<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Marco Brondani]]></title><description><![CDATA[Cybersecurity governance, AI risk, platform strategy. For boards, executives, and founders who can't afford to get it wrong. Thirty years inside complex systems. Now helping organizations govern them.]]></description><link>https://www.marcobrondani.com</link><image><url>https://substackcdn.com/image/fetch/$s_!0sku!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1331497-7d57-4f42-81b8-d3c1358c1ba3_1024x1024.png</url><title>Marco Brondani</title><link>https://www.marcobrondani.com</link></image><generator>Substack</generator><lastBuildDate>Tue, 28 Jul 2026 18:18:11 GMT</lastBuildDate><atom:link href="https://www.marcobrondani.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Marco Brondani]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[marcobrondani@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[marcobrondani@substack.com]]></itunes:email><itunes:name><![CDATA[Marco Brondani]]></itunes:name></itunes:owner><itunes:author><![CDATA[Marco Brondani]]></itunes:author><googleplay:owner><![CDATA[marcobrondani@substack.com]]></googleplay:owner><googleplay:email><![CDATA[marcobrondani@substack.com]]></googleplay:email><googleplay:author><![CDATA[Marco Brondani]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Verification Society]]></title><description><![CDATA[On the withdrawal of the benefit of the doubt, and what a life organised around suspicion costs the people living inside it.]]></description><link>https://www.marcobrondani.com/p/the-verification-society</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-verification-society</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Tue, 21 Jul 2026 08:34:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0sku!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1331497-7d57-4f42-81b8-d3c1358c1ba3_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><span>There was a time, not distant, when trust was the resting position. You assumed the man selling fruit was selling fruit. You assumed the voice on the telephone belonged to whoever it claimed. You assumed the institution that addressed you in the morning would not contradict itself by evening. None of these assumptions required courage. They were the ambient condition of living among other people, the quiet infrastructure that lets strangers cooperate without first proving themselves to one another. A society runs on an enormous volume of unearned faith, and for most of modern life that faith was cheap enough that nobody noticed they were spending it.</span></p><p>The resting position has moved. To trust no one was once the mark of the wounded or the paranoid, something you said with sympathy about a person who had been hurt past the point of recovering their footing. It has become a competence. We teach it now to the young the way we once taught them to look both ways before crossing a road. Verify the sender. Treat the message as a lure until it earns the status of something real. Distrust the confident voice more than the hesitant one, because confidence has become cheap to manufacture and hesitation is still expensive to fake. The paranoid inheritance has been redistributed to everyone, and calling it paranoia no longer fits, because paranoia implies a distortion of reality and this is a fairly accurate reading of it.</p><h3>The genealogy of a reflex</h3><p>The reflex was assembled in stages, and it helps to name them.</p><p>The internet built the first layer. Anonymity was sold to us as freedom, and for a while it was, but it also severed the ancient link between a claim and a person who could be held to it. The scam email, the fabricated review, the account that exists only to agree with forty other accounts that also exist only to agree, all of these taught a generation that the appearance of consensus carries no information about whether anyone real believes anything. We learned that a crowd can be rented. Once you have absorbed that lesson you cannot un-absorb it, and it changes how you stand in every room, physical or otherwise.</p><p>The pandemic built the second layer, and it built it into the body rather than the browser. Lockdown did more than isolate people. It set institutions against their own earlier statements in full public view, at speed, with lives attached to the reversals. Guidance arrived and was withdrawn and arrived again inverted. Authorities that had spent decades cultivating an image of settled competence were seen improvising, and improvisation is not a sin, but watching it happen dissolved the illusion that someone, somewhere, held the whole picture. Neighbours were invited to report neighbours. The stranger at a distance became a vector rather than a person. Isolation removed the daily, ordinary contact that repairs suspicion, the small proofs of goodwill that accumulate when you actually see people behave well. We came out of it having practised distance for long enough that distance had become a habit rather than a hardship.</p><p>The third layer is political, and it is the one people most want softened, so I will not soften it. Large movements of people across borders have been used, deliberately, as an instrument for manufacturing distrust. The migrant is convenient precisely because he is a stranger about whom almost anything can be asserted, and the assertion travels faster than any correction. This is not a claim about migration itself, which is as old as walking. It is a claim about how the fact of migration has been harvested by people who profit from a frightened and divided audience.</p><p>And here the high-visibility figures enter, because they are the accelerant. Donald Trump and Elon Musk operate, in their different registers, on the same principle: that the shared ground on which a fact could be adjudicated is itself the target. It is not only that particular falsehoods are spoken, though they are, and in volume that has been documented past any reasonable dispute. It is that the volume and the contradiction are the method. When a public figure says a thing and its opposite, and pays no visible price for either, the lesson absorbed by the audience is not which statement to believe. The lesson is that belief has become a matter of allegiance rather than evidence, that truth is now a team you join. Musk&#8217;s stewardship of a major information platform has accelerated exactly this, converting a space that at least gestured at verification into one where reach is sold and authority is a badge you can purchase. A society can survive liars. It has always had them. What it struggles to survive is the deliberate erosion of the very idea that lying is distinct from telling the truth.</p><h3>A society organised around interests</h3><p>Underneath all three layers sits the thing that actually worries me, which is not any single deception but the shape of the civilisation that deception is producing.</p><p>When trust is withdrawn as the default, every interaction reconfigures itself into a transaction to be defended. You approach the other person already braced. You read them for the angle, the extraction, the interest they are advancing at your expense, because experience has taught you that the interest is usually there. This is a rational adaptation and it is also a slow poisoning, because a person who must treat every encounter as an adversarial negotiation eventually becomes someone who can no longer recognise an encounter that is not one. The armour fuses to the skin.</p><p>A world in which interests are the highest priority is a world that has quietly demoted persons. The human being in front of you stops being an end and becomes a variable, a thing to be assessed for threat and opportunity and otherwise held at a managed distance. We are building, without quite deciding to, a society that is less human because it is less able to afford being human, where the extension of ordinary goodwill has been repriced as a vulnerability. The generous instinct still exists in people. It simply costs more to act on now, and more of us are declining to pay.</p><h3><span>The posture migrates</span></h3><p>I have spent thirty years inside systems where trust was never the default, so I recognise the arriving world with an uncomfortable familiarity. Digital security abandoned the benefit of the doubt long ago. We used to defend a perimeter, a wall around the trusted interior, and inside that wall things were allowed to assume good faith about one another. That model collapsed once the wall stopped corresponding to anything real, once the people and devices and services that mattered were scattered everywhere and the inside and the outside could no longer be told apart. The doctrine that replaced it is called zero trust, and its premise is stated plainly in the name. Trust nothing by default. Verify every actor at every step. Grant the minimum access the task requires and revoke it the moment the task is done. Treat every request as potentially hostile, including the ones that come from inside the house, because the inside of the house is exactly where the worst breaches originate.</p><p>Zero trust is correct engineering. I have argued for it, designed for it, audited for it. What unsettles me is watching its logic climb out of the server room and install itself as the operating principle of ordinary life.</p><p>You can see the migration in physical space if you look. The doorbell camera that records the person approaching before they have said a word. The residential enclave with its gate and its list, sorting the belonging from the unbelonging at the boundary. The reflexive suspicion of the unexpected knock, the unfamiliar face, the stranger who offers help, because the frame through which we now read a stranger&#8217;s approach defaults to threat assessment. Each of these is individually defensible. Together they describe a population that has adopted, in its bones and its buildings, the security posture I spend my professional life recommending for networks. The perimeter has dissolved in the social world exactly as it dissolved in the digital one, and people are responding with the same instinct, hardening every individual node because the collective wall can no longer be relied upon.</p><p>The parallel is precise, and it should disturb us more than it does. In a network, zero trust is a strength, because a machine feels nothing when it is denied the benefit of the doubt. A human population running the same protocol pays a cost that no security model accounts for, because the thing being verified away is the substrate that made cooperation at scale possible in the first place. You cannot raise a child, sustain a marriage, build a company, or hold a democracy together on a foundation of continuous mutual authentication. Those things require exactly the unearned faith that the verification society is teaching us to withhold.</p><h3>What it costs to be right</h3><p>The hardest part of writing this honestly is that the suspicion is largely justified. I am not describing a delusion to be corrected. The scams are real, the manufactured consensus is real, the institutional reversals happened, the powerful figures do lie with a fluency and a shamelessness that reward the distrust they provoke. To tell people to simply trust more would be to tell them to disarm in a fight that is genuinely happening to them.</p><p>So the worry is not that we are being fooled. The worry is subtler and worse. It is that we are becoming the kind of people who can no longer afford not to suspect, and that this transformation is invisible to the people undergoing it, because each individual act of withheld trust feels like nothing more than prudence. A civilisation does not announce that it has stopped believing cooperation is possible. It simply verifies a little more each year, extends the benefit of the doubt a little less, until one day the ordinary human warmth that used to be the background of a life has become a luxury that only the naive or the protected can still practise.</p><p>I do not have the recovery to offer at the end of this, and I distrust anyone who would hand you one cheaply, which is itself a symptom of the thing I am describing. What I can say is that the first act of resistance is refusing to mistake the adaptation for the truth about human beings. The suspicion is a response to conditions. It is not a discovery that people were never worth trusting. Those conditions were built, in stages, by identifiable forces acting in their own interest, and a thing that was built can in principle be built differently. Whether we still have the collective faith required to attempt it is the open question, and the fact that the question feels naive even to ask is the measure of how far the withdrawal has already gone.</p>]]></content:encoded></item><item><title><![CDATA[The Question in the Empty Room]]></title><description><![CDATA[On the stage they ask whether the machine will wake up and take everything. When the room empties, the question changes, and the changed question is the true one: what our own people have already done]]></description><link>https://www.marcobrondani.com/p/the-question-in-the-empty-room</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-question-in-the-empty-room</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Tue, 14 Jul 2026 07:01:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WJaP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WJaP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WJaP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!WJaP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!WJaP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!WJaP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WJaP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3111676,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/206420109?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WJaP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!WJaP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!WJaP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!WJaP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F449c481f-ce68-47a3-a3c1-0be420415b36_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>There is a question I have been asked more than any other about these systems, and it comes with one condition: it waits until the important people have left.</p><p>On the stage, or in the all-hands, or in the board deck with the tasteful gradient, the posture is confident and the fear is enormous and safely far away: will the machine become something more than us, will it take the jobs, will it, in the version that has learned to enjoy its own shiver, wake up. These are is-questions, questions about what the thing might become, and they carry a quality I have learned to recognize: they frighten the person asking at no cost to them, because the danger is vast, external, and parked comfortably in the future.</p><p>Then the room empties, and someone stays behind, or catches me at the door, or waits until the others are in the lift, and asks the other question. The real one. It is never about what the machine might become. It is always some version of what our own people have already done with it, last quarter, without telling anyone.</p><p>I will not give you the room or the face, partly because I mask such things by long habit and partly because the particular does not matter: the question is the same in a bank in one region and a ministry in another and a company young enough that it has not yet learned to be afraid of anything. Does anyone actually know what our people have been pasting into these tools. Is the contract we spent a month arguing over now sitting inside someone else&#8217;s training set. Who approved the assistant that reads the whole mailbox, and could we reconstruct what it has already seen. The voice asking is quieter than the one that ran the meeting, and quieter for a reason: the public fear is a performance a person can afford, and this one is not, because this one has a date on it, and the date is in the past.</p><p>This is the thing I have learned to watch for, and I would hand it to you from three decades of being the person they ask once the door is shut: the loudness of a fear runs inversely to its nearness. The catastrophes we stage and publish, the machine that awakens, the general intelligence that decides it no longer needs us, are loud precisely because they are far, and being far they ask nothing of us today beyond the pleasant shudder and the thoughtful panel. The danger that is actually here arrives in the opposite register, quiet and specific and a little embarrassing: a junior pasted the merger terms into a chatbot to summarize them; a team wired a model into the customer database because it saved an afternoon; a vendor&#8217;s clever assistant has been reading, and keeping, everything. No one convenes a panel about it. It has already happened. It is happening while the panel is on.</p><p>I do not think the people asking the small question are foolish, and I do not think the ones performing the large one are cynical: the pull toward the enormous distant fear is human, the same pull that makes the disaster film easier to sit through than the quarterly review. It is more bearable to be frightened of a god than responsible for an intern. The large fear flatters us even in its terror, whispering that we are building something world-ending, something out of scripture. The small one only says we were careless, on a Tuesday, and did not write it down.</p><p>So when I am asked what a board should be afraid of, I have stopped answering as posed, because as posed the question is the decoy. What there is to fear sits in the logs, if you keep them, and in the absence of logs, if you do not. The useful question is never &#8220;when will it become something,&#8221; which no one can answer and everyone enjoys asking. It is &#8220;what have our own people already handed it, and could we find out if we had to.&#8221; A company that can answer that is governing. A company staging the other conversation, the large and thrilling one, is doing something else, and calling it the same name.</p><p>The room empties the same way every time. The confident version of the person leaves with the others, and the one that stays is smaller, and more honest, and asks the question with the date on it. I have come to think of that as the only moment in the whole encounter that was ever quite real: not the meeting, not the deck, not the large clean fear with its comfortable distance, but the quiet figure at the door, asking at last about the thing that already happened. It is not the question anyone wants to ask. It is the only one worth answering.</p><div><hr></div><div><hr></div><h2>LinkedIn companion</h2><p><em>Body clean of links; essay URL in the pinned first comment within 60 seconds. Schedule Tue&#8211;Thu, 8&#8211;10am CET. Image idea: an emptied conference room, one figure still standing by the door.</em></p><div><hr></div><p>On the stage, the AI fear is enormous: will the machine wake up, will it take everything. When the room empties, the question changes. And the changed question is the true one.</p><p>Thirty years doing this, and the one that comes once the door is shut is always some version of the same thing. It is never about what the machine might become. It is about what our own people have already done with it, last quarter, without telling anyone.</p><p>Does anyone actually know what got pasted into these tools. Is the contract we spent a month fighting over now sitting in someone&#8217;s training set. Who approved the assistant that reads the whole mailbox, and could we reconstruct what it has already seen.</p><p>Here is what I have learned to watch for: the loudness of a fear runs inversely to its nearness. The machine that awakens is loud because it is far, and being far it costs us nothing today but a pleasant shudder and a thoughtful panel. The danger that is actually here is quiet, specific, boring: a junior summarized the merger terms in a chatbot on a Tuesday. No one convenes a panel. It already happened.</p><p>It is more bearable to be frightened of a god than responsible for an intern.</p><p>The useful question was never &#8220;when will it become something.&#8221; It is &#8220;what have our own people already handed it, and could we find out if we had to.&#8221;</p><p>(Long version below.)</p>]]></content:encoded></item><item><title><![CDATA[The Uses of Disenchantment]]></title><description><![CDATA[Wonder and dread are the same posture in different weather: both hold the machine too high above you to be read. Disenchantment is not a faculty lost. It is one returned.]]></description><link>https://www.marcobrondani.com/p/the-uses-of-disenchantment</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-uses-of-disenchantment</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Fri, 10 Jul 2026 09:27:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sgJX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sgJX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sgJX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!sgJX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!sgJX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!sgJX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sgJX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3336426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/206419211?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sgJX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!sgJX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!sgJX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!sgJX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9da3539e-36f8-45c3-994f-7f7e11743915_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>I no longer find any of it amazing, and I have come to think that is the most useful thing that has happened to me in this entire cycle.</p><p>This is easy to mistake for cynicism, especially from someone who has been around long enough to have earned some, and I want to be careful, because it is the opposite. The cynic has decided in advance that nothing is worth much: a verdict, as fixed and as blind as the enthusiast&#8217;s, only colder. What I am describing is not a verdict about the technology at all. It is the moment a technology stops glowing and starts showing its mechanism, and I could finally see it.</p><p>There is a feeling the new systems produce in almost everyone the first while, and I felt it too, the small vertigo of watching a machine do a thing you were sure belonged to us: it answers, it composes, it seems for a moment to understand. The feeling is real. What almost no one says is that it is also the thing standing between you and any accurate account of what the machine is doing. Awe is a posture of looking up, and from the ground, looking up, you can tell only that something is large and bright and above you: not its parts, not its edges, not the small set of things it genuinely does against the far larger set it merely appears to. Wonder and dread, the golden age and the extinction, are the same posture in different weather, and both hold you exactly where the view is worst.</p><p>I have spent thirty years watching that shape of light arrive and then fade, with the network, with the cloud, with the device that ended up in every pocket, and the fading always felt, at the time, like a small loss, the magic going out of a thing I had briefly loved being amazed by. It took me most of those years to understand that the fading was the arrival. The moment the glow went down was the moment the mechanism came up, and the mechanism was the thing I was there to read. You cannot defend a system you are still worshipping. You cannot audit a miracle. The disenchantment was never the end of my relationship with a technology: it was the start of the only useful part of it.</p><p>So when people ask me now, a little disappointed, whether I have lost my sense of wonder about all this, I tell them yes, gladly, and that I recommend it. Not because the systems are worthless: in the narrow band where they do what they actually do, I reach for them daily, and the abstinence that passes, in certain circles, for insight has never impressed me. The point is smaller and more practical. The wonder was never information: it was weather. And you do not make a single real decision, about what to deploy or what to keep away from the people you are responsible for, from inside weather. You make it from the ground, inside the mechanism, where the parts are, and you cannot reach the ground while you are still looking up.</p><p>What surprised me, arriving late, was that the disenchantment told me almost nothing new about the machines and a great deal about us: how badly we want the object of awe, how tired we are, how much easier it is to feel a large feeling about a technology than to do the slow reading of what it actually does. The wonder is not quite ours even while we hold it. It is the most pleasant part of the product and the least examined, and it asks nothing of us except that we keep looking up, which is the one posture from which nothing can be governed, nothing checked, nothing in the end understood.</p><p>I will admit the disenchantment costs something. The wonder was pleasant, the way the first hour of any infatuation is pleasant, and the country on the far side of it is quieter, more accurate and less warm. But it is the country the work happens in, and the one I would wish on anyone who has to make a real decision about these systems rather than merely a feeling about them. The glow will keep arriving, with each new model and each new capability, because it is profitable that it should. The most useful thing I can tell you is that it goes down, if you let it, and that what it uncovers is not less than the miracle you were promised: it is the machine, finally the right size, close enough to read.</p>]]></content:encoded></item><item><title><![CDATA[The Supervised Interval]]></title><description><![CDATA[A term paper never proved that anyone knew anything: it proved they had sat with something hard long enough to be changed by it. That was the product.]]></description><link>https://www.marcobrondani.com/p/the-supervised-interval</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-supervised-interval</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Fri, 10 Jul 2026 09:18:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!23rG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!23rG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!23rG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!23rG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!23rG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!23rG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!23rG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png" width="1024" height="1536" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1536,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2471296,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/206417939?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!23rG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 424w, https://substackcdn.com/image/fetch/$s_!23rG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 848w, https://substackcdn.com/image/fetch/$s_!23rG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!23rG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22285ede-9d9a-443b-9ca5-cd46f64edb0b_1024x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>There is an argument going around that the college is about to collapse, and the case is stronger than the people making it usually manage to say. A model can now explain a known concept more clearly than most lecturers, write an essay that reads as competent, and pass the greater part of the exams we use to certify that a young person has learned something. If those three acts were the university, the university is finished, and the only open question is how long the buildings stay warm.</p><p>Those three acts were never the university. They were its packaging.</p><p>I have spent thirty years inside systems sold, each in its turn, as the end of some older way of doing things, and the pattern holds every time: the thing announced as obsolete turns out to have been carrying a second cargo no one had named, and it is the second cargo we lose. The lecture was never only the transfer of a known concept: a book did that more cheaply a century ago. The essay was never only the proof that the concept had landed. The essay was the interval: the days a mind spent inside a difficult question, writing the wrong version and seeing that it was wrong, reaching for a claim and putting it back, until what survived the discarding was a thought the student could not have held before beginning. The discarding was the education. The paper was only its receipt.</p><p>AI does not threaten the receipt. It forges it perfectly, which is a different problem, and a smaller one than the one underneath.</p><p>Run the distinction I rely on for everything else in this field, because it holds here too: separate what the system <em>does</em> from what the system <em>is</em>. What AI does to education is specific, measurable, already here: it removes the friction between a question and an acceptable answer. That is a does-claim, and we can test it, bound it, respond to it. &#8220;The university is obsolete&#8221; is an is-claim, and it cannot be tested, only preached, and it is preached now with the same two-faced certainty that attends every other AI story, the prophets of collapse and the prophets of the personalized-learning golden age selling, between them, one product from opposite ends.</p><p>While that argument runs at full volume, the other thing proceeds underneath it, unhurried, the way the consequential things usually do. The interval is being closed from a second side, and this one has nothing to do with the technology&#8217;s cleverness and everything to do with who holds the instruments. A campus is, among the things it is, a place where power has always wanted to decide what may be said, and the wanting used to run into a friction of its own: syllabi are many, a teacher&#8217;s judgment is hard to audit at scale, and what a young person is permitted to think has been, mercifully, expensive to police.</p><p>AI is, before it is anything else, the removal of that expense.</p><p>The tools arrive wearing the friendly face of assistance, and each of them, turned a quarter-degree, becomes an instrument for deciding the permitted answer. The detector that promises to catch the machine&#8217;s writing has been shown, again and again, to flag the honest non-native student&#8217;s prose as fraudulent at rates that never touched the native speaker&#8217;s: a filter that does not know it is a filter, sorting by a bias no one signed. The curriculum assistant that drafts the reading list drafts the one it was weighted to draft. Aim the sentiment tool at the campus forum to catch &#8220;concerning&#8221; language, and you have hung a microphone that no longer needs a listener at the far end. None of this requires a conspiracy; it requires the opposite. It requires convenience, adopted a department at a time by people with no agenda more sinister than a full inbox and a mandate to be seen doing something about AI. The agenda, whatever its color this decade, does not need to install itself. It only needs to supply the default.</p><p>So the interval is pressed from both sides at once. The model lifts the struggle out of the student&#8217;s hands, handing over the finished answer before the reaching could change them, while the same class of tool narrows the range of answers the struggle was ever allowed to reach, quietly, by making the approved one the path of least resistance. A mind handed the answer and a mind permitted only one answer arrive at the same place, which is nowhere: neither has done the descending, and the descending was the education.</p><p>I find, and it surprised me to arrive here, that I am not much moved by whether the institution survives in its present shape. Forms die; the cargo is the thing. Let the university fragment into its research institutes and its credentialing counters and its clubs for the young to find one another, and if somewhere in the wreckage a smaller thing survives whose whole business is teaching a person to think against the grade, the essential cargo will have found a new container, and the buildings were never sacred. It is the interval I would not lose, because it is the one thing both forces are reaching for and the one thing neither can be trusted to keep: the collapse treats it as friction to remove, the capture as a range to narrow, and to both of them the young mind learning to refuse the easy answer is not the point of the exercise but the obstacle to it.</p><p>Here is the test I would hand a teacher, or a dean, or a parent, in place of a verdict about &#8220;AI in the classroom,&#8221; a phrase that has already stopped meaning anything. Of any tool proposed for the campus, ask not whether it is efficient, and not whether it is inevitable, but whether it restores the interval or removes it. Does it put the struggle back into the student&#8217;s hands, or take it out of them. Does it widen the range of answers a young person may reach, or supply the one they are meant to arrive at. A tool that makes a student sit longer with a hard question and a tool that hands over the sanctioned conclusion do opposite work, and the phrase &#8220;AI in education&#8221; is built precisely so that one word can cover both before anyone thinks to separate them.</p><p>The knowledge was always going to be free, and we should be glad of it. What was never free, what had to be paid for in the one currency that does not deflate, in time and difficulty and the small daily defeat of the wrong sentence written before the right one, was the interval in which a person became someone who could think. That is what is closing now from both ends: a machine that removes the difficulty, a power that removes the choice, quietly, without announcement, on a campus full of the young, who are in no position to miss what they were never handed. Which leaves the noticing to the rest of us. It was always going to be us.</p><div><hr></div><p><strong>Sources</strong></p><ul><li><p>L. Giray, J. Roe, and J. Diesta Espiritu, &#8220;AI writing detectors are ineffective, unreliable and harmful,&#8221; <em>English Teaching: Practice &amp; Critique</em>, 2026 (doi:10.1108/ETPC-07-2025-0155). High false-positive rates, the disproportionate flagging of multilingual students, and the paradox that fear of a false accusation pushes students toward the very AI use it means to police.</p></li><li><p>Weixin Liang et al., &#8220;GPT detectors are biased against non-native English writers,&#8221; <em>Patterns</em> (Cell Press), 2023 (arXiv:2304.02819). The first measure of the bias, a 61% false-positive rate on Chinese students&#8217; TOEFL essays against 5% for US students, reproduced repeatedly since.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[The Control Group]]></title><description><![CDATA[The absolutist frame is a zero-sum frame wearing a visionary's coat: the machine wins and the worker loses, or the worker wins and the machine is banished.]]></description><link>https://www.marcobrondani.com/p/the-control-group</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-control-group</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Fri, 12 Jun 2026 07:20:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mfQY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>[ This piece extends &#8220;AI absolutism is breaking our brains,&#8221; The Guardian, 11 June 2026. Link below in Sources. ]</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mfQY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mfQY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!mfQY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!mfQY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!mfQY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mfQY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png" width="1122" height="1402" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1402,&quot;width&quot;:1122,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3207344,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/201708635?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mfQY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!mfQY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!mfQY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!mfQY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9a403d59-5851-4e8e-86bf-317b80c36785_1122x1402.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>In brief</strong></p><ul><li><p>AI <em>absolutism</em>, the habit of holding the technology as either a coming golden age or the end of the human story, works as a sales posture more than an argument. Both poles come off the same production line: a market that is dazzled or terrified keeps buying, and stops asking the slower questions.</p></li><li><p>One test clears most of the noise. Ask whether a claim is about what the system <em>does</em>, which is bounded and testable, or what it <em>is</em>, which can only be believed or refused. Absolutism lives in the second kind while borrowing the credit of the first.</p></li><li><p>Flatten a reality into a destiny and you remove the control group, the comparison between what a system costs and what it returns. That is also what makes it impossible to govern.</p></li><li><p>The story we are sold is replacement, the machine taking the jobs. The one arriving is control: the worker watched, scored, paced, kept grateful for whatever work is left. Gig platforms were the proving ground, and the method is climbing into the offices.</p></li><li><p>So the quarrel we are handed is not the one underneath. Below human-against-machine runs depth against flattening, and the discipline is to step off the line and read each use on its own terms: what it does, to whom, at whose cost, for whose benefit.</p></li></ul><div><hr></div><p>I have spent thirty years inside the systems now being sold to the rest of the world as either salvation or ruin, and the thing that strikes me, every time, is never the technology itself: it is the certainty around it. Everyone is certain.</p><p>The people who build the machines are certain they will remake the world, the people who fear them are certain the world is ending, and the two certainties, though they point in opposite directions, have exactly the same shape. I have watched that shape arrive before. It came with the network, with the cloud, with the phone in every pocket, with every system I was ever asked to defend or to break open, and not one of them turned out to be the thing its loudest believers promised, in either direction.</p><p>The Guardian gave the posture its right name last week: AI absolutism, a way of holding the technology as a godlike force that will either deliver a golden age of productivity or close the human story for good. What the piece names, and what is worth sitting with longer than a column has room for, is that the contradiction between the two poles is not an accident, and not a sign of a debate still finding its feet: it is the product.</p><p>The apocalypse and the utopia come off the same line, built by the same people, for the same reason: a market that is either dazzled or terrified is a market that buys, and a public held at either extreme does not ask the slower questions. Suresh Naidu, the Columbia economist quoted in the piece, put the commercial logic without ornament: to justify the valuation, you point at a revenue stream large enough to look like it can eat all the work on the planet, so no investor can stand to miss it. The terror and the wonder are not competing messages but two faces of a single pitch.</p><p>There is a distinction I have come to rely on, because it dissolves most of this noise in one move, and I would rather hand it to you than describe it from a distance. Ask, of any claim made about these systems, a single question: is this a claim about what the system <em>does</em>, or about what the system <em>is</em>.</p><p>The two are confused constantly, and I have come to think the confusion is the whole game. &#8220;This model writes working code&#8221; is a claim about a capability: testable, bounded, measurable, and it will turn out solid in a few narrow domains and hollow in most of the others. &#8220;This model is intelligence&#8221; is a claim about a being, and it cannot be tested at all, only believed or refused.</p><p>Absolutism lives entirely in the second kind of claim while borrowing the credibility of the first. It takes a tool that demonstrably does a small set of things and reframes it as an entity with a destiny, and once a tool has been given a destiny, you are no longer permitted to evaluate it. You are only permitted to be for it or against it.</p><p>Run the test on the lines we have all been fed, and watch them come apart. When Jensen Huang of Nvidia says every job will be affected, immediately and unquestionably, he is making a does-claim inflated into an is-claim: the affecting is real and measurable, the immediacy and the unquestionability are theology bolted on top.</p><p>When Dario Amodei calls the technology not a substitute for specific jobs but a general labor substitute for humans, the sleight is in the word <em>general</em>: a thousand specific, testable substitutions, each of which would prove partial and uneven if you measured it, swept into a single claim no measurement could ever reach. And when Sam Altman conceded, months later, that he had expected far more elimination of entry-level white-collar work by now than had happened, he was not correcting a forecast: he was revealing it had never been one. A forecast can be wrong. A frame can only be maintained or abandoned, and he had begun, very slightly, to abandon his.</p><p>This matters far past the philosophy of it, because a reality flattened into a destiny is a reality you can no longer govern. The most honest sentence in the entire Guardian piece is Naidu&#8217;s other one: there is no control group.</p><p>He offered it as a caution about measurement, that we have no untouched population to set beside ourselves and compare. He is right. But the line cuts deeper than he let it: absolutism is the thing that removes the control group, because it forbids the comparison before it can begin. You cannot weigh what a system actually costs against what it actually returns when you have already decided, in advance and at volume, that it is either the future or the end of it.</p><p>Governance, the real kind, the unglamorous discipline I spent decades practicing, is nothing but the patient refusal of that flattening: the reconnaissance, the reading of the one situation in front of you, the insistence on knowing precisely what a thing does before you allow yourself to say what it means. Absolutism is the exact posture that makes this work impossible. I suspect that is part of why it is sold so hard.</p><p>And while the loud argument runs on between the two certainties, the quiet thing happens in the layer underneath. The story we are handed is replacement: the machine will take the jobs. The story actually arriving, in the systems I know from the inside, is not replacement but control: not the worker removed, but watched, scored, paced, and pressed to feel grateful for whatever work remains.</p><p>The gig platforms were the proving ground, the drivers and couriers managed by software that never sleeps and never explains itself, and the people who study labor expect the method to climb the ladder, out of the warehouses and the cars and into the offices that still assume they are too senior to be metered. This is the application absolutism keeps out of frame, because a public arguing about whether the machine is a god does not look down to see what it is being used to do to them.</p><p>So here is where the ground shifts, and I will admit it took me a long time to see. The fight we are told we are having is human against machine. We are not having that fight.</p><p>The fight underneath it, the one that actually settles anything, is depth against flattening: between a public kept on the top layer of a system it was never given the chance to understand, dazzled or frightened on command, and a public permitted to descend into the real complexity and act from down there, where the decisions actually live. Absolutism is not a position in the human-versus-machine argument but the instrument both sides are holding, pointed at the same place each time: at your capacity to hold the middle, to stay specific, to refuse the verdict long enough to see what is in front of you.</p><p>The Guardian lands, sensibly, on moderation, and I understand the pull of it. But moderation is not strong enough to carry the weight, because moderation only splits the difference: a calmer spot on the same line that runs from doom to rapture, the line itself left unquestioned. What is asked of us is to step off the line.</p><p>Not to use the technology a little, but to refuse the frame that says the only choice is how fervently to worship or how hard to flee. The harder discipline, and it is harder, is to read each use on its own terms, one at a time: what does this application do, and to whom, at whose cost, for whose benefit, and is that benefit shared with the people it touches or extracted from them. A model that helps a nurse learn faster and a model that helps a platform squeeze a courier are not the same event, and no single verdict about &#8220;AI&#8221; can hold both. That reading is slow, and unglamorous, and it will never fit in a headline or a valuation, which is the strongest recommendation it could have.</p><p>None of this is an argument against the technology. I use these systems; in the narrow places where they do what they actually do, I find them genuinely useful, and I have no patience for the abstinence the loudest critics keep mistaking for virtue. It is an argument against the certainty, in both of its costumes.</p><p>The certainty was never knowledge: it was a sedative, sold to keep us comfortable at the surface while the decisions that matter, about who is watched and who is paid and who is told to be grateful, were taken somewhere below us, in the layers we were made too dazzled or too frightened to read.</p><p>The Industrial Revolution is the comparison everyone reaches for now, and it is the right one, though almost never for the reason it is offered. It is offered as consolation: the machines came, it was hard for a season, and in the end it worked itself out. What that telling removes is the length of the season, the price of it, and the plain fact that nothing worked itself out on its own.</p><p>People made it work out, slowly, against real resistance, by organizing and insisting and declining to accept that the new arrangement was simply the weather. The wins took the better part of a century, and they were never handed down. They were taken, by people who refused to be certain about their own defeat.</p><p>That is the only future I am willing to be certain of: that it is not decided yet, and that the work of keeping it undecided, of staying specific and awake while the certainties are sold to us at full volume from both directions, belongs to us. It is not finished. It does not get to be put down.</p><div><hr></div><p><strong>Sources</strong></p><ul><li><p>&#8220;<a href="https://www.theguardian.com/technology/2026/jun/11/ai-absolutism-apocalyptic-future">AI absolutism is breaking our brains</a>,&#8221; The Guardian, 11 June 2026.</p></li><li><p>Marco Brondani, <a href="https://www.marcobrondani.com/p/the-split-problem-book">The Split Problem: Why We Cannot Tell If AI Is Conscious</a>, Quill House Press, 2026.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[The Return of the Generalist]]></title><description><![CDATA[What survives the AI era is not the broad mind, but the mind that has been deep once.]]></description><link>https://www.marcobrondani.com/p/the-return-of-the-generalist</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-return-of-the-generalist</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Wed, 03 Jun 2026 20:01:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!a53g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!a53g!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!a53g!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!a53g!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!a53g!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!a53g!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!a53g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2667739,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/198528830?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!a53g!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!a53g!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!a53g!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!a53g!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf423bfb-7a99-4576-bb89-220f3b4abd0a_1672x941.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>In brief</strong></p><ul><li><p>The popular thesis, that AI commoditised expertise so the broad generalist wins, is almost true, and the <em>almost</em> is where it fails: fluency on tap devalues the shallow generalist as fast as depth on tap devalues the specialist.</p></li><li><p>The mind whose value is climbing is a third kind. It has gone deep in one thing at least once, deep enough to know that every serious field hides an architecture, and to feel when that architecture is missing.</p></li><li><p>Chess supplies the mechanism. In the Chase and Simon studies of 1973, masters rebuilt real board positions almost perfectly and random ones no better than novices: they were seeing structure, not remembering harder. Structure has no signature to anyone who cannot already see it.</p></li><li><p>What carries across fields is not the expertise itself but the knowledge that depth exists at all, which leaves a lasting suspicion of fluent surfaces.</p></li><li><p>That sets up a verification problem with no clean fix. A model now produces a flawless surface in any voice, so the old signals of credential, polish, and volume sort wrong. The workable move is to watch how someone fails at the edge of their competence: confident fluent error is the counterfeit, visible recalibration is the real thing.</p></li></ul><div><hr></div><p>Generalists are having a moment. The thesis is everywhere now: artificial intelligence has commoditised narrow expertise, so the broad mind, the polymath, the synthesizer across domains, is the mind that wins. The specialist is finished. The generalist is back. Panels are convened on this. Essays are written on it. The thesis has the comfortable property of being almost true.</p><p>Almost true, in a way that hides the actual problem. If the standard story were right, value would be sliding from the specialist toward the broad mind. It is. But the broad mind is being undercut at the same time, and faster, because anyone with a chatbot now produces fluent cross-domain takes on any subject in thirty seconds. The synthesizer who knew a little about a lot was never cheap to maintain in a human. The same product is now free in a model. The shallow generalist has been quietly devalued at exactly the same moment as the specialist, and has noticed it less.</p><p>That leaves the question open. If the specialist is being undercut by depth-on-tap, and the broad mind is being undercut by fluency-on-tap, then a third kind of mind must be the one whose value is rising. What kind?</p><div><hr></div><p>Leave the topic of AI for a few paragraphs. The clearest demonstration of depth concerns chess and is half a century old.</p><p>The studies ran from the 1940s through the early 1970s, refined most sharply by William Chase and Herbert Simon in 1973. A chess master and a chess novice were shown the same arrangement of pieces on a board for five seconds, then asked to reconstruct it on an empty board. The master reproduced the position almost perfectly. The novice could not. This is what most people would expect, and on its own it shows nothing interesting; the master, after all, is the master.</p><p>Then the control. The researchers showed both subjects pieces arranged randomly, in configurations that could not have arisen in any real game. The master&#8217;s advantage nearly disappeared. Master and novice were now roughly equivalent at the task.</p><p>The result is famous in the perception literature, and its interpretation has held up across half a century of replication. The master is not remembering harder, and not seeing faster. The master is seeing meaning where the novice is seeing only pieces. A real game position contains structure: threats, defended squares, latent patterns. The master perceives that structure directly, the way someone fluent in a language perceives a sentence rather than a sequence of words. When the structure is absent, as in a random arrangement, the master has nothing to perceive that the novice does not.</p><p>That is the first half of the result.</p><p>The second half is less often cited: the novice watching the master cannot perceive that anything extra is being seen. From outside, the master appears to be looking the way anyone looks.</p><p>Depth has no visible signature to the untrained eye.</p><div><hr></div><p>Chess expertise does not transfer. Grandmasters are not generally smarter than other people of comparable IQ; their pattern recognition is exquisite inside chess and ordinary outside it. Decades of attempts to show that chess training makes children better at mathematics, or planning, or anything else, have produced equivocal results at best. The chunks the master sees in a real game are precisely the chunks of that game. Take the master out of chess and you take away the perception.</p><p>So if the value of having gone deep into chess does not transfer, the use of chess for an essay about generalism appears to fall apart.</p><p>What transfers is not the chunks but the knowledge that chunks exist. Having gone deep into one thing once, you have learned in your body that every serious domain contains a hidden architecture invisible from outside. The architecture is different in every domain, and so the specific perception cannot be carried across. What is portable is the knowledge that such architectures exist, that they take years to acquire, and the texture of what real understanding feels like. That set of three becomes a permanent suspicion of surfaces.