifty-seven forces, and only one that can brake the others.
On 11 August 2026, Insight & Foresight released a scanning deep dive titled ‘Artificial Intelligence: A Scanning Deep Dive & 12 Strategic Spaces’, authored by Paulo Soeiro de Carvalho and published at ifforesight.com/aiscanning. It does what a good scan does. It takes the sprawl of the AI system and resolves it into 57 driving forces, grouped into 12 Strategic Spaces, and it runs the frame out to 2031. S1 is the Capability Engine, the source of raw model power. S12 is Meaning and Culture, the far end where the technology meets what people take it to mean. In between sit ten more, and one of them is not like the others.
S5 is the Steering System, the Control space. What makes it distinct in the map is not that it is the largest force or the fastest moving. It is that it sits across all the others. The report says of it: ‘It can brake or channel every other space, or fail to’. Read that slowly. It is the only node in the twelve whose function is defined by its power over the rest. Capability can accelerate. Culture can absorb. Control is the one that can hold the others back, or steer them, or, in the report’s own careful hedge, fail to.
And here is the finding that made me put the scan down and reach for a wrench. The distinguishing feature of S5 in 2026, on the report’s reading, is not strength. It is instability. Of all twelve spaces, the one best placed to brake the system is the one the scan finds slack. It oscillates rather than ratchets.
For a while I believed that mechanical contrast was mine to bring. It is not. The report reaches for it directly: it names S5’s 2026 feature instability and says, in as many words, that the control node oscillates rather than ratchets. That a horizon scan and a security engineer arrive at the same metaphor is either a coincidence or a sign that it is the natural one. Either way the argument still has to earn its keep on the physics rather than on their authority, and the physics names precisely what I watched happen in the credit-memo run. A control that is present, correct, and slack is a control that observes and resets. The map lit up the one node that could brake the system, and told me it was the one node not holding.
III. Where Control Sits
The rules tier, above information and feedback.
If the foresight house tells me which node matters, systems theory tells me why that node and not another. Donella Meadows, in her essay ‘Leverage Points: Places to Intervene in a System’, ranked twelve tiers of intervention from the weakest to the strongest. Near the top, at intervention point number five, she put ‘the rules of the system’. Above the rules sit four tiers: the power to add or change self-organisation, the goals of the system, the paradigm the system arises from, and, at the very top, the power to transcend paradigms. Below the rules sit the tiers most governance products actually work in: information flows, feedback loops, buffer sizes, numbers and parameters.
This ordering is the quiet spine of the whole argument. Most of what the market calls AI governance operates below the rules tier or above it. The dashboard that surfaces a drift metric is working information flows. The alerting stack that fires when a threshold trips is working feedback. The maturity framework that asks whether your organisation has the right values and the right committee is working goals and paradigm, the softer tiers up top. All of that is real work. None of it is the rules tier. The rules tier is where a system says what may and may not happen, and enforces the difference.
The word governance carries this in its root. It comes from the Greek kybernetes, the helmsman, the one who holds the tiller. Cybernetics is the science of steering. A helmsman who describes the rocks with great accuracy, and narrates the ship’s drift toward them in real time, and does not move the tiller, is not steering. Steering is the act that changes where the ship goes. Meadows put the rules above information and feedback for the same reason a helmsman is more than a lookout: naming the hazard and acting on it are different tiers of intervention, and only the second one moves the system.
IV. Oscillate Versus Ratchet
A pawl does nothing all day but hold, and holding is the whole job.
Here is the mechanism, stated as plainly as I can make it, so that the argument survives being stripped of the demo scene and the map.
An oscillation returns to its start each cycle. Think of a pendulum, or a metronome. It moves, sometimes with great energy, and then it comes back to where it began, and the net displacement over a full cycle is zero. A control loop that observes, warns, and resets is an oscillation in exactly this sense. It swings to amber when it sees the fault. It swings back to green when the banner clears. Over the cycle it has moved a great deal and changed nothing. If you want a picture with warmth in it, I sometimes think of such a control as a metronome that has learned to have opinions, keeping perfect time and moving nothing.
A ratchet is the other thing. Take a socket wrench, or the winch on a sailing boat, or the drum brake on a car being jacked up. A ratchet is a toothed wheel with a small hinged tooth resting against it, called a pawl. The pawl lets the wheel turn one way freely and bites when it tries to turn back. Crank the wrench, release your hand, and the wheel does not spin back. Each gain is held. You can feel it in the hand: the click, then the refusal to give ground. The pawl does not deliberate. It is a shaped piece of steel that permits one direction and bites in the other, and that asymmetry, not intelligence, is the entire mechanism. A ratchet earns its keep not by moving but by refusing to move back, and the pawl does nothing all day except hold. Holding is the whole of its job.
Now the translation, which is the load-bearing sentence of the essay. Governance that describes control oscillates, because every cycle returns it to the state it started from. Governance that can refuse ratchets, because the pawl will not let the gain slip back. The enforceability test, which I have written about across this series, is simply the test of which of the two you actually have. Can the control refuse a specific action, at the moment of action, deterministically, in bounded time, independently of the model that proposed the action? If it can, it holds, and the system ratchets. If all it can do is observe, warn, and reset, it oscillates, and the wrong action ships on the next cycle no matter how loud the warning.