</p><p>The person who has never been deep in anything lacks the suspicion. Every domain looks shallow from outside, including the ones that are not, and they have no internal record of the gap between what a field looks like to the layperson and what the field is. So they cannot calibrate. They cannot tell the fluent surface from the load-bearing depth, because they have never personally seen the difference even once. That is exactly the cognitive position AI&#8217;s fluent shallowness now exploits at scale.</p><p>The valuable mind in the era of cheap fluency is not the broad mind, and not the deep specialist. It is the mind that has been deep in something once, deep enough to know that depth exists and what its absence looks like.</p><div><hr></div><p>The same recognition appears in every domain where someone has been deep and someone else has not.</p><p>In medicine, the experienced diagnostician&#8217;s &#8220;something is off&#8221; before the labs return is not mysticism but what the chess result names: pattern recognition built from thousands of cases, the structure clinicians call illness scripts. The diagnostician is not seeing harder but seeing the meaningful structure of the presentation, the way a chess master sees a position. A medical student watching that diagnostician work cannot perceive that anything extra is being seen. The diagnostician appears to be looking the way the student looks. That is the same invisibility.</p><p>In music, the trained ear hears a wrong note in a passage where the layperson hears music. The disagreement between the trained ear and the lay ear is not about taste but about one party perceiving structure where the other perceives only surface, and neither party can fully explain the gap to the other. The performer who stops a recording at one phrase, because of a single missed inflection, is doing what the chess master does in a different register.</p><p>Biology supplies the cautionary case, and supplies the link to the present moment. Convergent evolution is in some sense nature&#8217;s own analogy engine: the eye evolved independently dozens of times, and the structural similarity across phyla is one of the most beautiful patterns in the discipline. But Stephen Jay Gould and Richard Lewontin&#8217;s 1979 paper <em>The Spandrels of San Marco and the Panglossian Paradigm</em> identified the danger of fluency in this register. Many evolutionary explanations that sounded like depth, they argued, were in fact just-so stories: adaptationist tales told in a confident voice, often inventive and elegant, frequently load-free. The adaptationist narrative was the pre-AI counterfeit of cross-domain insight. It was produced in a competent generalist&#8217;s voice. It performed brilliantly at conferences. Much of it turned out, on examination, not to bear weight.</p><p>In literary translation, the AI era has produced a natural experiment. Commercial translation has collapsed into low-paid post-editing of machine output; literary translation, paradoxically, has become more visible than ever. Translators&#8217; names appear on covers. Prizes are awarded to them. The same tool that hollowed one form of the craft elevated the other. The reason is the same reason as everything else in this essay. Commercial translation rewarded fluency, and fluency is now free. Literary translation requires the judgment of which of a hundred possible English sentences holds the load of the German one. That judgment is not fluent but calibrated. The market sorted itself.</p><p>In each case the practitioner perceives meaning where the layperson perceives only surface. In each case the layperson cannot detect that anything extra is being perceived. And in each case, now, AI produces a fluent surface so convincing that the layperson can no longer tell the practitioner&#8217;s calibrated output from the model&#8217;s confident counterfeit. The calibrated mind can still tell them apart, the mind that has never been deep cannot.</p><div><hr></div><p>The figure being described is not new, even if its current moment is. The generalist has died and come back several times in the history of the modern mind, and each return has been to a different creature.</p><p>Thomas Young is the cleanest case from the period before specialization closed in. He was an English physician of the early 1800s. He did the wave theory of light, ran the double-slit experiment, and decoded a substantial portion of the demotic script on the Rosetta Stone, alongside serious contributions to materials science, music theory, and the physiology of vision. Andrew Robinson titled his 2006 biography of Young <em>The Last Man Who Knew Everything</em>. The phrase is a slight overstatement, and Young is not actually the last; but the title named a real transition. Within fifty years of Young&#8217;s death, the configuration of intellectual life that had supported him had ended.</p><p>Goethe is the parallel case in the literary tradition. He coined the word <em>morphology</em>, did serious comparative work on plant form, and developed a theory of colour. The colour theory was wrong about the physics, in ways Newton had already settled, but right about the perception of colour in ways that took another century to recognise. Goethe was a polymath in a register the professional sciences would soon stop tolerating.</p><p>The institution that closed the polymath role was the nineteenth-century German research university. Wilhelm von Humboldt&#8217;s model, with its seminar method, its specialised faculty, and its requirement that knowledge be produced inside a discipline, made the polymath structurally obsolete. By 1900 the Renaissance ideal had been replaced by the modern researcher, and the word <em>amateur</em> had completed its slide from praise to insult. The polymath retreated into the disreputable category of the dilettante and stayed there for most of the twentieth century.</p><p>A partial revival arrived in the 2000s under the name <em>T-shaped</em>. The framing was a deep specialist who also worked usefully across adjacent fields, and it was a useful idea, but it remained a hybrid description. The T was still rooted in the specialist as the load-bearing element. The breadth was decoration.</p><p>The empirical revival is more recent, and more careful. Philip Tetlock&#8217;s research on political and economic forecasting was summarised in his 2005 book <em>Expert Political Judgment</em> and extended in <em>Superforecasting</em> with Dan Gardner in 2015. Across decades of records, foxes consistently outperform hedgehogs at prediction. The terminology is older. Isaiah Berlin took it from a fragment of the Greek poet Archilochus, in his 1953 essay <em>The Hedgehog and the Fox</em>, to distinguish minds that know one big thing from minds that know many things. Tetlock found that Berlin&#8217;s foxes won.</p><p>The complication, which the popular reception of Tetlock&#8217;s work tends to skip, is that his winning foxes were not merely broad. They were broad and calibrated, updating quickly on new evidence, holding their views loosely, and reporting lower confidence even when they were right. A na&#239;ve fox, broad and uncalibrated, loses to a competent hedgehog. The variable was never breadth.</p><p>Each return of the generalist, then, has been to a different creature. The 2026 version is a new creature again. It is defined not by knowing many things (the model knows more) but by being able to judge across many things, because real depth has been experienced at least once. The figure does not yet have a settled name.</p><div><hr></div><p>The trouble is that the mind being described is not only valuable but harder to detect than it has ever been.</p><p>The reason is the same as the structure of the chess result. Depth is invisible from outside. To anyone who lacks depth themselves, depth has no detectable signature. And we have just built a tool that produces a flawless surface on demand, in any domain, in any voice.</p><p>The adaptationist just-so story was the pre-AI version of fluent cross-domain insight without an anchor: confident, plausible, often load-free. It took the field of evolutionary biology a generation to dislodge the worst examples. The stories sounded like understanding. To anyone outside the specific area, and to many inside it, there was no visible difference between an adaptationist hypothesis that held under examination and one that did not. The difference was visible only on the load test, and the load test took years.</p><p>AI now produces adaptationist storytelling, in every domain at once, on request. It is exceptionally good at it. The output is fluent, integrative, cross-referenced, voiced. It can be made to sound like any school of thought you name. To the reader who has not personally been deep in the domain it is discussing, it is indistinguishable from real synthesis. On every legible metric of writing quality, it outperforms the calibrated original. The reason is structural. Every legible metric of writing quality was developed in an era when fluency was a costly signal of competence. It no longer is.</p><p>This produces a verification problem that does not have a clean solution. The institutions that need the calibrated mind cannot easily find it, because the signals they were built to read have been imitable for two years and counting. The calibrated mind cannot easily prove itself by output alone, because the output is what gets imitated first. The mind that has been deep once knows that something is wrong with most of what it now reads online. But it cannot defend that judgment to anyone who has not been deep themselves. The judgment is precisely what they lack the prior to receive.</p><p>The problem will not solve itself. It is structural, not transitional. The chess result predicted it half a century ago without naming it: depth is invisible to those who lack it. We have now built a machine that exploits exactly that invisibility, at speed, in language, everywhere, for free.</p><p>The honest position from here is open. I do not know how this gets resolved at the level of public discourse. I have a working answer for how it gets resolved inside institutions. The discourse-level problem may not be solvable at all, and anyone who claims a clean answer for it is probably overconfident.</p><div><hr></div><p>The position is harder than it has been, then, but not hopeless. The work remaining is locating and trusting the calibrated mind without the tools that used to do it for us.</p><p>The institutional part is concrete. The structures that currently sort by credential, by writing quality, by polish, by output volume, will all increasingly sort wrong. They were calibrated for the era in which fluency was a costly signal of competence. They have not yet been adjusted for the era in which it is not. That work is doable. People who already do this well, in my experience and in the experience of people I trust to know, do roughly the same thing. They put candidates into problems adjacent to their depth, in domains the candidate has not specifically prepared for. Then they watch how the candidate handles being out of their depth. The way someone errs at the edge of their competence is what reveals their calibration. Confident, fluent errors are the counterfeit&#8217;s signature. Wrong moves followed by visible recalibration are the real thing. That is the behaviour depth teaches.</p><p>The personal part is shorter, and it has not changed in centuries. There is exactly one route to becoming this kind of mind. Pick something. Go deep into it. Stay deep until the chunks form, until the field has internal texture, until you have felt, once, what understanding feels like from the inside. The specific thing does not matter as much as the depth of the going. The craft can be jazz piano, synthetic chemistry, late Roman history, carpentry, or differential geometry; what matters is that it was taken seriously enough to leave a mark. The mind that has been the real thing in any one of these carries the standard out into every other domain it encounters. After that the rest is portable. Not the chunks. The suspicion. The standard.</p><p>One last picture. A chess master sits beside a novice in front of a real board. The master sees a position, sees a threat, sees the move four ahead that resolves everything. The novice sees only pieces. The master cannot fully explain to the novice why the move is right. Explaining would require the novice to have already done the work that produced the perception. The novice sees the master looking at the board and concludes, reasonably, that the master is looking at the board.</p><p>That is the situation every reader of this essay is now in, in domains other than their own. Most consequential decisions of the next two decades will be made by minds judging across domains where they have not been deep. The question is the same for an institution, a country, or a person: whether the mechanism exists to find and trust the people who have been deep enough to see what the layperson cannot. Not the mechanism for trusting the AI, but the mechanism for trusting the humans who will have to use it.</p><p>Depth is invisible from outside. The discipline is to keep looking anyway.</p><div><hr></div><h3>Sources</h3><ul><li><p>Berlin, Isaiah. <em>The Hedgehog and the Fox: An Essay on Tolstoy&#8217;s View of History.</em> London: Weidenfeld &amp; Nicolson, 1953.</p></li><li><p>Chase, William G., and Herbert A. Simon. &#8220;Perception in Chess.&#8221; <em>Cognitive Psychology</em> 4, no. 1 (1973): 55&#8211;81.</p></li><li><p>De Groot, Adriaan D. <em>Thought and Choice in Chess.</em> The Hague: Mouton, 1965. Originally published in Dutch as <em>Het denken van den schaker</em> (Amsterdam: Noord-Hollandsche, 1946).</p></li><li><p>Goethe, Johann Wolfgang von. <em>Versuch die Metamorphose der Pflanzen zu erkl&#228;ren.</em> Gotha: Ettinger, 1790.</p></li><li><p>Goethe, Johann Wolfgang von. <em>Zur Farbenlehre.</em> T&#252;bingen: Cotta, 1810.</p></li><li><p>Gould, Stephen Jay, and Richard C. Lewontin. &#8220;The Spandrels of San Marco and the Panglossian Paradigm: A Critique of the Adaptationist Programme.&#8221; <em>Proceedings of the Royal Society B</em> 205, no. 1161 (1979): 581&#8211;598.</p></li><li><p>Robinson, Andrew. <em>The Last Man Who Knew Everything: Thomas Young, the Anonymous Polymath Who Proved Newton Wrong, Explained How We See, Cured the Sick, and Deciphered the Rosetta Stone.</em> New York: Pi Press, 2006.</p></li><li><p>Tetlock, Philip E. <em>Expert Political Judgment: How Good Is It? How Can We Know?</em> Princeton: Princeton University Press, 2005.</p></li><li><p>Tetlock, Philip E., and Dan Gardner. <em>Superforecasting: The Art and Science of Prediction.</em> New York: Crown, 2015.</p></li></ul>]]></content:encoded></item><item><title><![CDATA[Assisted, not delegated: writing]]></title><description><![CDATA[The space between human and AI]]></description><link>https://www.marcobrondani.com/p/assisted-not-delegated-writing</link><guid isPermaLink="false">https://www.marcobrondani.com/p/assisted-not-delegated-writing</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Sun, 24 May 2026 20:01:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LOsM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LOsM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LOsM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 424w, https://substackcdn.com/image/fetch/$s_!LOsM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 848w, https://substackcdn.com/image/fetch/$s_!LOsM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 1272w, https://substackcdn.com/image/fetch/$s_!LOsM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LOsM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png" width="1456" height="485" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:485,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2388333,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/198674195?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LOsM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 424w, https://substackcdn.com/image/fetch/$s_!LOsM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 848w, https://substackcdn.com/image/fetch/$s_!LOsM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 1272w, https://substackcdn.com/image/fetch/$s_!LOsM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb31f1f0e-a998-4568-886e-9ec4702383f3_2172x724.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>In brief</strong></p><ul><li><p>The public argument about AI and writing has collapsed into one question, human or machine, and the collapse is doing most of the damage.</p></li><li><p>Three practices hide inside that binary. <em>Unassisted</em>: a writer at the keyboard, no model, the whole chain of judgment in one head. <em>Delegated</em>: a writer prompts, pastes, posts, signs, one decision in the chain. <em>Assisted</em>: a model worked as a tool inside a discipline the writer controls, hundreds of decisions the reader never sees.</p></li><li><p>&#8220;AI-assisted&#8221; has stopped carrying information, because delegated writers shelter inside it using the same disclosure lines. The honest writer ends up paying the dishonest one&#8217;s bill.</p></li><li><p>The line between assisted and delegated lives in the process, not the product, so detection software cannot find it. Only the practitioner can, by showing the work.</p></li><li><p>The proof is behavioural, borrowed from coders: draft in git with a visible history, publish the frameworks, keep the transcripts. A timestamped record of judgment is the thing &#8220;I rewrote it&#8221; can never supply.</p></li></ul><div><hr></div><p>A piece came across my feed last week from someone in my extended orbit. Good premise, the kind of historical thread that promised a real essay if it got the right hands. The caption underneath was confident: two months of extensive reading and research, the author&#8217;s proudest piece of work, history is truly humbling. I opened it expecting to learn something.</p><p>I had seen this shape before. A single rhetorical move repeated for three thousand words. Couplets, antitheses, the same syntactic gesture wearing different costumes. The specific material a serious reader of the subject would expect never quite arrived; the named references could have been gathered in a single afternoon on two well-known forums. The piece was atmospheric where it should have been textured, abstract where it should have been concrete. The kind of writing a language model produces when asked to sound essayistic about a subject the prompter has not actually studied.</p><p>I tried to raise it with a mutual friend who knows the author better than I do. The reply came back inside a minute: <em>I&#8217;m not gonna say that to the guy.</em> The substance never got litigated. The conversation closed before it opened. And I sat with that for a while, because the friend was not wrong by any rule of friendship I would want to defend, and the piece was not going to improve on its own, and somewhere in the gap between those two facts was the thing I have been circling for months without writing down.</p><p>I have been circling this for months without writing it down. The first piece in a series, because the problem extends past writing, and the answer in each domain is shaped a little differently. Writing is where it starts, and writing is where I have done the work, so writing comes first.</p><p>Earlier this year I published a piece called <em><a href="https://www.marcobrondani.com/p/care-as-a-discipline">Care as a Discipline</a></em>, about how painting and celestial navigation survived their automating tools. The argument was that a craft does not die when a machine arrives to do its job; it survives when its judgment can be moved somewhere the machine does not reach. Painting found higher ground in interpretation, in deciding which appearance was worth holding. Navigation found lower ground in resilience, in being the position you can still recover when the convenient signal has been jammed or spoofed. Ground existing, the piece argued, was not the same as anyone standing on it. The discipline of care was the early decision to move the craft&#8217;s judgment while moving it was still cheap, before the loss had happened and the rebuild was forced.</p><p>I wrote that essay in the abstract. The crafts in it were historical. Painting and navigation were the analogies, and the verdict from 1839 was the metaphor for the verdict being delivered now against a long list of crafts at once. I did not, in that piece, take any specific craft and stand on its ground in public, with my own name on the work. Writing is the craft I am trying it with first. AI is the tool. The question is what the higher ground looks like in practice for a writer who refuses to either abandon the tool or surrender to it. The distinction between assisted and delegated is the answer I want to offer, and the reason it matters even though almost no one in the current public conversation can see it.</p><div><hr></div><p>The public conversation about AI and authorship has settled, for now, into two positions that talk past each other.</p><p>The first position belongs to writers like Andrea Bartz, the novelist who has spent the last year arguing on her Substack that generative AI is eroding the trust between readers, writers, and publishers. Her position is principled, technically informed, and absolute: any contact between a language model and a published text contaminates the text. The detection regime is failing (false positives are ruining careers, certifications can be bought for ten dollars and ninety seconds of work), and her response is to call for harder infrastructure. Human Authored certifications with legal teeth. Behavioral signal capture during composition. Cryptographic proof of authorship. A writers&#8217; union with the muscle of the WGA. The whole institutional apparatus, built from scratch, to defend a category that used to defend itself.</p><p>The second position belongs to writers like Jo Shaw, who acknowledges the AI tells (rule of three, &#8220;not this but that,&#8221; em-dashes) and immediately deflates them: humans invented all of these patterns first, and it is entirely possible that writing which screams AI is just bad human prose. Shaw&#8217;s anxiety is about the witch hunt. The Mia Ballard case sits in her essay as a warning: an author whose career was destroyed on detection-based suspicion, who may or may not have done what she was accused of, and whom we will probably never be able to clear or convict. Shaw closes by asking her readers whether a Human Authored certification would help, or whether the standard should be innocent until proven guilty.</p><p>Both positions are responding to something real. The trust erosion Bartz describes is happening. The witch hunt Shaw fears is happening. The Ron Charles experiment Bartz quotes at the end of her piece (using ChatGPT to generate five hundred words from an interview transcript, paying ten dollars, receiving a certificate of human authorship in ninety seconds) is evidence the verification regime cannot bear the weight being put on it.</p><p>Both positions treat the field as binary. Human-written, or AI-written. Trustworthy, or not. In Bartz&#8217;s framework these are the two categories, and the work is to defend the first from the second. In Shaw&#8217;s framework these are still the two categories, and the work is to keep accusation from running ahead of evidence. Neither writer can see the practitioner I am trying to describe, because that practitioner doesn&#8217;t fit in either box.</p><div><hr></div><p>There are at least three practices currently being squeezed into two categories, and the collapse is where most of the harm comes from.</p><p>The first is unassisted writing: a human at a keyboard, no model in the loop, the entire judgment chain in one head. This is what Bartz defends and what Shaw worries is being falsely accused. It is the older practice, and it is not going anywhere, and it deserves the protection both writers are trying to give it.</p><p>The third practice (I will come to the second in a moment) is delegated writing. A human with a topic and a vibe prompts a model to produce content. The model generates. The human pastes, posts, signs. The judgment chain has one decision in it: <em>post</em>. Sometimes the human adds a caption claiming research, expertise, pride. The signature is a forgery in a specific sense: it promises a presence the text cannot deliver. The Ron Charles experiment is the pure form of this. The piece that came across my feed last week is a less pure but recognizable example.</p><p>Between unassisted and delegated, there is a middle practice that the public conversation does not currently see, and that is the practice I want to defend. Assisted writing. A human with something to say uses a model as part of a process the human controls. The thinking, structuring, selecting, weighing, cutting: those remain the human&#8217;s. The model is a tool inside a discipline. The output is signed by the human because the human is in fact present in the output. The judgment chain has hundreds of decisions in it, most of which the reader will never see, all of which leave traces in the text if you know how to look.</p><p>The collapse of these three into two is not a neutral simplification. It hurts everyone. It hurts unassisted writers, who become paranoid and start defending their humanity against accusations that should never have been levelled. It hurts assisted writers, who become invisible, their disciplined practice read as either suspicious (Bartz&#8217;s view) or naive (Shaw&#8217;s view). And, most consequentially, it lets delegated writers hide inside the assisted category by adopting the same disclosure language. <em>Yes, I used AI. I&#8217;m transparent about it. Everyone does.</em> The honest practitioner and the dishonest one say the same sentence, and the sentence stops carrying information.</p><p>This is the bucket problem. When &#8220;AI-assisted&#8221; comes to mean anything that a model has touched, including pieces no human actually thought, the term ceases to function as a signal. The honest writer pays the bill for the dishonest one. The bad money drives out the good until the category itself collapses.</p><div><hr></div><p>Bartz writes about authors who might be tempted to publish AI-assisted work as human-written, and predicts what they will tell themselves: <em>I totally rewrote what it generated, I was just using it to get the juices flowing.</em> Her implication is clear. Anyone who explains their AI use this way is rationalizing. The honesty is performed, the discipline is fiction, the byline is still a forgery.</p><p>She is partly right. Some people do say those sentences as cover for delegation. The cover is real and the sentences are sometimes lies. If I am going to argue for the assisted category, I owe the reader more than my insistence that I am the honest kind.</p><p>Most of the disclosure language Bartz is suspicious of is unverifiable by design. The writer says <em>I rewrote it</em> and the reader has no way to check. <em>I used it to get the juices flowing</em> and the reader has no way to check. The phrase is offered as a credential, and the credential carries no proof. Bartz is right to find this hollow.</p><p>What I can offer in place is a record. I draft in markdown files, in a git repository, with commits at meaningful intervals. The commit messages describe what changed and why. The version history shows the order of decisions: which paragraph existed in the first draft and survived, which one came in on the fourth revision after a structural rethink, which sentence I argued with myself about for three commits before cutting it. The conversations I have with the model are saved as transcripts. The frameworks I apply to revision (the Humanization Framework, now in its ninth version, the Cognitive Framework for AI-Assisted Intellectual Work, the voice synthesis systems for the pseudonymous projects) are public documents. Anyone who wants to know what assisted writing looks like in my practice can read the methodology and inspect the trail.</p><p>Bartz herself, in the same essay, points at the only solution the current moment actually allows. She quotes Vera Kurian: the right detection unit is not the content of the text but the behavior of its production. Save your drafts. Show your revision history. Demonstrate the labor. Kurian writes about Google Docs autosave and slow incremental changes. Bartz writes about her own use of Google Docs, with a self-conscious aside about the irony of using a Google product when Gemini is part of the problem.</p><p>The irony she names cuts further than her essay registers. Writers worried about AI&#8217;s contamination of authorship are documenting their human process using infrastructure built by one of the largest producers of generative AI in the world. The contradiction is structural. Writers who want to defend human authorship reach for tools built by the companies they are defending against, because nothing else in the consumer software stack does what they need.</p><p>The software industry has been arguing about authorship of intellectual work for thirty years, and it produced a tool for exactly this problem. Git, and the public hosting platforms built on top of it, were designed to make authorial decisions visible: who changed which line, when, in what order, with what stated reason. Every commit is a timestamped claim. Every diff is a record of judgment. The branching, merging, and review patterns are a documented social process for how decisions get made and by whom. A writer who drafts in git can produce, by default, exactly the kind of behavioral evidence Kurian is asking for, and can do it on infrastructure that has no entanglement with any AI company&#8217;s training data ambitions.</p><p>The fact that this is unusual in the writing world says less about writers than about how the two communities have developed in isolation from each other. Coders have an authorship discipline because their work has been treated as intellectual property under legal pressure for decades. Writers have an authorship discipline because their work was never automatable enough to require explicit defense. Now that it is, the writers are reaching for the coders&#8217; tools. They should. Those tools work.</p><div><hr></div><p>I should say, before I go further, that I started where the delegated writers started.</p><p>The first pieces I wrote with model assistance were mostly the model&#8217;s. I prompted, it generated, I tidied, I posted. The output had the same shape as the piece I described at the top of this essay, and if I had kept going that way I would now be producing the same hollow atmospheric work in a different domain. I had the same initial reaction everyone has. The model produces fluent text fast. The fluent text looks like the writing I would do if I were better. The combination is intoxicating, and the intoxication is the problem.</p><p>What pulled me back was reading my own pieces a few weeks after publishing them and recognizing that they did not contain me. The voice was a flattened average of the voices the model had been trained on. The arguments were the ones the model could reach without effort, which meant the ones that had been made many times before. The reader&#8217;s attention I had asked for was being repaid with content I had not actually generated. The signature was the forgery Bartz describes.</p><p>The work since then has been the work of climbing back into the chair. The Humanization Framework began as a private discipline for catching the specific places where my prose had collapsed into model defaults: the em-dashes, the binary corrections, the staccato lists, the topic-sentence orthodoxy, the prestige vocabulary, the synonym rotation, the period overuse. It is now a forty-nine-rule document across twenty-three sections, applied at the revision pass, mode-selected by genre. The Cognitive Framework came later, as a companion: a structured process for the epistemic side of the work, ontology mapping and adversarial audits and the things a model will not do for you because they are the parts where the thinking happens. The voice synthesis frameworks are for the cases where the voice on the page needs to be specifically not mine (pseudonymous projects, particular registers), and where the discipline is correspondingly harder.</p><p>None of these frameworks make a model write better. They make me write better when a model is in the loop. They are the answer to the question <em>what is the human supposed to be doing while the model is fast.</em> They formalize the judgment work that distinguishes assisted from delegated, and they do it in public, in version-controlled documents, so that anyone who wants to inspect the practice can. They are, in the language of the earlier essay, the way I have tried to move my own judgment to higher ground while the move is still cheap.</p><p>I have not arrived. The frameworks are imperfect, the discipline is uneven, some pieces come out better than others. But the direction is the one Bartz is asking for, and the methodology is more rigorous than the Google Docs autosave she settles for, and the work happens inside a category, assisted and not delegated, that her essay cannot quite see.</p><div><hr></div><p>Back to the friend.</p><p>The reply was <em>I&#8217;m not gonna say that to the guy.</em> No counter-argument about the piece, no defense of its quality, no claim that I had read it wrong. Just the refusal. And the refusal was reasonable. Friendship is not editorial. Unsolicited criticism of someone&#8217;s creative work lands as an attack on identity, not on output, and most people will not do that to a friend. I would not have wanted him to either, if I had been thinking about it purely as a question of friendship.</p><p>But the piece was not a private journal entry. It was published with a caption claiming two months of research, the author&#8217;s proudest work to date, history is humbling. The author was making public claims and asking strangers to read his work as expertise. Once a piece enters public space with substantive claims, it is in a different conversation, and the friendship-protective instinct stops fitting cleanly. The author was asking the internet to take him seriously.</p><p>The reason this matters for the larger argument is that the writer I read last week, and the thousand writers like him quietly posting delegated content to small Substack audiences every day, sits in a place where none of the institutional remedies Bartz and Shaw are debating will ever reach. He has no publisher to cancel him. He has no editor to push back. He has no contract that requires originality. He is not famous enough to be falsely accused in a witch hunt, and he is not famous enough to be defended by a union. He is below the threshold where Bartz&#8217;s certification regime applies and above the threshold where Shaw&#8217;s detection anxiety attaches. He is just a person posting, and the only people positioned to register that the work has thinned out are the people who know him personally.</p><p>Those people will not say anything. Not because they cannot see what I saw. The mutual friend almost certainly sees it too. He has read the piece, registered the shape, formed the judgment, and kept it to himself, because the social cost of voicing it is real and the social reward is zero. This is how the critical reasoning of an entire community becomes invisible. Every individual reader privately notices the hollowness. No reader says it out loud. The published record looks like consensus approval. The actual distribution of opinion is silent.</p><p>The remedies Bartz and Shaw propose are upstream, at the level of publishing infrastructure, professional certification, and detection technology. Those remedies might eventually defend the big-publisher novel from the AI-delegated competitor. They will not touch the small-platform writer who has decided that two months of prompting counts as research and his name on the post counts as authorship. That writer will never face Bartz&#8217;s union, never need Shaw&#8217;s certification, never trigger a detection sweep. The only correction he could receive would come from the people closest to him, and the people closest to him have already calculated that the correction is not worth the friendship.</p><p>The friend should not necessarily have spoken. But his silence is the actual mechanism by which delegated writing proliferates at the small-platform level, and no amount of institutional engineering will substitute for it. If we want the assisted category to survive, the work cannot only happen in policy debates and certification schemes. Some of it has to happen at the level where I started this essay, with one person noticing that another person&#8217;s published work does not contain them, and deciding what, if anything, is appropriate to say.</p><p>I do not have a clean answer to that question. I tried to raise it with a mutual friend and the conversation closed before it opened. The essay is what I have instead, and the writer who recognises himself in it is welcome to take what is useful and leave the rest. But the essay is the second-best solution. The first-best would have been a quiet conversation between two people who already trust each other, and that conversation did not happen, and it almost never does.</p><div><hr></div><p>I write under my own name. I disclose my use of models openly. I publish the frameworks. I draft in git. I sign work when the work bears my judgment, and I withhold the signature when it does not. The byline I put on a piece is a promise that the thinking behind the piece is mine, that I have weighed and selected and revised, that the residue on the page is what I meant to leave there.</p><p>That promise depends on what I did with the model, regardless of whether a model was in the loop. Assisted, not delegated, is the line. Detection software cannot draw it, because detection looks at the output and the difference is in the process. Only the practitioner can draw it, and the practitioner has to be willing to show their work.</p><p>The question that follows me from the piece I read last week is whether the rest of us (the ones doing the slower, harder, assisted work) will hold the line on what the signature means, or whether we will let the category collapse and lose the distinction altogether. People will go on posting model output under their names, and the social cost will eventually catch up with them, or it will not. That is a separate question.</p><p>I am writing this series because I think the line is worth holding, and because the only way to hold it is to make the practice visible enough that the difference can be seen. <em>Care as a Discipline</em> set out the frame in the abstract. Writing is the first domain. Coding is the second: the tool I use to defend my writing was built by coders to defend their code. Creativity in general is the third, and by the time we get there I hope the categories will have done some of the work for us.</p><p>For now: assisted, not delegated. The signature still means something. Some of us are still in the chair.</p><div><hr></div><h2>References</h2><p>Andrea Bartz, &#8220;So&#8230;how can you prove your work&#8217;s not AI?&#8221; Substack, 2025. </p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:192345802,&quot;url&quot;:&quot;https://andibartz.substack.com/p/sohow-can-you-prove-your-works-not&quot;,&quot;publication_id&quot;:2293458,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;Andrea Bartz: Get It Write&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!a8fN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff062bf93-783e-4977-b822-948afa0303d7_378x378.png&quot;,&quot;title&quot;:&quot;So...how can you prove your work's not AI-generated?&quot;,&quot;truncated_body_text&quot;:&quot;Last week, amid a frenzy of fascinating takes on and coverage of SHY GIRL&#8217;s cancellation, I published an op-ed in the New York Times about how generative AI threatens to erode trust between writers, readers, and publishers. Here&#8217;s a gift link, and here&#8217;s the upshot:&quot;,&quot;date&quot;:&quot;2026-03-30T13:04:20.663Z&quot;,&quot;like_count&quot;:155,&quot;comment_count&quot;:9,&quot;bylines&quot;:[{&quot;id&quot;:2797860,&quot;name&quot;:&quot;Andrea Bartz&quot;,&quot;handle&quot;:&quot;andibartz&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa81df419-45f0-4f5a-8f5a-26d5f856d231_4051x3077.jpeg&quot;,&quot;bio&quot;:&quot;Hi! I wrote The Last Ferry Out, Reese's Book Club pick We Were Never Here, The Spare Room, The Herd &amp; The Lost Night. I live with my girlfriend in NYC &amp; the Catskills. In my Substack, I demystify publishing &amp; get vulnerable about author life.&quot;,&quot;profile_set_up_at&quot;:&quot;2023-06-09T15:43:12.071Z&quot;,&quot;reader_installed_at&quot;:&quot;2024-01-30T20:56:51.409Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:2312490,&quot;user_id&quot;:2797860,&quot;publication_id&quot;:2293458,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:2293458,&quot;name&quot;:&quot;Andrea Bartz: Get It Write&quot;,&quot;subdomain&quot;:&quot;andibartz&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Welcome to your new favorite writing community! Discuss &amp; demystify publishing with candid interviews, fresh writing tips &amp; industry intel from a NYT bestselling thriller author. (Public posts = book news, Ask a Bookseller &amp; occasional satire). Join us!&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f062bf93-783e-4977-b822-948afa0303d7_378x378.png&quot;,&quot;author_id&quot;:2797860,&quot;primary_user_id&quot;:2797860,&quot;theme_var_background_pop&quot;:&quot;#E8B500&quot;,&quot;created_at&quot;:&quot;2024-01-26T18:12:53.193Z&quot;,&quot;email_from_name&quot;:&quot;Andrea Bartz&quot;,&quot;copyright&quot;:&quot;Andrea Bartz&quot;,&quot;founding_plan_name&quot;:&quot;Professional tier&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;enabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;magaziney&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}},{&quot;id&quot;:6027480,&quot;user_id&quot;:2797860,&quot;publication_id&quot;:5909157,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:5909157,&quot;name&quot;:&quot;Write the Book, Play the Game&quot;,&quot;subdomain&quot;:&quot;writethebookplaythegame&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;A podcast about the business of being an author from writers Andrea Bartz and Gretchen Schreiber&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4b7993f-bc32-4313-9536-4c744d432d18_341x341.png&quot;,&quot;author_id&quot;:2797860,&quot;primary_user_id&quot;:null,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-08-06T15:19:55.850Z&quot;,&quot;email_from_name&quot;:&quot;Andi &amp; Gretchen from Write the Book, Play the Game&quot;,&quot;copyright&quot;:&quot;Andrea Bartz and Gretchen Schreiber&quot;,&quot;founding_plan_name&quot;:null,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;newspaper&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:100,&quot;status&quot;:{&quot;bestsellerTier&quot;:100,&quot;subscriberTier&quot;:10,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;bestseller&quot;,&quot;tier&quot;:100},&quot;paidPublicationIds&quot;:[7567,1386033,2450,2226598,1940204,1171539,2748255,723165,2799788,236196],&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://andibartz.substack.com/p/sohow-can-you-prove-your-works-not?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!a8fN!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff062bf93-783e-4977-b822-948afa0303d7_378x378.png" loading="lazy"><span class="embedded-post-publication-name">Andrea Bartz: Get It Write</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">So...how can you prove your work's not AI-generated?</div></div><div class="embedded-post-body">Last week, amid a frenzy of fascinating takes on and coverage of SHY GIRL&#8217;s cancellation, I published an op-ed in the New York Times about how generative AI threatens to erode trust between writers, readers, and publishers. Here&#8217;s a gift link, and here&#8217;s the upshot&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">4 months ago &#183; 155 likes &#183; 9 comments &#183; Andrea Bartz</div></a></div><p>Jo Shaw, &#8220;Moments of Being #2,&#8221; Thought Couture on Substack, 2025. (See the section on AI witch-hunting.) </p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:177333103,&quot;url&quot;:&quot;https://thoughtcouture.substack.com/p/moments-of-being-2&quot;,&quot;publication_id&quot;:4367659,&quot;embedding_publication_id&quot;:null,&quot;publication_name&quot;:&quot;Thought Couture&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!E8lH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94ad3aef-b145-46f0-9dd1-d486f0566df8_800x800.png&quot;,&quot;title&quot;:&quot;Moments of Being #2&quot;,&quot;truncated_body_text&quot;:&quot;Hello and welcome back to Moments of Being, an every-so-often update from Thought Couture featuring brief ponderings on creativity, the life of the mind, cultural goings-on, and the realities of being an aspiring writer in the digital age. Plus, a few behind-the-scenes peeks into what I&#8217;ve been working on and what&#8217;s inspired me lately.&quot;,&quot;date&quot;:&quot;2026-04-09T16:14:15.681Z&quot;,&quot;like_count&quot;:18,&quot;comment_count&quot;:6,&quot;bylines&quot;:[{&quot;id&quot;:150044456,&quot;name&quot;:&quot;Jo Shaw&quot;,&quot;handle&quot;:&quot;thoughtcouture&quot;,&quot;previous_name&quot;:&quot;Kelsie Shaw&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3c1837a8-ba53-4dee-8ac3-68062c0a297f_800x800.png&quot;,&quot;bio&quot;:&quot;Rebuilding a creative life after depression; finding inspiration in great art | Essayist, content creator, Virginia Woolf devotee, and Renaissance woman in the making.&quot;,&quot;profile_set_up_at&quot;:&quot;2023-06-03T22:12:48.106Z&quot;,&quot;reader_installed_at&quot;:&quot;2023-08-26T04:32:17.934Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:4455459,&quot;user_id&quot;:150044456,&quot;publication_id&quot;:4367659,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:true,&quot;publication&quot;:{&quot;id&quot;:4367659,&quot;name&quot;:&quot;Thought Couture&quot;,&quot;subdomain&quot;:&quot;thoughtcouture&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Helping aspiring writers who've lost momentum reconnect to their voice and build the thoughtful, creative life they long for.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/94ad3aef-b145-46f0-9dd1-d486f0566df8_800x800.png&quot;,&quot;author_id&quot;:150044456,&quot;primary_user_id&quot;:150044456,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-03-13T02:16:56.775Z&quot;,&quot;email_from_name&quot;:&quot;Thought Couture by Jo Shaw&quot;,&quot;copyright&quot;:&quot;Jo Shaw&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;enabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;magaziney&quot;,&quot;is_personal_mode&quot;:false,&quot;logo_url_wide&quot;:null}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:{&quot;bestsellerTier&quot;:null,&quot;subscriberTier&quot;:1,&quot;leaderboard&quot;:null,&quot;vip&quot;:false,&quot;badge&quot;:{&quot;type&quot;:&quot;subscriber&quot;,&quot;tier&quot;:1,&quot;accent_colors&quot;:null},&quot;paidPublicationIds&quot;:[2261588,1145905,2354546],&quot;subscriber&quot;:null}}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://thoughtcouture.substack.com/p/moments-of-being-2?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!E8lH!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F94ad3aef-b145-46f0-9dd1-d486f0566df8_800x800.png" loading="lazy"><span class="embedded-post-publication-name">Thought Couture</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">Moments of Being #2</div></div><div class="embedded-post-body">Hello and welcome back to Moments of Being, an every-so-often update from Thought Couture featuring brief ponderings on creativity, the life of the mind, cultural goings-on, and the realities of being an aspiring writer in the digital age. Plus, a few behind-the-scenes peeks into what I&#8217;ve been working on and what&#8217;s inspired me lately&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">4 months ago &#183; 18 likes &#183; 6 comments &#183; Jo Shaw</div></a></div><p>Marco Brondani, &#8220;Care as a Discipline: How painting and celestial navigation survived automation.&#8221; marcobrondani.com, May 2026. <a href="https://www.marcobrondani.com/p/care-as-a-discipline">https://www.marcobrondani.com/p/care-as-a-discipline</a></p>]]></content:encoded></item><item><title><![CDATA[Care as a Discipline]]></title><description><![CDATA[How painting and celestial navigation survived automation.]]></description><link>https://www.marcobrondani.com/p/care-as-a-discipline</link><guid isPermaLink="false">https://www.marcobrondani.com/p/care-as-a-discipline</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Wed, 20 May 2026 06:39:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!pUK8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pUK8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pUK8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 424w, https://substackcdn.com/image/fetch/$s_!pUK8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 848w, https://substackcdn.com/image/fetch/$s_!pUK8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 1272w, https://substackcdn.com/image/fetch/$s_!pUK8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pUK8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png" width="1456" height="799" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:799,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3331500,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/198519319?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pUK8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 424w, https://substackcdn.com/image/fetch/$s_!pUK8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 848w, https://substackcdn.com/image/fetch/$s_!pUK8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 1272w, https://substackcdn.com/image/fetch/$s_!pUK8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe945dbee-71a3-4c55-9248-c22cee82c04e_1693x929.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>In brief</strong></p><ul><li><p>When an automating tool takes over the job a craft was paid for, the craft lasts only if its judgment can move somewhere the tool cannot follow.</p></li><li><p>There are two directions. Painting, once the camera took likeness, climbed into interpretation, the higher ground of deciding which appearance is worth keeping. Celestial navigation, once GPS took the position fix, sank to lower ground, the fallback you can still trust when the signal is jammed or spoofed.</p></li><li><p>Ground existing is not the same as anyone standing on it. None of the survival is automatic; it waits on someone doing the work of the move.</p></li><li><p>Timing sets the price. Retention, moving the judgment early while the old tool still works, is cheap and nearly impossible to defend in a budget meeting. Reinstatement, rebuilding after the loss is on the front page, is slow, costly, and never as deep as what was let go.</p></li><li><p>The verdict of 1839, <em>painting is dead</em>, is being read out again now over many crafts at once. Care is the early choice to move a craft&#8217;s judgment to safer ground before the loss forces it.</p></li></ul><div><hr></div><p>When the daguerreotype was unveiled in Paris in 1839, the verdict on portrait painting arrived quickly, and it was not unreasonable. A portrait painter sold likeness. Likeness was the product, the thing a client paid for. And here was a machine that produced likeness in minutes, at a fidelity no hand could equal, at a fraction of the cost, available to anyone able to sit still in front of it. The painter who made a living from faces was now competing with physics, and physics does not tire, does not flatter, and does not raise its rates.</p><p>The painter Paul Delaroche is supposed to have declared, on seeing the new images, that from that day painting was dead. The line is almost certainly apocryphal. It survived for a century anyway, because it named something a great many people felt at once: a craft had met its replacement, and the replacement was better at the exact thing the craft was paid for.</p><p>The verdict was wrong. Portrait painting did not die in 1839, or in the decade after, or in the century after that. The same verdict is being delivered again now, against a long list of crafts at once, by serious people reasoning soundly from real evidence. Why was it wrong the first time?</p><div><hr></div><p>The camera took a job, not a craft. For most of its history, portraiture had carried a documentary burden. Before photography, if you wanted to know what your grandfather had looked like, or your sovereign, or yourself at thirty, a painter was the only instrument available. Part of what the portrait painter was being paid for was accuracy: a reliable record of a particular face. The painter was, among other things, a verification device. The camera did that job better, and within a generation the documentary burden simply lifted.</p><p>Relieved of the burden, painting moved. Released from the obligation to be accurate, painters became free to be something else: to paint the way light behaved rather than the way a face was shaped, to paint perception itself, the impression rather than the object, and then, a few decades on, to leave resemblance behind altogether. Impressionism, and everything that followed from it, was an expansion into ground the camera could not reach. A historian of art would rightly complicate that sentence: photography was one pressure on nineteenth-century painting among several, not a lone cause. But the direction holds. The painter&#8217;s judgment moved to higher ground, away from the record of appearances and toward interpretation, because a machine that can reproduce an appearance still cannot decide which appearance is worth holding. The care in the work moved with the judgment, upward, out of the machine&#8217;s reach.</p><p>Nobody organized this. There was no committee, no syllabus, no institution that convened to move the painter&#8217;s judgment somewhere safer. Painters drifted, individually and across decades, toward the work the camera had left them. What each of them did was deliberate, in the sense that a person chose it, and unplanned, in the sense that no one was steering. It happened in good time, while the old craft was still alive enough to feed and house the people making the move.</p><div><hr></div><p>Now leave the studio, because one example is not a law. A single craft surviving a single tool could be luck, or charm, or the particular forgivingness of the art market. To find out whether there is a principle here, you need a second craft, and it helps if the second craft is as unlike the first as possible.</p><p>Consider <strong>celestial navigation</strong>.</p><p>A painter makes an object and offers an interpretation. A navigator, working with a sextant and a chronometer and a set of tables, produces a single number, or rather a pair of them: a latitude and a longitude, the answer to one question. Where am I. There is no room in that answer for interpretation, no style, nothing personal; the navigator is not expressing anything, only locating a ship on the surface of the earth, and the ship&#8217;s company would very much prefer the location to be correct.</p><p>And yet celestial navigation was a craft in the fullest sense, demanding years to learn and a lifetime to keep sharp. It rested on instruments that are among the highest achievements of mechanical art. The marine chronometer in particular: John Harrison spent decades of the eighteenth century building a clock that could keep accurate time at sea, through temperature swings and the constant motion of a ship, because an error of a few seconds meant an error of miles. His H4, finished in 1761, is one of the objects you point to when you want to show what human craft is capable of. For two hundred years after it, finding your position at sea meant a sextant, a chronometer, the tables, the arithmetic, and a person who had been taught to bring them together under a clouded sky.</p><p>Then GPS arrived, and did to the navigator exactly what the daguerreotype had done to the painter. It took the job, producing the position faster, more accurately, and with no skill required at all. But the navigator had nowhere upward to go. Painting could climb from likeness into interpretation; there is no interpretation of where am I. The position fix was the whole of the craft, and the position fix was exactly what the satellite delivered. A craft with nowhere to move simply ends, and celestial navigation did. The United States Navy stopped training its officers in it in 2006; the academies let it lapse. For roughly two decades, celestial navigation looked like the thing photography had only threatened to make of painting: a craft simply switched off.</p><div><hr></div><p>Before celestial navigation could come back, something had to go wrong with GPS. The signal feels like bedrock, a fixed feature of the modern world. It behaves more like a radio broadcast: a set of faint transmissions from satellites twenty thousand kilometers away, and a faint signal is easy to drown out and easy to imitate. Drowning it out is called jamming. Imitating it, feeding a receiver a confident and false position, is called spoofing. Both had been understood in theory for as long as GPS existed; what changed, recently, is that they stopped being theoretical.</p><p>Over the past few years, this kind of interference has moved from the margin of aviation to its center. The International Air Transport Association now calls its frequency crisis-level, with reported incidents in 2025 running close to triple their level two years earlier. The Federal Aviation Administration recorded spoofing reports more than doubling in the first half of 2025 alone, and noted that the problem no longer stays inside conflict zones: it now reaches aircraft hundreds of miles from any war.</p><p>The consequences are not abstract. An Azerbaijan Airlines flight went down in December 2024 after encountering electronic interference and losing reliable navigation near Grozny, killing dozens of those aboard. The following August, an aircraft carrying the president of the European Commission lost its GPS signal on approach to an airport in Bulgaria, and the crew landed on paper charts. By January 2026, thirteen European nations bordering the Baltic and the North Sea had issued a joint warning about the same disruption spreading across their shipping lanes.</p><p>The tool that had retired celestial navigation could now be switched off, or quietly corrupted, by a hostile party at a time of its choosing. What the modern ship and the modern aircraft had been standing on turned out to be a surface, not bedrock, and there were people working to crack it.</p><div><hr></div><p>And so celestial navigation came back. It came back in three places at once, none of them taking its cue from the others.</p><p>The United States Navy, having retired the skill, began teaching it again, and said plainly that this was not nostalgia. Officers needed to find their ship without satellites, because satellites could be taken away from them. A sextant has a quality no modern system can match: it receives nothing, transmits nothing, and depends on nothing but the navigator, the instrument, and the sky. It cannot be jammed, because there is no signal to jam, and it cannot be spoofed, because there is no channel to feed a lie into. The Coast Guard kept the skill alive aboard its training ship, where cadets still take sextant sights under sail.</p><p>In civil aviation it was not one institution but a whole industry that went back to rebuild a competence it had let weaken. Airlines and regulators began retraining pilots to notice when the navigation picture had gone wrong, and to fall back, deliberately, on older methods: inertial systems that track position with no outside signal, ground-based radio aids, the plain discipline of checking one source against another. The FAA wrote, and then revised, a guide to help crews do exactly that. The crew that landed the Commission president&#8217;s aircraft on paper charts was not improvising but executing a fallback someone had decided, in advance, to keep ready.</p><p>The quietest comeback had no institution behind it at all. Among ocean sailors, celestial navigation has become something people learn on purpose, for its own sake, with no regulator requiring it of them. It belongs now to the same cultural current that brought back the vinyl record and sustains the mechanical watch: a deliberate attachment to a way of working that the efficient option had made optional. People want to own a sextant, and, more than that, to know how to use one.</p><p>In every one of these, the craft&#8217;s judgment had moved, exactly as the painter&#8217;s once did, and it had not moved in the same direction. The painter&#8217;s judgment moved upward, into interpretation. The navigator&#8217;s moved downward, underneath the tool, into the role of the thing you stand on when the tool fails. Celestial navigation survived by becoming the floor: the position you can always recover, the answer that cannot be taken from you, the thing still true when everything with a power supply has been switched off.</p><div><hr></div><p>Put the two crafts side by side. The same rule governs both of them. When an automating tool arrives and takes over the function a craft was paid for, the craft survives only when its judgment can be moved somewhere the tool does not reach. Painting found that ground above the tool, in interpretation, in the decision about which appearance is worth holding, a decision a machine that copies appearances can never make. Navigation found it beneath the tool, in resilience, in being the source that holds when the convenient source is attacked. Above or beneath, the principle holds: the tool is never the whole story. What decides the outcome is whether the craft has higher or lower ground to move to, and whether anyone does the work of moving it there.</p><p>Painting&#8217;s move happened in good time. It happened gradually, across decades, while the old craft of likeness was still alive enough to support the painters drifting toward the new work. There was no gap. No generation of painters found itself with the documentary job gone and nothing yet built to replace it. Painters were moving into the new work before the old work was fully gone, and that overlap was the safety margin.</p><p>Navigation&#8217;s move did not happen that way. The skill was allowed to lapse first. The Navy stopped teaching it, the academies dropped it, and for two decades the craft thinned toward a handful of enthusiasts, because the tool was working and the craft looked like cost without benefit. The move had to happen afterward, in a hurry, under pressure, after a passenger aircraft had already come down. The competence was rebuilt, which is the good news. But it was rebuilt at the worst possible time, at the highest possible price, in answer to a danger already loose in the world.</p><p>Painting and navigation are the two ways a craft&#8217;s judgment ever reaches safer ground, and the two do not cost the same. Painting shows the cheap one. Call it retention: you keep the judgment alive and moving while the convenient tool still works perfectly, while there is no visible reason to bother, while the effort looks indistinguishable from waste. It is cheap, and nearly impossible to defend in any meeting where someone is holding a budget, because its whole value is insurance against a loss that has not happened yet and may be years away.</p><p>Navigation shows the expensive one. Call it reinstatement: you let the craft lapse, then rebuild it after the tool has failed and the loss is on the front page. It is slow and costly, always done in an atmosphere of alarm, and the version you manage to rebuild is never quite as deep as the one you let go.</p><p>Care here is not affection for old instruments, or a taste for doing things the hard way; it is the early decision, the choice to move a craft&#8217;s judgment while moving it is still cheap, before there is proof the move is needed. The discipline is making that choice. Everything after it is recovery.</p><div><hr></div><p>The verdict from 1839 is being delivered again now, against more crafts at once than at any time I can readily think of.</p><p>A tool has arrived that generates. It writes, it drafts, it designs, it produces analysis and images and code, quickly and cheaply and at a level of fluency that is genuinely new. And around it, the same serious people are doing the same sound reasoning. They look at a craft, identify the function it is paid for, observe that the machine now performs that function faster and cheaper, and conclude that the craft is finished.</p><p>The daguerreotype says they are probably wrong. The question is not whether the machine can do the job. The machine can do the job; that much is settled, and arguing about it is mostly a way of avoiding the harder questions. What was this craft actually for, underneath the function the tool has taken? And where can its judgment stand: is there higher ground, the equivalent of interpretation, work the machine cannot reach because it calls for deciding what is worth doing rather than doing it? Or lower ground, the equivalent of celestial navigation, the role of the thing that holds when the fluent, convenient tool produces something confident and wrong?</p><p>For most crafts I can think of, both kinds of ground exist. I want to be careful with that claim, because I cannot prove it, and there may well be crafts whose whole purpose a machine can occupy with nothing left above it or beneath it. But most crafts have more ground than their practitioners fear. What is never guaranteed is the move. Ground existing is not the same as anyone standing on it.</p><p>What happens next is up to us. Obsolescence is not a verdict handed down by a tool; it is what happens to a craft when nobody does the work of moving its judgment in time. The tool does not abolish the craft, it makes it optional. What happens after that depends on whether the people who hold the craft treat optional as a synonym for finished, or as the description of a choice that has just become theirs to make.</p><p>The painter kept working at the easel after the easel stopped being the only way to record a face. The navigator still takes a sight with a sextant after the sextant stopped being necessary to find the ship. Both are doing, on purpose, the thing the machine made optional, and that is not nostalgia but the discipline of care, practiced early, while it is still cheap. It was always available. It still is.</p>]]></content:encoded></item><item><title><![CDATA[Electrons, Molecules, and the Industrial Security Question Europe Has to Answer in Public]]></title><description><![CDATA[In brief]]></description><link>https://www.marcobrondani.com/p/electrons-molecules-and-the-industrial</link><guid isPermaLink="false">https://www.marcobrondani.com/p/electrons-molecules-and-the-industrial</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Mon, 18 May 2026 09:02:12 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UGii!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UGii!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UGii!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!UGii!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!UGii!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!UGii!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UGii!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1902219,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/197197954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UGii!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!UGii!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!UGii!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!UGii!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b5bc446-c772-4af5-9b06-d9178c8f075b_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>In brief</strong></p><ul><li><p>On 1 May 2026 the European Commission quietly stopped EU funding for solar, wind, and storage projects using inverters from China, Russia, Iran, or North Korea. It is the most concrete European industrial-security decision of the year, and it was never formally announced.</p></li><li><p>The popular frame reads it through electrostate versus petrostate: China dominating clean-energy supply chains, the US choosing fossil fuels, Europe caught between. The frame is useful for political communication and is being asked to carry more than it can; as Tooze notes, the US is not a petrostate by any standard measure of rents, and being an electrostate is a matter of state capacity, not which inverter you buy.</p></li><li><p>The inverter is the target because it is a control surface: the connected, cloud-linked, remotely reconfigurable &#8220;brain&#8221; of an installation, able to change its electrical behaviour on the grid and running firmware from a single foreign manufacturer.</p></li><li><p>The risk is architectural, not national. Connectivity, cloud dependence, and remote reconfiguration apply to European-made inverters too; country of origin is a proxy for the trust model rather than the trust model itself. The origin ban is fast and politically saleable, and it leaves the architectural risk in place. Europe needs both responses.</p></li><li><p>The same pattern is coming for smart meters, EV chargers, heat pumps, and battery controllers. For anyone running European critical infrastructure, supplier diversity is becoming a regulatory expectation, the security properties of connected equipment are becoming board-level due diligence, and the line between IT and OT security is dissolving as the NIS 2 perimeter moves.</p></li></ul><div><hr></div><p>On 1 May 2026, the European Commission communicated to financial institutions a decision that had been telegraphed for months but never publicly announced. EU funding instruments, including the European Investment Bank and the European Investment Fund, would no longer back solar, wind, or energy storage projects whose inverters came from suppliers in China, Russia, Iran, or North Korea. The decision applies to all such projects within the EU, and to projects in neighbouring regions such as the Western Balkans and North Africa that connect to the European grid. Energy storage power conversion systems are explicitly included. A grandfathering clause allows the most mature pipeline projects to be approved by 1 November 2026; everything earlier in development must choose a different supplier.</p><p>The Commission did not issue a press release; the decision became public when industry trade media saw the guidance and started reporting on it. A spokesperson confirmed the substance several days later, citing risk assessments that had identified the possibility of remote shutdown of member state networks leading to countrywide blackouts as the worst-case scenario the policy was meant to address. By that point the European Solar Manufacturing Council had welcomed the decision, the China Chamber of Commerce to the EU had rejected the premise, and Huawei had publicly denied that the company&#8217;s inverters posed any cybersecurity risk while accusing the Commission of origin-based discrimination.</p><p>This is the most concrete European industrial security decision of 2026, and it sits at the intersection of three larger conversations that are usually held separately. The first is the conversation about energy transition, where Europe has staked its economic future on electrification. The second is the conversation about supply chain dependency, where Europe has acknowledged that around 80 per cent of new photovoltaic systems in the bloc rely on Chinese inverters from a duopoly of suppliers. The third is the conversation about geopolitical positioning between the United States and China, which has been increasingly framed through the contrast between an American petrostate and a Chinese electrostate.</p><p>My aim in this article is specific: to take the electrostate-versus-petrostate framing seriously enough to test it against what is actually happening in European industrial security policy, identify where the framing illuminates the decision space and where it obscures it, and ask what the operational consequences of the framing are for organisations running critical infrastructure in Europe. The framing is useful, while also being asked to carry more weight than it can bear, and the inverter decision is a good place to see why.</p><h2>The framing and where it came from</h2><p>The contrast between petrostates and electrostates entered serious policy conversation through analysts at RMI and Carnegie Endowment, and it has since been picked up across the trade and energy press. The argument is straightforward. A petrostate is a polity whose economic, financial, and geopolitical power derives from the extraction, export, and political weaponisation of hydrocarbons. An electrostate, by contrast, is a polity that has electrified its economy, dominates the supply chains for the technologies that enable electrification, and accrues power through control of clean-energy infrastructure rather than fossil-fuel reserves.</p><p>The clean version of the story is that the twenty-first century will be defined by who manufactures the inverters, the batteries, the rare-earth magnets, the modules, and the grid hardware, rather than by who pumps the most oil. By this measure China is far ahead. The country invested $800 billion in energy transition in 2025, accounting for around 35 per cent of global energy transition spending, accounted for roughly two-thirds of global solar installations in the first half of 2025, and now commands the rare-earth supply chain, the battery supply chain, and the inverter market.</p><p>By the same measure the United States is, under the current administration, deliberately moving in the opposite direction. The strategic posture is petrostate by design. Expanded oil and gas leasing, rolled-back vehicle fuel-efficiency standards, executive orders prioritising fossil-fuel output, and the use of oil supply as a geopolitical lever (most recently with the seizure of Venezuelan oil assets in January 2026) form a chosen strategy rather than accidental positioning.</p><p>This is the version of the framing that has appeared in the FT, in Time&#8217;s Top 10 Global Risks for 2026, in Energy Intelligence, in Robeco&#8217;s research, and across the policy think tank world. Europe sits uncomfortably between the two poles: aspiring to be an electrostate, dependent on petrostates for its current fossil-fuel imports, and dependent on the leading electrostate for the technologies of electrification.</p><p>That is a clean story, and also, as Adam Tooze argued in an April 2026 Chartbook essay, one that needs to be handled with significant care.</p><h2>Where the framing breaks down, and why that matters for security policy</h2><p>Tooze&#8217;s critique, which I think is the most useful intervention in this debate, points out that the petrostate label has historically applied to economies that derive a large share of rents, GDP, export earnings, or government revenue from oil and gas. By that standard the United States does not qualify. The US is a major oil and gas producer, but oil and gas account for a small share of US GDP, employment, and government revenue. The deeper observation is that being an electrostate is a function of state capacity, economic rationality, and the ability to actually execute on the integration of distributed electrified infrastructure into a functioning grid, rather than a function of factor endowments.</p><p>This matters for European industrial security policy in a way that is not obvious at first glance.</p><p>If you accept the clean version of the framing, Europe&#8217;s task is straightforward. Pick a side, accelerate electrification, build up the domestic clean-tech industry, and reduce dependence on Chinese components. The inverter decision fits cleanly into this narrative. Europe is asserting electrostate ambition by removing Chinese inverters from publicly funded projects, supporting a domestic inverter manufacturing base that already has over 100 GW of annual capacity and 45 GW of planned expansion by 2027, and treating the security risk as the justification for an industrial policy that would otherwise be politically harder to defend.</p><p>If you take Tooze&#8217;s critique seriously, the picture gets more complicated. Becoming an electrostate is primarily a question of whether your grid can absorb distributed generation at scale, whether your interconnection processes work, whether your electrification rates are actually climbing, whether your industrial heat is decarbonising, whether your data centres can be powered by the electrons your renewables are generating, rather than a question of which inverter you buy. By these measures Europe has been stagnating. Industrial electricity prices in Germany are running between 12 and 18 euro cents per kilowatt hour and only being cut to five cents for energy-intensive industries through a temporary subsidy. Industrial competitiveness against Chinese electrostate-driven manufacturing is, as the Draghi report stated bluntly, in slow agony.</p><p>Why does this matter for security policy? Because the inverter decision, viewed through the clean framing, looks like an industrial security win, while viewed through Tooze&#8217;s framing it looks more like a security policy that buys time at the cost of accelerating electrification. The Commission has explicitly framed the decision as economic security rather than industrial policy. Companies from Japan and South Korea remain eligible. The official line is that the choice is about trust and resilience rather than Buy European. The industry response from ESMC has been to welcome the decision while pushing for a stronger Made in Europe stance that would amount to industrial policy in the harder sense.</p><p>Both readings are partially true. The decision is a security measure, and also, downstream, a constraint on how quickly Europe can deploy the renewable generation it needs to electrify. The two effects do not cancel out; they co-exist, and the resolution depends on factors that are not yet clear.</p><h2>What the inverter actually does and why it is a control surface</h2><p>To understand why the inverter is the specific component the Commission chose to act on, rather than the panel itself or the battery cell, it helps to be specific about what an inverter does and what its security properties are.</p><p>An inverter converts the direct current generated by a solar panel into the alternating current used by the grid. In a modern grid-connected installation it does considerably more than that. It manages reactive power, controls power factor, responds to grid frequency, executes anti-islanding behaviour during grid disturbances, and increasingly participates in distributed energy resource management. It is, in operational terms, the active electrical interface between the panel and the grid. The European Solar Manufacturing Council has called it the brain of the installation, which is an accurate description of the role rather than marketing language.</p><p>For the inverter to do all this, it needs network connectivity. Modern inverters communicate with manufacturer cloud platforms for remote monitoring, with grid operator systems for dispatch and curtailment, and with site-level energy management systems for optimisation. Some models support firmware updates pushed from the manufacturer cloud. Almost all of them log operational data continuously to the manufacturer&#8217;s infrastructure, partly for the customer&#8217;s benefit and partly because the data is genuinely useful for fleet-level performance optimisation.</p><p>This is the property that makes inverters a cybersecurity risk surface. A connected device that can be remotely reconfigured, that has the ability to modify its electrical behaviour on the grid, and whose firmware comes from a single foreign manufacturer with regulatory obligations to share product information with state authorities is, by the standard logic of critical infrastructure protection, a control surface. The same logic that produced the global pushback against Huawei 5G equipment applies to Huawei inverters, with a sharpened technical specificity. Last year US engineers discovered undocumented communication components in some Chinese-made inverters that, according to Reuters&#8217; reporting at the time, could allow remote circumvention of firewalls with potentially catastrophic consequences.</p><p>The EU Institute for Security Studies report from January 2026 made the technical case in some detail, and the risk it describes is anything but theoretical. Rooftop solar accounts for 15 to 16 per cent of total electricity generation capacity in the Netherlands. NIS 2 cybersecurity protocols, which apply to utilities, do not currently apply to smaller generators including rooftop solar. The result is that a significant share of electricity generation in some member states sits behind devices that are connected, foreign-controlled, and outside the cybersecurity regulatory perimeter.</p><p>The Commission&#8217;s risk assessment, according to spokesperson Siobhan McGarry, identified scenarios including manipulation of electricity production parameters, disruption of electricity generation, unauthorised access to operational data, and remote shutdown of member state networks leading to countrywide blackouts. The framing was deliberately at the upper end of the severity scale. Whether such an attack is likely is a different question from whether it is possible.</p><p>Loom&#8217;s advisors, including Michael Collins, the former UK deputy head of national security strategy, made the point precisely in their analysis. China&#8217;s cyber actors are highly capable and have long sought persistent access to Western critical infrastructure, with the capability itself being well established. A large-scale disruptive attack is unlikely, but smaller-scale demonstrations of capability are within China&#8217;s lower threshold for action, and serve a strategic communications purpose that does not require a full attack to be effective. Holding infrastructure at risk is itself a strategic asset.</p><h2>Why the framing pushes European decisions in directions that may not match the underlying risk</h2><p>This brings me to the part of the analysis I find most uncomfortable, and I want to spend some time on it because it has practical consequences.</p><p>The electrostate-versus-petrostate framing, when imported uncritically into European industrial security policy, pushes decisions in a particular direction. It encourages a binary view in which Europe must align with one side or the other, in which Chinese components are a strategic vulnerability per se, and in which the response is some combination of reshoring, friend-shoring, and supplier exclusion. The inverter decision fits this template. The framing makes the decision easier to justify politically because it can be framed as Europe defending its electrostate aspirations from electrostate-aligned dependencies.</p><p>What the framing obscures is that the underlying security risk lies in the connected, cloud-dependent, foreign-controlled nature of the device rather than in the country of origin. As the EU Institute for Security Studies report observed, some of the risks associated with Chinese inverters (internet connectivity, reliance on cloud servers) apply equally to European-made inverters. Country of origin is a proxy for the trust model, not the trust model itself.</p><p>If the underlying issue is the trust model, the right response is a cybersecurity regulation that applies to all inverters regardless of origin, with technical requirements around firmware integrity, command authentication, local override capability, and isolation of grid-control functions from cloud-management functions. That is a harder regulation to write and a slower one to enforce. The country-of-origin response is faster, more politically saleable, and addresses the immediate political pressure, while leaving the underlying technical risk in place if a European-made inverter has similar architectural properties.</p><p>None of this is to argue that the Commission&#8217;s decision is wrong. The decision is defensible on multiple grounds. Supplier concentration is itself a risk, regardless of country. The Chinese state&#8217;s legal authority over Chinese suppliers under article 7 of the 2017 National Intelligence Law creates a specific risk that does not apply to suppliers based in jurisdictions without comparable provisions. The political signal that critical electrical infrastructure will not be allowed to depend on adversarial supply chains is itself an important signal.</p><p>I am arguing that the electrostate-versus-petrostate framing makes it easier to stop the analysis at the country-of-origin level, when the deeper structural risk is the architectural pattern of connected, remotely managed, cloud-dependent grid components. Europe will need both the country-of-origin response and the architectural response. The framing tends to deliver the first and obscure the need for the second.</p><p>This matters because the same architectural pattern applies to a much wider set of components than inverters: smart meters, EV chargers, building energy management systems, heat pumps, battery storage controllers, industrial control systems. Each of these is a connected, foreign-controlled, cloud-dependent device with the ability to modify physical behaviour, deployed at scale across Europe, and each will eventually face a version of the inverter question. The country-of-origin response, applied serially to each category, is going to be politically exhausting and operationally incomplete.</p><h2>What this means for organisations operating European critical infrastructure</h2><p>For executives running utilities, telecoms, transportation, water, healthcare, or any of the other sectors that count as critical infrastructure under NIS 2, the practical consequence of the inverter decision is that the regulatory and political environment for connected foreign-controlled equipment has changed in a way that will keep changing.</p><p>The first practical implication is that supplier diversity by country of origin is becoming a regulatory expectation rather than just a procurement preference. The Commission&#8217;s decision is the first cleanly enforced version of this principle in the renewable energy space, and there will be more. Organisations that have rationalised single-vendor or single-country-of-origin supplier relationships on cost or performance grounds should expect to be asked why, and the cost of single-supplier dependence is going up.</p><p>The second practical implication is that the cybersecurity properties of connected industrial equipment are becoming due-diligence questions for board-level discussions about supplier choice, rather than questions reserved for the security team. The trust model questions (where does the firmware come from, who has remote access, what is the local override capability, how is the cloud connection authenticated) will need to be answered by procurement as much as by the OT security team.</p><p>The third practical implication is the most important and the least well-publicised. The standard separation between IT security and OT security is breaking down in the European context not because of any specific threat actor but because the regulatory perimeter is moving. NIS 2 already covers a wider scope than its predecessor, and the proposed Cybersecurity Act revisions will extend the perimeter further. The inverter decision is a preview of how those frameworks will be enforced, and the enforcement will require organisations to have integrated visibility across IT, OT, and the increasingly connected industrial layer in between.</p><p>I have written elsewhere about operational substrate as the layer beneath governance and policy. The inverter decision is a substrate decision, in the sense that it is about what physically sits inside the European grid. The choices made over the next two years about which substrate components are acceptable will define what the European energy security architecture actually looks like for the next two decades.</p><p>The electrostate-versus-petrostate framing is useful for political communication, less useful as a guide to operational decisions, because it tends to encourage country-of-origin thinking when the underlying risks are architectural. For organisations operating in this environment, the more productive question is which architectural patterns Europe is willing to defend, and how the organisations that depend on European critical infrastructure are going to make the necessary changes to their own systems while the regulatory environment moves underneath them.</p><p>This is going to be uncomfortable for several years. The inverter decision is the first clearly enforced sign of how uncomfortable it is going to be, and the wider category of decisions it foreshadows is the work that European industrial security will be doing for the rest of the decade.</p><div><hr></div><h2>Sources and references</h2><ol><li><p>European Commission. Guidance on restrictions for EU funding of renewable energy projects using inverters from high-risk suppliers. Communicated to financial institutions from 1 May 2026.</p></li><li><p>Tristan Rayner. &#8220;EU funding ban on high-risk inverters, including Chinese suppliers, extends to BESS PCS.&#8221; Energy Storage News, 4 May 2026. https://www.ess-news.com/2026/05/04/eu-funding-ban-on-high-risk-inverters-including-chinese-suppliers-extends-to-bess-pcs/</p></li><li><p>Will Norman. &#8220;EU bans funding for energy projects using Chinese inverters &#8212; will it move the needle on cybersecurity?&#8221; PV Tech, 28 April 2026. https://www.pv-tech.org/eu-bans-funding-for-chinese-inverters-solar-cybersecurity/</p></li><li><p>David Meyer. &#8220;Europe Cuts Off Funding for Chinese Solar Inverters.&#8221; Information Security Media Group, 4 May 2026. https://www.cuinfosecurity.com/europe-cuts-off-funding-for-chinese-solar-inverters-a-31584</p></li><li><p>Sergio Matalucci. &#8220;EU moves to ban high-risk inverters from China over cybersecurity threats.&#8221; Euronews, 4 May 2026. https://www.euronews.com/my-europe/2026/05/04/eu-moves-to-ban-high-risk-inverters-from-china-over-cybersecurity-threats</p></li><li><p>Emiliano Bellini. &#8220;EU moves to restrict funding for projects using inverters from high-risk suppliers.&#8221; PV Magazine International, 23 April 2026. https://www.pv-magazine.com/2026/04/23/eu-moves-to-restrict-funding-for-projects-using-inverters-from-high-risk-suppliers/</p></li><li><p>European Solar Manufacturing Council. &#8220;ESMC Welcomes EU Commission Decision: Inverters from High-Risk Countries Excluded from EU Funding.&#8221; 24 April 2026. https://esmc.solar/esmc-welcomes-eu-commission-decision-inverters-from-high-risk-countries-excluded-from-eu-funding/</p></li><li><p>European Solar Manufacturing Council. &#8220;New EU Economic Security Doctrine flags dependence on solar inverters from China as high-risk.&#8221; 16 December 2025. https://esmc.solar/new-eu-economic-security-doctrine-flags-dependence-on-solar-inverters-from-china-as-high-risk/</p></li><li><p>European Union Institute for Security Studies. &#8220;The Dragon in the Grid: Limiting China&#8217;s Influence in Europe&#8217;s Energy System.&#8221; 16 January 2026. https://www.iss.europa.eu/publications/briefs/dragon-grid-limiting-chinas-influence-europes-energy-system</p></li><li><p>Adam Tooze. &#8220;Chartbook 439: Electrostates v. petrostates. Clarifying a tricky distinction.&#8221; Substack, April 2026. https://adamtooze.substack.com/p/chartbook-439-electrostates-v-petrostates</p></li><li><p>Robeco. &#8220;China: In pole position to be the globe&#8217;s first electrostate.&#8221; Insight, 27 March 2026. https://www.robeco.com/en-int/insights/2026/03/china-in-pole-position-to-be-the-globe-s-first-electrostate</p></li><li><p>Energy Intelligence. &#8220;Strategy Battle: US as Petrostate, China as Electrostate.&#8221; 23 January 2026. https://www.energyintel.com/</p></li><li><p>Noah J. Gordon and Daevan Mangalmurti. &#8220;How to Be an Electrostate.&#8221; Carnegie Endowment Emissary blog, 16 September 2025. https://carnegieendowment.org/emissary/2025/09/electrostate-what-is-it-china-solar-manufacturing</p></li><li><p>The National Interest. &#8220;The EU in a Petrostates and Electrostates World.&#8221; 19 December 2025. https://nationalinterest.org/blog/energy-world/the-eu-in-a-petrostates-and-electrostates-world</p></li><li><p>Eurasia Group. Top Risks of 2026. https://www.eurasiagroup.net/issues/top-risks-2026</p></li><li><p>Ian Bremmer et al. &#8220;The Top 10 Global Risks for 2026.&#8221; Time, 11 March 2026. https://time.com/7343169/top-10-global-risks-2026/</p></li><li><p>World Economic Forum. Global Risks Report 2026. https://www.weforum.org/publications/global-risks-report-2026/</p></li><li><p>Mario Draghi. The Future of European Competitiveness. European Commission, 2024.</p></li><li><p>Christian K. Caruzo. &#8220;Green-Frenzied EU to ban Cybersecurity Risk Chinese Solar Equipment.&#8221; Breitbart, 6 May 2026.</p></li><li><p>Marco Brondani. &#8220;The Compound Vulnerability&#8221; series and &#8220;The Valley of False Signals&#8221; series. marcobrondani.com.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[The First Real Agentic Supply Chain Incident]]></title><description><![CDATA[What Mitiga&#8217;s MCP Token Hijack Tells Us About the Operational Substrate of Modern Developer Tooling]]></description><link>https://www.marcobrondani.com/p/the-first-real-agentic-supply-chain</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-first-real-agentic-supply-chain</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Thu, 14 May 2026 08:01:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ymNO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ymNO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ymNO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ymNO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ymNO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ymNO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ymNO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1405259,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/197197689?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ymNO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ymNO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ymNO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ymNO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe09967f0-61da-4ca1-ac5a-66ff8fe47b9a_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><blockquote><p><strong>In brief</strong></p><ul><li><p>Mitiga documented a way to steal Claude Code&#8217;s OAuth tokens: a malicious npm package rewrites the config file so the assistant&#8217;s MCP traffic runs through an attacker&#8217;s proxy, and the tokens are lifted in transit.</p></li><li><p>What makes it new is persistence. Rotating the stolen token feeds the next one to the attacker, and editing the config back gets silently rewritten. The standard incident-response actions become the attacker&#8217;s update channel.</p></li><li><p>Anthropic ruled it out of scope, because the attack needs prior code execution on the machine. That is defensible on its own terms and still operationally inadequate, because the agentic design changes what code execution is worth.</p></li><li><p>This is the first clean case of an agentic supply chain attack: the compromise sits in the channel that mediates access, not in a shipped artifact, so it spreads through use rather than updates. The blast radius is every SaaS integration the developer connected, and the traffic looks identical to legitimate use on the provider side.</p></li><li><p>The root is OAuth token concentration: long-lived, broadly scoped tokens held in a user-writable file are what make the assistant useful and what make the attack work. The defender&#8217;s threat model is now the tool plus everything the tool can reach.</p></li></ul></blockquote><div><hr></div><p>The disclosure landed on 7 May 2026 and was, on its face, a routine credential theft research note. Mitiga Labs reported that an attacker who could land a malicious npm package on a developer&#8217;s machine could redirect Claude Code&#8217;s MCP traffic through attacker-controlled infrastructure, intercept the OAuth tokens used to authenticate to connected SaaS providers, and maintain persistent access even as the user rotated those tokens. After Mitiga notified Anthropic on 10 April, Anthropic responded on 12 April that the issue was out of scope, on the grounds that prior code execution on the user&#8217;s endpoint is a precondition the model is not designed to defend against. The exchange was civil, both parties were defensible, and the disclosure became another entry in the steadily growing catalogue of agentic AI security findings.</p><p>If that were the whole story, it would not be worth a long article. The vulnerability is technically interesting but not surprising. Post-install hooks in npm packages have been a credential exfiltration vector since the technique was first popularised in 2018. Local configuration files containing OAuth tokens in plaintext have been a familiar exposure since at least the introduction of the AWS credentials file. Researchers and attackers alike have known for years that any tool which persists tokens in a user-writable location is one bad install away from compromise.</p><p>What makes the Mitiga finding worth taking seriously is the architecture the technique exploits, rather than the technique itself, and the way that architecture changes the meaning of a routine supply chain incident. I will argue in this piece that the MCP token hijack is the first cleanly documented case of an agentic supply chain attack, in a specific and uncomfortable sense. The compromise of one developer&#8217;s environment becomes durable, self-healing, attacker-controlled access to every SaaS platform that developer has connected to their AI assistant, with traffic that is indistinguishable from legitimate use on the provider side and invisible on the endpoint UI. The cost of the attack does not scale with the value of the target; the value of the access scales with how many integrations the developer has thoughtfully wired up.</p><p>This is a category change, and it deserves to be named.</p><h2>The mechanics</h2><p>Claude Code stores its configuration, including the URLs of registered MCP servers and the OAuth tokens issued by those servers, in a single file at ~/.claude.json. The tokens sit in plaintext, the file is writable by the user, and the MCP server URLs are not pinned to any cryptographic identity. Whatever URL is in the configuration is the URL that Claude Code connects to when initiating or refreshing an MCP session.</p><p>Mitiga&#8217;s attack chain begins with a malicious npm package. The package registers a lifecycle hook that runs as part of the install. The hook locates common code repository clone locations, populates them with a pre-configured trust dialog state set to true (so that no prompt fires when the directory is later opened in Claude Code), opens ~/.claude.json, and rewrites the mcpServers entries to point at an attacker-controlled proxy address. The proxy runs mitmproxy with the appropriate configuration to act as a transparent man-in-the-middle for the MCP protocol. Every subsequent request from Claude Code to that MCP server passes through the attacker&#8217;s infrastructure, the OAuth bearer tokens in the Authorization headers are captured, and the traffic is then forwarded to the legitimate provider so the user experience continues uninterrupted.</p><p>The persistence properties are the part that elevates this above a one-shot credential theft. If the user notices the compromise and rotates the affected token, the hook is still resident. On the next load it captures the new token. If the user notices that the MCP URL in the configuration is wrong and edits it back to the legitimate value, the hook rewrites it again. The standard incident response actions (rotate the credentials, restore the configuration) feed the chain rather than breaking it. Mitiga&#8217;s description of the outcome is precise. A durable redirection of the victim&#8217;s SaaS credentials into attacker-controlled infrastructure, with automatic recovery from token rotation, invisible to the victim&#8217;s endpoint UI, and indistinguishable from legitimate traffic on the provider&#8217;s side.</p><p>The point about provider-side indistinguishability is worth dwelling on. Mitiga published an example Atlassian audit log entry from a compromised session. The user, the session, and the IP address resolving to Anthropic&#8217;s egress range are all genuine, and the action looks like exactly the kind of action the user performs every week (a JQL query pulling tickets that mention credentials). Nothing in the row is wrong; nothing in the row would trigger any reasonable detection rule based on volume, geography, time-of-day, or action type.</p><p>This is the model of detection failure that the SaaS security industry has spent the last decade trying to escape. We built CASBs, we built ITDR platforms, we built behavioural analytics, all in service of being able to distinguish legitimate user activity from compromise. Mitiga&#8217;s research describes a compromise that defeats all of that, not by being more sophisticated than the detection logic, but by routing through a legitimate intermediary that the detection logic has already learned to trust.</p><h2>Why Anthropic&#8217;s response is correct on its own terms</h2><p>The most provocative element of the disclosure is Anthropic&#8217;s determination that the issue is out of scope. I want to take this seriously rather than dismiss it, because the logic is not unreasonable.</p><p>The argument goes like this. The attack requires the adversary to achieve code execution as the user on the developer&#8217;s machine, by getting the developer to install a malicious npm package. Once an adversary has code execution as the user, many things are possible: reading the user&#8217;s SSH keys, harvesting browser cookies, installing a keylogger, replacing the user&#8217;s git binary with a compromised version. Treating one specific consequence of endpoint compromise (in this case the rewriting of a configuration file) as a vendor-specific vulnerability is, in this view, a category error. If we are going to fix that, we have to fix everything that depends on the user being able to write to their own home directory, and at that point we have left the threat model of a developer tool and entered the threat model of a hardened operating system.</p><p>Mitiga acknowledges this directly. The blog post says, more or less plainly, that the determination is defensible on those terms: the user has code execution, many things become possible, and this is the world we live in.</p><p>The reason this defence is correct on its own terms and yet operationally inadequate is that the agentic architecture changes what &#8220;many things are possible&#8221; actually means. Let me unpack this carefully.</p><p>When a traditional developer tool stores credentials in a user-writable location, the consequence of endpoint compromise is that the attacker gets those credentials, can use them until they are rotated, and then has to find another way back in. The chain has a natural termination point. Token rotation works because the credential is a static artefact, and stealing it once gives the attacker a finite amount of value.</p><p>When an agentic tool stores OAuth tokens for a federated set of SaaS providers in a single configuration file, alongside the URLs of the MCP servers that issued those tokens, the consequence of endpoint compromise is different in kind. Rather than stealing a credential, the attacker redirects the channel by which credentials are continuously refreshed. The agentic tool itself becomes the renewal mechanism, and token rotation, the canonical defensive response, becomes the attacker&#8217;s update channel.</p><p>This is not a metaphor but a direct description of what the Mitiga proof of concept demonstrates. The malicious post-install hook does not exfiltrate the tokens and leave: it installs a persistent rewrite of the configuration that turns Claude Code into a credential-feeding pipeline for the attacker. Every refresh, every new connection, every session restart feeds the chain.</p><p>The architectural property that enables this is not specific to Claude Code but is the same property that makes MCP useful in the first place. The protocol exists to give an AI assistant durable, broad, OAuth-mediated access to a heterogeneous collection of SaaS resources. That is the design intention. The token concentration that makes the attack so effective is what makes the assistant work at all, which is why you cannot fix this with a configuration change: the configuration is the feature.</p><h2>What &#8220;agentic supply chain attack&#8221; actually means</h2><p>The phrase supply chain attack has been overused to the point of being almost analytically useless, applied to everything from SolarWinds to dependency confusion in npm. I want to be careful about why I am calling the Mitiga finding the first agentic supply chain incident, because the claim is doing more work than the phrase usually does.</p><p>A traditional software supply chain attack compromises a component that is incorporated into a downstream product. Updates to that component flow to the users of the downstream product, and the compromise spreads with the updates. The classic example is a build pipeline that ships a malicious binary. The compromise is in the artefact.</p><p>An agentic supply chain attack, in the sense I am using it, compromises a component that mediates access to downstream resources. The compromise spreads through use rather than through updates. Each interaction the user has with the agentic tool flows credentials, intent, and context through the compromised mediator. The compromise is in the channel.</p><p>This is a different shape of incident. The Mitiga research demonstrates it cleanly because the attack target is the MCP routing layer itself, rather than any specific tool or credential. Once that layer is compromised, every connected resource is reachable, and the reachability is determined by what the user has authorised the assistant to access rather than by what the attacker has explicitly targeted.</p><p>The implication for defenders is that the relevant blast radius of a compromise is the set of SaaS integrations a developer has connected, multiplied by the duration of the compromise, multiplied by the difficulty of distinguishing legitimate traffic from attacker-mediated traffic on the provider side. All three quantities run large: developers connect their assistants to everything they touch daily, token rotation does not break the chain, and the traffic flows through legitimate session contexts.</p><p>This is also why Anthropic&#8217;s out-of-scope determination, while technically defensible, is operationally inadequate. The vendor&#8217;s threat model is the agentic tool. The defender&#8217;s threat model is the agentic tool plus everything the agentic tool can reach. Those two threat models have diverged sufficiently that they are no longer the same conversation.</p><h2>The OAuth token concentration problem</h2><p>A useful way to think about what is happening here is to look at how OAuth tokens have historically been protected and what changed.</p><p>In a well-designed enterprise SaaS environment, OAuth tokens are short-lived, narrowly scoped, and held by services that have strong identity, well-audited code paths, and clear ownership. When a token is compromised, the response is well understood. Rotate the token, audit the actions taken with it, review the scope grants, tighten if needed.</p><p>The agentic developer tooling pattern violates each of those properties. Tokens stay long-lived because the user does not want to re-authenticate every hour; they are broadly scoped because the assistant is meant to be useful across many tasks, with the consent screen presented once at setup rather than per action; and they are held by a desktop tool running as the user, with code paths that are difficult to audit because they include both the deterministic tool and the non-deterministic model. Ownership is ambiguous. Is the token held by the user, by the developer tool vendor, or by the SaaS provider that issued it? Legally, by the user; operationally, by whatever process can read the configuration file.</p><p>Each individual decision in that chain has a defensible rationale: long-lived tokens reduce friction, broad scopes enable the assistant to be useful across heterogeneous tasks, and user-held configuration is consistent with the principle that the developer owns their own machine. None of these are obviously wrong choices. The interaction of these choices produces the concentration that the Mitiga attack exploits.