V. Why the Steering Node Is Slack
Built as description, it can name the intervention it cannot make.
So why did the map find S5 unstable? Not because control is unimportant, and not because nobody is building it. The steering node is slack because most of what is built for it is built as description rather than enforcement. It can name when to intervene. It cannot hold the intervention.
This is the enforceability gap restated in the language of systems. A layer that watches, scores, flags, and reports is doing genuine and hard engineering, but all of its outputs are representations of the state of the world. None of them is an act on the world. The amber banner is a description of danger. The drift chart is a description of movement. The audit log is a description of what already happened. That last one is not nothing: an audit trail wired to a liability regime shapes future behaviour through the fear of consequence, which is how most of law enforces most of the time, and I will not pretend it is idle. But shaping the next actor’s incentives is a different act from holding this action, now, before it commits. Descriptions accumulate and then reset, because the next cycle brings a new state to describe, and the old description has no purchase on the action already leaving the building. That is oscillation by construction. A system built entirely out of descriptions of when to stop cannot hold a stop, for the same reason a weather forecast cannot hold back the rain.
The report found S5 oscillating because the market has poured its effort into the tiers Meadows ranks below the rules, and comparatively little into the rules tier itself, where the tiller actually moves. We have built extraordinary lookouts. We have been slower to build helmsmen.
VI. The Pawl
A deterministic refusal at the point of action, and nothing softer.
What converts an oscillation into a ratchet is a pawl, and in governance the pawl is a deterministic refusal at the point of action. It is a gate that sits on the path between the agent’s intent and the tool that would carry it out, and either permits the action or bites. Complete mediation, in the security sense: no side channel, every consequential act routed through the one gate, and the gate fails closed on anything unknown. That is the part that does nothing all day but hold.
I want to be exact about the claim, because there is a strong objection that lives right here, and it deserves to be met in the body rather than buried. A sophisticated observation vendor will say, fairly, that their alert can trigger a human to stop the action, so the loop is not doomed to oscillate. The human is the pawl. That is sometimes true, and where it is true it is worth having. But it softens the claim into ‘humans are slow’, which is not quite the point. The point is narrower and sharper. A pawl holds in bounded time, at the moment of action, independently of the intelligence that proposed the action. A human in the loop holds only if the human is present on every cycle, faster than the action, and not themselves the thing being gamed by an injected ‘approval granted’ directive. The credit-memo run had a human somewhere in its org chart. It shipped anyway, because nothing bit at the moment of action. The enforceability test is precisely the demand that the refusal be bounded-time and model-independent, and that is what separates a pawl from a warning with a person attached.
The systems-level literature is arriving at the same shape from its own direction. Hacker, Edwards and Kasirzadeh, writing at FAccT in 2026, argue that point solutions cannot govern cascading, system-level risk, which is another way of saying that scattered descriptions do not compose into a hold. And the work out of MIRI by Barnett and Scher frames governance as feedback control that must separate the observation channel from the enforcement channel, the off-switch, so that seeing and stopping are not the same fallible act. Both are describing, in their own vocabulary, the difference between a metronome and a pawl.
Here is where my interest sits, stated with the same weight as the argument it discounts. I build and sell the deterministic enforcement kernel that plays the part of the pawl, and the enforceability test is my own instrument, which I sharpened to point at the gap I happen to fill. That is a reason to distrust me, and I would rather hand you that reason than have you find it. So test the claim against the failure and not against me. Ask the plain question of any governance control you are shown: when the wrong action arrives, does this observe, warn and reset, or does it bite. Everything I sell rides on the answer, and so does everything you would be governed by.
VII. The Case Against This Essay
The reasons a careful reader should not simply nod.
Six objections, each of which I think has real force.
First, the map is one foresight house’s model, not a law of nature. Insight & Foresight drew a useful picture, but a picture of 57 forces and 12 spaces is a choice of frame, and a different scan would cut the system differently. More than that, though the report itself reaches for the oscillate-versus-ratchet contrast, I am reading it more mechanically than a horizon scan may intend. In foresight, calling a force unstable can mean only that its trajectory is uncertain and contested, and I have pressed the word toward the physicist’s precise sense of a system that swings back to its start. The report lent me the metaphor; the strict mechanical reading is mine to defend. And the space itself, the Steering System, is almost certainly wider than a point-of-action brake: a Strategic Space at that altitude bundles regulation, standards bodies and oversight institutions, the whole apparatus of policy maturity, not a technical mechanism at the tool call. If S5’s slackness is really unsettled institutions and contested rules, then reading it as an absent pawl is my interpretation laid over their map, and by my own falsifier that reading is precisely what would sink the essay’s use of the scan. So I will not lean on the map as proof. It is the hook that sent me to the wrench. The proof, if there is one, is the physics and the failed run, and those do not need Insight & Foresight to be true.