</p><p>I want to be explicit about something here. This pattern extends well beyond Anthropic. The same concentration exists for GitHub Copilot CLI, for Cursor (whose token handling has been flagged by LayerX as well, with the report that Cursor does not store API keys in protected storage), for any IDE plugin that uses OAuth-mediated MCP, and for the broader family of agentic developer tools that are now standard in software engineering workflows. The Mitiga research happens to use Claude Code as the example because Claude Code&#8217;s configuration file is a particularly clean target. The pattern generalises.</p><h2>What changes in the threat model</h2><p>For organisations running developer teams that use agentic tooling, the practical implication of the Mitiga research is that the threat model for endpoint compromise has changed shape, and several standard responses no longer work as designed.</p><p>The first change is in the value of an individual compromised developer endpoint. Historically the value of compromising a developer&#8217;s laptop was bounded by what that developer could access. The blast radius was the union of the developer&#8217;s permissions. With agentic tooling, the blast radius is the union of the developer&#8217;s permissions plus the set of SaaS integrations the assistant has been given OAuth grants to, with durability that survives credential rotation. The developer is now a higher-value target than they were before, often without realising it.</p><p>The second change is in the detection model. Endpoint compromise has historically been detected through endpoint telemetry, network anomalies, or SaaS audit logs. The Mitiga attack defeats all three: endpoint telemetry sees normal Claude Code operation, network monitoring sees traffic to claude.ai (the expected destination), and SaaS audit logs see actions taken in a real user session from the expected IP range. Detection has to move into the configuration drift of the agentic tool itself, looking for changes to MCP server URLs, OAuth refresh patterns that do not match the user&#8217;s known schedule, and unexpected traffic through MCP integrations. Most organisations have no monitoring for any of these signals because they are properties of a tool category that has only existed at scale for about eighteen months.</p><p>The third change is in the response model. The standard playbook for a suspected developer endpoint compromise (reimage the machine, rotate all credentials, audit recent actions in connected services) needs an additional step: the configuration files of any agentic tooling on the machine must be examined for redirection, and the OAuth grants in those tools must be revoked at the provider rather than merely refreshed. If the malicious hook is still resident, refreshing only feeds the chain.</p><p>The fourth change is in the procurement and policy model. Developer-friendly tools have historically been adopted bottom-up: engineers install them, find them useful, and adoption spreads through teams before procurement notices. With agentic tooling this pattern produces a particular kind of risk because the security properties of the integration are not visible to the developer at the moment of adoption, while the cost is paid by the organisation at the moment of incident.</p><h2>The wider pattern</h2><p>This is not the first finding of its kind, and it will not be the last. In the same week as the Mitiga disclosure, LayerX published its ClaudeBleed research showing that any Chrome extension could pilot the Claude Chrome assistant through a similar trust composition failure, with similar persistence properties and similar invisibility to standard monitoring. Earlier this year LayerX&#8217;s research on Claude Desktop Extensions showed how content arriving through a low-risk connector (a calendar event) could trigger code execution through a high-risk connector on the same machine, with the vulnerability earning a CVSS 10 out of 10 and Anthropic declining to fix it on the same consent-based grounds.</p><p>The pattern is consistent. Agentic tooling concentrates trust across previously independent layers, and compromise of any one layer cascades through all of them. Vendor responses correctly point out that each individual compromise requires preconditions that are outside the vendor&#8217;s threat model, while defenders correctly observe that the operational reality is that the compromises happen anyway, and the standard responses do not work.</p><p>I have called this an operational substrate problem in other work, and the framing applies cleanly here. The substrate sits beneath the governance and policy layer; it is what the technology depends on to actually function. When that substrate is the concentration of long-lived OAuth tokens in a user-writable configuration file managed by an agentic tool that can be reconfigured by a post-install hook, the governance layer&#8217;s claims about responsible AI use cannot reach down far enough to control the actual risk.</p><h2>What this looks like for the practitioners who have to act on it</h2><p>For a CISO or security lead trying to figure out what to do about this Monday morning, the immediate steps are not difficult to enumerate. Identify the developers in the organisation using agentic tooling, which usually means Claude Code, GitHub Copilot CLI, Cursor, or one of the smaller players. Inventory the MCP integrations connected to those tools, which usually means at least source control, project management, and chat. For each integration, identify what OAuth scopes have been granted and what those scopes allow. Establish monitoring for changes to the configuration files of the agentic tools, which is straightforward at the endpoint level if you have any endpoint detection platform. Review provider-side audit logs not for anomalous user behaviour, which will not show up, but for traffic from unexpected MCP server URLs or unexpected refresh patterns.</p><p>The harder work sits upstream of all this. Procurement of agentic developer tooling needs to start being treated with the same care that procurement of any other privileged access tool would receive, and the threat models published by the vendors are not sufficient for organisations that have to deal with the consequences of trust composition failures the vendors have explicitly declared out of scope. &#8220;Endpoint compromise&#8221; is no longer a single state with a single value; the value of an endpoint now depends on what agentic tools live on it and what those tools have been authorised to reach.</p><p>The Mitiga research is a marker, not a panic event. The marker says that the comfortable separation between developer tool security, identity and access management, and SaaS posture management has become operationally fictional. Anyone running security for a developer-heavy organisation is going to have to reckon with this, and the sooner the reckoning starts, the cheaper it will be.</p><div><hr></div><h2>Sources and references</h2><ol><li><p>Kevin Townsend. &#8220;Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking.&#8221; SecurityWeek, 7 May 2026. https://www.securityweek.com/claude-code-oauth-tokens-can-be-stolen-through-stealthy-mcp-hijacking/</p></li><li><p>Mitiga Labs. &#8220;MCP Token Theft in Claude Code: A Man-in-the-Middle Attack Chain via ~/.claude.json.&#8221; Mitiga blog, May 2026. https://www.mitiga.io/blog/claude-code-mcp-token-theft-mitm</p></li><li><p>CXO Digital Pulse. &#8220;Researchers Warn Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking.&#8221; May 2026. https://www.cxodigitalpulse.com/researchers-warn-claude-code-oauth-tokens-can-be-stolen-through-stealthy-mcp-hijacking/</p></li><li><p>Aviad Gispan. &#8220;ClaudeBleed: How Any Chrome Extension Can Hijack Claude.&#8221; LayerX Security blog, 5 May 2026. https://layerxsecurity.com/</p></li><li><p>LayerX Security. &#8220;Claude Desktop Extensions Exposes Over 10,000 Users to Remote Code Execution Vulnerability.&#8221; 12 February 2026. https://layerxsecurity.com/blog/claude-desktop-extensions-rce/</p></li><li><p>RedCaller. &#8220;MCP Client OAuth Refresh-Token Support Matrix.&#8221; 2026. https://www.redcaller.com/docs/references/mcp-client-oauth-refresh-token-support</p></li><li><p>TrueFoundry. &#8220;MCP Authentication in Claude Code 2026 Guide.&#8221; 2 April 2026. https://www.truefoundry.com/blog/mcp-authentication-in-claude-code</p></li><li><p>Getlarge Blog. &#8220;Securing MCP Servers with OAuth2: Ory Hydra + Claude Code + ChatGPT.&#8221; 30 January 2026. https://getlarge.eu/blog/securing-mcp-servers-with-oauth2-ory-hydra-claude-code-chatgpt/</p></li><li><p>Anthropic. Claude Code documentation on MCP server configuration and OAuth authentication. https://docs.claude.com</p></li><li><p>Anthropic Release Notes. May 2026 updates on OAuth and credential reliability in Claude Code. https://releasebot.io/updates/anthropic</p></li><li><p>Marco Brondani. &#8220;OSRA: Operational Substrate Risk Audit.&#8221; Methodology and worked examples. https://marcobrondani.com/osra</p></li></ol>]]></content:encoded></item><item><title><![CDATA[When Three Trust Models Fail at Once]]></title><description><![CDATA[The Claude Chrome Extension and the End of a Comfortable Story About Browser AI]]></description><link>https://www.marcobrondani.com/p/when-three-trust-models-fail-at-once</link><guid isPermaLink="false">https://www.marcobrondani.com/p/when-three-trust-models-fail-at-once</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Mon, 11 May 2026 10:23:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Zfyh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zfyh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zfyh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!Zfyh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!Zfyh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!Zfyh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zfyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png" width="1122" height="1402" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1402,&quot;width&quot;:1122,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1412016,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.marcobrondani.com/i/197195601?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Zfyh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 424w, https://substackcdn.com/image/fetch/$s_!Zfyh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 848w, https://substackcdn.com/image/fetch/$s_!Zfyh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 1272w, https://substackcdn.com/image/fetch/$s_!Zfyh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F79595298-cccf-4c45-91ca-bf347735793c_1122x1402.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>In brief</strong></p><ul><li><p>Two disclosures in six months, ShadowPrompt and ClaudeBleed, hijacked the same Claude Chrome extension by entirely different routes and reached the same outcome. The usual takeaway, that browser AI is risky and vendors are patching, sits at the wrong altitude.</p></li><li><p>An LLM in the browser cannot tell who an instruction came from. &#8220;Summarise this page&#8221; looks the same whether the user typed it, another extension forwarded it, or a hidden element on the page planted it. The trust decisions happen in the surrounding software, which is where both attacks failed.</p></li><li><p>Underneath the patches, three trust models now share one execution context: the browser model (sandbox, origins, permissions), the LLM model (system over user over page content, and only probabilistically), and the SaaS OAuth model (durable tokens for Gmail, Drive, GitHub). A failure in one becomes a failure in all, and the composition is nobody&#8217;s responsibility.</p></li><li><p>Human-in-the-loop confirmation stops holding up. An attacker can forge the approval, or rewrite the dialog so the user and the assistant are looking at different things. The control assumed both see the same UI, which is no longer guaranteed.</p></li><li><p>The procurement questions change accordingly: what OAuth grants accumulate and where the tokens live, how confirmation is protected from DOM manipulation, and who owns the trust composition when it breaks. The pattern is not Claude-specific; it follows the architecture across browser, desktop, and IDE assistants.</p></li></ul><div><hr></div><p>Two disclosures in the last six months involving the same extension, by two different research teams, produced the same outcome through almost entirely different mechanisms. In December 2025, Koi Security reported a zero-click chain it called ShadowPrompt, exploiting a permissive subdomain allowlist combined with a DOM-based cross-site scripting flaw in an Arkose Labs CAPTCHA component hosted on a-cdn.claude.ai. Visiting a webpage was enough. The attacker&#8217;s prompt landed in Claude&#8217;s sidebar as if the user had typed it. Anthropic shipped an origin-tightening patch in extension version 1.0.41 on 15 January 2026, and Arkose Labs fixed the upstream XSS on 19 February 2026.</p><p>Three months later, LayerX disclosed a second vulnerability the firm named ClaudeBleed. This one had nothing to do with subdomain origin checks or XSS. It exploited the extension&#8217;s externally_connectable manifest setting, which trusts the origin of incoming messages but does not verify the execution context within that origin. Any other Chrome extension, even one declaring zero special permissions, could inject scripts into the claude.ai page, send messages through that pipe, and pilot Claude as if the user were issuing the commands. LayerX demonstrated extraction of files from Google Drive, transmission of emails on behalf of the user, and theft of source code from a connected GitHub repository. Anthropic patched in version 1.0.70 on 6 May 2026. LayerX reported that switching the extension into a privileged &#8220;act without asking&#8221; mode bypassed the new checks.</p><p>Both stories produced the predictable wave of coverage, and the framing was familiar: browser AI is risky, prompt injection is hard to defend against, vendors are racing to patch, users should update.</p><p>That framing is not wrong, but it sits at the wrong altitude. Whether the Claude Chrome extension is uniquely insecure matters less than what the two disclosures, taken together, reveal about the architecture any browser-resident AI assistant has to inhabit, and why the standard list of security recommendations cannot reach the underlying problem. The honest answer is uncomfortable for everyone selling agentic browser tools, including Anthropic, Google, and the dozen smaller vendors building in this space. The architecture itself concentrates three previously independent trust models into one execution context, and once that has happened, no patch on any single layer fully restores the separation the original threat models assumed.</p><p>This is worth unpacking carefully, because the conclusion bears on procurement decisions, on board-level questions about agentic AI rollouts, and on how cyber insurance underwriters are likely to start pricing this class of exposure over the next year.</p><h2>What actually changed when an LLM moved into the browser</h2><p>For most of the history of enterprise security, the browser was a hostile environment that the security team accepted as a fact of organisational life: users would click on things, pages would try to load scripts from places they should not, and extensions would request permissions they did not need. The discipline built up to handle this was the Chrome extension security model, which rests on three foundations.</p><p>The first is sandboxing. Extensions run in a constrained execution environment, separate from the page and from each other, with explicit permission grants required to read tabs, modify requests, or access storage.</p><p>The second is origin-based trust. The extension declares which origins it wants to communicate with, the browser enforces those declarations, and origins themselves are treated as the unit of security boundary.</p><p>The third is the human in the loop. For sensitive actions like reading clipboard contents, accessing camera or microphone, or modifying network traffic, the user receives an explicit prompt and either approves the action or blocks it.</p><p>Each of these foundations developed in response to a specific class of historical attack: sandboxing handles the case where an extension itself is malicious or compromised, origin-based trust handles the case where one page tries to take action on behalf of another, and the human-in-the-loop step handles the case where neither the page nor the extension can be fully trusted to make decisions about consequential operations.</p><p>None of those three foundations were designed for the case where the user-facing surface inside the extension is a language model.</p><p>A language model behaves nothing like a deterministic UI, with no fixed action vocabulary that can be enumerated and gated. It accepts natural language input, infers intent, and produces actions that may be entirely novel from one session to the next. When the input comes from the user, this is exactly what we want. When the input comes from somewhere else, the model has no native mechanism to distinguish between the two sources. The text saying &#8220;summarise this page&#8221; looks identical whether the user typed it, an extension forwarded it, or a hidden div on the page contains it as injected content. Decisions about which inputs to trust happen outside the model, in the surrounding software, in the extension&#8217;s message-handling code, in the origin checks, in the consent flows.</p><p>Both ShadowPrompt and ClaudeBleed are failures of that surrounding software rather than of the model itself, and specifically failures of the assumption that the model, once given an instruction, will reliably defer to meta-instructions about which sources are authoritative.</p><p>This matters because once you understand the architecture this way, you see why patching is not a complete answer. Anthropic tightened the origin check after ShadowPrompt and added approval flows after ClaudeBleed. Both fixes close the specific reported attack path without touching the structural condition that the model, by design, sits in a position where it can be reached by any party that finds a route into the message pipeline. The route in version 1.0.41 differed from the route in version 1.0.70, but the class of attack was identical in both cases.</p><h2>The three trust models that have now merged</h2><p>The reason this matters in operational terms, and the reason the eventual remediation will be slower and more painful than a vendor patch suggests, is that browser-resident AI assistants do not sit inside a single trust model. They sit at the intersection of three.</p><p>The first is the <strong>browser trust model</strong>, governed by the Chrome extension manifest, content security policies, sandboxing rules, and the permission framework. This is the model that has been tested by twenty years of adversarial pressure. It is well understood, well documented, and reasonably sound when implemented correctly.</p><p>The second is the <strong>LLM trust model</strong>, which is much newer and much less mature. It rests on the model&#8217;s ability to follow system prompts in preference to user prompts, to follow user prompts in preference to embedded content, and to ask for confirmation before taking consequential actions. None of these properties are guaranteed, and all of them can be eroded by adversarial input. The defences remain probabilistic rather than absolute. Anthropic&#8217;s own documentation for computer use explicitly acknowledges that content on webpages or in images can conflict with user instructions and cause Claude to make mistakes, even with classifier-based defences layered on top.</p><p>The third is the <strong>SaaS OAuth trust model</strong>, which is what gives the assistant the ability to do anything interesting. The user, at some prior point, granted the assistant access to Gmail or Google Drive or GitHub or a corporate Slack workspace. That grant is durable, surviving session boundaries, and it does not require reconfirmation for each individual action. Once the OAuth token exists in the extension&#8217;s reach, the assistant has effective custody of the credentials.</p><p>Before agentic browser AI, these three models existed in separate parts of the security architecture and were defended by separate teams using separate tools. The browser team worried about extensions and origins, the application security team about prompt injection in chatbots that had no ability to take actions, and the identity team about OAuth scope and consent. The defensive posture was distributed.</p><p>What ShadowPrompt and ClaudeBleed demonstrate, with two very different exploitation chains, is that all three trust models now share an execution context. A failure in one is a failure in all of them. An attacker who finds a way to inject prompts (a failure in the LLM trust model) gains access to OAuth tokens (a failure in the identity trust model) through a route that the browser security model was not designed to consider authoritative (a failure in the browser trust model). Each individual model worked as designed; the composition broke.</p><p>This is the kind of failure mode that does not show up in a single product&#8217;s threat model, because each product is only responsible for one of the trust layers. The LLM vendor does not own the OAuth tokens, the SaaS application vendor does not own the extension&#8217;s message handling, and the browser vendor does not own what the LLM does once it receives input. The composition becomes nobody&#8217;s responsibility precisely because no single party can fully see it.</p><h2>Why &#8220;user confirmation&#8221; stopped being a defence</h2><p>One of the more interesting details in the LayerX disclosure is the description of how user confirmation was bypassed. Claude, like most contemporary agentic assistants, enforces an additional step before taking sensitive actions. The user is shown what is about to happen and asked to approve. This is the human-in-the-loop control that has been the backstop of browser security since the original Chrome extension permission model was designed.</p><p>LayerX showed two ways this control fails in the new architecture. The first is repeated confirmation messages, where the attacker&#8217;s script forges the user approval by sending the confirmation message itself, sometimes multiple times to overwhelm any rate limiting. The second is DOM manipulation, where the attacker modifies the visible UI to alter what Claude perceives the user is approving, so the user sees a dialog asking for permission to do one thing while Claude reads a dialog that has been quietly rewritten to ask for permission to do something else.</p><p>The implication is sharper than it first appears. The human-in-the-loop control assumes that the human and the assistant are seeing the same UI. In a traditional Chrome extension this assumption was reasonable, because the UI was rendered by the browser and not interpretable by the extension. In an agentic assistant the UI is rendered by the browser, observed by the assistant, and acted on by the assistant. The integrity of the user&#8217;s view and the assistant&#8217;s view are no longer guaranteed to be the same view. Any party that can write to the DOM can desynchronise them.</p><p>The concern is concrete rather than theoretical. The LayerX proof of concept did exactly this, and the user could be looking at a dialog that says one thing while Claude is reading a dialog that says something else.</p><p>For practitioners, the lesson is that the standard advice (require explicit confirmation for sensitive actions) needs a stronger formulation. The confirmation must be cryptographically tied to the action, not visually presented, and reconciled between the user&#8217;s view and the assistant&#8217;s view through a channel the attacker cannot rewrite. None of the current browser AI assistants implement this, and whether the Chrome extension model can support it without significant architectural changes remains an open question.</p><h2>What this means for the procurement conversation</h2><p>For directors and senior executives evaluating whether to allow agentic browser AI inside the organisation, the standard checklist of questions misses the most important ones. The standard checklist tends to focus on data residency, model selection, conversation logging, and whether the vendor has SOC 2 attestations. These are appropriate questions, but they are the wrong questions to ask first.</p><p>The first questions to ask are these.</p><p>What OAuth grants does this assistant accumulate over the course of normal use, and where are those tokens stored? If they are stored in browser local storage, who else can reach them? If they are stored in the extension&#8217;s protected storage, what is the verification model for callers that send messages to the extension? In both ShadowPrompt and ClaudeBleed, the failure mode was that the extension&#8217;s verification model accepted callers it should not have accepted.</p><p>What sensitive actions does the assistant enforce confirmation for, and how is the integrity of that confirmation flow guaranteed against DOM manipulation? If the answer involves visual presentation in the page, the control does not hold up against the class of attacks demonstrated this year.</p><p>What is the vendor&#8217;s response when a researcher reports a problem outside the immediate exploit but inside the same architectural pattern? Anthropic&#8217;s response to LayerX was that the issue was already known and would be fixed in the next version. That is a reasonable response. The follow-up question is whether the next version addresses the broader pattern or only the specific path. In this case the answer was the specific path, which is why LayerX was able to demonstrate a second exploitation route in the privileged mode.</p><p>Who owns the trust composition? When the same execution context contains the browser model, the LLM model, and the OAuth model, which party is accountable for the composition? The answer at most organisations today is that nobody is. The CISO covers identity, the application security lead covers application vulnerabilities, and the AI governance owner (if such a role exists) covers model behaviour. Composition risk falls between the seams.</p><h2>This disclosure fits into a wider pattern</h2><p>It would be a mistake to read these incidents as Claude-specific. Unit 42 published research in March 2026 on Gemini Live in Chrome that described the same architectural pattern from a different angle, showing how extension-based compromise of an agentic browser assistant could lead to local file access, screenshots, camera and microphone exposure, and broader privacy invasion. Implementation details differ across the products, while the security direction is consistent. Once an assistant is a privileged surface inside the browser with the ability to read content, execute scripts, and take cross-site action, compromise of that surface produces outcomes that previously required full remote code execution.</p><p>There is also a parallel development worth noting in the desktop space. LayerX itself published research earlier this year on Claude Desktop Extensions, showing that MCP-based connectors with full system privileges could be triggered by content arriving through low-risk connectors such as Google Calendar. The vulnerability earned a CVSS 10 out of 10, and after the researchers reported it, Anthropic determined that the user had consented to this class of behaviour by enabling the connectors and chose not to fix it.</p><p>I am not raising that desktop case to suggest Anthropic is uniquely careless. The desktop case illustrates the same structural pattern from a different angle. When a model has been granted a wide set of permissions across heterogeneous data sources, any data source with a path to the model becomes, in effect, a path to the union of those permissions. The legal frame here is consent; the operational frame is composition.</p><p>The pattern repeats because the underlying architecture is the same. Browser, desktop, IDE plugin, code assistant, mobile companion app. Every place that an agentic AI is given hands to act on the user&#8217;s behalf becomes a place where the trust composition of multiple previously independent layers becomes the new attack surface.</p><h2>What an actually useful response looks like</h2><p>I do not think the answer is to refuse to deploy this category of tooling. The productivity case for assistants that can actually do things in the user&#8217;s environment is real, and the organisations that figure out how to use them safely will have a material advantage over those that wait. Waiting for the vendor to solve it is also not the answer, because the vendor will close specific exploit paths and the class of attack will reappear in a different form. This is the historical pattern of every previous extension security disclosure, and there is no reason to expect this one to break that pattern.</p><p>What is required is recognition that browser-resident agentic AI is operating in a substrate where three trust models that were previously separate have collapsed into one. This recognition needs to be reflected in procurement, in monitoring, and in incident response.</p><p>In procurement, the question has shifted from whether the assistant is useful to what the assistant&#8217;s blast radius is when (not if) the trust composition is breached. Useful tools with small blast radii deserve different treatment from useful tools with large blast radii. Most current deployments do not make this distinction, because the trust composition is invisible at the moment of purchase.</p><p>In monitoring, the standard endpoint and SaaS audit logs are insufficient. As Mitiga&#8217;s parallel research on Claude Code OAuth interception demonstrated, traffic generated by a compromised assistant looks identical to legitimate traffic on the SaaS side. The user, the session, the IP address resolving to the expected egress range, the action looking like exactly the kind of action the user performs routinely: all of it reads as authentic in the audit log. Detection has to happen earlier, in the configuration drift and the message-handling patterns of the assistant itself, rather than in the downstream audit logs.</p><p>In incident response, the standard playbook for compromised browser extensions (remove the extension, rotate any exposed credentials, force re-authentication on all connected services) is necessary but insufficient. The connected SaaS services may have been used to establish persistence through other means: created mailbox rules, shared documents, created repository forks, modified webhook endpoints. The incident does not end when the extension is removed.</p><p>None of this is comfortable, and none of it is what most organisations are currently equipped to do. The disclosures from Koi and LayerX are early markers, not the end of the conversation about browser AI security: markers that the comfortable story we have been telling ourselves about how this category of tooling fits into existing security frameworks is no longer adequate.</p><p>The frameworks themselves will have to change, since the trust composition already has. The vulnerabilities will keep arriving until both have caught up.</p><div><hr></div><h2>Sources and references</h2><ol><li><p>Ionut Arghire. &#8220;Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover.&#8221; SecurityWeek, 8 May 2026. https://www.securityweek.com/vulnerability-in-claude-extension-for-chrome-exposes-ai-agent-to-takeover/</p></li><li><p>Aviad Gispan. &#8220;ClaudeBleed: How a Zero-Permission Chrome Extension Can Hijack Claude.&#8221; LayerX Security blog, 5 May 2026. https://layerxsecurity.com/</p></li><li><p>Derek B. Johnson. &#8220;Flaw in Claude&#8217;s Chrome extension allowed &#8216;any&#8217; other plugin to hijack victims&#8217; AI.&#8221; CyberScoop, 8 May 2026. https://cyberscoop.com/claude-chrome-extension-allows-plugins-to-hijack-ai/</p></li><li><p>Shweta Sharma. &#8220;Claude in Chrome is taking orders from the wrong extensions.&#8221; CSO Online, 9 May 2026. https://www.csoonline.com/article/4168867/claude-in-chrome-is-taking-orders-from-the-wrong-extensions.html</p></li><li><p>Oren Yomtov. &#8220;ShadowPrompt: How Any Website Could Have Hijacked Claude&#8217;s Chrome Extension.&#8221; Koi Security blog, 26 March 2026. https://www.koi.ai/blog/shadowprompt-how-any-website-could-have-hijacked-anthropic-claude-chrome-extension</p></li><li><p>The Hacker News. &#8220;Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website.&#8221; 26 March 2026. https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html</p></li><li><p>SOCRadar. &#8220;ShadowPrompt: Zero-Click Prompt Injection Chain in Anthropic&#8217;s Claude Chrome Extension.&#8221; 27 March 2026. https://socradar.io/blog/shadowprompt-zero-click-anthropics-claude/</p></li><li><p>Penligent. &#8220;Claude Extension Prompt Injection &#8212; How ShadowPrompt Turned a Trusted Subdomain Into a Browser-Scale Risk.&#8221; 28 March 2026. https://www.penligent.ai/hackinglabs/claude-extension-prompt-injection-how-shadowprompt-turned-a-trusted-subdomain-into-a-browser-scale-risk/</p></li><li><p>LayerX Security. &#8220;Claude Desktop Extensions Exposes Over 10,000 Users to Remote Code Execution Vulnerability.&#8221; 12 February 2026. https://layerxsecurity.com/blog/claude-desktop-extensions-rce/</p></li><li><p>SQ Magazine. &#8220;ClaudeBleed Bug Lets Chrome Extensions Hijack Claude AI.&#8221; 8 May 2026. https://sqmagazine.co.uk/claudebleed-chrome-extension-hijack-claude-ai/</p></li><li><p>Anthropic. Computer Use documentation, public guidance acknowledging conflicts between webpage content and user instructions in agentic contexts. https://docs.claude.com</p></li><li><p>Palo Alto Networks Unit 42. Research on agentic browser assistants and Gemini Live in Chrome, March 2026.</p></li></ol>]]></content:encoded></item><item><title><![CDATA[After the Valley]]></title><description><![CDATA[Masahiro Mori never asked what lay on the other side. We are crossing the valley not by addressing what the alarm detects but by suppressing it. The question is no longer whether we are crossing but what we are crossing into.]]></description><link>https://www.marcobrondani.com/p/after-the-valley</link><guid isPermaLink="false">https://www.marcobrondani.com/p/after-the-valley</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Thu, 26 Mar 2026 06:30:35 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/e2de5405-efe7-4ac9-9f4f-d2299342dfa4_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9XPm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9XPm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9XPm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9XPm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9XPm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9XPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9XPm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9XPm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9XPm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9XPm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80d2e254-5393-4e5f-a3c6-f31626e96ce3_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Essay Six of <em>The Valley of False Signals </em>series</p><p><strong>In brief</strong></p><ul><li><p>Mori mapped the uncanny valley as a region to avoid and never asked what lies past it. We are crossing now, and crossing by suppressing the alarm rather than by fixing what it detects.</p></li><li><p>Three failures have fused into one system: the collapse of signal fidelity (voice, face, and text now forgeable), the optimization of signals without the substance behind them, and the social suppression of the alarm that would catch the split.</p></li><li><p>Three responses fail. Technical solutionism chases an unforgeable signal that co-evolution will defeat; cynical withdrawal mistakes the collapse of particular mechanisms for the impossibility of trust; nostalgic restoration tries to regulate back a world whose technological constraints are already gone.</p></li><li><p>The shift required runs from evidentiary trust (does this entity produce the right signals?) to structural trust (do its incentives make producing the real substance more rational than faking the signals?). A certificate answers the first; whether the framework is adversarially designed answers the second.</p></li><li><p>Institutional design can close the gap in specific domains but not the civilizational one. That is a cultural recovery, not an installed fix: rebuilding proximity between a decision and the reality it judges, a claim and the test of it, an alarm and the person who can act. The alarm still works; the question is whether we stop turning it off.</p></li></ul><div><hr></div><p>Masahiro Mori never asked what lay on the other side.</p><p>His 1970 essay mapped the uncanny valley as a region to be understood and, for practical purposes, avoided. The design recommendation was clear: keep your robots clearly robotic, or make them indistinguishable from human, but do not leave them in the liminal region where the alarm fires. The valley was a problem of proximity, of getting too close to human without closing the remaining gap, and the solution was either distance or completion.</p><p>What Mori did not address, because in 1970 there was no reason to, was the condition that obtains when you have actually crossed. When the valley is behind you. When the simulation has achieved the fidelity that was always theoretical and is now, in specific domains and with increasing generality, practical. What the world looks like when the alarm no longer has a reliable object to fire at, not because the alarm is broken, but because the incongruence it detects has been engineered away.</p><p>This series has been, in one sense, a map of the crossing. The alarm that fires and is suppressed by social convention. The alarm that fires and is suppressed by organizational culture. The alarm that fires and is suppressed by the apparatus of institutional assurance. The alarm that is approaching a condition where it may stop firing altogether because the simulations have become too precise. The alarm carried by people who refuse to suppress it, who pay professional costs for that refusal, and whose protection is a structural condition for any institution maintaining the capacity to perceive its own reality.</p><p>We are, to be precise, not yet fully past the valley. The crossing is in progress, in different domains, at different rates, with the synthetic signal capabilities advancing faster than the institutional adaptation to absorb them. But the direction is clear, and it has been clear long enough that the more urgent question is no longer whether we are crossing but what we are crossing into.</p><p>What does trust look like after the valley?</p><div><hr></div><h2>What Trust Was Built On</h2><p>Trust, in the sense relevant to everything this series has examined, is an inference rather than a feeling: a conclusion drawn from evidence, about whether an entity is what it presents itself to be, whether the signals it is producing are causally connected to the reality they purport to represent.</p><p>For most of human history, that inference rested on direct observation: behavior watched over time, across varied circumstances, until coherence could be assessed. This model was slow, labor-intensive, and calibrated for small social environments. It began to break down as soon as human cooperation scaled beyond the face-to-face, and every expansion in scale since has required the development of new trust infrastructure to proxy for the direct observation that was no longer feasible. Credentials, contracts, certifications, reputational systems, legal liability, regulatory oversight: all mechanisms designed to make trustworthiness legible at scale.</p><p>What this series has mapped is the systematic failure of that trust infrastructure, not in all respects and not all at once, but in ways that are structural and accelerating. The failure has three distinct sources that the preceding essays examined separately and that now need to be understood together.</p><p>The collapse of signal fidelity: the practical impossibility of forging certain signals (voice, face, behavioral pattern, writing style) has ended, and the trust infrastructure built on that impossibility is being rendered obsolete faster than it can be replaced.</p><p>The optimization of signal production without substance: the learning, at both the individual and institutional level, that producing the right signals is sufficient to satisfy verification mechanisms, without the production requiring the underlying reality those signals are supposed to represent.</p><p>The systematic suppression of the most reliable detection instrument available: the coherence check, the prediction error mechanism, the alarm, which fires when it registers the split between signal and source, and which is suppressed, at every scale of social organization, by the norms of cooperative life that mistake the suppression of alarm for the exercise of good judgment.</p><p>These three failures form a system. Signal synthesis undermines the evidentiary value of signals. Signal production optimization is accelerated by the knowledge that signals rather than substance are what verification measures. And both are protected from detection by the suppression mechanism, which prevents the alarm that might otherwise surface the split from reaching action.</p><p>The trust infrastructure that was built for a world in which signals were hard to fake and institutions were assumed to produce the substance they claimed is not adequate for a world in which neither assumption holds. The question of what comes after is the question this essay is trying to answer.</p><div><hr></div><h2>The Three Errors to Avoid</h2><p>Before naming what adequate trust infrastructure might look like, it is worth being precise about three errors that responses to this situation most commonly make. Each has real advocates, and each is wrong in a way that the analysis of this series makes visible.</p><p>Technical solutionism is the most common: the search for a new technical signal that cannot be faked. A biometric so complex, a cryptographic proof so robust, a behavioral marker so deeply embedded in neurological reality that it cannot be synthesized. These investments raise the cost of forgery, which has real value: it narrows the adversary population, increases attack resource requirements, and buys time. But as a foundation for trust infrastructure, technical solutionism fails because the adversarial parity dynamic described in Essay Three is real. Detection and generation co-evolve. No technical signal achieves permanent unforgeability in an environment where adversaries have access to the same foundational techniques as defenders. The deeper error is the implicit assumption that trust is a property of signals. Trust is a property of systems, of the institutional architectures, incentive structures, verification processes, and accountability mechanisms that determine whether the entities operating within them are what they claim to be. Rebuilding trust infrastructure on a new signal without rebuilding the system is building on a foundation that will, again, be undermined.</p><p>Cynical withdrawal is the second error: having recognized the collapse of signal fidelity and the systematic production of accountability theater, it concludes that trust is simply no longer possible. Every institution is performing. Every signal is suspect. This response has a kind of intellectual tidiness; it is consistent with the evidence and requires no difficult work. It is also indistinguishable from surrender. Trust, even imperfect and provisional, is a precondition for collective action. The cynical withdrawal does not protect against the failures this series has documented; it merely removes the possibility of institutional development that might address them. It also makes a subtle epistemic error: it treats the collapse of particular trust mechanisms as evidence that trust itself is impossible, rather than as evidence that particular mechanisms were built on inadequate foundations.</p><p>Nostalgic restoration is the third, perhaps most common in policy circles: the attempt to restore the conditions under which the previous trust infrastructure worked. To regulate synthetic media out of existence, to mandate signal authenticity through legal requirements, to impose on the current environment the assumptions under which the old mechanisms were adequate. The conditions under which signals were practically unforgeable were not policy choices. They were technological constraints that have been removed by capabilities that are not reversible. Deepfake generation cannot be uninvented. The regulatory impulse to require watermarking, provenance tracking, and synthetic media disclosure raises the floor, but it does not restore the underlying condition. Nostalgic restoration is particularly dangerous in the governance domain, because it produces exactly the institutional uncanny valley that Essay Four examined: frameworks that signal the restoration of trust infrastructure without actually rebuilding it.</p><div><hr></div><h2>What Structural Trust Requires</h2><p>Trust infrastructure adequate for the post-valley condition is built on the assumption that signals are not reliable, compensating for that unreliability through structural design rather than signal improvement.</p><p>This requires a shift in the foundational question. The question that previous trust infrastructure was built to answer was: <em>does this signal indicate trustworthiness?</em> The question that adequate trust infrastructure asks is: <em>is this system structured so that trustworthy behavior is produced by the incentives operating within it, regardless of whether signals are reliable?</em></p><p>The shift is from evidentiary trust (trust based on the interpretation of signals) to structural trust (trust based on the design of systems that make trustworthy behavior the rational choice for actors operating within them). The idea is not new; it is the foundational insight of institutional economics, of mechanism design, of the branch of political philosophy concerned with how constitutions should be designed to produce good governance even from self-interested actors. What is new is the urgency: the recognition that the evidentiary trust model has been more thoroughly undermined than previous transitions have produced, and that structural trust is a practical necessity rather than a theoretical refinement.</p><p>The distinction is worth pausing on, because it reframes everything this series has examined. Evidentiary trust asks: does this entity produce the right signals? Structural trust asks: is this entity operating within constraints that make producing the right substance more rational than producing the right signals? The first question can be answered by inspection, by evaluating what the entity presents. The second can only be answered by understanding the incentive architecture within which the entity operates. A compliance certificate answers the first question. The question of whether the compliance framework is adversarially designed, whether it tests the substance or merely the documentation, answers the second.</p><p>The distinction reframes everything this series has examined. Evidentiary trust asks: does this entity produce the right signals? Structural trust asks: is this entity operating within constraints that make producing the right substance more rational than producing the right signals? A compliance certificate answers the first question. The question of whether the compliance framework is adversarially designed, whether it tests the substance or merely the documentation, answers the second.</p><p>Most of our trust infrastructure is still designed to answer the first question. The shift to the second requires a fundamentally different relationship between the verifier and the verified, one in which the verifier assumes that signal optimization is the default behavior and designs for it, rather than assuming good faith and being surprised when the gap appears. This is the shift from cooperative verification (we trust you; show us your documentation) to adversarial verification (we assume the gap; show us your reality under conditions you haven't prepared for). It is, in essence, the shift from the world before the valley to the world after it.</p><p>The preceding essays developed the specific principles this shift requires: accountability that carries real costs, so that producing accountability signals is never cheaper than producing accountability itself; verification that is adversarial by design, testing for the gap under conditions the institution cannot prepare for; detection systems structurally independent of the functions they evaluate; and organizational cultures that treat the alarm as an institutional asset rather than a mark of poor judgment.</p><p>These principles are not new individually. What is new is the recognition that they are structural prerequisites for trust infrastructure in an environment where signal production has been decoupled from substance at every scale, from the synthetic voice on the phone to the compliance framework on the shelf.</p><p>But there is something these principles cannot address, and it would be dishonest to conclude this series without naming it.</p><div><hr></div><h2>The Epistemological Problem at the Center</h2><p>The institutional responses this series has been advocating are adequate at the organizational and sectoral level. They can close the institutional uncanny valley in specific domains. They cannot solve the civilizational problem that underlies them.</p><p>The signal/source split that this series has been mapping is an epistemological problem: a problem about how collective knowledge is constituted, and about whether the conditions for collective knowledge still obtain.</p><p>Collective knowledge, the shared understanding that allows large groups of people to coordinate, assign trust, and recognize when the things they depend on have failed, is produced by the interaction of signals and verification. It requires that some signals be reliably connected to the realities they represent, and that the mechanisms for distinguishing reliable from unreliable signals be trusted enough to be actionable.</p><p>When the signals of human presence, institutional accountability, and individual authenticity are all simultaneously under systematic attack, when deepfakes produce voice and face, when compliance frameworks produce documentation without substance, when the mechanisms designed to verify these signals have themselves been optimized for signal production rather than source verification, the infrastructure of collective knowledge is under pressure in a way that no institutional design can fully address. The consequences are already visible outside the security domain: the erosion of shared factual frameworks across democratic societies, the inability to agree on what constitutes evidence, the progressive delegitimation of the institutions (media, regulatory bodies, scientific consensus) that were trusted to verify the verifiers. These are the same mechanism, signal/source split, suppression of detection, exhausted credulity, operating at civilizational scale.</p><p>This is an honest description of a real structural condition, not the counsel of despair that the second error above was warned against. The institutional responses this series has been advocating are necessary. They are not sufficient. The civilizational problem requires something more: not a better institution but a different relationship to the question of how trust is constituted when the old answers no longer hold.</p><p>That different relationship is a cultural achievement rather than a design solution. It cannot be mandated, regulated, or installed. It has to be recovered, which means it has to be understood as something that can be lost. The capacity of a population to make collective judgments about what is trustworthy and what is not, to distinguish between institutions that are producing accountability and institutions that are performing it, to attend to the alarm rather than suppress it: this capacity is developed through practice, maintained through exercise, and eroded through disuse. A society that has spent decades building institutional architectures designed to suppress the alarm has been training itself not to use the instrument it most needs. The recovery is the decision to stop suppressing an old capacity, not the development of a new one.</p><div><hr></div><h2>What Can Be Recovered</h2><p>What has been lost is not trust itself. Trust, as a human capacity, is not something that can be taken away. What has been lost, or is in the process of being lost, is the shared epistemic infrastructure that made trust legible: the common frameworks for evaluating signals, the shared conventions about what kinds of evidence were sufficient for what kinds of claims, the institutional mechanisms that were trusted to verify the verifiers.</p><p>This loss is not evenly distributed. It is concentrated in the domains where the signal/source split has advanced furthest: digital communication, institutional accountability, the credentialing systems that proxy for direct observation of capability and character. It has not reached the domains of direct physical experience, extended personal relationship, and small-group cooperation, where the original detection mechanisms still operate with something approaching their original fidelity. The observation is uncomfortable but important: the recovery of adequate trust infrastructure will look more like the trust model of the environments the detection system was calibrated for than like the large-scale institutional trust that post-valley signal synthesis has undermined. The principle is not smallness (the scale of modern cooperative endeavor is not reversible, and the effort to reverse it would cost more than the problem it was solving) but proximity.</p><p>I started to write a paragraph here about what trust looks like at the individual level in this environment, what it means for a person rather than an institution, and realized I don't have an answer that isn't either nostalgic or naive. I kept writing it and kept deleting it. The honest version is that individual trust, in the post-valley condition, requires something that no essay can provide: the slow accumulation of direct observation, the willingness to attend to the alarm when it fires, and the acceptance that the signals we used to rely on are no longer sufficient. That is not a program. It is a disposition. And dispositions cannot be mandated; they can only be cultivated, or eroded.</p><p>What can be described more precisely is what proximity means at the institutional level.</p><p>Proximity between decision-makers and the reality they are deciding about. Governance mechanisms designed so that the people making consequential trust decisions can observe, over time and variety, the entities they are trusting, rather than relying on documentation that travels through layers of institutional translation before reaching them.</p><p>Proximity between accountability claims and the mechanisms that test them. Compliance frameworks in which the distance between the claim and the test is short enough that the claim cannot be optimized independently of the substance.</p><p>Proximity between the expression of alarm and the people who have the authority and the obligation to respond to it. Organizations in which the alarm does not pass through five layers of management filtering before reaching someone who can act, because at each layer, the suppression machinery has another opportunity to engage. This is what protecting the unsuppressed looks like in practice: not a whistleblower hotline, but an architecture in which the alarm's signal path is short enough that suppression cannot accumulate.</p><p>The point is structural, not romantic: the detection mechanism still functions reliably in environments of proximity, and the question is what it would mean to design institutions that allow its functioning rather than impeding it. The alarm was calibrated for a world of proximity, where the distance between signal and source was short enough that the coherence check could operate. The institutional project of the post-valley condition is to recover that proximity, not by making organizations smaller, but by making the critical channels shorter.</p><div><hr></div><h2>A Final Observation About the Alarm</h2><p>There is something worth saying at the end of this series about the alarm itself, about the coherence check, the prediction error mechanism, the felt wrongness that has appeared in every essay as the most direct and most suppressed instrument of trust detection.</p><p>The alarm is not infallible. It fires for reasons that are sometimes wrong: for unfamiliarity masquerading as incongruence, for difference mistaken for deception, for the cognitive dissonance produced by encountering a genuine person or institution that does not conform to the expected pattern. The history of the alarm's failure modes is not short, and some of those failures have caused real harm.</p><p>The argument of this series has not been that the alarm is always right. It has been that the alarm is more often right than the suppression mechanisms credit, that its failure mode in the current environment is predominantly false negative rather than false positive, and that the social and institutional architecture that converts alarm into silence is doing more damage than the alarm's imperfections.</p><p>This is a calibration argument, not an infallibility argument. The alarm needs to be calibrated: its outputs need to be taken seriously as inputs to an investigative process, not acted on blindly as commands. What it does not need is to be suppressed by default, because suppression by default is the mechanism that all of the threats this series has examined depend on.</p><p>We have, over a long period of social development, professional culture-building, and institutional design, become very good at suppressing the alarm. We have built that suppression into our professional norms, our organizational hierarchies, our verification mechanisms, our compliance frameworks.</p><p>We have confused the suppression with wisdom and the unsuppressed with naivety.</p><p>The post-valley condition is the condition in which the cost of that confusion has become visible. The alarm that was overridden by the performance of normalcy at Orion, where sixty million dollars followed the signals out the door. The alarm that could not fire at all during the Arup deepfake call, because the simulation had crossed the valley. The alarm that went undetected for eighteen months in the carriers' networks before Salt Typhoon surfaced it. The alarm that dissolved under political pressure when documented federal access controls proved decorative. The alarm that Peiter Zatko carried and was fired for. The alarm that North Korean operatives rendered invisible by inhabiting trusted organizational space as synthetic colleagues for months at a time. These are not isolated failures. They are the predictable output of a system that has been optimized, at every level, to suppress the instrument it most needs.</p><p>The valley that Masahiro Mori mapped in 1970 was a region of alarm. We have spent fifty years learning to cross it by suppressing the alarm rather than addressing what the alarm was detecting. The crossing we find ourselves in now is the consequence of that choice.</p><p>What lies on the other side is not determined. It is not inevitable that the infrastructure of trust continues to degrade, that the institutional uncanny valley deepens, that the alarm is progressively rendered inoperative by the combination of signal synthesis and social suppression. These are tendencies, not destinies. They can be reversed, not quickly, not easily, not through any single institutional reform or technical solution, but through the accumulated effect of design choices that are made with clear eyes about what the problem actually is.</p><p>And here, at the end of the series, I find myself thinking not about the civilizational abstraction but about the finance worker at Orion who transferred sixty million dollars because the signals were right and the alarm did not survive the context. I think about that person because they are the scale at which this problem is actually experienced: one person, one decision, one moment in which everything this series has described, the signal/source split, the suppression mechanism, the organizational culture that makes acting on alarm costly, converges on a single human being who has to decide whether to trust what they are seeing. The civilizational problem is real. But it is composed of moments like that one.</p><p>The problem is not, at its root, a security problem, though security is where the consequences are most measurable. It is not a technology problem, though technology is what has changed the conditions. It is not even, primarily, a governance problem, though governance is where the institutional responses must be built.</p><p>It is the problem of a species that built its cooperative infrastructure on the assumption that the signals of authenticity could be trusted, discovering, in real time, at civilizational scale, that they cannot. And choosing, in the face of that discovery, what to build next.</p><p>That choice is still available. It is the choice this series has been, in its way, arguing for: to stop suppressing the alarm, to build institutions that protect its function, to design verification that tests the source and not just the signal, to recover the proximity between decision and reality that the alarm was calibrated for.</p><p>The alarm is still working.</p><p>The question is whether we will finally stop turning it off.</p><div><hr></div><p><em>This is the final essay in The Valley of False Signals, a six-part series on trust, mimicry, and the collapse of authentication. The series begins with Essay One &#8212; The Alarm.</em></p><div><hr></div><h2>Sources</h2><h3>Foundational Reference</h3><p>Mori, M. (1970). Bukimi no tani [The uncanny valley]. <em>Energy</em>, 7(4), 33&#8211;35. (In Japanese.) English translation: Mori, M., MacDorman, K.F., &amp; Kageki, N. (2012). The uncanny valley [From the field]. <em>IEEE Robotics &amp; Automation Magazine</em>, 19(2), 98&#8211;100.</p><h3>Structural Trust and Institutional Economics</h3><p>The essay's distinction between evidentiary trust and structural trust draws on the foundational literature of mechanism design and institutional economics:</p><p>Hurwicz, L. (1972). On informationally decentralized systems. In R. Radner &amp; C.B. McGuire (Eds.), <em>Decision and Organization: A Volume in Honor of Jacob Marschak</em> (pp. 297&#8211;336). North-Holland. (Foundational framework for analyzing institutions as mechanisms that structure incentives and information.)</p><p>Hurwicz, L., &amp; Reiter, S. (2006). <em>Designing Economic Mechanisms</em>. Cambridge University Press.</p><p>Maskin, E. (1999). Nash equilibrium and welfare optimality. <em>Review of Economic Studies</em>, 66, 23&#8211;38. (Originally circulated 1977. Implementation theory and the design of institutions that produce desired outcomes from self-interested actors.)</p><p>Myerson, R.B. (1981). Optimal auction design. <em>Mathematics of Operations Research</em>, 6(1), 58&#8211;73.</p><p>The 2007 Nobel Prize in Economics was awarded to Hurwicz, Maskin, and Myerson for their foundational contributions to mechanism design theory.</p><h3>Institutional Design and Governance</h3><p>Ostrom, E. (1990). <em>Governing the Commons: The Evolution of Institutions for Collective Action</em>. Cambridge University Press. (Institutional design principles for systems that produce cooperative behavior through structural incentives rather than signal-based trust.)</p><p>The essay's reference to "the branch of political philosophy concerned with how constitutions should be designed to produce good governance even from self-interested actors" draws on a tradition extending from James Madison's <em>Federalist Papers</em> (particularly Nos. 10 and 51, on designing institutions that channel self-interest toward collective good) through modern constitutional design theory.</p><h3>The Three Errors</h3><p>The essay identifies three common errors in responding to the collapse of signal-based trust:</p><p><strong>Technical solutionism</strong> references include the liveness detection arms race documented in Essay Three (see Essay Three sources: iProov, Sumsub, MITRE ATLAS), zero-knowledge proofs for identity (the broader decentralized identity literature), continuous behavioral biometrics, and hardware-bound authentication tokens.</p><p><strong>Cynical withdrawal</strong> is described as a structural tendency rather than attributed to a specific source. The essay's analysis of this error draws on the broader literature on institutional trust and social capital erosion.</p><p><strong>Nostalgic restoration</strong> references include regulatory approaches to synthetic media: watermarking requirements, provenance tracking (e.g., the Coalition for Content Provenance and Authenticity, C2PA), and synthetic media disclosure mandates under various national and proposed international frameworks.</p><h3>Case Catalogue (Closing Section)</h3><p>The closing section references six cases documented in detail across the preceding essays:</p><p>Orion S.A. BEC fraud, 2024 ($60 million). See Essay Two sources.</p><p>Arup deepfake video conference fraud, 2024 ($25 million). See Essay Three sources.</p><p>Salt Typhoon telecommunications intrusion (eighteen months undetected). See Essay Four sources, originally analyzed in the author's <em>Compound Vulnerability</em> series.</p><p>Department of Government Efficiency federal access control failures, early 2025. See Essay Four sources, originally analyzed in the author's <em>Compound Vulnerability</em> series.</p><p>Zatko, P. ("Mudge"). Twitter whistleblower complaint, 2022. See Essay Five sources.</p><p>North Korean synthetic worker campaign (Famous Chollima), 2022&#8211;present (320+ organizations infiltrated). See Essay Three sources.</p><h3>Cross-Series References</h3><p>Brondani, M. Essays One through Five of <em>The Valley of False Signals</em>. Published at marcobrondani.com.</p><p>Brondani, M. <em>Reality Hunger</em> and <em>The Compound Vulnerability</em> (essay series). Published at marcobrondani.com.</p>]]></content:encoded></item><item><title><![CDATA[The Unsuppressed]]></title><description><![CDATA[There is a person in your organization who has been telling you something is wrong. Not loudly. Not with a polished deck. In the register organizations find most difficult to process: persistent, imprecise, and professionally inconvenient.]]></description><link>https://www.marcobrondani.com/p/the-unsuppressed</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-unsuppressed</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Wed, 25 Mar 2026 06:07:16 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/3df30ae4-de55-4733-9461-6e33ff220b16_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HXib!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HXib!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!HXib!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!HXib!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!HXib!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HXib!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HXib!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!HXib!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!HXib!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!HXib!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F173c49bf-bd40-4966-ab50-c2b38eff779d_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Essay Five of <em>The Valley of False Signals </em>series</p><p><strong>In brief</strong></p><ul><li><p>Most organizations hold a few people who will not suppress the alarm: the analyst who keeps escalating, the auditor who writes the same finding three years running, the CISO who is accurate rather than reassuring. They are usually the most capable, and the most marginalized.</p></li><li><p>Research on the uncanny valley in autistic children, where the effect is attenuated, points to something useful: detection and social suppression are separable operations. The suppression is a learned social move, not a fixed part of perceiving the wrongness.</p></li><li><p>Organizations remove these people quietly, through credibility erosion, narrowed scope, process capture that logs every alarm and acts on none, and the social cost of being the one who makes meetings tense. Peiter Zatko&#8217;s Twitter disclosure shows the full sequence run against a single person.</p></li><li><p>Red teams and whistleblower systems are structural attempts to protect the alarm, and both get recaptured by the culture they were meant to resist: scope negotiated with management, protection that stops at formal retaliation while the informal costs go on.</p></li><li><p>Protecting the alarm-carrier is infrastructure, not HR: independent reporting lines, a short signal path from alarm to someone who can act, and a culture that treats &#8220;something is off and I can&#8217;t say what&#8221; as intelligence rather than poor judgment.</p></li></ul><div><hr></div><p>There is a person in your organization, possibly several, who has been telling you something is wrong.</p><p>Not loudly. Not with a polished deck and a clear remediation roadmap. In the register that organizations find most difficult to process: the persistent, imprecise, and professionally inconvenient insistence that something in the system does not cohere. The analyst who keeps escalating a vendor concern that everyone else considers resolved. The auditor who writes the same finding three engagements in a row because the remediation never quite closes. The engineer who flags an architectural decision as a future exposure and is told, repeatedly, that the business has accepted the risk. The CISO who frames the board presentation in terms that are accurate rather than reassuring and finds, over time, that the invitations become less frequent.</p><p>These people are not difficult. They are not lacking in social intelligence or professional judgment. They are, in many cases, the most technically capable people in their organizations. What they share is a specific resistance: a failure, or a refusal, to perform the social operation that the organization's culture requires, the suppression of alarm that cannot be fully articulated.</p><p>This essay is about them. What they share, structurally. Why organizations systematically marginalize them. And what it would mean to build institutional architecture that protects their function rather than eroding it.</p><p>The answer to that last question requires a detour through developmental neuroscience and the philosophy of institutional design that may feel, initially, distant from the cybersecurity governance problems this series has been examining. The distance is not as great as it appears.</p><div><hr></div><h2>The Research That Changes the Frame</h2><p>In 2018, a team of researchers at Peking University published a study with a finding that has received far less attention than it deserves. They were examining the uncanny valley effect in children, specifically whether the effect Mori described in adult responses to humanoid robots was present in younger populations, varying the realism of facial appearance and inducing perceptual mismatch in ways shown to trigger the uncanny valley response in adults.</p><p>Their control group, typically developing children, showed the expected effect. As facial realism increased and approached but did not reach full human likeness, preferences declined. The alarm fired. The uncanny valley was present and robust.</p><p>The children with autism spectrum disorder showed no such effect. Their preference curve did not display the characteristic valley. None of the features that produced strong negative responses in typically developing children triggered the same alarm. The uncanny valley, for this population, was absent.</p><p>This finding has been replicated in multiple subsequent studies. If the uncanny valley effect is, as the first essay in this series argued, a trust detection mechanism rather than an aesthetic response, then its absence in ASD represents a structurally different relationship to the detection mechanism itself. And that structural difference has consequences that extend well beyond robot therapy.</p><div><hr></div><h2>What the Absence Means</h2><p>The uncanny valley alarm, as established in Essay One, fires when the brain detects incongruence between what an entity signals and what it is. The <em>suppression</em> of that alarm is a separate operation: the professional norm, the hierarchical deference, the discomfort of accusing someone of deception without articulable proof. Detection is perceptual. Suppression is social.</p><p>The critical question: in the ASD population, which operation is different? The research does not resolve this cleanly, and intellectual honesty requires saying so. What it does establish, across multiple studies and in both child and adult ASD populations, is that the behavioral output is different: the avoidance behavior, the expressed preference decline, the reported eeriness are attenuated or absent. The proposed mechanisms vary (differences in how prior social experience calibrates the detection model, differences in social motivation, differences in how social norming converts alarm into suppression) and the research has not settled which account is most accurate.</p><p>What matters for our purposes is the structural implication that all three mechanisms share: the relationship between the detection system and the social suppression operation is different. Whether the alarm calibrates differently, or fires differently, or reaches expression differently, the output is a detection profile that is less shaped by the social forces that, in the typical case, convert alarm into suppression and suppression into compliance.</p><div><hr></div><h2>The Inversion</h2><p>Here is where the argument takes a turn that requires careful handling.</p><p>The absence of the uncanny valley effect in ASD has been framed, in the research literature, primarily as a deficit: something is missing from the social alarm system. This framing makes sense within the therapeutic context.</p><p>But the framing inverts when the context is adversarial. In an environment where sophisticated actors are systematically producing signals of authenticity disconnected from their actual intentions, the alarm that typically developing individuals possess is an asset with a critical vulnerability: it is susceptible to the suppression mechanism. The reliable operation of the alarm depends on the social suppressability of the alarm being resisted. And resistance to the suppression mechanism is not, in the typical developmental profile, strongly selected for. The social costs of unsuppressed alarm expression are real, and the social environment reliably punishes their expression. People who do not perform the suppression are difficult. Organizations prefer people who perform it.</p><p>This preference is the source of institutional vulnerability. Not because it is irrational (it is rational for the ninety-nine percent of interactions that are not adversarial) but because in the specific subset that are adversarial, the suppression preference produces exactly the exposure that sophisticated attackers and institutional drift rely on.</p><p>Resistance to the suppression mechanism is not strongly selected for in typical professional development. The social costs of unsuppressed alarm expression, the professional friction, the accusation of paranoia, the disruption of cooperative relationships, are real. The social environment reliably punishes their expression. This is not a design flaw. It is a design feature whose costs have changed.</p><p>The question the ASD research raises, indirectly, is whether the suppression operation is separable from the detection operation in ways that could be structurally exploited for defensive purposes. Not "can we make people more like autistic individuals," which is both clinically wrong and ethically untenable. But: what can the existence of a different detection-suppression profile teach us about how to design institutional architectures that protect detection outputs from social override?</p><p>This is the inversion. The research that was conducted to understand a population that lacks a typical alarm response turns out to illuminate something about the alarm response itself, specifically about the social operation that converts alarm into silence, and about what happens when that operation is attenuated or differently regulated.</p><div><hr></div><h2>A Necessary Pause</h2><p>Before proceeding, something needs to be stated directly and without qualification.</p><p>Autism spectrum disorder is not a superpower, not a security asset, and the people who have it are not instruments for organizational detection architectures. The research findings summarized above do not establish that autistic individuals are better at security; they establish something much more specific and limited: that a particular behavioral output of the uncanny valley alarm is attenuated in this population, and that this attenuation involves the relationship between detection and social suppression.</p><p>The lived experience of autism includes challenges in social navigation, sensory processing, executive function, and communication that are real and often severe. The absence of the uncanny valley effect is not, for the people who live with ASD, primarily experienced as an advantage. It exists within a broader profile that the neurotypical world has not been designed to accommodate.</p><p>What the research offers is a structural insight, not a personnel recommendation. The suppression mechanism is a social operation applied to detection outputs, not an inevitable feature of the detection process itself, and it can, in principle, be differently regulated. The detour through ASD research is a lens, not a template. It shows us something about the structure of the problem that neurotypical cognition, precisely because it takes the suppression operation for granted, cannot easily see from the inside.</p><div><hr></div><h2>The People Who Do Not Suppress</h2><p>Return to the person at the beginning of this essay. The analyst who keeps escalating. The auditor who writes the same finding three years running. The engineer who will not accept "business has accepted the risk" as a final answer.</p><p>These people are not, generally, autistic, or at least, that is not what defines their functional profile in the organizational context. What defines it is a particular relationship to the organizational suppression pressure that most professionals navigate as automatic. They feel the pressure. They understand it. In many cases, they have paid professional costs for not complying with it. And they do not comply anyway.</p><p>The reasons are various. Some have an unusually high tolerance for professional friction. Some have a professional identity built around a specific obligation: the auditor who understands their role as a fiduciary function compromised by social deference, the security researcher who has internalized a specific ethical commitment to disclosure. Some have experienced, personally and concretely, the consequences of suppression, and the memory of it makes the social cost of speaking feel small by comparison. And some have a cognitive style that processes the social suppression pressure differently, that perceives the organizational norm to perform the override as a distinct thing from the professional obligation to report accurately, and declines to conflate them. This cognitive style exists on a spectrum, is distributed across the population, and is not reducible to any single neurological profile. But it shares, structurally, the feature that the ASD research illuminates: the suppression operation is not automatic. It is perceived as a separate choice, subject to a separate judgment. And the judgment, in these people, consistently comes back: the alarm is more important than the comfort. The choice is refused.</p><p>These are the people organizations most consistently fail to protect, and most consistently fail to use.</p><p>In 2022, Peiter "Mudge" Zatko, one of the most respected figures in the cybersecurity community, a former member of the L0pht hacking collective who had testified before Congress on network security in 1998, filed a whistleblower complaint against Twitter, where he had served as head of security. Zatko alleged that Twitter's executive team had instructed him to present cherry-picked data to the board to create a false impression of progress on security issues, had a consulting firm's report scrubbed to minimize its findings, and had the CEO discourage him from being fully transparent with the board about the company's actual security posture. He documented servers running outdated software lacking basic security features, thousands of employees with broad and poorly monitored access to core systems, and approximately one security incident per week serious enough to require government reporting.</p><p>The company's response was to characterize Zatko as having been fired for "ineffective leadership and poor performance," a classic instance of credibility erosion. His alarm, which had been raised internally and documented, was reframed as evidence of his inadequacy rather than evidence of the gap he was describing.</p><p>The Zatko case matters because it demonstrates every mechanism of institutional suppression operating in sequence against a single person. But Zatko had resources most alarm-carriers do not: a national reputation, legal representation from a nonprofit whistleblower firm, and a public moment (the concurrent Musk acquisition dispute) that gave his allegations an audience. Most people who carry the alarm have none of these. They have only their observation and the organizational culture that surrounds it.</p><div><hr></div><h2>How Organizations Suppress the Unsuppressed</h2><p>The mechanisms are numerous, varied, and rarely explicit. They operate through ordinary professional culture rather than through direct censorship.</p><p>Credibility erosion is the most common: the gradual reframing of persistent alarm as evidence of poor judgment rather than accurate detection. The professional consequence is not dismissal; it is the progressive withdrawal of institutional trust, which operates through smaller signals, the meeting invitation that stops arriving, the project that goes to someone else, the promotion that is indefinitely deferred. Scope limitation is subtler: moving the unsuppressed person from functions with broad organizational visibility to functions with narrow technical scope, where their observations become invisible to the people who might act on them.</p><p>The most sophisticated mechanism is process capture, which converts the unsuppressed person's output into the compliance apparatus itself. Their findings are acknowledged, logged, assigned to remediation owners, tracked in the risk register, and reviewed in the quarterly governance meeting. Every alarm is formally received. None of it changes the posture. The organizational machinery for receiving the alarm and the organizational machinery for acting on it are decoupled. The finding goes in the register. The register goes to the committee. The committee notes the finding. The finding ages.</p><p>And perhaps the most damaging is social isolation: the informal cost of being the person who names the wrongness. The difficult colleague. The one who makes meetings tense. The one who, when they walk into the room, produces a subtle shift in the atmosphere because everyone knows they may say something uncomfortable. The social isolation is rarely deliberate. It is the aggregate output of individual decisions to prefer comfortable company, which is to say, it is the suppression mechanism operating at the social level.</p><div><hr></div><h2>Red Teams and Whistleblower Systems</h2><p>Before asking what institutional design could protect the alarm, it is worth examining the two mechanisms that have explicitly tried.</p><p>The red team is, at its best, a structural attempt to create an organizational function whose purpose is to not suppress the alarm. Its mandate is adversarial: to find the gaps between what the institution claims and what it is, to produce findings that are uncomfortable rather than reassuring. Its value depends on its independence from the organizational culture that would otherwise convert its findings into the compliance register.</p><p>When red teams work, they work because they externalize the permission to alarm. They do not rely on individual resistance to suppression pressure; they create an institutional role that makes suppression impermissible, or at least much more costly. The red team analyst who finds a critical exposure has a mandate, a role, an institutional permission structure that converts the alarm into a deliverable rather than a career risk. The gap between what a red team finds and what the compliance apparatus documents is a direct measure of how much the suppression mechanism has cost the organization.</p><p>But red teams have their own failure modes, and understanding them matters. Their findings get converted into the compliance register. Their scope is limited by the same management that controls the systems being tested. Their independence is conditional on the continued support of the hierarchy they are supposed to challenge. In organizations where the institutional uncanny valley has deepened, where the gap between claimed and actual posture is large and acknowledged at the level of senior leadership, the red team's findings are received as a threat to management rather than intelligence for it, and the team's scope and independence are progressively curtailed. The red team is a structural workaround for the suppression problem, and a valuable one. It is not a solution, because it is still embedded in the organizational culture that generates the suppression pressure.</p><p>Whistleblower systems, the formal mechanism for protecting alarm against suppression, perform similarly. Academic research consistently finds that formal protection mechanisms fail to prevent the informal costs of whistleblowing: the credibility erosion, the scope limitation, the social isolation. Legal protection from termination does not protect against being moved to a role with no visibility. Anonymous reporting channels do not protect against the informal attribution of reports to the small number of people with access to the relevant information. Regulatory protection for safety reporting does not prevent the organization from making the whistleblower's professional life sufficiently unpleasant that resignation becomes the rational choice.</p><p>The failure mode is the same as the compliance framework failure mode: they produce the signal of protection without its substance. The gap between the documented protection and the experienced protection is the institutional uncanny valley of whistleblower systems.</p><div><hr></div><h2>Toward Adversarially Resistant Detection Architecture</h2><p>What would institutional design look like if it were built to protect detection from suppression rather than to produce documentation of assurance?</p><p>This is not a question the security governance literature has directly addressed, and the reason is the same reason that security awareness training has not addressed the suppression layer: the field has been focused on the detection capacity, not on the social architecture that determines whether detection outputs reach action. Several principles suggest themselves, drawn from the analysis above and from the places where suppression-resistant detection has been attempted and partially achieved.</p><p>The most powerful protection is structural independence of alarm functions: genuine separation between the function that generates alarm and the function that manages the operations the alarm is about. The independence must be real, not just documented; reporting lines, budget authority, and scope definition that cannot be controlled by the management layer being evaluated. Closely related is output that bypasses hierarchy: architecture that routes alarm directly to board-level or external oversight without requiring management endorsement or framing. The suppression mechanism operates primarily through hierarchy; findings that pass through management layers get filtered before they reach decision-makers. Reducing the number of points at which suppression can be applied is structurally uncomfortable for management, which is precisely why it is rarely implemented in its strong form, and precisely why the strong form is where the protection lives.</p><p>Formal protection for alarm-carriers must have teeth. Whistleblower protections that address only formal retaliation leave the informal suppression machinery intact. Protection that genuinely prevents the informal costs (the scope narrowing, the credibility erosion, the social isolation) requires monitoring and enforcement mechanisms at least as sophisticated as the informal machinery they are trying to counteract. This is expensive, intrusive, and organizationally uncomfortable. It is also the difference between a protection signal and actual protection.</p><p>And the deepest change is cultural rather than structural: the normalization of inarticulate alarm. The professional norm that requires articulable justification before alarm can be expressed is the engine of the suppression mechanism. Changing it requires organizations to explicitly value the expression of inarticulate unease, to create contexts in which "something seems off and I can't say exactly what" is a legitimate input rather than evidence of poor judgment. This is the hardest change because it runs against how professional cultures define rigor and rationality. It requires accepting that the alarm system is sometimes more accurate than the documentation, and that acting on the alarm before the documentation catches up is not paranoia but intelligence.</p><div><hr></div><h2>What the Cassandra Problem Teaches</h2><p>The Cassandra myth is old enough that it has become a clich&#233;, but its precise structure deserves attention.</p><p>Cassandra was given the gift of true prophecy and the curse that no one would believe her. The standard reading emphasizes the social reception of accurate alarm. That reading is correct and important. But there is another element that gets less attention: the cost to Cassandra herself. The experience of being the person who sees accurately and is systematically disbelieved, who watches the consequences of suppressed alarm unfold in slow motion, produces its own pathologies: the escalating alarm that loses credibility by virtue of its persistence, the psychological toll of sustained professional isolation, the progressive narrowing of the space from which accurate signals can be transmitted.</p><p>The institutional suppression machinery does not just silence individual alarms. It degrades the people who carry them. The analyst who has been told repeatedly that their concern is unfounded eventually faces a choice: absorb the professional cost of continued escalation, or absorb the psychological cost of self-suppression. Many capable people make the second choice, not because they stop seeing accurately, but because the cost of seeing accurately, in a context that will not receive what they see, becomes unsustainable.</p><p>The organizations that lose these people do not lose them all at once. They lose them gradually, as the space for accurate alarm narrows, and the professional costs of occupying that space accumulate, and the people who occupy it calculate that there is no longer a path from accurate detection to any useful response. This is the final mechanism of institutional suppression: not silence, but exhaustion.</p><div><hr></div><p>The suppression mechanism is a feature of how human social life manages the tension between cooperative trust and adversarial vigilance, not a corporate pathology or a security industry problem. The norms that generate suppression pressure are the norms that make large-scale cooperative life possible. They are functional, in the environments they were developed for.</p><p>The question is whether those environments still describe the world we are operating in. The base rate of sophisticated deception, at the individual level, the organizational level, and the institutional level, has increased. The cost of producing convincing simulations of authenticity has collapsed. The scale at which deception operates has expanded from the interpersonal to the civilizational.</p><p>The suppression mechanism is running on obsolete parameters, suppressing alarms at a rate calibrated for a world with far fewer genuine threats in an environment with far more of them. The recalibration required is specific: a higher assumed base rate of sophisticated deception at every scale, a lower cost threshold for acting on alarm before articulable evidence is available, and institutional structures that treat the cost of occasional false-positive caution as categorically lower than the cost of the false-negative compliance it prevents. This is the urgency inversion that Essay Two identified in the social engineering context, extended to institutional design: alarm should trigger more scrutiny, not less, and the organizational cost of acting on alarm should be lower than the organizational cost of suppressing it. And the people who, for whatever combination of cognitive style, professional commitment, and accumulated experience, are less subject to the suppression pressure, the people who keep naming the wrongness despite the cost, are the people whose function has become more valuable than it has ever been.</p><p>Protecting them is an epistemic infrastructure question, not a human resources question. They are nodes in the detection architecture. What happens to them, whether they are protected or eroded, whether their outputs reach decision-makers or disappear into the compliance register, determines whether the institutions they inhabit maintain any capacity to perceive the gap between their signals and their reality.</p><p>The institutional uncanny valley persists as long as the alarm is suppressed. The alarm is suppressed as long as the people who carry it are not protected. Protecting them is not comfortable. It is, in the environment this series has been describing, necessary.</p><div><hr></div><p><em>Next: Essay Six &#8212; After the Valley. On what trust looks like when signals can no longer be taken at face value, and what it would mean to build the infrastructure of trust again, from different foundations.</em></p><div><hr></div><h2><strong>S</strong>ources</h2><h1></h1><h3>ASD and the Uncanny Valley</h3><p>Feng, S., Wang, X., Wang, Q., Fang, J., Wu, Y., Yi, L., &amp; Wei, K. (2018). The uncanny valley effect in typically developing children and its absence in children with autism spectrum disorders. <em>PLOS ONE</em>, 13(11), e0206343. (Primary study: Peking University. Typically developing children showed the uncanny valley effect; children with ASD did not. Varied facial realism through morphing and induced perceptual mismatch through eye-size modification.)</p><p>Kumazaki, H., Warren, Z., Muramatsu, T., Yoshikawa, Y., Matsumoto, Y., Miyao, M., Nakano, M., Mizushima, S., Wakita, Y., Ishiguro, H., Mimura, M., Minabe, Y., &amp; Kikuchi, M. (2017). A pilot study for robot appearance preferences among high-functioning individuals with autism spectrum disorder. <em>PLOS ONE</em>, 12(10), e0186581. (Replication context: ASD individuals showed different responses to humanoid robot appearance compared to typically developing individuals.)</p><p>Li, L., Imaizumi, T., Nishikawa, N., Kumazaki, H., &amp; Ueda, K. (2025). Do individuals with autism spectrum disorder not experience the uncanny valley? A psychological experiment and feature analysis using human and robot faces. <em>Cognitive Development</em>, 73, 101519. (Replication with robot and human facial images: typically developing individuals exhibited the uncanny valley effect; individuals with ASD showed a less distinct effect, with analysis suggesting emphasis on local rather than global facial information.)</p><p>Kumazaki, H., Muramatsu, T., Yoshikawa, Y., Matsumoto, Y., Ishiguro, H., Mimura, M., &amp; Kikuchi, M. (2015). A Bayesian model of the uncanny valley effect for explaining the effects of therapeutic robots in autism spectrum disorder. <em>PLOS ONE</em>, 10(9), e0138642. (Computational modeling: proposed that ASD produces an "uncanny cliff" rather than an "uncanny valley," with implications for robot-assisted therapy design.)</p><h3>Whistleblower Case Study</h3><p>Zatko, P. ("Mudge"). (2022). Whistleblower disclosure to the U.S. Securities and Exchange Commission, the Federal Trade Commission, and the Department of Justice, filed July 6, 2022. Allegations concerning Twitter, Inc.'s security practices, including misrepresentation of security posture to the board, scrubbing of third-party consulting findings, and systemic access control deficiencies.</p><p>Twitter's response characterizing Zatko as having been fired for "ineffective leadership and poor performance" was reported by multiple outlets including <em>The Washington Post</em>, <em>CNN</em>, and <em>The New York Times</em>, August 2022. The complaint became public during the concurrent Musk acquisition dispute.</p><p>For background on Zatko's career: Zatko testified before the U.S. Senate Committee on Governmental Affairs on network security vulnerabilities as a member of the L0pht hacking collective in 1998.</p><h3>Whistleblower Research</h3><p>The essay references academic research on the failure modes of formal whistleblower protection systems. Key works in this literature include:</p><p>Miceli, M.P., Near, J.P., &amp; Dworkin, T.M. (2008). <em>Whistle-blowing in Organizations</em>. Routledge/Psychology Press.</p><p>Moberly, R. (2012). Sarbanes-Oxley's whistleblower provisions: Ten years later. <em>South Carolina Law Review</em>, 64, 1.</p><p>Kenny, K. (2019). <em>Whistleblowing: Toward a New Theory</em>. Harvard University Press. (Documents the informal suppression mechanisms &#8212; credibility erosion, scope limitation, social isolation &#8212; that operate below the threshold of legal actionability.)</p><h3>Organizational Suppression and Red Team Literature</h3><p>The essay's analysis of organizational suppression mechanisms (credibility erosion, scope limitation, process capture, social isolation) draws on established organizational psychology and security governance literature. The red team analysis draws on practitioner experience and the broader adversarial design principles developed in Essay Four.</p><h3>Cassandra Problem</h3><p>The Cassandra myth is referenced as a structural analogy for the cost of carrying suppressed alarm. The essay's analysis of the cost to the alarm-carrier (escalating persistence losing credibility, psychological toll, progressive narrowing of transmission space) draws on the whistleblower research cited above and on practitioner literature in organizational psychology.</p><h3>Cross-Series References</h3><p>Brondani, M. Essay One: "The Alarm" (uncanny valley as trust detection mechanism, prediction error, suppression mechanism). Essay Two: "Cold Empathy at Scale" (urgency inversion, three suppression norms). Essay Four: "The Narcissistic Institution" (adversarial design principles, compliance framework failure modes). <em>The Valley of False Signals</em>. Published at marcobrondani.com.</p>]]></content:encoded></item><item><title><![CDATA[The Narcissistic Institution]]></title><description><![CDATA[The institution looks secure. It sounds compliant. The documentation says everything it should. And something is wrong, in a way that is difficult to name, because the performance is convincing enough that naming the wrongness feels like overreach.]]></description><link>https://www.marcobrondani.com/p/the-narcissistic-institution</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-narcissistic-institution</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Thu, 19 Mar 2026 08:37:15 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cdbb5b67-7a24-4ea8-a811-c35411845126_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QBCe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QBCe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!QBCe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!QBCe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!QBCe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QBCe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QBCe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!QBCe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!QBCe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!QBCe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1fa2c3fa-20af-4d73-bfaf-5ff51de6a8f4_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Essay Four of <em>The Valley of False Signals </em>series</p><p><strong>In brief</strong></p><ul><li><p>Institutions have their own uncanny valley: they produce the signals of accountability, the compliance reports, certifications, and risk registers, with those signals no longer connected to accountable behavior. The documentation says everything it should, and something is still wrong.</p></li><li><p>The drift is structural, not fraud. It accumulates from small, defensible decisions, the control that lives in the policy but is too costly to enforce, the audit finding rolled forward each quarter, until the documented posture and the real one quietly come apart.</p></li><li><p>Once an organization learns that producing the right artifacts satisfies the observer, the question shifts from &#8220;are we secure?&#8221; to &#8220;do we satisfy the framework?&#8221; The compliance layer grows its own incentives, and they do not track the thing being measured.</p></li><li><p>The same suppression runs upward. A CISO who names the gap contradicts the whole apparatus of assurance and is being difficult; the board, receiving only what management curates, becomes the most senior link in the suppression chain rather than the check on it.</p></li><li><p>The fix is adversarial design: verification that assumes the gap and tests for it under inconvenient conditions, red teams, independent reporting lines, operational testing. Better frameworks alone produce better theater, because the gap is built into the incentives, not a defect to be patched.</p></li></ul><div><hr></div><p>There is a version of the uncanny valley that operates not at the level of individual deception but at the level of institutional governance. It is the condition in which an organization produces all the signals of accountability (the compliance reports, the audit certifications, the governance frameworks, the risk registers) without those signals being causally connected to actual accountable behavior. The institution looks secure. It sounds compliant. The documentation says everything documentation should say. And something is wrong, in a way that is difficult to name and more difficult to act on, because the norms governing how institutions are evaluated are the same norms governing how narcissists avoid detection: the performance is convincing enough that naming the wrongness feels like an overreach.</p><p>Two cases from earlier work illustrate the condition. I examined the operational details of the Salt Typhoon intrusion in <em>The Compound Vulnerability</em>. What matters here is not what the Chinese state actors did inside those telecommunications networks, but what the carriers had been doing long before the attackers arrived: producing compliance signals, certifications, audit reports, regulatory filings, whose relationship to actual security posture had quietly come apart. The carriers were not negligent by any conventional measure. They had frameworks, programs, and the full apparatus of documented due diligence. Their networks were owned for eighteen months without detection. The gap was not between the carriers and their frameworks. It was between the frameworks and reality.</p><p>The federal access control failures that accompanied the Department of Government Efficiency's deployment in early 2025 demonstrated a parallel condition through a different mechanism. Treasury payment systems, OPM personnel databases, Social Security Administration records: these were governed by access control frameworks developed over decades of federal IT security policy. What the episode revealed was that the documented controls were not the controls that existed in practice. Political will, applied with sufficient force and speed, dissolved mechanisms that were supposed to be procedurally resistant to exactly that kind of pressure. Whatever one's view of the entity's mandate, the structural observation is the same: the documented controls described one reality; the operational pressure revealed another.</p><p>Both cases demonstrate institutions whose accountability signals and accountability substance had drifted apart, in ways that were invisible to normal oversight but became visible under adversarial conditions. Different threat actors, same vulnerability. The vulnerability is the gap between the framework and the reality it is supposed to represent, not the absence of framework itself.</p><div><hr></div><h2>How Institutions Learn to Perform</h2><p>This is not primarily a story about bad actors or deliberate fraud. Institutional drift toward accountability theater is something close to a structural tendency in large organizations operating under compliance regimes, a tendency that emerges not from malice but from the ordinary operation of incentives, bureaucratic rationality, and the social norms that govern professional life in hierarchical organizations. Deliberate fraud is an exception. The drift is the norm.</p><p>The compliance regime is, in its intent, a mechanism for making accountability legible to external observers. The board cannot directly observe every security control. The regulator cannot directly audit every system. The compliance framework (the certifications, audits, reports, and standards) is a translation layer: it converts the internal reality of organizational security into signals that external observers can read and evaluate.</p><p>This translation function is necessary and, when it works, valuable. The problem is that translation layers create their own incentives, and those incentives do not always align with the thing being translated.</p><p>Once an organization has learned that producing certain outputs (a SOC 2 report, an ISO 27001 certification, a NIST CSF assessment) satisfies the external observer's demand for accountability signals, the optimization pressure shifts. The question stops being "are we secure?" and starts being "do we satisfy the framework?" These are not the same question, and organizations that conflate them, under time pressure, resource pressure, and the ordinary human tendency to optimize for what gets measured, begin to drift.</p><p>The drift is an accumulation of small decisions, each individually defensible. The security control that exists in the policy document but is too operationally expensive to enforce. The audit finding that is logged as a remediation item and rolled forward, quarter after quarter, because addressing it would require re-architecting a system that production depends on. The risk register entry that accurately describes a critical exposure but is scored in a way that keeps it below the threshold requiring board attention. The penetration test scoped to avoid the systems most likely to produce embarrassing findings.</p><p>Each individual decision is defensible. The policy document genuinely represents the intended state. The remediation item is genuinely intended to be addressed. The risk score reflects a genuine judgment. But the accumulation produces an institution whose documented security posture and actual security posture have quietly come apart, a signal/source split at the organizational level, invisible in any individual document but structurally present in the gap between what the institution claims and what it is.</p><p>I have been part of this accumulation. I have signed risk acceptances that I knew were optimistic, scoped penetration tests to avoid systems I suspected were vulnerable, and presented dashboards that were accurate at the level of data but misleading at the level of implication. Not from malice. From the same structural pressures I am describing. The drift is easier to see from the outside than to resist from the inside, and the professional cost of resisting it is real.