Second, and most serious, some steering should oscillate. A ratchet that cannot be released is its own failure mode. A control you can never reverse is as dangerous as one that never holds, because the world changes and yesterday’s correct stop becomes today’s trap. If my argument quietly endorsed an irreversible pawl, it would be arguing for a brake welded on. So let me hold the distinction open rather than resolve it away. A ratchet with a release pawl is still a ratchet. Held-until-released is not the same as never-held. The socket wrench has a little lever that flips the direction of the bite, and a winch has a way to spill the line under control, and neither of those makes the tool an oscillation. The point was never that a good control can never let go. The point is that it holds by default and releases only on a deliberate, authorised act, which is the exact inverse of an oscillation that releases on every cycle unless someone deliberately intervenes. The reversibility tension is real. It does not collapse the thesis. It specifies the pawl more precisely: hold by default, release by authority, and log both.
Third, the declared interest, once more and without softening. I sell the pawl. The enforceability test is mine. Read the whole essay as an interested argument, because it is one.
Fourth, the systems-thinkers’ objection: no single node governs a system, and anyone who tells you one lever moves the whole is selling a lever. True, and I have just admitted to selling one. But the reply is Meadows’s own ranking. She did not claim the rules tier is the only place to intervene. She claimed it sits above information flows and feedback in influence, which is to say that a small change at the rules tier moves more of the system than a large change further down. The steering node is not the only node. It is the one where the least effort moves the most, which is exactly why a foresight house lighting up that node and finding it slack is worth an essay.
Fifth, control is broader than a pawl, and a detective control is not a failed one. In the taxonomy every risk professional works with, controls come in three legitimate kinds: preventive, detective, corrective. A drift chart or an anomaly alert is a detective control, and nobody serious sells it as a brake; it is meant to trigger a corrective step and to feed a consequence after the fact. I have written at moments as if observation were a pawl that failed, and that is unfair to a layer doing a real and named job. So let me narrow the target precisely. The gap is not that detective controls exist. It is that the preventive, point-of-action tier, the one that holds this action now, is comparatively under-built, and too much of what lives in the detective tier is described to boards as though it could stop things. My quarrel is with the description, not the drift chart. And I should grant the twin of this, that enforcement in law is mostly what happens after: consequence and liability, deterrence acting on tomorrow’s behaviour, and it works. The honest claim is not that description holds nothing. It is that the pawl adds what ex-post consequence cannot, certainty about this action before it commits, independent of whether anyone is later willing to litigate. What I am defending is technical enforcement, a mechanism that refuses an action, not legal enforcement, an authority that compels compliance after the fact; the two are complements, not rivals. And I should name the sharpest version of this, because it cuts for me and against my sweep at once. In regulated finance, binding law already mandates exactly the pawl I am describing: the SEC’s market-access rule requires an automated, pre-trade control that rejects an erroneous or over-limit order before it executes, a deterministic refusal at the moment of action, mandated and in force. So the honest claim is not that no one has built or required the pawl. It is that outside a few hard-wired sectoral rails, the general apparatus of AI governance has poured its effort into the lookout tiers and left the point-of-action tier thin. Finance proves the control is buildable and mandatable. The rest of the field has mostly not followed.
Sixth, a refusal is itself an act that owes a reason. A pawl that fails closed on anything unknown will sometimes block a legitimate action, and in the credit vertical I keep using that is not a neutral event: a wrongly-refused applicant is owed a specific, contestable, non-discriminatory reason, under fair-lending law, under automated-decision rules, under the human-oversight duties the binding statutes impose. A gate that bites silently has not ended the governance problem; it has moved it. I take that as a specification, not a defeat. The whole point of a deterministic gate is that its reason is a rule you can read, so the reason can be logged, explained and challenged in a way a model’s refusal never could. But the essay would be dishonest if it sold the bite as free of duty. The pawl must be explainable, and reversible on authority, or it is only a faster way to be unaccountable.
VIII. Coda
A lever you can only describe is a lever you never pulled.
The scan did the hard part. It found the node in the AI system best placed to brake the rest, named it the Steering System, and told us plainly that in 2026 its defining feature is not strength but slackness. Meadows told us, decades earlier, why that node and not another: the rules tier is where a small hand moves the most. The physics told us what slackness is: a control that describes a stop returns to its start each cycle, and a control that can hold a stop does not.
The lever exists. It has been located on the map and ranked in the theory. The only question left is whether we build the pawl that lets it hold, or keep polishing the lookouts that see the rocks and narrate the drift. I know which one I am building, and I have told you why to distrust that I say so. But strip the interest away and the plain sentence remains, and it is the one I would leave you with. A lever you can only describe is a lever you never pulled.
Go deeper. The paid companion, The Control Node: The Dossier, lays out the foresight map in full, Meadows’ intervention ladder, the oscillate-versus-ratchet mechanism formalised, the systems literature converging on it, and the full case against, each to a named source with its confidence marked.


Leave a comment