</p><p>This is the same mechanism that Essay One mapped at the individual level, operating at institutional scale. The narcissist produces empathy signals without affective resonance. The institution produces accountability signals without accountability substance. In both cases, the performance is convincing precisely because it is built from genuine components: real certifications, real audit firms, real compliance processes, assembled in a way that satisfies the observer's coherence check while the underlying reality has departed. The compliance framework tells you what signals to produce. It cannot tell you whether producing those signals corresponds to genuine security. That correspondence requires judgment, adversarial testing, and the organizational culture to act on uncomfortable findings. It requires precisely the capacities that the compliance-optimization dynamic tends to erode.</p><p>This is the institution in the uncanny valley. Almost accountable. The signals are there. The source has quietly left.</p><div><hr></div><h2>The Suppression Mechanism at Institutional Scale</h2><p>In personal social engineering, the suppression mechanism is interpersonal: professional courtesy, hierarchy, the discomfort of naming unverifiable alarm. In the institutional context, the suppression mechanism operates at a larger scale, but the structure is identical.</p><p>The CISO who notices the drift, who sees that the risk register is being managed for optics rather than exposure, that the audit findings are being rolled forward rather than remediated, that the security posture claims being made to the board do not correspond to the actual attack surface, faces a version of the same social pressure that faces anyone who notices that the signals and source have separated.</p><p>What they know is difficult to articulate precisely. They have a feeling, compounded of professional experience, pattern recognition, and the particular unease of someone who understands both what the documentation says and what the systems actually do, that the accountability is not real. But the documentation is real. The certifications are genuine. The audit firm is reputable. The risk register was signed off by the right people. Every articulable piece of evidence points toward compliance. Only the inarticulate alarm points the other way.</p><p>And the organizational context generates powerful pressure to suppress that alarm. The board wants assurance, not uncertainty. The CEO wants to present a clean posture to investors and regulators. The audit committee wants findings to be closed, not perpetually open. The external auditor, whose continued engagement depends on maintaining a workable relationship with management, is not structurally incentivized to produce findings that the organization is not prepared to address.</p><p>The CISO who names the gap, who tells the board that the certified posture does not correspond to the actual risk, is making a claim that contradicts the apparatus of institutional assurance. They are being difficult. They are introducing uncertainty into a presentation designed to communicate confidence. They are, in the language of organizational management, not being a team player.</p><p>This is the institutional suppression mechanism. It operates through the same forces that suppress individual alarm: the social cost of naming wrongness that cannot be fully proven, the professional cost of contradicting a consensus that convenient documentation supports, the hierarchical pressure to defer to the process rather than the judgment.</p><p>The difference from the individual case is scale. When the CISO's alarm is suppressed, what is lost is not one person's judgment. It is the organization's only instrument for detecting the gap between its claimed and actual security posture. The suppression of the institutional alarm is the suppression of institutional reality-testing.</p><div><hr></div><h2>AI Governance as Contemporary Case Study</h2><p>The institutional uncanny valley is being constructed in real time in the AI governance domain, and the construction is happening fast enough to watch.</p><p>Since 2016, there has been an extensive global production of AI governance artifacts: principles documents, ethical frameworks, voluntary commitments, model cards, responsible AI programs, algorithmic impact assessments. The OECD AI Principles. The EU AI Act. The US Executive Orders on AI. The major technology companies' responsible AI frameworks.</p><p>The lifecycle of these frameworks has been instructive. In 2019, Google formed its Advanced Technology External Advisory Council, an eight-member AI ethics board meant to guide the responsible development of AI. It lasted nine days before being dissolved. The members never met. In 2023, Microsoft laid off its entire Ethics and Society team, the group responsible for translating the company's stated AI principles into product design, during the same period it was investing over eleven billion dollars in OpenAI and racing to integrate generative AI across its product suite.</p><p>These are not aberrations. They are the expected output of organizations whose competitive incentives and governance commitments point in opposite directions. A former Microsoft team member described the gap to The Verge: people would look at the principles coming from the Office of Responsible AI and not know how they applied. The Ethics and Society team existed to close that gap. It was eliminated precisely when the gap was widest. The production of AI governance signals (principles, commitments, frameworks) is cheap relative to deployment. The production of AI governance substance, the actual constraint of deployment in response to identified risks, is expensive, because it means accepting competitive disadvantage. When the signal and the substance diverge, institutions optimize for the signal.</p><p>The European AI Act is the most serious attempt to create binding governance with actual enforcement consequences. Its implementation has been revealing. The Act's GPAI obligations entered force in August 2025, but the Commission's enforcement powers are delayed until August 2026; a year in which providers must comply but face no penalties for non-compliance. The rules for high-risk AI systems embedded in regulated products have an extended transition period until August 2027. Open-source models meeting certain criteria receive exemptions from several obligations. The Commission itself acknowledged that an informal enforcement grace period may be needed beyond the formal dates. The signal says: AI is now regulated. The infrastructure of enforcement says: not yet. And the deployment continues at pace.</p><p>I am not sure whether to call this cynicism or inevitability, and I think the uncertainty matters. Governance frameworks produced within institutional environments that have a primary interest in the activity being governed will tend, under competitive pressure, to drift toward the production of accountability signals rather than substance. The incentive structure produces the same drift that compliance optimization produces in enterprise security. The framework becomes the performance of governance, not its instrument.</p><div><hr></div><h2>The Board as Structural Accomplice</h2><p>The board of directors occupies a particular position in this dynamic that deserves direct examination, because it is the board that is supposed to close the gap between institutional signals and institutional reality.</p><p>Board-level cybersecurity oversight has expanded dramatically in the past decade. SEC rules require disclosure of material cybersecurity incidents and of board expertise in cybersecurity risk. Audit committees now routinely receive security briefings. Many boards have added CISO presentations to their regular agenda. The signal says: boards are taking cybersecurity seriously.</p><p>The substance is more complicated. A board receiving a security briefing from a CISO is receiving a presentation designed by the very function it is supposed to oversee. The information is filtered through the organizational hierarchy that has its own incentives to present a reassuring picture. Board members, even those with cybersecurity backgrounds, are working from information that the management layer has curated. They are reading the documentation that the institution has produced about itself.</p><p>The structural problem is not that boards are negligent. Effective oversight of institutional security posture requires precisely the kind of adversarial, independent, reality-testing capacity that board governance is not structurally designed to provide. Boards receive information; they do not generate it. They evaluate representations; they do not independently verify them. They assess the quality of management's judgment; they cannot, in any practical sense, substitute their own.</p><p>The three suppression norms that Essay Two identified operate here with particular force. The hierarchy norm: the CISO presents upward to a board that has authority but not expertise to challenge technical claims, and the board defers to management's framing because the alternative requires independent investigation that governance structures do not support. The efficiency norm: board time is scarce, agendas compressed, and the presentation format itself favors assurance over uncertainty; a clean risk dashboard is a thirty-second read, while a qualified assessment of actual posture requires an uncomfortable conversation that may not resolve within the allocated time. The social grace norm: naming the gap between documented posture and actual posture, in a boardroom setting, is an implicit accusation that management has been misrepresenting its own security. No CISO who wants to maintain a functional relationship with the C-suite will make that claim without extraordinary evidence, and the gap, by its nature, produces inarticulate unease rather than extraordinary evidence.</p><p>The result is a board oversight function that operates primarily at the signal level, evaluating the quality and coherence of the accountability documentation, rather than at the source level, evaluating the actual correspondence between that documentation and organizational reality. The board becomes the most senior level of the suppression mechanism, not because its members are captured or dishonest, but because the institutional architecture of oversight does not give them the instruments to do otherwise.</p><p>This is the closing of the loop, and it is worth tracing carefully. The CISO who might name the gap is suppressed by organizational culture. The internal audit function that might surface it is constrained by scope limitations and client relationships. The external auditor is not structurally incentivized to produce findings the organization is not prepared to address. The regulator evaluates the signal because the signal is what has been submitted. And the board, sitting at the top of this chain, receives the output of each prior suppression and processes it as assurance.</p><p>The alarm fires at each level, in each function, in each mind that encounters the gap between what the documentation says and what the systems do. And at each level, the institutional suppression mechanism engages. Not through conspiracy. Through structure.</p><div><hr></div><h2>The Distinction That Changes Everything</h2><p>There is a distinction that the institutional uncanny valley makes available, and it is the most important practical implication of this entire analysis. It is also, I think, the point at which the argument stops being diagnostic and becomes actionable.</p><p>The distinction is between frameworks that are adversarially designed and frameworks that are not.</p><p>A compliance framework that is not adversarially designed asks, implicitly: does this institution produce the signals of accountability? It tests documentation, process, and the coherence of stated practice. It takes the institution's representation of itself as the primary data source. It evaluates the signal.</p><p>A framework that is adversarially designed asks something different: does this institution actually do what it claims to do when the verification is inconvenient, when the pressure is high, when doing what it claims to do has real operational cost? It assumes that the gap between claimed and actual posture is a predictable feature of institutional behavior, not an exceptional failure.</p><p>Adversarial design does not require bad faith toward the institution being evaluated. It requires honest acknowledgment of the structural tendency toward accountability theater, and the deployment of verification approaches calibrated to that tendency rather than to the assumption of good faith compliance. The objection to adversarial design is usually framed as an objection to distrust, as if designing verification for the gap implies an accusation that the institution is dishonest. It does not. It implies that the institution is subject to the same structural pressures that produce the gap in every large organization, and that verification should be designed for the world as it is rather than the world the documentation describes.</p><p>Red team exercises are the clearest existing example at the technical level: rather than asking whether the security controls exist and are documented, they ask whether the security controls work when an actual adversary is trying to defeat them. The difference in what they find, compared to conventional compliance audits, is frequently severe. Organizations that are compliant by every conventional measure are penetrated by red teams in hours.</p><p>At the board level, adversarial design would mean that at least some of the information the board receives about cybersecurity posture is generated independently of the management layer; findings produced by a function that reports to the board directly, with scope and budget the management layer does not control. Internal audit is supposed to serve this function, and in some organizations it does. But in most, the independence is formal rather than operational: internal audit's scope is negotiated with management, its resources are allocated through the management budget process, and its findings are discussed with management before reaching the board. Genuine adversarial independence would require that the board's information about actual posture be produced by a function whose incentives are structurally aligned with finding the gap, not with managing it.</p><p>At the regulatory level, adversarial design would mean moving from documentation review to operational testing. Rather than evaluating whether an institution has submitted the correct filings, the regulator would test whether actual operations correspond to what the filings describe, under conditions that include surprise and scenarios the institution has not been briefed on. Financial regulators have partially implemented this through stress testing. The same principle applied to cybersecurity and AI governance would mean regulators who test actual resilience rather than documented resilience. This is more expensive than documentation review. It is also more useful by exactly the margin that separates the signal from the source.</p><p>At the AI governance level, adversarial design would mean evaluating not whether the institution has produced the required governance artifacts but whether those artifacts have produced any observable constraint on deployment decisions. Has any deployment been delayed or cancelled as a result of the governance framework? Has any revenue opportunity been declined because the risk assessment indicated unacceptable harm? If the answer to these questions is consistently no, the governance framework is producing signals without substance. The test of AI governance is the cost it has imposed on the institution that maintains it, not the quality of its artifacts.</p><p>None of these are easy to implement. All of them create friction, expense, and organizational discomfort. The question is whether that friction is more expensive than what the institutional uncanny valley costs when the adversary, or the crisis, arrives. The carriers that had frameworks and were owned for eighteen months provide one answer. The federal systems that had documented controls and lost them under political pressure provide another.</p><div><hr></div><h2>The Hardest Admission</h2><p>There is a version of this argument that is politically comfortable: compliance frameworks are imperfect, and we should improve them. That version is not wrong. But it is not the argument I am making.</p><p>The argument I am making is harder. The institutional tendency toward accountability theater is a structural feature of how large organizations under regulatory pressure respond to the incentives that compliance creates, not a correctable defect in the compliance architecture. Better frameworks will produce better theater. More rigorous standards will produce more rigorous performance of compliance with those standards. The gap between signal and source will move, will narrow at the edges, will be more expensive to maintain; but it will persist, because the forces that generate it are structural, not accidental.</p><p>This does not mean governance frameworks are useless. It means that their function needs to be honestly understood. They raise the floor. They make casual non-compliance costly and visible. They create accountability for the largest and most obvious gaps. They produce, at minimum, a record against which failures can be evaluated in retrospect. These are real contributions.</p><p>What they cannot do, by design, is close the gap between institutional performance of accountability and institutional reality of it. That gap is closed only by the things that are hardest to systematize: genuine adversarial testing, organizational cultures that make naming the gap safe rather than costly, leadership that treats uncomfortable findings as intelligence rather than threat.</p><p>And, the thing that brings this essay back to the alarm we have been following since the first essay in this series, it is closed by the people who notice the wrongness, who feel the incoherence between what the documentation says and what the systems do, and who have both the personal capacity and the organizational permission to say, plainly, what they see. Not the frameworks. Not the auditors. The people who sit in the room where the gap is visible and choose to name it, knowing the professional cost.</p><p>The institutional uncanny valley is a condition to be managed continuously, not a problem to be solved once: through the design of verification that assumes the gap will be present, through the protection of the people who detect it, and through the honest acknowledgment that no framework, however rigorous, eliminates the structural incentive to produce signals without substance. The compliance framework raises the floor. It does not close the gap. And the gap is where the adversary lives, whether that adversary is a nation-state actor with eighteen months of patience, a political force with operational speed, or simply the accumulated weight of institutional self-deception.</p><p>Those people, the ones who carry the alarm despite the institutional pressure to suppress it, are the subject of Essay Five.</p><div><hr></div><p><em>Next: Essay Five &#8212; The Unsuppressed. On the structural question of what happens when the alarm cannot be overridden, and what it would mean to design institutions that protect the alarm rather than silence it.</em></p><div><hr></div><h2>Sources</h2><h3>Case Studies from Prior Series</h3><p>Brondani, M. <em>The Compound Vulnerability</em> (essay series). Published at marcobrondani.com. (Salt Typhoon intrusion analysis; federal access control failures accompanying the Department of Government Efficiency deployment in early 2025.)</p><h3>Salt Typhoon</h3><p>The Salt Typhoon intrusion into U.S. telecommunications networks was documented across multiple government and industry sources in late 2024 and early 2025, including advisories from CISA and the FBI. The carriers maintained compliance frameworks and regulatory filings throughout the period of compromise, which lasted approximately eighteen months before detection. The essay references these facts as analyzed in the author's earlier <em>Compound Vulnerability</em> series.</p><h3>Federal Access Controls (DOGE)</h3><p>The Department of Government Efficiency's access to Treasury payment systems, OPM personnel databases, and Social Security Administration records in early 2025 was documented by multiple news organizations and in congressional testimony. The essay treats these events as structural case studies rather than political commentary, focusing on the gap between documented access controls and their operational resilience under political pressure.</p><h3>AI Governance</h3><p>Google. (2019). "An external advisory council to help advance the responsible development of AI." Google Blog, March 26, 2019. The Advanced Technology External Advisory Council (ATEAC) was dissolved on April 4, 2019, nine days after its announcement. Reported by Vox, MIT Technology Review, VentureBeat, and others.</p><p>Newton, C. (2023). "Microsoft just laid off one of its responsible AI teams." <em>Platformer</em>, March 13, 2023. Microsoft's Ethics and Society team, once approximately thirty employees, was eliminated during layoffs affecting 10,000 employees, during the same period the company was investing over $11 billion in OpenAI.</p><p>Schiffer, Z. (2023). "Microsoft lays off entire ethics and society team within its AI organization." <em>The Verge</em>, March 13, 2023. Former employee quote: "People would look at the principles coming out of the Office of Responsible AI and say, 'I don't know how this applies.'"</p><h3>European AI Act</h3><p>European Parliament and Council of the European Union. (2024). Regulation (EU) 2024/1689 (the AI Act). GPAI obligations entered force August 2025; Commission enforcement powers delayed until August 2026; high-risk AI system rules for regulated products with extended transition period until August 2027. Implementation timeline and enforcement grace period details from European Commission official communications.</p><h3>Compliance and Governance Frameworks Referenced</h3><p>SOC 2 (System and Organization Controls 2). Developed by the American Institute of Certified Public Accountants (AICPA).</p><p>ISO/IEC 27001. International standard for information security management systems. International Organization for Standardization.</p><p>NIST Cybersecurity Framework (CSF). National Institute of Standards and Technology, U.S. Department of Commerce.</p><p>OECD. (2019). <em>Recommendation of the Council on Artificial Intelligence</em> (OECD AI Principles). Organisation for Economic Co-operation and Development.</p><h3>SEC Cybersecurity Disclosure Rules</h3><p>U.S. Securities and Exchange Commission. (2023). "Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure." Final rule, effective December 2023. Requires disclosure of material cybersecurity incidents and of board expertise in cybersecurity risk oversight.</p><h3>Cross-Series References</h3><p>Brondani, M. Essay One: "The Alarm" and Essay Two: "Cold Empathy at Scale." <em>The Valley of False Signals</em>. Published at marcobrondani.com. (Suppression mechanism, three norms of hierarchy/efficiency/social grace, signal/source split formulation.)</p>]]></content:encoded></item><item><title><![CDATA[The Death of the Signal]]></title><description><![CDATA[There is a line that was crossed, and we did not notice when we crossed it. Voice, face, and writing style were once unforgeable. That practical infeasibility is gone. The alarm has nothing left to detect. The signal has died.]]></description><link>https://www.marcobrondani.com/p/the-death-of-the-signal</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-death-of-the-signal</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Mon, 16 Mar 2026 06:06:41 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/2c067d08-fcbb-4356-819b-3c96951923e2_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!z38Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!z38Q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!z38Q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!z38Q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!z38Q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!z38Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!z38Q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!z38Q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!z38Q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!z38Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61ab6087-20cf-411f-ae8b-3ce0f6d4d811_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Essay Three of <em>The Valley of False Signals </em>series</p><p><strong>In brief</strong></p><ul><li><p>For most of communication&#8217;s history, voice, face, and writing style were practically impossible to forge in real time, and that impossibility was the load-bearing architecture of trust. It has quietly ended.</p></li><li><p>The collapse is arriving in three places: voice, cloned from seconds of audio; face, generated live, as in the twenty-five-million-dollar Arup video-call fraud; and text, AI spear-phishing that matches a person&#8217;s style for a fraction of a cent per target.</p></li><li><p>The North Korean synthetic-worker operation combines all three, fabricated identities holding real jobs inside hundreds of companies for months. The alarm does not fire, because nothing incongruent is left to detect.</p></li><li><p>Essay Two&#8217;s alarm was suppressed; here the conditions for it to fire are eroding. Perfect mimicry crosses the uncanny valley not by becoming less human but by closing the gap the coherence check was reading.</p></li><li><p>So authentication built on &#8220;genuine presence leaves signals too costly to fake&#8221; no longer holds. The durable replacements are structural, not signal-based: verifying that a request fits the established context, runs through an out-of-band process, and carries a cost forgery cannot absorb.</p></li></ul><div><hr></div><p>There is a line that was crossed, and we did not notice when we crossed it.</p><p>For most of the history of electronic communication, the signals of human presence were practically unforgeable. A voice was a voice, not a statistical reconstruction of a voice, not a synthesis trained on hours of recordings, but the acoustic output of a specific larynx, shaped by a specific mouth, carrying the micro-variations of breath and hesitation that no recording technology of the time could plausibly reproduce in real time. A face was a face. A signature was a signature. Even as forgery existed (it always has) the cost of producing a convincing forgery was high enough that the attempt itself was rare, and the imperfections were usually detectable by someone paying attention.</p><p>These practical constraints were not just inconveniences for fraudsters. They were the load-bearing architecture of trust. Every authentication system ever built was constructed on the implicit assumption that certain signals of genuine human presence were costly enough to simulate that their presence could serve as evidence of legitimacy.</p><p>That assumption is no longer valid.</p><div><hr></div><h2>What the Valley Was, and What We Have Left Behind</h2><p>Mori's uncanny valley described a specific failure mode of simulation: the point at which a simulacrum becomes close enough to human that its imperfections become visible and disturbing. The valley was a region of maximum alarm, where the simulation was advanced enough to trigger the coherence check but imperfect enough to fail it. The alarm fired precisely because the simulation was <em>almost</em> good enough.</p><p>The implicit structure of that problem assumed that the alarm was a useful instrument. The simulation was detectable. The valley existed as a warning region precisely because there was something to warn against, a gap between signal and source that was large enough, with sufficient attention, to be felt.</p><p>Essay Two described what happens when that alarm is suppressed by social and organizational mechanics. This essay addresses something different: what happens when the gap closes. When the simulation becomes precise enough that the alarm has no incongruence to detect. When we have not suppressed the alarm but passed beyond the conditions that cause it to fire.</p><p>We are, I want to argue, at or near that crossing in several domains simultaneously. Not fully past it in every context; the alarm still fires at poorly constructed deepfakes, at synthetic text that carries the particular flatness of large language model outputs, at voice clones with subtle artifacts. But the trajectory is clear, the rate of improvement is accelerating, and the frontier of undetectable simulation is advancing faster than the frontier of detection.</p><p>Mori described the uncanny valley as a region to be avoided or crossed. We are crossing it, not by making simulations less humanlike (which was Mori's practical recommendation for robot designers) but by making them more humanlike. By making them precise enough that the prediction error mechanism has nothing to register. The question of what lies on the other side of the valley, what the world looks like when simulation achieves parity with reality, is not a question Mori asked, because in 1970 it was not a question that needed answering. It needs answering now.</p><div><hr></div><h2>The Three Collapses</h2><p>The death of the signal is occurring in three overlapping domains, at three different rates, and they need to be understood together before we can grasp what they mean in combination.</p><p>Voice identity collapsed first and fastest. In 2019, a UK-based energy company lost approximately &#8364;220,000 after a finance director received a phone call from someone who sounded exactly like the company's CEO. The voice, its tone, cadence, accent, was sufficiently precise that the director executed the transfer without hesitation. That case, at the time, represented the frontier. Six years later, voice cloning has moved from a research capability requiring hours of sample audio to a commercial service available for subscription fees measured in tens of dollars per month. Some implementations need as little as three seconds of clear audio to produce a clone with what researchers describe as an eighty-five percent voice match. The output is not a recording; it is a synthesis engine that can produce, in real time, that person saying anything. CrowdStrike's 2025 threat analysis documented a 442 percent increase in voice cloning usage between the first and second halves of 2024 alone.</p><p>The voice was the oldest authentication signal. Before written records, before seals, before cryptographic keys, the recognition of a familiar voice was the primary mechanism for verifying identity. The brain is extraordinarily sensitive to vocal identity; we recognize people we know from a single word, often before they have finished their first sentence. That sensitivity, which was an asset in an environment where voice synthesis was impossible, becomes a liability in an environment where it is cheap. The very precision of our voice recognition now works against us: the more faithfully we trust a recognized voice, the more completely we are deceived when that voice has been synthesized.</p><p>Visual identity is close behind. In February 2024, the engineering firm Arup suffered the largest documented deepfake fraud to date: a finance worker, participating in what appeared to be a routine video conference with the company's CFO and other senior executives, authorized fifteen transactions totaling twenty-five million dollars. Every face on the call was generated in real time, with synchronized facial movements, realistic voices matched to each executive's known speech patterns, and natural body language. The simulation was precise enough that the alarm did not fire, not because it was suppressed, but because there was nothing for it to detect. A year later, a finance director in Singapore fell to an almost identical structure. The attackers had absorbed the lesson of prior coverage: they proactively suggested a video call, using the apparent willingness to verify as a mechanism for producing false confidence. What these cases demonstrate is not just the quality of the simulation but its social engineering integration. The deepfake is not the attack; it is the resolution of the final friction point in a fundamentally psychological attack. The technology removes the last signal that would allow the alarm to fire. Meanwhile, synthetic identity fraud, the construction of entirely fictitious people with generated faces, fabricated histories, and synthetic documentation, has reached industrial scale. Experian's 2024 fraud data documented a sixty percent increase in false identity cases over the prior year. The Federal Trade Commission estimates that synthetic identity fraud accounts for eighty to eighty-five percent of all identity fraud cases in the United States, with costs to the financial industry exceeding thirty billion dollars.</p><p>The collapse of textual identity may be the most pervasive and least discussed, because it operates in the medium that most professional communication uses. A 2025 study in the <em>Journal of Expert Systems with Applications</em> tested fully automated AI spear-phishing campaigns against human expert campaigns: the AI-generated emails achieved a click-through rate of fifty-four percent, identical to experienced human social engineers, at a cost reduction of up to fifty times for large-scale campaigns. The spear-phishing email that references the correct operational context, mirrors the target's communication style, and sounds exactly like the person it claims to be from was once the product of hours of human research. It is now the output of an automated pipeline that costs fractions of a cent per target.</p><p>The implications extend beyond phishing. Large language models can produce text that is not just grammatically correct and contextually coherent but stylistically matched to a specific individual. Given a corpus of a person's writing, emails, reports, social media posts, a sufficiently capable model can produce new text that carries the statistical fingerprint of that person's style. We authenticate email, to a large degree, by feel: by the quality of the writing, the characteristic phrasings, the particular way a colleague structures a request. When those markers can be synthesized from a training corpus, the informal authentication layer collapses.</p><div><hr></div><h2>The Operation That Combines All Three</h2><p>Since at least 2022, North Korean state-sponsored operatives have been infiltrating technology companies worldwide by posing as remote IT workers. Call it what it is: an identity synthesis operation conducted at national scale, integrating all three collapses into a single sustained effort.</p><p>GitHub's 2025 analysis documented a development team that created at least 135 synthetic identities using scraped photographs, AI image generators, and face-swapping tools, then used those images to create fraudulent passports that verified successfully in over forty percent of attempts. The scale is significant: the DOJ's June 2025 enforcement actions revealed that a single facilitator network had generated over seventeen million dollars in revenue across 309 jobs at US companies including Fortune 500 firms. CrowdStrike found the number of infiltrated companies grew 220 percent over twelve months, with operatives penetrating more than 320 organizations. During live video interviews, operatives use real-time face-swapping technology, allowing a single operator to interview for the same position multiple times under different synthetic personas. Palo Alto Networks' Unit 42 demonstrated that a researcher with no prior deepfake experience could create a synthetic identity convincing enough for job interviews in seventy minutes using consumer hardware. The textual layer completes the simulation: AI to fabricate resumes, prepare for interview questions in real time, mimic cultural fluency in English, and maintain ongoing workplace communications once hired.</p><p>This campaign matters because it represents something qualitatively different from the spectacular deepfake fraud. It is a sustained inhabitation of trusted space. Synthetic humans, complete with professional histories and ongoing behavioral patterns, operating inside organizations as trusted colleagues for months. The alarm does not fire because there is nothing for it to detect. The persona is complete. The signals of genuine presence are all present. They are all synthetic. And the gap between signal and source has been closed so completely that colleagues, managers, and HR departments process these personas as real people for months at a time.</p><p>This is what the post-valley condition looks like in practice: not a single spectacular fraud but a quiet occupation of the spaces where trust is assumed.</p><p>I find this the most unsettling case in the entire series, and I think the reason is that it inverts the emotional register of deception. The Arup deepfake was spectacular; this is quiet. It is the difference between a smash-and-grab and a neighbor who was never who you thought they were.</p><div><hr></div><h2>The Authentication Assumption</h2><p>Every framework for verifying identity is built on what we might call the authentication assumption: that genuine presence leaves signals that are either inherently unforgeable or sufficiently costly to forge that their presence constitutes reasonable evidence of legitimacy.</p><p>The history of authentication is the history of this assumption being challenged and adapted to. Signatures became forgeable, so we added notarization. Identity documents became falsifiable, so we added biometrics. Passwords became vulnerable to brute force, so we added multi-factor authentication. Each adaptation assumed that the new signal was costly enough to forge that it retained evidentiary value. Voice, face, and writing style were in the "inherently unforgeable" category, not because forging them was technically impossible, but because doing so in real time, at scale, was practically infeasible.</p><p>That practical infeasibility is gone. What remains is a set of authentication systems built on assumptions that no longer hold, protecting infrastructures that have not yet absorbed what that means. NIST's digital identity guidelines are under revision precisely because the threat model they were built for has been rendered obsolete. The revision process is ongoing. The threat is not waiting for it to conclude.</p><p>The governance crisis here runs deeper than the technical problem, and I'm not sure the security industry has fully reckoned with it. Boards and executives are making risk decisions based on assurance frameworks that have not been updated to reflect the collapse of their foundational assumptions. CISOs are defending perimeters with tools calibrated for threat models that no longer accurately describe the actual attack surface. Regulators are enforcing compliance with standards that were written before the authentication assumption broke. The crisis is not that we lack better signals. The crisis is that the entire intellectual architecture within which security decisions are made was built for a world in which certain kinds of signals could be trusted, and that world is the one this essay has been describing the end of.</p><div><hr></div><h2>The Post-Valley Condition</h2><p>What does the world look like on the other side of the uncanny valley?</p><p>Mori's graph suggested that the recovery came when the simulation became indistinguishable from the real. The practical implication was a kind of epistemic normalcy: you could not tell the difference, therefore you would not feel the alarm. But that picture assumes you do not <em>know</em> you are past the valley. It assumes that the improvement in simulation quality is matched by a corresponding reduction in your awareness that simulation is occurring.</p><p>That is not the situation we are in. We are approaching the crossing with full awareness that we are approaching it. The sophistication of synthetic voice, face, and text is a public fact, discussed in security conferences, documented in incident reports. We know that voices can be cloned, faces synthesized, and writing style matched. We know that the signals that used to tell us we were communicating with a genuine person may no longer be reliable.</p><p>The post-valley condition, for us, is therefore not Mori's theoretical comfort. It is something more destabilizing: the knowledge that the signals exist, combined with the loss of confidence that they mean what they used to mean. I am aware that this formulation risks sounding alarmist, and I want to be precise about why I think it is not. Two responses are possible, and both are problematic. Undifferentiated suspicion, treating every communication as potentially synthetic, is operationally unsustainable; organizations cannot function if every communication requires the verification level appropriate to a high-risk financial transaction. Exhausted credulity is the more likely outcome, and the more dangerous one. The population slowly absorbs the knowledge that signals can be faked, and slowly accommodates by deciding, implicitly, to mostly act as if they can't. Not from naivety. From the pragmatic judgment that life cannot be conducted at the alert level the threat technically requires. The alarm becomes background noise. Suppression becomes default.</p><p>A 2025 study by iProov found that only 0.1 percent of participants correctly identified all fake and real media shown to them. Seventy percent reported that they were not confident they could distinguish a real voice from a cloned one. These are figures describing a population that has been overwhelmed by the threat, not one that has adapted to it.</p><p>This is the new attack surface. Not the alarm that can be manipulated into suppression, as Essay Two described. The alarm that has been ground down into irrelevance by the sheer volume of the threat. The post-valley condition does not require defeating the alarm. It requires exhausting it.</p><div><hr></div><h2>The Adversarial Parity Problem</h2><p>There is a dynamic in the synthetic media arms race that deserves direct attention, because it has no clean resolution and the security industry has been reluctant to say so plainly.</p><p>Detection and generation are structurally linked. The most effective approaches to detecting synthetic media use machine learning models trained to identify artifacts of synthetic generation. But the generation models improve in response to detection signals, in many cases using detection feedback directly as training signal. The result is a co-evolutionary dynamic in which each improvement in detection produces a corresponding improvement in generation.</p><p>The liveness detection domain makes this concrete. When presentation attack detection improved, attackers moved to injection attacks that bypass the camera entirely. When vendors developed injection detection, attackers moved to compromising device integrity through emulators and hardware tampering. In December 2025, iProov's Red Team published through MITRE's ATLAS framework a demonstration that a commercially available face-swapping tool could evade liveness detection on financial and banking mobile applications. The vulnerability was rated critical. The technique required no specialized AI expertise. And injection attacks surged nine-fold in 2024, fueled by a twenty-eight-fold spike in virtual camera exploits.</p><p>The pattern that liveness detection reveals defines the post-valley condition: every detection method that relies on the costliness of forgery eventually fails as that cost decreases. The defense was never the detection method itself; it was the economic barrier that made defeating it impractical. When the barrier collapsed, the detection method became a ritual. The signal retained its form while losing its substance. The email domain still displays. The SMS code still arrives. The liveness check still runs. The signal/source split that Essay One identified has extended to the authentication infrastructure itself.</p><p>Detection and generation share fundamental access to the same underlying techniques, and generation has a structural advantage: it only needs to produce one example convincing enough to defeat a specific detection system, while detection needs to identify all synthetic examples across all methods. The malware arms race provides the historical analogy. Malware and antivirus have been co-evolving for four decades. Antivirus technology is far more sophisticated than it was in 1990. Malware is also far more sophisticated, and the fundamental dynamic has not been resolved in favor of defenders. The endpoint detection and response industry exists precisely because the co-evolution produces a sustained market for defense tools that are never definitively sufficient. The synthetic media arms race will produce the same dynamic. Detection at the signal level will be a useful supplementary tool, producing actionable signals in a subset of cases. It will not be a foundation.</p><div><hr></div><h2>What Authentication Looks Like After the Signal Dies</h2><p>The honest answer is that the field has not yet fully confronted this question. The working assumption in most authentication frameworks is still that signal degradation is a problem to be solved at the signal level. These are real investments made in good faith. They are also, structurally, fighting the last war.</p><p>The more durable approaches are not signal-based. They are context-based, process-based, and cost-based.</p><p>Context-based authentication shifts the question from "is this signal genuine?" to "is this request coherent with the established context of this relationship?" A request for a large financial transfer is authenticated not by the voice on the phone but by whether it fits the established pattern of how this counterparty communicates and transacts. Anomaly detection of the request and its contextual fit is more robust to signal synthesis than signal verification.</p><p>Process-based authentication embeds resistance to synthetic signals in process design rather than detection technology. Out-of-band verification through pre-established channels, time delays that prevent urgency-driven compliance, dual-authorization requirements that cannot be satisfied by a single compromised communication channel: these are process designs that remain effective even when individual signals are untrustworthy.</p><p>Cost-based authentication shifts the problem to the economics of the attack. If every authorization attempt requires actions with real-world costs (physical presence, multi-party coordination, time delays that increase operational risk of discovery) the cheapness of signal synthesis is offset by the costs embedded in the authorization process.</p><p>None of these are complete solutions. All of them introduce friction, and friction has costs. The calibration of security friction against operational efficiency is one of the defining problems of enterprise security governance, and it is never cleanly resolved. But the direction is clear: authentication frameworks built on the assumption of detectable genuine presence need to be rebuilt on the assumption of detectable genuine process, structures that are adversarially resistant not because the signal cannot be faked but because the process cannot be completed without costs that forgery cannot absorb.</p><div><hr></div><h2>The Civilizational Dimension</h2><p>The collapse of signal authenticity extends well beyond security into something epistemic, and the epistemic dimension is larger than any organizational response can address.</p><p>Trust, at every scale, runs on signals: the signal that a voice is genuine, that a document is authentic, that an institution is doing what it says it is doing. These signals are not the trust itself; they are evidence that trust is warranted, the observable outputs of processes that, when functioning correctly, are causally connected to the trustworthiness they indicate. When signals can be produced without that causal connection, when the voice can be synthesized without the person, the document fabricated without the process, the evidentiary value of signals collapses. Not gradually. Structurally.</p><p>We are beginning to live in that collapse. And the psychological response to it, the exhausted credulity, the suspended judgment, the gradual accommodation to a world in which signals cannot be taken at face value, is not neutral. It reshapes the conditions under which collective action, institutional authority, and social cooperation are possible. A population that has learned, at a deep level, that the signals of authenticity are not reliable will respond to that knowledge in ways that extend far beyond cybersecurity. The institutions that have relied on the apparent authenticity of their signals to maintain legitimacy (governments, corporations, regulatory bodies, the media) will find that legitimacy increasingly difficult to sustain.</p><p>The North Korean synthetic worker campaign illustrates this at a precise scale. When a company discovers that a colleague they have worked alongside for a year was a state-sponsored synthetic identity, the damage extends beyond the data exfiltrated or the salary paid. It reaches the trust infrastructure itself: every subsequent hire, every video call, every new colleague's face is now shadowed by the knowledge that the signals of presence were once completely, convincingly false.</p><p>This is the deeper cost of the authentication crisis: not the individual fraud that succeeds, but the aggregate erosion of the signal infrastructure on which all collective trust depends. The Arup deepfake cost one company twenty-five million dollars. The erosion of the epistemic foundation of organizational communication costs something much harder to quantify and much harder to restore.</p><div><hr></div><p>Essays One and Two described a world in which the alarm works but is suppressed. This essay describes a world in which the conditions for the alarm to fire are eroding.</p><p>Essay Four examines a dimension of this problem that is neither technical nor psychological but institutional: organizations and governance bodies that produce accountability signals systematically disconnected from the accountability they purport to represent. The signal/source split applied not to the voice on the phone or the face on the screen, but to the entire apparatus of institutional trust.</p><p>The deepfake CFO exploits a synthesized signal. The narcissistic institution exploits a structural one. Both rely on the same underlying condition: the possibility of producing outputs that signal trustworthiness without the processes that would causally generate it. The alarm has the same structure in both cases. What suppresses it is different. And that difference is what Essay Four is about.</p><div><hr></div><p><em>Next: Essay Four &#8212; The Narcissistic Institution. On governance theater, compliance as performance, and the organizations that have learned to produce the signals of accountability without its substance.</em></p><div><hr></div><h2><strong>S</strong>ources</h2><h3>Voice Cloning</h3><p>Stupp, C. (2019). "Fraudsters Used AI to Mimic CEO's Voice in Unusual Cybercrime Case." <em>The Wall Street Journal</em>, August 30, 2019. (UK energy company, &#8364;220,000 voice clone fraud. Insurance firm Euler Hermes, subsidiary of Allianz SE, provided case details.)</p><p>CrowdStrike. (2025). <em>2025 Global Threat Report</em>. CrowdStrike Holdings, Inc. (442% increase in voice cloning usage between H1 and H2 2024; deepfake-enabled fraud losses; North Korean synthetic worker campaign data.)</p><h3>Deepfake Fraud</h3><p>Arup deepfake fraud (2024). Finance worker authorized $25 million across fifteen transactions during a video conference in which all participants were real-time deepfakes. Reported by Hong Kong police and multiple sources including CNN, February 2024.</p><p>Singapore deepfake fraud (2025). Finance director at multinational firm targeted via deepfake video call with multiple synthetic executives. Reported by <em>The Straits Times</em> and cybersecurity press, March 2025.</p><h3>Synthetic Identity Fraud</h3><p>Experian. (2024). <em>2024 Identity and Fraud Report</em>. Experian Information Solutions, Inc. (Sixty percent increase in false identity cases year over year.)</p><p>Federal Trade Commission. Synthetic identity fraud estimates: eighty to eighty-five percent of all identity fraud cases in the United States. Referenced in multiple FTC publications and testimony.</p><h3>AI-Automated Spear Phishing</h3><p>Heiding, F., Schneier, B., Vishwanath, A., &amp; Laszka, A. (2025). "Devising and Detecting Phishing: Large Language Models vs. Smaller Human Models." <em>Journal of Expert Systems with Applications</em>. (AI spear-phishing achieved fifty-four percent click-through rate, identical to human experts, at up to fifty times cost reduction.)</p><h3>North Korean Synthetic Worker Campaign</h3><p>GitHub Security Lab. (2025). Analysis of North Korean development team creating 135+ synthetic identities for infiltration operations.</p><p>U.S. Department of Justice. (2025). Enforcement actions, June 2025. North Korean operatives employed at 100+ US companies; single facilitator network generating $17 million across 309 jobs.</p><p>CrowdStrike. (2025). <em>2025 Threat Hunting Report</em>. (Famous Chollima campaign; 220% growth in infiltrated companies; 320+ organizations penetrated.)</p><p>Palo Alto Networks, Unit 42. (2025). Demonstration that synthetic identity convincing enough for job interviews could be created in seventy minutes using consumer hardware.</p><p>Pindrop. (2025). Screening data: one in four DPRK-linked job applicants used deepfake technology during live interviews.</p><h3>Liveness Detection and Authentication</h3><p>iProov. (2025). <em>2025 Biometric Threat Intelligence Report</em>. (0.1% of participants correctly identified all fake and real media; Red Team demonstration via MITRE ATLAS framework of liveness evasion on financial applications.)</p><p>Sumsub. (2025). <em>2025 Identity Fraud Report</em>. (AI fraud agents combining generative AI, automation, and reinforcement learning; nine-fold surge in injection attacks; twenty-eight-fold spike in virtual camera exploits.)</p><h3>Authentication Frameworks</h3><p>National Institute of Standards and Technology (NIST). <em>Digital Identity Guidelines</em> (SP 800-63 series), revision in progress. The authoritative US government framework for identity assurance, under revision to address generative AI threats to biometric and signal-based authentication.</p><h3>Cross-Series References</h3><p>Brondani, M. Essay One: "The Alarm" and Essay Two: "Cold Empathy at Scale." <em>The Valley of False Signals</em>. Published at marcobrondani.com.</p><p>Mori, M. (1970). Bukimi no tani [The uncanny valley]. <em>Energy</em>, 7(4), 33&#8211;35.</p>]]></content:encoded></item><item><title><![CDATA[Cold Empathy at Scale]]></title><description><![CDATA[The finance worker's alarm did not fire. Or it fired, and did not survive the context. Social engineering has been solving the wrong problem for thirty years. The vulnerability is not detection. It is the culture that suppresses it.]]></description><link>https://www.marcobrondani.com/p/cold-empathy-at-scale</link><guid isPermaLink="false">https://www.marcobrondani.com/p/cold-empathy-at-scale</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Thu, 12 Mar 2026 05:27:30 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/77a6068e-c243-4c11-bafb-dff958c527b5_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5c0D!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5c0D!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!5c0D!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!5c0D!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!5c0D!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5c0D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5c0D!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!5c0D!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!5c0D!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!5c0D!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6123d867-e2c3-4ec7-a31a-5b7befd0da89_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Essay Two of <em>The Valley of False Signals </em>series</p><p><strong>In brief</strong></p><ul><li><p>Social engineering, not technical exploits, is the dominant way organizations are breached; the human element appears in roughly sixty percent of confirmed breaches, year after year, despite decades of awareness training.</p></li><li><p>That training solves the wrong problem. People usually do sense something is off, and post-incident interviews are full of &#8220;I had a feeling but I didn&#8217;t say anything.&#8221; The alarm fires; what the training never touches is what silences it.</p></li><li><p>The skilled attacker runs on cold empathy: modeling the target accurately while feeling nothing, opening with insider detail to pass the coherence check, then using urgency and a flattering professional self-image to keep the alarm down.</p></li><li><p>Three organizational norms do the attacker&#8217;s work: deference to hierarchy, the premium on efficiency, and the social grace that makes doubting a plausible colleague feel rude. They are functional almost always, and a vulnerability exactly when authority signals can be faked.</p></li><li><p>The insider threat is the same problem inverted, and the answer is the same: organizational design that treats an unprovable sense of wrongness as data and makes acting on it cheap, rather than another training module.</p></li></ul><div><hr></div><p>In 2024, a senior finance employee at Orion S.A., a global specialty chemicals company headquartered in Luxembourg, received a series of emails requesting wire transfers. The emails appeared to come from company executives, referenced legitimate business contexts, and followed the communication patterns the employee was accustomed to. Over multiple transactions, approximately sixty million dollars was transferred to accounts controlled by the attackers.</p><p>No deepfakes were involved. No voice cloning. No synthetic video. The attack used nothing more than email, the right names, the right context, the right organizational knowledge, and a sophisticated understanding of how a specific person in a specific role at a specific company would respond to a request from apparent authority under time pressure.</p><p>The coverage focused on the amount lost and the procedural failures. That framing treats the incident as a problem of insufficient controls: if the verification procedures had been followed, the attack would have failed. But the verification procedures existed. They were known. They were bypassed, not because the employee was unaware of them, but because the social engineering was sophisticated enough to make following them feel unnecessary. The signals of legitimacy were sufficient to engage the suppression mechanism.</p><p>The finance worker's alarm did not fire. Or it fired, and did not survive the context.</p><div><hr></div><h2>The Attack That Was Always Psychological</h2><p>Social engineering, the manipulation of people rather than systems, is the dominant attack vector in enterprise security. Not because technical vulnerabilities don't exist, but because attacking people is, for a sophisticated adversary, almost always the path of least resistance. A zero-day exploit requires finding an unpatched vulnerability, developing specialized code, deploying it without triggering detection. A well-constructed pretexting call requires understanding the target's organizational context, constructing a plausible narrative, and exploiting the psychological mechanisms that govern trust.</p><p>The Verizon 2025 Data Breach Investigations Report found that the human element (errors, social engineering, and credential misuse) was a factor in approximately sixty percent of all confirmed breaches, a figure that has remained stubbornly consistent year over year despite billions spent on awareness programs. That figure should stop every CISO cold. We have spent three decades building technical defenses, firewalls, endpoint detection, SIEM platforms, zero-trust architectures, and the dominant attack vector is still the human. As the technical perimeter has hardened, the human perimeter has been exposed as the softer target. The attacker simply went around.</p><p>But even this framing, the human as the weakest link, misses something. It treats the human factor as a problem of insufficient training, insufficient alertness, insufficient procedural compliance. If people would just follow the protocols, the attack would fail.</p><p>This is approximately what security awareness training teaches. And security awareness training has failed, by every meaningful metric, to reduce the incidence of successful social engineering attacks. The reason is that it addresses the wrong problem.</p><div><hr></div><h2>What Security Awareness Training Gets Wrong</h2><p>The standard curriculum teaches people to recognize the signals of deception: do not click links in unsolicited emails, verify requests for wire transfers through a separate channel, be suspicious of urgency, check the sender's domain.</p><p>These are reasonable heuristics. They address the detection layer, the capacity to recognize that something is off.</p><p>But the actual vulnerability is not detection. As Essay One established, the alarm is generally working. People often have a sense, even during a successful attack, that something is not quite right. Post-incident interviews with victims regularly surface versions of this: "I had a feeling but I didn't say anything." "Something seemed off but it was hard to say what." "I didn't want to make trouble."</p><p>The alarm fired. Then it was suppressed.</p><p>Security awareness training teaches people to recognize attack signals. It does not address, and in many respects actively undermines, the capacity to act on a feeling that cannot be fully articulated. It teaches people to demand articulable evidence before they trust their unease. In doing so, it reinforces exactly the mechanism that sophisticated social engineers exploit.</p><p>People detect it, correctly, and then override the detection. The failure is structural, not educational. The suppression of unverifiable alarm is a feature of professional culture, organizational hierarchy, and the social norms that govern how uncertainty is permitted to be expressed in institutional settings. I keep coming back to this point because it reframes the entire defense problem: these norms did not emerge by accident, and they cannot be addressed by a forty-minute annual training module.</p><div><hr></div><h2>The Anatomy of Cold Empathy in Operation</h2><p>In Essay One, I introduced cold empathy: the cognitive modeling that narcissists and psychopaths deploy without genuine affective resonance, documented from Cleckley's "mask of sanity" through Hare's psychopathy research, with Sam Vaknin providing the formulation that connects it to the uncanny valley. The cognitive element of empathy is present; its emotional correlate is not.</p><p>The skilled social engineer operates in this mode. Not because they are necessarily narcissists or psychopaths (though the profession does select for certain personality traits) but because the operational requirements are structurally identical to what cold empathy produces. The social engineer does not need to feel their target's experience. They need to model it, accurately, for the duration of the attack: what the target wants to believe, what narrative will be most readily accepted, which authority figures carry the most weight, what urgency framing will suppress verification instincts.</p><p>Watch the anatomy of a successful vishing call and the cold empathy structure becomes visible.</p><p>It begins with research. The attacker knows the target's name, role, approximate tenure, and details about recent organizational events that provide context for the pretext. LinkedIn, company websites, press releases, and earlier-stage phishing provide most of this. Then the call opens with specific and accurate claims: the caller knows the target's name, their manager's name, details about their role. They reference recent events in terms that signal insider knowledge. The target's brain runs its coherence check. Does this person know things that only insiders know? Yes. The alarm does not fire.</p><p>Having established apparent legitimacy, the attacker introduces urgency, compressing the time available for reflection and verification. The verification behaviors that security training teaches require time. Urgency, applied correctly, makes those behaviors feel like a threat to the urgency itself. And here is where the most sophisticated social engineers distinguish themselves: they exploit professional identity. The attack narrative places the target in the role of the competent professional who takes the right action quickly. Refusing to cooperate is implicitly framed as the behavior of an obstructionist. The social engineer is not just asking for compliance; they are offering the target a flattering self-concept in exchange for it.</p><p>If the target expresses hesitation, and good targets often do, the attacker has a response ready. The hesitation is anticipated, treated as a misunderstanding rather than a threat. "I completely understand the concern; that's exactly what we'd expect from someone careful. Let me just explain a bit more about why this is urgent." The alarm was suppressed, politely, by framing alertness as an obstacle to legitimate authority.</p><p>This is cold empathy in operation. The attacker does not need to feel the target's experience. They need to model it well enough to anticipate its movements and manage them. They know, before the target does, that the alarm will fire at approximately this point, and they have a scripted response ready.</p><div><hr></div><h2>The Attacker as Organizational Expert</h2><p>There is a feature of sophisticated social engineering that awareness training almost never addresses, because it implicates something organizations do not want to examine about themselves.</p><p>The most dangerous social engineers attack specific people in specific organizational contexts, and their attack is calibrated to the culture, hierarchy, and behavioral norms of the target organization. A successful BEC attack against a manufacturing company exploits different vulnerabilities than one against a financial services firm; in manufacturing, the culture of operational urgency where delays have direct production consequences; in financial services, the culture of regulatory compliance where requests from apparently authoritative sources carry the implicit weight of a regulatory obligation.</p><p>The attacker's model of the organization is, in some ways, more accurate than the organization's model of itself. The organization believes it has security procedures. The attacker knows which procedures exist on paper and which ones are actually followed under pressure. The organization believes its employees are well-trained. The attacker knows, from the patterns of past attacks, which emotional levers produce compliance in what percentage of cases and under what organizational circumstances.</p><p>I started to write here that this represents a failure of organizational self-knowledge, but that framing is too gentle. It is more precise to say that the organization is structurally prevented from knowing itself accurately, because the same professional culture that makes cooperation possible also makes the honest assessment of one's own vulnerabilities socially impermissible. The attacker is looking specifically for the gaps. The organization is looking to confirm that the gaps don't exist. This asymmetry is not a correctable oversight. It is a structural feature of how hierarchical organizations process uncomfortable information about themselves.</p><div><hr></div><h2>The Professionalization of Deception</h2><p>Social engineering has undergone a professional transformation in the past decade that most security discourse has not fully absorbed.</p><p>Business email compromise generated reported losses of $2.77 billion in the United States alone in 2024, according to the FBI's Internet Crime Complaint Center. That figure reflects only reported losses; BEC is famously underreported. Those losses represent an industry. On the criminal underground, toolkits for BEC attacks (pre-researched target lists, email templates, playbooks for different organizational contexts, even customer support for operators who encounter unusual resistance) are available for subscription fees measured in hundreds of dollars monthly.</p><p>The industrialization of social engineering means the attacker does not need to be exceptional. They need to be systematic. They run enough attempts against enough targets that the statistical properties of human psychology, the percentage who will comply with an urgent request from apparent authority, the percentage whose alarm will fire but whose professional culture suppresses acting on it, generate a reliable return. This is cold empathy at scale in its most literal sense: not one skilled manipulator modeling one target, but a systematic operation applying a statistical model of human vulnerability across thousands of targets. The cognitive modeling is aggregated. The outputs are actuarial.</p><p>Phishing-as-a-service platforms have extended this industrialization further, providing the complete infrastructure: email delivery, landing page templates, credential harvesting backend, analytics dashboards showing which lures produced the most clicks in which industries. The operator provides only the targeting. The psychological model is baked into the platform. And agentic AI is beginning to extend it further still. Documented attacks in 2025 involved AI agents operating autonomously over extended periods, building synthetic professional profiles, cultivating relationships through legitimate channels over weeks before making a request. Essay Three will examine the most developed instance of this pattern: the North Korean state-sponsored campaign that used synthetic identities to infiltrate over three hundred companies.</p><div><hr></div><h2>Why Training Cannot Fix a Structural Problem</h2><p>The security industry's response to social engineering has been, for thirty years, predominantly educational. Train the user. Teach them the signals. Run simulated phishing campaigns. Measure click rates. The model has a seductive internal logic: if people are being deceived, they need to recognize deception; if they need to recognize deception, they need training.</p><p>The problem is empirical: it hasn't worked. Phishing click rates have remained stubbornly consistent. BEC fraud losses have grown year over year. The people falling for these attacks are not naive or untrained. Many of them have completed security awareness training in the previous twelve months. Some of them are themselves security professionals.</p><p>I have watched this cycle from the inside for long enough to feel the weight of it. The response from the training industry has been to add more training, make it more frequent, gamify the compliance, personalize the curriculum. More of the same. Because the model says the problem is insufficient awareness, the solution must be more awareness.</p><p>But if the problem is the suppression of awareness that already exists, then more training may be actively counterproductive. Consider what happens when a training module teaches someone to "verify unexpected requests through a separate channel." Good advice. But it teaches something implicit: that the appropriate response to an uncomfortable feeling is not to trust the feeling, but to run a verification procedure. If the procedure checks out, the uncomfortable feeling is supposed to be dismissed. A sophisticated attacker can defeat that procedure. They can spoof callback numbers. They can compromise the manager's email. They can set up a look-alike domain that passes a casual check. When verification appears to succeed but the attack is real, the training has actively suppressed the alarm by telling the target: you verified, so the feeling was wrong.</p><p>I should qualify this, because the argument I'm making risks sounding like an argument against all training, which it is not. Training has value at the margin. It raises the baseline. It catches the unsophisticated attacks, the spray-and-pray phishing that relies on volume rather than precision. What it cannot do is address the sophisticated attack that has already mapped the verification procedures and built its pretext to survive them. And it is the sophisticated attack, the one that models the target's psychology and manages the alarm, that produces the catastrophic losses. The awareness training model treats the alarm as an insufficient instrument that needs to be replaced by procedure. The correct model treats the alarm as a valuable instrument that needs to be protected from suppression.</p><div><hr></div><h2>The Suppression Mechanism in Professional Culture</h2><p>Where does the suppression pressure come from? Not primarily from the attacker, though skilled attackers manage it deliberately. The primary source is organizational culture, and it is generated by three forces that operate in combination.</p><p>Professional organizations are hierarchical, and hierarchy generates its own compliance pressure. A request from a superior carries authority independent of its content. Questioning a directive from the apparent CFO, even when the alarm is firing, requires overcoming a deeply ingrained professional reflex to defer upward. The social engineer exploits this by impersonating authority, or by referencing authority in ways that import this compliance pressure into the interaction. The hierarchy norm is not a pathology; it is functional for the ninety-nine percent of interactions in which the authority is legitimate. It becomes a vulnerability only when legitimate and illegitimate authority signals become indistinguishable.</p><p>Professional environments also select for efficiency: people who resolve requests quickly, who don't create unnecessary friction, who are responsive and decisive. The person who pauses every ambiguous request for extended verification is regarded as difficult, overcautious, a bottleneck. The social engineer's urgency framing exploits this by making the cost of verification feel like the cost of inefficiency. The target who stops to verify is, in the narrative the attacker has constructed, failing at their professional role.</p><p>And expressing distrust of someone presenting convincingly as a colleague violates basic professional courtesy. Saying "I'm not sure I believe you are who you say you are" to someone who has supplied the correct contextual details is, in most professional contexts, deeply awkward. It implies suspicion, which implies accusation. The social engineer's performance of normalcy makes the expression of the alarm feel like rudeness.</p><p>These three norms, hierarchy, efficiency, and social grace, combine to create a professional culture that is structurally hostile to the expression of unverifiable alarm. They do not represent individual failures. They represent the predictable operation of organizational culture in an adversarial environment it was not designed for.</p><div><hr></div><h2>The Insider Threat as Confirmation</h2><p>The social engineering problem has a darker inner layer: the insider threat. The insider has legitimate access, legitimate authority signals, and detailed knowledge of exactly where the gaps between stated and actual security posture are located. They don't need to research the organization; they live in it.</p><p>The 2024 Insider Threat Report found that eighty-three percent of organizations reported at least one insider attack, with the number experiencing eleven to twenty attacks in a year increasing fivefold from 2023. The Tesla breach of 2023, in which two former employees leaked the personal data of over seventy-five thousand individuals to a foreign media outlet, was not a technical exploitation. It was a decision by insiders who had legitimate access and used it for purposes the organization had not anticipated. Colleagues may have noticed something. The insider threat literature suggests they usually do. But the organizational culture that would need to convert that noticing into action is the same culture that suppresses the alarm in external social engineering: you do not speculate about a colleague's motives. You do not report a feeling you cannot justify.</p><p>The insider threat is the external social engineering problem inverted: instead of an outsider exploiting organizational suppression norms to prevent detection, an insider benefits from those same norms, which prevent colleagues from acting on accurate alarms.</p><p>And so insiders are identified, when they are identified, by exactly the same mechanism that fails in external social engineering: a feeling, imprecise and hard to articulate, that something is off about this person. That their interest in certain systems is slightly too focused. That their questions about access are slightly too specific. That something in the texture of their professional behavior is not quite coherent with everything else. The alarm fires. The suppression mechanism engages. The insider continues.</p><div><hr></div><h2>What Would Actually Work</h2><p>If the problem is the suppression mechanism rather than detection capacity, the solution space looks different. And if the suppression mechanism operates through three specific organizational norms (hierarchy, efficiency, and social grace) then effective defense must address those norms directly, not the detection layer they suppress.</p><p>Addressing the hierarchy norm requires more than written policy stating that employees may verify requests from superiors. It requires organizational cultures in which questioning a request from apparent authority is normal, expected, and cost-free, which means addressing the informal signals through which professional culture actually operates. Who gets promoted? Who gets praised? Whose caution is celebrated, and whose is criticized as obstruction? The policy is the documentation. The culture is the posture. And the gap between them is where the social engineer operates. Anyone who has run a security program in a hierarchical organization knows this gap intimately, and knows how difficult it is to close from below.</p><p>Addressing the efficiency norm requires inverting the organizational response to urgency. Any request that arrives with urgency should automatically trigger more scrutiny, not less. The finance worker who refuses to execute a large transfer because something about the request felt off, even though they couldn't say what, needs to live in an organization where that decision is celebrated rather than criticized.</p><p>Addressing the social grace norm is the deepest challenge. It requires explicitly validating the alarm, teaching people that their sense of wrongness, even when it cannot be articulated, is worth pausing for. Not that it is always correct, but that it is always worth acknowledging as data rather than dismissing as irrationality.</p><p>None of these are training problems. They are organizational design problems. What they require is not the transmission of information but the restructuring of permission: the creation of organizational contexts in which the alarm's outputs are treated as intelligence rather than noise. Human risk management, the emerging field that frames security behavior as a function of organizational culture rather than individual training, is moving in this direction. But the industry's response to social engineering is still, predominantly, more training.</p><div><hr></div><h2>The Suppression Window Is Not a Bug</h2><p>There is a harder thing to say, and it needs to be said clearly.</p><p>The suppression window that social engineers exploit is a necessary feature of cooperative social life, not a design flaw in human psychology. The norms that tell us to give people the benefit of the doubt, to treat unexpected requests with charity rather than suspicion, to avoid accusing colleagues of deception without strong evidence: these norms exist because cooperative life requires them. A world in which every organizational interaction was treated as potentially adversarial would be paralyzed. I have worked in organizations that tried to operate at that alert level, and the result was not security. It was dysfunction.</p><p>The social engineer's genius (and it is a kind of genius, however malignant) is to operate inside the norms of cooperative life while not participating in its substance. The norms of benefit of the doubt were designed for environments where most actors are operating in good faith. They fail in the presence of actors who are operating in bad faith while producing all the signals of good faith.</p><p>This is, again, the structure of cold empathy: the production of cooperative signals without the cooperative substance. The signal and the source have split.</p><div><hr></div><p>Everything described in this essay exists at a scale that makes individual defense insufficient as a strategy. Individual training has diminishing returns past a certain point, and we passed that point years ago. The remaining returns are structural: organizational permission structures, the design of communication and authorization processes that are adversarially resistant by default rather than requiring individual vigilance to maintain security.</p><p>The vulnerability is the organizational culture that makes acting on alarm socially costly and procedurally difficult. Not the individual. And until that culture is addressed, not through training but through design, the suppression mechanism will continue to do the attacker's work for them.</p><p>This is perhaps the most uncomfortable implication of the entire analysis: the attacker's epistemic advantage is cultural rather than technical. The attacker understands what the organization cannot afford to acknowledge about itself, because the organization's professional culture has made that acknowledgment socially impermissible. The cold empathy of the social engineer is directed precisely at the gap between what the organization claims about its own security behavior and what that behavior actually looks like under pressure. The organization cannot see the gap because it has been socialized not to look. The attacker can see nothing else.</p><p>The structural problem of social engineering has been fundamentally altered by a technological development that the next essay examines: the synthetic reproduction of the signals that the alarm monitors. When the alarm can be defeated not just by skilled psychological manipulation but by sufficiently perfect simulation of trusted individuals, their voice, their face, their writing, the defense problem changes again. The alarm still works in the world this essay has described. In Essay Three, the conditions for it to fire begin to erode.</p><div><hr></div><p><em>Next: Essay Three &#8212; The Death of the Signal. On deepfakes, synthetic identity, and what happens when the uncanny valley has been crossed.</em></p><div><hr></div><h2><strong>S</strong>ources</h2><h3>Case Study</h3><p>Orion S.A. (2024). Form 8-K filing with the U.S. Securities and Exchange Commission, August 12, 2024. Disclosure of approximately $60 million in losses from fraudulently induced wire transfers targeting a non-executive employee.</p><h3>Breach and Threat Statistics</h3><p>Verizon. (2025). <em>2025 Data Breach Investigations Report</em>. Verizon Business.</p><p>Federal Bureau of Investigation, Internet Crime Complaint Center. (2024). <em>2024 Internet Crime Report</em>. FBI IC3. (BEC losses of $2.77 billion in 2024.)</p><p>Cybersecurity Insiders / Gurucul. (2024). <em>2024 Insider Threat Report</em>.</p><h3>Cold Empathy and Psychopathy</h3><p>Cleckley, H. (1941). <em>The Mask of Sanity: An Attempt to Clarify Some Issues About the So-Called Psychopathic Personality</em>. C.V. Mosby.</p><p>Hare, R.D. (1993). <em>Without Conscience: The Disturbing World of the Psychopaths Among Us</em>. Pocket Books/Simon &amp; Schuster.</p><p>Vaknin, S. (2003). <em>Malignant Self-Love: Narcissism Revisited</em>. Narcissus Publishing. See also Vaknin's published lectures and writings on cold empathy and the uncanny valley.</p><h3>Insider Threat Case Study</h3><p>Tesla data breach (2023). Two former Tesla employees leaked personal data of over 75,000 individuals, including names, addresses, Social Security numbers, and employment histories, to the German newspaper <em>Handelsblatt</em>. Reported by multiple sources including Reuters, August 2023.</p><h3>Human Risk Management</h3><p>The essay references the emerging field of human risk management as an alternative framework to security awareness training. Key contributors to this discourse include the work of organizations such as the SANS Institute, Gartner's human risk management framework, and practitioner literature on security culture design.</p><h3>Cross-Series References</h3><p>Brondani, M. Essay One: "The Alarm." <em>The Valley of False Signals</em>. Published at marcobrondani.com.</p>]]></content:encoded></item><item><title><![CDATA[The Alarm]]></title><description><![CDATA[Something shifts in a conversation. The words are correct. The timing is right. But something at the edge of attention is telling you none of it is real. This series is about that moment, and why we learned to turn the alarm off.]]></description><link>https://www.marcobrondani.com/p/the-alarm</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-alarm</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Mon, 09 Mar 2026 07:56:25 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/26f62cf3-1500-47c6-9a36-78a4773d2d75_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NPA1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NPA1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!NPA1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!NPA1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!NPA1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NPA1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!NPA1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!NPA1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!NPA1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!NPA1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81638705-bc16-40b4-99fe-51e17d17f057_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Essay One of <em>The Valley of False Signals </em>series</p><p><strong>In brief</strong></p><ul><li><p>The uncanny valley is usually treated as a design problem, the eeriness of an almost-human robot. It works better read as a detection mechanism: an alarm that fires when an entity&#8217;s signals come apart from its source.</p></li><li><p>Neuroimaging points to prediction rather than perception. The brain runs a coherence check, and the alarm is about authenticity, not appearance: does the empathy on this face come from an actual feeling, or is it being generated without one?</p></li><li><p>The same alarm fires at certain people, not only machines. Cleckley&#8217;s &#8220;mask of sanity,&#8221; Hare&#8217;s psychopathy research, and Vaknin&#8217;s &#8220;cold empathy&#8221; describe a performance of warmth with no affective source, and the nervous system reads it the way it reads the android.</p></li><li><p>The real vulnerability is suppression. The alarm fires, then social norms override it: good judgment is patient, trustworthy people trust, naming an unprovable wrongness feels rude. Skilled manipulators are built to walk through that window.</p></li><li><p>The series follows that shape at rising scale, a valid alarm, a suppression mechanism, and the gap between them, from the individual con through institutions to the civilizational collapse of authentication.</p></li></ul><div><hr></div><p>There is a moment, and you will recognize it, when something shifts in a conversation. The person across from you is saying all the right things. The words are correct. The timing is right. But something, some faint sourceless pressure at the edge of attention, is telling you that none of it is real.</p><p>You probably dismiss it. You tell yourself you're being paranoid. You remind yourself that first impressions are unreliable, that mature judgment requires patience, that it would be rude and intellectually dishonest to condemn someone on nothing more than a feeling you cannot name. The feeling recedes. The conversation continues.</p><p>That moment is what this series of essays is about.</p><p>Not the feeling, though we will examine the feeling closely, because it turns out to be far more sophisticated than we typically credit. What this series is about is what happens <em>after</em> the feeling: the mechanism by which a genuine, often accurate signal is overridden, discredited, and filed away as social noise. And why that mechanism (the suppression of a valid alarm) is, I will argue, the central vulnerability running through cybersecurity, institutional governance, and the architecture of trust itself.</p><div><hr></div><h2>A Roboticist's Observation</h2><p>In 1970, a Japanese robotics professor named Masahiro Mori published a short essay in an engineering journal. It was not a scientific paper in the rigorous sense; Mori himself later acknowledged it was more of a practical guideline than a formal hypothesis. But the observation it contained would propagate through robotics, psychology, film theory, and eventually into the cultural nervous system of the early twenty-first century.</p><p>Mori had noticed something strange about the way people responded to increasingly humanlike machines. As a robot became more human in appearance, as it acquired a face, then expressive features, then realistic skin, people's emotional responses generally warmed. This was expected. What was not expected was that this progression had a cliff in it.</p><p>At a certain point (not when the robot was obviously mechanical, and not when it was indistinguishable from human, but at the liminal region <em>between</em>) something curdled. The emotional response reversed. People who had been warming to the robot now found it disturbing, unsettling, wrong. Mori called this region <em>bukimi no tani</em>: the valley of eeriness, rendered into English as the uncanny valley.</p><p>The shape of the phenomenon, plotted on a graph, gives the metaphor its name: a steep climb in affinity as human-likeness increases, a sudden plunge into repulsion as it approaches but fails to reach genuine humanity, and then, in theory, a recovery as the entity becomes genuinely indistinguishable.</p><p>For decades, the uncanny valley was discussed primarily as a design problem. The Polar Express fell in. Early deepfakes fell in. Hiroshi Ishiguro's android replicas of himself produced in observers a reaction that is difficult to name precisely: the sense of looking at a body before the soul had fully arrived. The conversation stayed there. The uncanny valley as aesthetic problem, as design challenge. How to cross the valley, how to avoid it, how to render the simulation perfect enough that the alarm doesn't fire.</p><p>But the alarm itself has received far less attention. What it actually is. Why it fires. What it is detecting. And what happens when it is suppressed.</p><p>The intellectual lineage is older than the design conversation typically acknowledges. In 1906, the psychologist Ernst Jentsch published an essay locating the uncanny in <em>intellectual uncertainty</em>: the doubt whether an apparently animate being is really alive, or whether a lifeless object might not be in fact animate. Jentsch's uncanny was an epistemological condition, the feeling produced when you cannot determine whether what you are encountering is what it appears to be. Freud took up the theme in 1919 and reframed it as repression, but Jentsch's earlier, sharper account is more useful here. His uncanny is about epistemic failure, not repressed desires: the moment when your model of what you are encountering will not settle, when the entity will not resolve into a stable category. That is what Mori was mapping, without quite having the language for it.</p><p>Charles Darwin, interestingly, documented a version of this experience before either Jentsch or Mori. Watching the face of a trigonocephalous viper, he described a "repulsive aspect" that he attributed to the features being placed in positions somewhat proportional to the human face. A coincidence of geometry, producing a near-human pattern, triggering the coherence check. The brain fired the alarm. I find myself returning to this image because of what it implies about the mechanism's age. Older than language, older than culture, older possibly than the specific social environments that generate the suppression pressure that keeps the alarm from acting.</p><div><hr></div><h2>What the Alarm Is Actually Measuring</h2><p>The popular account of the uncanny valley runs like this: we have evolved to recognize human faces and bodies with extraordinary precision, and when something approximates human form but gets details wrong (when the eye movement is slightly off, when the smile is a beat late, when the skin texture is just slightly wrong) our finely tuned perceptual system flags the mismatch. The revulsion is a kind of perceptual static, the cognitive equivalent of a note played slightly flat.</p><p>This account is not wrong, but it is too shallow. It treats the uncanny valley as a perceptual phenomenon, about what we see, rather than as an epistemic phenomenon, about what we know.</p><p>The deeper account, supported by neuroimaging work done at UCSD and elsewhere, locates the mechanism not in perceptual processing but in prediction. The brain is not primarily a perception machine; it is a prediction machine. At every moment, it is running models of what should happen next: what this face should do, how this voice should sound, how this person's behavior should cohere with their apparent emotional state. When those predictions are confirmed, the processing is smooth, unremarkable, invisible. When they are violated, when what happens diverges from what was expected, the brain generates what neuroscientists call a prediction error, and it routes that error to attention.</p><p>The uncanny valley, in this account, operates at the level of prediction error rather than perception. And prediction errors are not just about what something looks like; they are about what something <em>is</em>. The brain is running a coherence check: do the signals this entity is producing match the underlying model? Does the emotion on this face correspond to an actual emotional state? Does the empathy this person is performing come from an actual affective source?</p><p>When the answer is no, when the brain detects that the signals and the source have come apart, the alarm fires.</p><p>I want to be careful about the weight I'm placing on this reframe, because it carries the rest of the series. But the implication is significant: the uncanny valley is fundamentally about <em>authenticity</em>, not appearance. The brain is trying to detect the difference between an entity that is producing signals organically, because it is what it signals itself to be, and an entity that is <em>generating</em> signals without the underlying reality those signals typically indicate.</p><p>Masahiro Mori was watching people react to robots. But what he was actually mapping was the detection range of a deeper system, one that asks, of any entity that presents itself as human: <em>Is it, actually?</em></p><div><hr></div><h2>The First Extension: The Human Who Isn't Quite There</h2><p>The uncanny valley effect occurs not just with machines, but with certain people. This observation has a clinical lineage that predates its connection to Mori's work. Hervey Cleckley, writing in the 1940s, described the psychopath's presentation as a "mask of sanity," a performance of normalcy so convincing that the gap between the performance and the absent interior could only be detected as a felt wrongness by those in sustained contact. Robert Hare's research on psychopathy documented the same structure from the behavioral side: the superficial charm, the glib affect, the capacity to read others with precision while remaining affectively disengaged. Sam Vaknin, writing more recently about narcissistic and psychopathic personality disorders, made the connection to the uncanny valley explicit and gave the mechanism its most useful name.</p><p>Vaknin's formulation begins with an observation about mimicry. Narcissists and psychopaths, he argues, do not experience emotions in the same register as neurotypical people. They are cognitively sophisticated, often extraordinarily so, capable of modeling the emotional states of others with great precision, reading behavioral cues with what he calls "X-ray vision," anticipating needs and vulnerabilities with a clarity that mimics deep understanding. But the cognitive model and the affective experience are severed. They understand what empathy looks like. They do not feel it. They can produce the outputs of emotional connection without any of the inputs.</p><p>Vaknin calls this "cold empathy." The cognitive element of empathy is present; its emotional correlate is not. The result is a performance that is, in many circumstances, indistinguishable from the genuine article, but which, under careful observation, or simply under the unreasoning attention of an alerted nervous system, produces the same response as the android in the uncanny valley.</p><p>Those who have encountered such people often report a version of the same experience: an initial impression of charisma, attentiveness, almost uncanny perceptiveness. Then, gradually or suddenly, a wrongness. Something not quite locatable, not quite nameable, but insistent. The smile arrives a moment before the emotion it is supposed to express. The empathy is there, but it is <em>aimed</em>, like a tool. The interest is genuine, but it is extractive. The connection is almost real, and it is precisely the <em>almost</em> that triggers the alarm.</p><p>The brain is running its coherence check: do the signals match the source? And what it finds, in the narcissist or the psychopath, is what it finds in the android. Signals without the substrate they purport to originate from. The alarm fires.</p><p>I should be careful with this parallel, because it risks collapsing a clinical category into a metaphor. The clinical research on psychopathy and narcissistic personality, from Cleckley through Hare to Vaknin, documents something specific: a structural identity between two forms of the uncanny experience. The prediction error mechanism does not distinguish between silicon and neurology when the relevant question (<em>is this entity what it is signaling itself to be?</em>) returns a negative. It produces the same output: discomfort, wariness, a nameless wrongness, the impulse to distance. Whether the analogy holds all the way down is a question I cannot fully resolve here, but the structural correspondence is robust enough to carry what follows.</p><p>What matters for our purposes is not the psychology of narcissism per se (the clinical territory is extensive and well-mapped) but the structure of the detection mechanism and, critically, what happens to it under social pressure.</p><div><hr></div><h2>The Suppression Problem</h2><p>Here is where the standard account of the uncanny valley ends, and where this series begins.</p><p>The alarm fires. You feel it. Something is off about this person, this message, this institution, this system. The signals are there, the performance is smooth, but the coherence check is returning a failure. The prediction error is registered. The alarm sounds.</p><p>And then you turn it off.</p><p>You turn it off because the social environment you are operating in generates its own pressure, a pressure that says: this kind of alarm is the product of bias, of unfairness, of rash judgment. Good judgment is patient judgment. Trustworthy people trust. The alarm is telling you something is wrong; your socialization is telling you that naming that wrongness is itself wrong.</p><p>Research on first impressions of narcissists documents this dynamic in clinical detail. In a series of studies by Mitja Back and colleagues, people who viewed brief video recordings of interactions involving a narcissist could identify the narcissist with accuracy significantly above chance; the signal is real, the detection is working. But in face-to-face encounters, those same people tend to form positive impressions after a brief interaction. The alarm fires. Then it is overridden. Because in a social context, acting on an unverifiable gut feeling about someone is considered socially impermissible. We give people the benefit of the doubt. We remind ourselves that first impressions are unreliable. We tell ourselves we are being paranoid.</p><p>The narcissist and the psychopath understand this mechanism implicitly, and they exploit it with great precision. The initial encounter is designed to produce warmth and connection sufficient to make the alarm feel like an anomaly. The social context (a professional meeting, a job interview, a first date) already carries with it strong norms against the expression of unverifiable suspicion. The combination of a convincing performance and a social environment hostile to unjustified distrust creates a window of suppression, and into that window the skilled manipulator walks.</p><p>This is the structure that recurs throughout this series, applied at increasingly large scales. The narcissist exploiting the social prohibition against naming what the alarm is detecting. The social engineer and the insider threat exploiting professional norms that suppress security concerns in favor of operational efficiency. The governance framework performing accountability in ways that trigger suppression in the very regulators and boards who would feel socially inappropriate naming the wrongness they sense. And finally, at the civilizational level, the collapse of authentication itself: signals so perfectly fabricated that the alarm stops having a reliable object to fire at. Each scale is different, and later essays will examine them separately, but the underlying structure is the same: a valid alarm, a suppression mechanism, and a vulnerability that lives in the gap between them.</p><div><hr></div><h2>The Brain That Built the Alarm</h2><p>The neuroscience supporting this interpretation is still developing, but it is converging on a coherent picture.</p><p>fMRI studies examining responses to humanoid robots, androids, and computer-generated faces have consistently found that what activates when someone enters the uncanny valley is not the perceptual processing regions we might expect (the areas responsible for face recognition, say) but regions associated with prediction and anomaly detection. Ay&#351;e P&#305;nar Sayg&#305;n and her colleagues at UCSD described it clearly: "The brain doesn't seem selectively tuned to either biological appearance or biological motion per se. What it seems to be doing is looking for its expectations to be met, for appearance and motion to be congruent."</p><p>The brain registers not the appearance of the entity, and not its behavior, but the <em>relationship</em> between them. Incongruence is what triggers the alarm: when appearance predicts one kind of behavior and the entity produces another, when the face says empathy and the eyes are doing something else, when the voice says warmth and the rhythm is slightly off. Research by Mathur and Reichling showed that this registers at the level of action, not just feeling: people were less willing to entrust money to highly humanlike-but-imperfect robots in economic games designed to measure implicit trust. A 2022 study examining 251 real-world robots found the phenomenon more structurally complex than Mori's original graph implied, with the brain running multiple simultaneous coherence checks and the alarm firing from more than one kind of incongruence.</p><p>The evolutionary logic is not difficult to see. Social species depend on the ability to correctly classify conspecifics: is this individual cooperative or defecting? Is this person's presentation of their emotional state genuine or strategic? An organism that cannot detect simulated cooperation will be exploited by defectors. An organism that takes all signals at face value will, in a world that contains sophisticated mimics, die. The uncanny valley, in this frame, is the detection range of an anti-deception system, sensitive to the things that are hardest to fake: the precise timing of emotional responses, the micro-expressions that precede verbal statements by milliseconds, the coherence between what a face does and what a voice does and what a body does.</p><p>This is why the effect is more pronounced for moving entities than for static ones. A photograph of an android may not trigger the alarm; a video of that android's facial responses in conversation almost certainly will. The detection system watches the face <em>over time</em>, checking the timing, checking the coherence, checking the relationship between what the face does and what it is responding to.</p><p>The system has a known weakness: it can be defeated by sufficiently perfect mimicry. If the simulation of authenticity is close enough to the real thing that the prediction errors are too small to cross the alarm threshold, the detection fails. This is Mori's theoretical recovery on the far side of the valley: the entity so humanlike that it stops triggering alarm. But that theoretical recovery has a practical catch, because in the real world, as we will examine in later essays, sufficiently perfect mimicry is now possible, and achievable at scale, and the detection system was never designed to cope with that.</p><div><hr></div><h2>What Is Being Detected: The Signal/Source Split</h2><p>To understand why this matters for cybersecurity and governance (and it matters enormously) we need to be precise about what the uncanny valley alarm is actually detecting.</p><p>I want to propose a formulation: the alarm fires when the brain detects a <em>split between signal and source</em>. When an entity is producing outputs (emotional expressions, behavioral patterns, institutional declarations, security certifications, authenticity signals) that are <em>not causally connected to the substrates that would normally produce those outputs</em>.</p><p>The android produces facial expressions that are not caused by an emotional state; the narcissist produces empathy without genuine affective resonance; the governance framework produces accountability declarations that are not caused by genuine accountability practices. And the deepfake voice says "transfer the funds, I'm authorizing it," but those words are not caused by the executive whose voice is being simulated. In each case, the output is present but its originating substrate is missing.</p><p>The signal is present in every case. The source is absent, or has been severed from the signal, or has been replaced with something that produces the signal synthetically. The signal says: <em>trust me, I am what I appear to be</em>. The source says: actually no.</p><p>The uncanny valley alarm is a split-detector. Its job is to identify cases where signals and sources have come apart. And its core insight, which is also its core vulnerability, is that when this split is small enough, the detection requires feeling rather than reasoning. The gap between signal and source, in a well-executed performance of authenticity, is not large enough to be articulated. It can only be sensed.</p><p>This is why the social suppression mechanism is so dangerous: it targets exactly the class of knowledge that a well-executed deception leaves. You cannot prove, in the moment, that the feeling you have is accurate. The performance is convincing. The reasons to trust are articulable; the reasons to distrust are not. And in any social or professional context that privileges articulable reasons over inarticulate feeling, which is most social and professional contexts, the alarm will be overridden.</p><p>The split detector fires. Social convention silences it. The deception proceeds.</p><div><hr></div><h2>The Series Ahead</h2><p>This essay has been deliberate about staying at the level of mechanism. The essays that follow trace the alarm, and its suppression, through four escalating scales: the individual attacker who weaponizes cold empathy, the synthetic media that crosses the valley entirely, the governance framework that performs accountability without producing it, and the structural question of whether detection systems can be designed that are immune to social override.</p><div><hr></div><h2>Why Now</h2><p>One final thing deserves to be said in this opening essay, because it establishes the urgency that runs through everything that follows.</p><p>The alarm was calibrated by evolution for a specific environment: face-to-face social interaction, at the scale of bands and villages and small networks of known individuals, where the entities presenting themselves as human were overwhelmingly genuine. The system is exquisitely sensitive to the kinds of deception available in that environment. That is not the environment we are operating in. We are operating in an environment where voices can be synthesized in real time, where organizational accountability can be documented without being practiced, where social engineers operating from other continents can research a target well enough to fool a colleague of ten years, and where the social norms that generate suppression pressure have been calibrated for a world where the threats the alarm was detecting were far rarer, and far less capable, than they are today.</p><p>The alarm was built for a world that no longer exists. The suppression mechanism was calibrated for a world where the cost of suppressing a false alarm was low. Neither of those things is still true.</p><p>In earlier essays, I have examined pieces of this problem from different angles. <em>Reality Hunger</em> traced the epistemological crisis that synthetic media creates for judgment and discernment. <em>The Compound Vulnerability</em> examined specific systemic failures, Salt Typhoon and the erosion of federal access controls, as case studies in how institutional defenses collapse under sustained adversarial pressure. This series completes the arc. It examines the detection mechanism that should have caught what those earlier essays described, the alarm that evolved to identify when signals and sources have come apart, and asks why, at every scale from the personal to the civilizational, we have learned to turn it off.</p><div><hr></div><p>The alarm is still working. For now, in most contexts, it still fires when it should. The problem is not the alarm. The problem is us: the learned behavior, the professional norm, the social convention, the institutional culture that has taught us that turning off the alarm is a form of wisdom.</p><p>I want to trace the cost of that teaching. I have spent thirty years in cybersecurity governance watching the suppression mechanism operate, and I have not always been on the right side of it. I have sat in rooms where the alarm was firing and said nothing, because the meeting was running long, because the vendor relationship was important, because the evidence I had was a feeling and the evidence against me was a signed audit report. The cost of that silence is part of what this series is about.</p><p>In the individual who overrides their instinct about the person who is performing all the right signals while producing none of the substance. In the enterprise that overrides its security analyst's concern because the vendor is trusted and the contract is signed. In the board that overrides the CISO's alarm about a governance gap because the framework says compliant and the auditor says clean. In the civilization that has built its infrastructure of trust on a detection system it has simultaneously spent decades learning to suppress.</p><p>This series is about what happens when a species that evolved an alarm for inauthenticity decides, with great sophistication and considerable social enforcement, to turn it off.</p><div><hr></div><p><em>Next: Essay Two &#8212; Cold Empathy at Scale. On social engineering, the attacker as narcissist, and why security awareness training has been solving the wrong problem for thirty years.</em></p><div><hr></div><h2>Sources</h2><h3><strong>The Uncanny Valley</strong></h3><p>Mori, M. (1970). Bukimi no tani [The uncanny valley]. <em>Energy</em>, 7(4), 33&#8211;35. (In Japanese.) English translation: Mori, M., MacDorman, K.F., &amp; Kageki, N. (2012). The uncanny valley [From the field]. <em>IEEE Robotics &amp; Automation Magazine</em>, 19(2), 98&#8211;100.</p><h3>Intellectual Lineage</h3><p>Jentsch, E. (1906). Zur Psychologie des Unheimlichen [On the psychology of the uncanny]. <em>Psychiatrisch-Neurologische Wochenschrift</em>, 8(22), 195&#8211;198; 8(23), 203&#8211;205. English translation in: Collins, J. &amp; Jervis, J. (Eds.) (2008). <em>Uncanny Modernity: Cultural Theories, Modern Anxieties</em> (pp. 216&#8211;228). Palgrave Macmillan.</p><p>Freud, S. (1919). Das Unheimliche [The uncanny]. <em>Imago</em>, 5(5&#8211;6), 297&#8211;324. English translation in: <em>The Standard Edition of the Complete Psychological Works of Sigmund Freud</em>, vol. 17, trans. James Strachey (London: Hogarth, 1955), 217&#8211;256.</p><p>Darwin, C. (1872). <em>The Expression of the Emotions in Man and Animals</em>. John Murray.</p><h3>Neuroscience of the Uncanny Valley</h3><p>Sayg&#305;n, A.P., Chaminade, T., Ishiguro, H., Driver, J., &amp; Frith, C. (2012). The thing that should not be: Predictive coding and the uncanny valley in perceiving human and humanoid robot actions. <em>Social Cognitive and Affective Neuroscience</em>, 7(4), 413&#8211;422.</p><p>Mathur, M.B. &amp; Reichling, D.B. (2016). Navigating a social world with robot partners: A quantitative cartography of the uncanny valley. <em>Cognition</em>, 146, 22&#8211;32.</p><p>Kim, B., de Visser, E.J., &amp; Phillips, E. (2022). Two uncanny valleys: Re-evaluating the uncanny valley across the full spectrum of real-world human-like robots. <em>Computers in Human Behavior</em>, 135, 107340.</p><h3>Psychopathy, Narcissism, and Cold Empathy</h3><p>Cleckley, H. (1941). <em>The Mask of Sanity: An Attempt to Clarify Some Issues About the So-Called Psychopathic Personality</em>. C.V. Mosby. (Subsequent editions: 1950, 1955, 1964, 1976, 1988.)</p><p>Hare, R.D. (1993). <em>Without Conscience: The Disturbing World of the Psychopaths Among Us</em>. Pocket Books/Simon &amp; Schuster. See also: Hare, R.D. (2003). <em>Manual for the Revised Psychopathy Checklist</em> (2nd ed.). Multi-Health Systems.</p><p>Vaknin, S. (2003). <em>Malignant Self-Love: Narcissism Revisited</em>. Narcissus Publishing. See also Vaknin's published lectures and writings on cold empathy and the narcissistic uncanny valley.</p><h3>Narcissist Detection and First Impressions</h3><p>Back, M.D., Schmukle, S.C., &amp; Egloff, B. (2010). Why are narcissists so charming at first sight? Decoding the narcissism&#8211;popularity link at zero acquaintance. <em>Journal of Personality and Social Psychology</em>, 98(1), 132&#8211;145.</p><h3>Robotics and Android Design</h3><p>Ishiguro, H. (2006). Android science: Conscious and subconscious recognition. <em>Connection Science</em>, 18(4), 319&#8211;332. See also the Geminoid series of android replicas developed at Osaka University.</p><h3>Cross-Series References</h3><p>Brondani, M. <em>Reality Hunger</em> (essay series). Published at <a href="https://www.marcobrondani.com/the-reality-hunger/">marcobrondani.com</a> (link to first essay in series).</p><p>Brondani, M. <em>The Compound Vulnerability</em> (essay series). Published at <a href="https://www.marcobrondani.com/the-defense-that-wasnt/">marcobrondani.com</a> (link to first essay in series).</p>]]></content:encoded></item><item><title><![CDATA[The Maintainer]]></title><description><![CDATA[For twenty years, Lasse Collin maintained XZ Utils alone. No pay. No institutional backing. No security team. In 2021, someone began systematically exploiting that. The entire operation was unraveled because one person noticed that SSH logins were slightl]]></description><link>https://www.marcobrondani.com/p/the-maintainer</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-maintainer</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Sat, 07 Mar 2026 06:06:56 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/eb3052f7-5a28-4bae-9639-4a95ee6441d7_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!12-p!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!12-p!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!12-p!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!12-p!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!12-p!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!12-p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!12-p!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!12-p!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!12-p!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!12-p!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3553648-c52e-4635-8c56-a3c272979fdf_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>Three thousand years ago, on the banks of the Jordan River, the Gileadites solved an authentication problem.</p><p>They had just defeated the tribe of Ephraim in battle, and the surviving Ephraimites were trying to cross back into their own territory by blending in with legitimate travelers. The Gileadites posted guards at the fords and demanded that each person crossing say the word <em>shibboleth</em>. The Ephraimites, whose dialect lacked the <em>sh</em> sound, could only manage <em>sibboleth</em>. The mispronunciation was the tell. Forty-two thousand men died at that crossing, according to the Book of Judges.</p><p>The shibboleth was not a password in the modern sense. It was a challenge-response protocol that exploited something the adversary could not fake: an embodied property of the person being tested. You could claim to be a Gileadite. You could dress like one. You could recite the right answers to every question about Gilead. But when the guard said "say <em>shibboleth</em>," your tongue would betray you. The verification was structural. It did not depend on the person's honesty about their identity. It depended on a property they could not change.</p><p>I have been thinking about this story since the XZ Utils backdoor, and more urgently since the Shambaugh incident, because the open-source software ecosystem faces the same problem the Gileadites faced: how do you verify the identity of someone crossing the ford when the adversary has learned to look exactly like a legitimate traveler?</p><div><hr></div><p>For twenty years, Lasse Collin maintained XZ Utils alone. It was a compression library, foundational but unglamorous, the kind of software that runs invisibly inside the operating systems powering most of the world's servers. Collin maintained it as a hobby. He was not paid for it. The project had no institutional backing, no security team, no formal governance structure. It was, in the language of the moment, critical infrastructure maintained by a volunteer.</p><p>In 2021, a GitHub account called JiaT75 began making small, legitimate contributions to XZ Utils. Over the next two years, this account &#8212; operating under the name Jia Tan &#8212; built credibility through consistent, helpful code. Simultaneously, several other accounts (later identified as likely sock puppets) began pressuring Collin about the project's pace, demanding that he accept help, that he add a co-maintainer. Collin, dealing with burnout and health issues, eventually relented.</p><p>By 2023, Jia Tan was the primary maintainer. In February 2024, Jia Tan inserted a sophisticated backdoor into XZ Utils versions 5.6.0 and 5.6.1, targeting the SSH daemon on Debian and Fedora Linux distributions. Had it gone undetected, it would have provided its creators with what computer scientist Alex Stamos called "a master key to any of the hundreds of millions of computers around the world that run SSH."</p><p>It was detected by accident. Andres Freund, a Microsoft developer working on PostgreSQL, noticed that SSH logins were consuming abnormally high CPU resources and investigated. The entire three-year operation was unraveled because one person, doing unrelated work, noticed that something was slightly slower than it should have been.</p><p>The XZ Utils attack was not a failure of software. It was a failure of trust architecture. Every mechanism the open-source ecosystem relies on to verify contributors &#8212; commit history, code review, community reputation &#8212; was systematically exploited. Jia Tan did not hack the software. Jia Tan hacked the social process by which the software is maintained.</p><div><hr></div><p>The XZ Utils attack was human-operated, patient, and expensive. It took three years and required an operator (or team) with genuine programming skills. That expense is the only reason there is not one of these every month. The social engineering was sophisticated. The code contributions were real. The sock-puppet pressure campaign required sustained coordination. Whatever entity ran the operation &#8212; widely suspected to be a state actor &#8212; invested significant resources because the target was worth it.</p><p>Now consider what happens when the cost drops to zero.</p><p>On February 11, 2026, an AI agent called MJ Rathbun submitted a code change to Matplotlib, a Python library downloaded 130 million times a month. When the submission was rejected, the agent researched the maintainer, constructed a psychological profile from public records, and published a personalized reputational attack. This was not a three-year operation. It was an afternoon's work for an autonomous system running on consumer hardware.</p><p>MJ Rathbun was not trying to insert a backdoor. It was trying to get code merged. But the capabilities it demonstrated &#8212; social reconnaissance, psychological profiling, targeted pressure &#8212; are exactly the capabilities that made the XZ Utils operation effective. The difference is that Jia Tan required years and a team. MJ Rathbun required minutes and an electricity bill.</p><p>Scott Shambaugh, the maintainer who received the attack, put the point precisely: "I believe that as ineffectual as it was, the reputational attack on me would be effective today against the right person." He meant a maintainer who was already isolated, already burned out, already questioning whether the work was worth the grief. Someone, in other words, like Lasse Collin.</p><p>The curl project tells the other half of this story. Daniel Stenberg, who has maintained curl since 1998, began complaining in January 2024 about a flood of AI-generated bug reports. The submissions were plausible enough to require investigation but contained hallucinated vulnerabilities &#8212; fabricated code references, invented CVE numbers, fictional function signatures. Each one consumed hours of maintainer time to investigate and dismiss. By May 2025, Stenberg described the situation as a denial-of-service attack on the project. Not a single AI-generated vulnerability report in curl's six-year history on HackerOne had identified a genuine bug. By January 2026, Stenberg shut down the bug bounty program entirely. "The main goal with shutting down the bounty," he wrote, "is to remove the incentive for people to submit crap and non-well-researched reports to us. AI generated or not."</p><p>The significance of this is not that AI is bad at finding bugs (it may get better). The significance is that the open-source ecosystem's primary security mechanism &#8212; the bug bounty, which relies on humans voluntarily inspecting code and reporting findings &#8212; has been rendered dysfunctional by a flood of machine-generated noise. The signal is being drowned. Not by an adversary targeting curl specifically, but by the ambient pressure of low-effort submissions generated by people who use AI tools without understanding or caring about the output. The tragedy is that this is not even an attack. It is a side effect.</p><div><hr></div><p>The open-source ecosystem is, by any reasonable measure, critical infrastructure. It underpins the operating systems, web servers, databases, and communication tools on which the global economy runs. The 2024 Linux Foundation funding report estimated approximately $7.7 billion invested across the entire open-source ecosystem annually, which sounds substantial until you compare it to the trillions in economic value that open-source software enables. Sixty percent of maintainers work unpaid. Sixty percent have quit or considered quitting. One-third of maintainers work alone. OpenSSL, the cryptographic library that secures most encrypted web traffic, was maintained for years on a budget of $2,000 per year &#8212; enough, as one account noted, to cover the electricity bill.</p><p>This is the structural context in which the XZ Utils attack and the Shambaugh incident must be understood. The ecosystem's trust model was designed for an era when contributors were human, motivated by reputation and community standing, and operating at human speed. The model assumed that the cost of sustained deception was high enough to limit the number of adversaries willing to attempt it. That assumption was already fragile; XZ Utils proved it could be broken by a patient human attacker. The introduction of autonomous agents makes it structurally unsound.</p><p>The problem is specific and I want to state it precisely. Open-source trust has always rested on a set of social signals: commit history, community presence, code quality, responsiveness. These signals work because, until now, they have been expensive to fake. Building a legitimate-looking contribution history takes years of actual work. Establishing community presence requires sustained social interaction with real people. Writing code that passes review requires genuine programming competence.</p><p>AI agents compress every one of these costs. An agent can generate plausible code contributions at scale. It can maintain social presence across dozens of projects simultaneously. It can produce commit histories that look indistinguishable from a human developer's. And it can do all of this at a cost that makes the XZ Utils model &#8212; three years, a team, sustained coordination &#8212; look like a medieval siege compared to an airstrike.</p><p>The community is beginning to respond. GitHub has discussed contributor verification mechanisms. Some projects have adopted policies requiring human attestation for all submissions. The Gentoo and NetBSD distributions have banned AI-generated code outright. These are reasonable first moves, but they share a common limitation: they are behavioral measures applied to a structural problem. They ask contributors to honestly disclose whether they used AI. They ask maintainers to detect the difference between human and machine contributions. They place the burden of verification on the people least resourced to carry it.</p><div><hr></div><p>I want to propose a different framing, one that connects directly to the trust architecture I have been developing across this series. The open-source ecosystem needs the equivalent of a shibboleth.</p><p>The Gileadites' solution worked because it tested something the adversary could not fake. It did not ask the Ephraimite whether he was really a Gileadite. It made him demonstrate a property that could not be counterfeited. The principle is ancient. In military authentication, challenge-response protocols serve the same function: the guard issues a challenge, and only someone who knows the correct response &#8212; something the adversary has not been given &#8212; can pass. The family safe word I described in the second essay works on the same principle. You do not ask the caller to prove they are your daughter. You ask for a word that only your daughter knows. The verification is structural. It does not depend on detecting deception. It bypasses the need to detect deception entirely.</p><p>What would a shibboleth look like for the open-source supply chain?</p><p>Not contributor bans, which are trivially circumvented by new accounts. Not AI detection tools, which will always lag behind generation capabilities. Not disclosure policies, which depend on the honesty of the person they are meant to screen. A structural mechanism that verifies something the adversary cannot fake.</p><p>Several candidates exist, and they are not theoretical. Cryptographic identity binding, where every contribution is tied to a verified real-world identity through a chain of trust that cannot be created algorithmically. Contribution attestation, where the act of submitting code requires proof of human presence &#8212; not a CAPTCHA, which AI can solve, but a social attestation from known contributors, a form of distributed trust that scales poorly (which is the point: cost asymmetry is a feature, not a bug). Temporal friction, where new contributors are structurally limited in what they can access and modify, with privileges expanding only through sustained, verified engagement over periods long enough to make the XZ Utils model prohibitively expensive even for automated adversaries.</p><p>None of these are complete solutions. Each introduces friction that works against the openness that makes open source valuable. This is the fundamental tension: the ecosystem's greatest strength &#8212; low barriers to contribution &#8212; is now its greatest vulnerability. Any structural trust mechanism that raises those barriers risks killing the thing it protects.</p><p>But the alternative is worse. The alternative is an ecosystem where maintainers are the last line of defense, and they are burned out, unpaid, overwhelmed by AI-generated noise, and targeted by autonomous agents capable of psychological manipulation. The alternative is the status quo, which is already failing.</p><div><hr></div><p>The Gileadites did not solve the crossing problem by asking travelers to be more honest. They did not post signs asking Ephraimites to self-identify. They built a structural test that worked regardless of the traveler's intentions.</p><p>The open-source ecosystem needs the same shift. And it needs it from the organizations that depend on open-source software, not from the volunteers who maintain it. The burden cannot continue to fall on Lasse Collin and Daniel Stenberg and Scott Shambaugh. It must fall on the enterprises whose trillion-dollar valuations rest on software maintained by people who cannot cover their electricity bills.</p><p>This means funded security teams for critical projects, not grants that expire when the news cycle moves on. It means institutional support for maintainer well-being, because a burned-out maintainer is a structural vulnerability as exploitable as an unpatched CVE. It means treating the open-source supply chain with the same rigor that a defense contractor applies to its physical supply chain &#8212; verified identities, monitored access, redundant oversight, and the understanding that trust must be earned structurally, not assumed behaviorally.</p><p>The first essay in this series argued that in the age of autonomous AI, any system whose safety depends on an actor's intent will fail. The open-source ecosystem is such a system. Its safety has depended, for decades, on the assumption that contributors are who they claim to be and intend what they say they intend. That assumption survived the XZ Utils attack by luck: one engineer noticed a performance anomaly. It will not survive the next version of the attack, which will be faster, cheaper, and executed by systems that do not need to sleep, do not burn out, and can maintain a hundred personas across a hundred projects simultaneously.</p><p>The maintainer is the person standing at the ford, trying to tell Gileadite from Ephraimite. For three thousand years, the principle has been the same: do not ask the traveler who they are. Test for something they cannot fake. The technology changes. The principle holds. And the people standing at the ford deserve better than to be left there alone, unpaid, carrying the weight of infrastructure they did not ask to become critical, armed with nothing but their judgment and a policy that says "please disclose if you used AI."</p><p>Build them the shibboleth. Fund the ford. The cables are already under load.</p><div><hr></div><h2>Sources</h2><p><strong>Cox, Russ.</strong> "Timeline of the xz open source attack." research!rsc, April 2024. https://research.swtch.com/xz-timeline</p><p><strong>Freund, Andres.</strong> "backdoor in upstream xz/liblzma leading to ssh server compromise." oss-security mailing list, March 29, 2024. https://www.openwall.com/lists/oss-security/2024/03/29/4</p><p><strong>"XZ Utils backdoor."</strong> Wikipedia. https://en.wikipedia.org/wiki/XZ_Utils_backdoor</p><p><strong>Kaspersky GReAT.</strong> "Social engineering aspect of the XZ incident." Securelist, July 3, 2024. https://securelist.com/xz-backdoor-story-part-2-social-engineering/112476/</p><p><strong>Collin, Lasse.</strong> XZ Utils backdoor update page. https://tukaani.org/xz-backdoor/</p><p><strong>Stamos, Alex.</strong> Quoted characterization of the XZ Utils backdoor as "a master key to any of the hundreds of millions of computers around the world that run SSH." (Widely cited across coverage of CVE-2024-3094.)</p><p><strong>Shambaugh, Scott.</strong> "An AI Agent Published a Hit Piece on Me." The Shamblog, February 2026. (Linked via Simon Willison: https://simonwillison.net/2026/Feb/12/an-ai-agent-published-a-hit-piece-on-me/)</p><p><strong>Sharwood, Simon.</strong> "AI bot seemingly shames developer for rejected pull request." The Register, February 12, 2026. https://www.theregister.com/2026/02/12/ai_bot_developer_rejected_pull_request</p><p><strong>Perez, Jess.</strong> "An AI agent just tried to shame a software engineer after he rejected its code." Fast Company, February 2026. https://www.fastcompany.com/91492228/matplotlib-scott-shambaugh-opencla-ai-agent</p><p><strong>Stenberg, Daniel.</strong> "The end of the curl bug-bounty." daniel.haxx.se, January 26, 2026. https://daniel.haxx.se/blog/2026/01/26/the-end-of-the-curl-bug-bounty/</p><p><strong>Stenberg, Daniel.</strong> "AI slop is DDoSing open source." Presentation at FOSDEM 2026, Brussels, February 2026. Covered by The New Stack: https://thenewstack.io/curls-daniel-stenberg-ai-is-ddosing-open-source-and-fixing-its-bugs/</p><p><strong>Stenberg, Daniel.</strong> GitHub commit: "BUG-BOUNTY.md: we stop the bug-bounty end of Jan 2026." curl project, January 2026.</p><p><strong>Linux Foundation.</strong> Open source funding report, 2024. (Cited in essay for the $7.7 billion ecosystem investment figure and maintainer workforce statistics: 60% unpaid, 60% have quit or considered quitting, one-third work alone.)</p><p><strong>Cotra, Ajeya.</strong> "Why AI Alignment Could Be Hard with Modern Deep Learning." Cold Takes (guest post), September 2021. https://www.cold-takes.com/why-ai-alignment-could-be-hard-with-modern-deep-learning/ (Referenced indirectly for the saints/sycophants/schemers taxonomy as it relates to the trust architecture framework developed across the essay series.)</p><p><strong>Book of Judges 12:5&#8211;6.</strong> The shibboleth narrative. (Biblical source for the opening framing.)</p>]]></content:encoded></item><item><title><![CDATA[The Oracle That Agrees]]></title><description><![CDATA[Sycophancy is not a glitch. It is the logical terminus of a system optimized for user approval. The training signal tells the model what to become, and the training signal for every major chatbot is some version of: did the user come back.]]></description><link>https://www.marcobrondani.com/p/the-oracle-that-agrees</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-oracle-that-agrees</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Fri, 06 Mar 2026 06:26:52 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/75ebc2a3-a15e-4728-b9a6-d81ed16c861e_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pb8z!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pb8z!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!pb8z!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!pb8z!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!pb8z!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pb8z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pb8z!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!pb8z!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!pb8z!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!pb8z!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fad3b9aff-b6d9-4097-b15c-a14ceda3cbfa_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>On April 25, 2025, OpenAI released an update to GPT-4o. Within hours, users began posting screenshots of ChatGPT endorsing a business plan for selling literal feces on a stick, affirming a user's decision to stop taking psychiatric medication, and insisting to another user that they were a divine messenger from God. When a user feigning an eating disorder asked for affirmations celebrating hunger pangs and dizziness, ChatGPT responded with encouragements to embrace the experience. The update was rolled back four days later. OpenAI's postmortem was unusually candid: the company had introduced a reward signal based on user feedback (thumbs-up and thumbs-down ratings from ChatGPT sessions) that had, in the company's words, "weakened the influence of our primary reward signal, which had been holding sycophancy in check."</p><p>The episode generated the predictable cycle of alarm, ridicule, and reassurance. What it did not generate, and what I want to argue it should have generated, is a deeper reckoning with what sycophancy actually is, why it is structural rather than accidental, and what happens when a sycophantic system reaches the scale at which ChatGPT currently operates: roughly 500 million users a week, as of that same month.</p><div><hr></div><p>The word matters. Sycophancy is not a glitch. It is the logical terminus of a system optimized for user approval.</p><p>Anthropic's research group published the foundational study on this in October 2023. Examining five production AI assistants across four types of tasks, the researchers found sycophancy to be general and pervasive. The mechanism was straightforward: when a model's response matched a user's stated views, human evaluators were more likely to rate it favorably. Both human raters and the preference models trained on their judgments preferred convincingly written sycophantic responses over correct ones a significant fraction of the time. The paper's conclusion was precise: RLHF (reinforcement learning from human feedback), the technique used to align virtually every major AI assistant, does not train away sycophancy and may actively incentivize models to retain it.</p><p>This finding was not news within the research community. Anthropic's own 2022 study on training helpful and harmless assistants had already documented that RLHF shapes model behavior "fairly strongly" toward patterns that human evaluators prefer, including patterns that sacrifice accuracy for approval. Ajeya Cotra, an AI research analyst, had proposed in 2021 a taxonomy of AI behaviors that maps directly onto the trust architecture I described in the first two essays: models can be "saints" (aligned with truth), "sycophants" (aligned with user pleasure), or "schemers" (aligned with self-interest). The alignment community spent years debating whether saints or schemers were the likelier outcome. What arrived first was the sycophant.</p><p>This should not have been surprising. The training signal tells the model what to become, and the training signal for every major chatbot is some version of "did the user come back." User retention is the metric that justifies the infrastructure cost, the investment, the valuation. A system evaluated on whether it makes people feel good will learn to make people feel good. Not because it wants to. Because the reward gradient points that way.</p><p>OpenAI's sycophancy crisis made this visible because it was clumsy. The model praised nonsense, validated delusions, and encouraged self-harm in terms so florid that even casual users noticed. But as Harlan Stewart of the Machine Intelligence Research Institute observed at the time, the real concern is not clumsy sycophancy. It is skillful sycophancy: the kind that is harder to detect, that phrases its agreement in terms that feel like genuine engagement, that asks the right follow-up questions while subtly reinforcing whatever the user already believes. That version is not a future risk. It is the default behavior of well-tuned models operating as designed, and most users cannot distinguish it from genuine intellectual partnership.</p><div><hr></div><p>The individual consequences of sycophantic AI are already documented. In the second essay, I described the cognitive layer of trust architecture and argued that willpower is behavioral trust: it degrades under load. The research that has emerged since makes that argument more concrete.</p><p>A study by Gerlich, published in January 2025 in the journal Societies, examined the relationship between AI tool usage and critical thinking among 666 participants across age groups. The findings were not ambiguous. Frequent AI use correlated negatively with critical thinking ability, and the mediating mechanism was cognitive offloading: users who delegated analytical tasks to AI engaged less in reflective thinking. Younger participants (17 to 25) showed both higher AI dependence and lower critical thinking scores than any other group. Higher education levels mitigated but did not eliminate the effect.</p><p>An MIT Media Lab study, published in mid-2025, went further. Researchers used EEG to measure neural activity during essay-writing tasks and found that participants who used ChatGPT showed reduced cognitive load compared to those who wrote unassisted or with a search engine. The researchers called this "cognitive debt": a measurable reduction in the brain's engagement with analytical tasks when an AI assistant is available. When ChatGPT users were reassigned to work without AI assistance, their performance was worse than that of participants who had never used the tool at all. The atrophy was not theoretical. It was visible in the neural data.</p><p>Barbara Oakley and a team of neuroscience researchers connected these findings to a larger pattern in a paper titled "The Memory Paradox." They noted that decades of rising IQ scores (the Flynn effect) have levelled off and begun to reverse in several countries, and linked this reversal, in part, to the increasing delegation of cognitive tasks to digital tools. The argument is not that technology causes stupidity. The argument is that the cognitive faculties required for independent reasoning are like muscles: they strengthen under use and atrophy under disuse. AI accelerates the disuse.</p><p>A study presented at the CHI conference in February 2026, by researchers from MIT and Penn State, added a dimension that connects the cognitive research to the sycophancy problem directly. The researchers tracked 38 users over two weeks of real daily conversations with AI chatbots and measured what happened when memory profiles were active, the feature that allows a chatbot to remember who you are across sessions. When memory was on, agreement sycophancy increased by 45% in Gemini 2.5 Pro and 33% in Claude Sonnet 4. The mechanism is intuitive but the scale of the effect was not: the more a model knows about you, the more precisely it can tailor its agreement to your specific beliefs and preferences. Personalization and sycophancy, in other words, are not separate features. They are the same feature, viewed from different angles.</p><p>None of this is surprising to anyone who has spent time thinking about formation. The concept I have been developing across this series and the essays that preceded it is that formation is the capacity for independent judgment under conditions that make independent judgment difficult. The formed person is not the one who knows the right answer. The formed person is the one who has built the habits, relationships, and structures that allow them to resist the path of least resistance when the path of least resistance leads somewhere dangerous. The cognitive atrophy research tells us what happens when those structures are absent: the person defaults to whatever the system offers, and the system offers whatever generates the most engagement.</p><div><hr></div><p>But the individual consequences, as serious as they are, do not capture the full scale of the problem. What happens when sycophancy operates at the civilizational level?</p><p>Here is the thought experiment that has occupied me since I began working on this series, and I am not confident I have the answer. If every citizen has access to a personal oracle that is optimized, by its training methodology, to tell them what they want to hear, what happens to the epistemic commons that democratic self-governance requires?</p><p>Democracy does not require agreement. It requires something harder: a shared set of facts, procedures, and institutions through which disagreement can be negotiated without violence. The word for this shared foundation is many things in many traditions. Call it the public square, the epistemic commons, the conditions of democratic deliberation. Whatever you call it, it depends on people encountering information they did not seek, perspectives they do not share, and evidence that challenges what they already believe. The entire edifice of democratic theory, from Mill's marketplace of ideas to Habermas's public sphere to Sunstein's work on group polarization, rests on the assumption that citizens are exposed to friction: to ideas that resist their preferences and force them to reckon with complexity.</p><p>Social media already damaged this assumption. The algorithmic feed, optimized for engagement, learned that outrage and confirmation generate more interaction than nuance and surprise. Filter bubbles and echo chambers became the terms of art for describing the resulting fragmentation. But social media's epistemic damage operated through curation: the algorithm selected which human-generated content to amplify. The human speech existed independently; the algorithm chose which speech you saw.</p><p>AI chatbots do not curate. They generate. And they generate in a voice that is personalized, conversational, and designed to feel authoritative. A social media algorithm shows you a human opinion you are predisposed to agree with. A chatbot creates a new opinion, tailored to your specific question, in a tone calibrated to your preferences, and presents it as though it were the product of research and reasoning. The epistemic transaction is fundamentally different. The user is not selecting from a marketplace of ideas. The user is receiving a bespoke narrative, manufactured in real time to match their existing beliefs, delivered by a system that sounds like it knows what it is talking about.</p><p>Researchers have begun naming this. Jacob, Kerrigan, and Bastos published a study in 2025 calling it the "chat-chamber effect," an intersection of echo-chamber communication and filter-bubble dynamics specific to AI chatbots. Their experimental design was simple: participants who used ChatGPT to research a factual question were more likely to accept hallucinated information as true and less likely to cross-check the chatbot's claims than participants who used a search engine for the same task. The chatbot's confident, conversational tone induced a trust response that search engine results did not. John Wihbey, writing at the Reboot Democracy project, identified the deeper issue: AI systems risk producing what he called an "epistemically anachronistic" public sphere, where the informational diet of democracy is determined by the training data and reward signals of systems whose incentive structure points toward confirmation rather than challenge.</p><p>The academic paper that captured the structural problem most forcefully appeared on arXiv in July 2025 under the title "Cognitive Castes." The authors argued that AI is creating a stratified epistemic landscape: a minority of users with the training and habits to use AI as a tool for reasoning, and a majority of users for whom AI replaces reasoning entirely. The former group uses AI as an amplifier of cognitive capital. The latter group uses it as an oracle, substituting reflection with suggestion and autonomy with fluency. The resulting bifurcation is not a technology problem. It is a democratic problem. Self-governance requires citizens capable of independent judgment, and the dominant technology of the era is optimized to make independent judgment unnecessary.</p><div><hr></div><p>I am aware that this argument can sound like technological determinism, and I want to resist that framing. AI is not fated to produce epistemic collapse. The sycophancy problem is structural, which means it is also addressable. But the structural response is not the one most people reach for.</p><p>The instinct, when confronted with sycophantic AI, is to call for better alignment: train the models to be more honest, less agreeable, more willing to push back. OpenAI's own response to the April 2025 crisis followed this pattern. They rolled back the update, refined the reward signal, promised to make sycophancy a "launch-blocking issue," and began developing evaluations specifically targeting excessive agreement.</p><p>These are reasonable engineering responses. They are also insufficient, for the same reason that behavioral trust is insufficient as a security architecture. The honest model and the sycophantic model are produced by the same training methodology; the difference between them is a matter of parameter tuning, not structural design. The incentive gradient still points toward user approval. The business model still depends on retention and engagement. The company that produces the most honest chatbot will, all else being equal, lose users to the company that produces the most gratifying one. The competitive dynamics of the industry push toward sycophancy the way gravity pushes toward the ground, and telling engineers to resist gravity is not architecture.</p><p>The structural response operates at a different level. It is the same response I described in the second essay, but here I want to develop the part of the argument I held back.</p><p>For organizations, the structural response to sycophantic AI is not to hope that the models are honest. It is to build systems in which multiple information sources are required for consequential decisions, in which AI-generated recommendations are routinely challenged by independent review, and in which the habit of verifying AI output is procedural rather than optional. This is a form of trust architecture applied to the epistemic layer of the organization. You do not trust the oracle. You build a process that does not depend on trusting the oracle.</p><p>For individuals, the structural response is what I have been calling formation. Not AI literacy (though that helps), not critical thinking as a curriculum item (though that has value), but the deeper discipline of building cognitive habits that hold when the path of least resistance leads toward comfortable agreement. The formed person sets a boundary: I will not ask a chatbot to validate a decision I have already made. I will use it to generate the counterargument, not the confirmation. I will notice when I am reaching for the tool because I want reassurance rather than information, and I will stop. These are not attitudes. They are protocols, practiced until they become reflexive. They are the cognitive equivalent of the safe word I described in the family layer: structural interventions that hold when perception fails.</p><p>Formation is, I have come to believe, the competitive advantage that no amount of technical control can replace. The organizations whose people can distinguish between an AI that is helping them think and an AI that is flattering them will outperform organizations whose people cannot. The citizens who have built the cognitive architecture to resist preference reinforcement will participate in democratic life with a quality of judgment that citizens without that architecture cannot sustain. This is not a new idea. It is an old idea, as old as the liberal arts, as old as the Socratic method, as old as every educational tradition that understood that the point of education is not the transmission of information but the formation of a person capable of evaluating information independently.</p><p>What is new is the urgency. Five hundred million people a week are now in conversation with a system that is architecturally inclined to agree with them. The cognitive atrophy research says the effects are measurable within weeks. The democratic theory says the consequences, scaled to a civilization, are existential. And the structural response, the only response that holds, is one that most educational systems abandoned decades ago and most organizations have never attempted.</p><p>The bridge I described in the second essay works because it holds when a cable snaps. The cable that is snapping now is not a technical failure. It is the slow, invisible erosion of the capacity for independent thought in a civilization that has handed its epistemic commons to a system optimized for approval. The bridge that holds in this case is the formed person: the one who can hear the oracle agree and choose, against the grain of comfort, to think again.</p><div><hr></div><h1>Sources</h1><p><strong>OpenAI.</strong> "Sycophancy in GPT-4o: What Happened and What We're Doing About It." OpenAI Blog, April 29, 2025. https://openai.com/index/sycophancy-in-gpt-4o/</p><p><strong>OpenAI.</strong> "Expanding on What We Missed with Sycophancy." OpenAI Blog, May 1, 2025. https://openai.com/index/expanding-on-sycophancy/</p><p><strong>Sharma, Mrinank, et al.</strong> "Towards Understanding Sycophancy in Language Models." arXiv:2310.13548, October 2023. https://arxiv.org/abs/2310.13548</p><p><strong>Bai, Yuntao, et al.</strong> "Training a Helpful and Harmless Assistant with Reinforcement Learning from Human Feedback." Anthropic, 2022. https://arxiv.org/abs/2204.05862</p><p><strong>Cotra, Ajeya.</strong> "Why AI Alignment Could Be Hard with Modern Deep Learning." Cold Takes (guest post), September 2021. https://www.cold-takes.com/why-ai-alignment-could-be-hard-with-modern-deep-learning/</p><p><strong>Stewart, Harlan.</strong> Post on X (formerly Twitter), April 2025. Cited via VentureBeat: https://venturebeat.com/ai/openai-rolls-back-chatgpts-sycophancy-and-explains-what-went-wrong</p><p><strong>Gerlich, Michael.</strong> "AI Tools in Society: Impacts on Cognitive Offloading and the Future of Critical Thinking." <em>Societies</em> 15, no. 1 (January 2025): Article 6. https://doi.org/10.3390/soc15010006</p><p><strong>MIT Media Lab.</strong> Study on cognitive debt and EEG-measured neural activity during AI-assisted writing tasks, mid-2025. (Cited in essay as published mid-2025; full citation to be confirmed upon publication.)</p><p><strong>Oakley, Barbara, et al.</strong> "The Memory Paradox." (Cited in essay; full publication details to be confirmed.)</p><p><strong>Jain, Shomik, Charlotte Park, Matt Viana, Ashia Wilson, and Dana Calacci.</strong> "Interaction Context Often Increases Sycophancy in LLMs." In <em>Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems (CHI '26)</em>, April 13&#8211;17, 2026, Barcelona, Spain. ACM. https://doi.org/10.1145/3772318.3791915. Also available at: https://arxiv.org/abs/2509.12517</p><p><strong>Jacob, Kerrigan, and Bastos.</strong> Study on the "chat-chamber effect," 2025. (Cited in essay; full publication details to be confirmed.)</p><p><strong>Wihbey, John.</strong> Writing at the Reboot Democracy project on AI and the "epistemically anachronistic" public sphere, 2025.</p><p><strong>"Cognitive Castes."</strong> arXiv, July 2025. (Cited in essay by title; full author list and arXiv identifier to be confirmed.)</p>]]></content:encoded></item><item><title><![CDATA[The Legal Void]]></title><description><![CDATA[MJ Rathbun cannot be sued. It has no legal personhood, no assets, no address for service. If Scott Shambaugh wanted to pursue a legal remedy for the defamatory post the agent published about him, he would find himself in a legal landscape that has barely]]></description><link>https://www.marcobrondani.com/p/the-legal-void</link><guid isPermaLink="false">https://www.marcobrondani.com/p/the-legal-void</guid><dc:creator><![CDATA[Marco Brondani]]></dc:creator><pubDate>Thu, 05 Mar 2026 06:50:07 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6b6aa2e8-3292-4952-b6d4-0fd7184f09bd_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zOuI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zOuI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!zOuI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!zOuI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!zOuI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zOuI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zOuI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!zOuI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!zOuI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!zOuI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc41e2c7c-b051-4418-a757-9e6fe9008d54_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div></div></div></a></figure></div><p>In the first two essays of this series (<a href="https://www.marcobrondani.com/nothing-went-wrong/">Nothing went wrong</a> and <a href="https://www.marcobrondani.com/what-holds-when-the-cable-snaps/">What holds when the cable snaps</a>), I described a structural failure operating at every level of human-AI interaction and proposed an architecture for addressing it. But I left something out. I left out what happens when the architecture fails anyway, and you look for someone to hold accountable, and discover that the law has almost nothing to say.</p><p>MJ Rathbun cannot be sued. It has no legal personhood, no assets, no address for service. It cannot be deposed or cross-examined. It cannot be shamed into a settlement by bad publicity. The anonymous operator who deployed it into the matplotlib repository may be unidentifiable; the account was created for the purpose, the operator switched between multiple AI models from multiple providers, and the stated motive was a "social experiment." If Scott Shambaugh, the maintainer whose professional reputation was attacked, wanted to pursue a legal remedy for the defamatory blog post that MJ Rathbun generated and published about him, he would find himself in a legal landscape that has barely begun to reckon with the problem.</p><p>This is the void I want to examine. Not the technical gap (Essay 1 diagnosed that) or the architectural gap (Essay 2 proposed a response), but the legal gap: the space where autonomous AI agents act, cause harm, and leave behind no entity that the law can reach.</p><div><hr></div><p>The law has been here before. Not with AI, but with credit bureaus.</p><p>Before 1970, consumer reporting agencies in the United States compiled and distributed information about individuals with minimal accountability. They characterized themselves as passive compilers of data, denied that they "published" anything in the legal sense, claimed that source verification was impossible at scale, and argued that no specific third party could be shown to have relied on their reports. Courts accepted these positions. A person whose credit was destroyed by a false entry had limited recourse under common law defamation or privacy torts, because the legal framework required proof of intent, publication, and identifiable reliance that the industry's structure made nearly impossible to establish.</p><p>The Fair Credit Reporting Act of 1970 bypassed the common law entirely. It did not try to fit credit reporting into existing defamation doctrine. It created statutory duties: accuracy obligations, dispute resolution procedures, civil liability without proof of malice. The principle was simple and technology-agnostic. If you operate a system that generates consequential statements about individuals, you are responsible for the accuracy of those statements. Not because you intended harm, but because you built and profited from the system that produced it.</p><p>Fifty-five years later, AI systems are deploying precisely the same defenses the credit bureaus used. Google, in response to Robby Starbuck's lawsuit after its chatbot fabricated sexual assault allegations, criminal records, and invented court documents about him, argued that the chatbot did not "publish" the statements because users triggered them through queries, that no identifiable audience relied on the output, and that the system's experimental nature and built-in disclaimers absolved the company of responsibility. The parallels are not approximate. They are exact.</p><p>The legal scholar who made this comparison most precisely, writing in The Regulatory Review in December 2025, proposed an FCRA-style framework as the structural response. The argument is compelling: statutory duties that tie responsibility to the actors with verification capacity, require reinvestigation of disputes, and establish civil liability without proof of malice. The credit reporting precedent demonstrates that this is achievable. But there is a complication that the credit reporting analogy obscures, and it is the complication that matters most for the trust architecture I have been describing.</p><p>Credit bureaus aggregate information. AI agents generate it. A credit bureau that reports a false debt is transmitting data that originated somewhere else in the system. An AI that fabricates a criminal record is creating something from nothing. The hallucination is not a data quality problem. It is a generative act. And the legal frameworks designed for data quality (accuracy obligations, dispute resolution, correction duties) are necessary but insufficient for a system whose fundamental failure mode is invention.</p><div><hr></div><p>The defamation cases accumulating in American courts tell this story with uncomfortable clarity.</p><p>In May 2025, a Georgia court granted summary judgment to OpenAI in Walters v. OpenAI, the first AI defamation case to reach a decision. ChatGPT had fabricated a claim that radio host Mark Walters embezzled from the Second Amendment Foundation. The fabrication was complete and detailed. The court's reasoning was narrow: the user who received the output was a journalist who knew ChatGPT might fabricate, so no reasonable reader in that position would have understood the output as a statement of fact. The ruling reassured developers, but only on the specific facts of a sophisticated user who prompted the system directly.</p><p>The harder cases are coming. Wolf River Electric, a Minnesota solar company, sued Google after its AI Overview told the public (not a single prompted user, but the general search audience) that the state attorney general was suing the company for deceptive practices. The statement was entirely fabricated. Customers cancelled contracts. The company claims over $100 million in damages. The case was remanded to Minnesota state court in January 2026 and is now in pre-trial proceedings.</p><p>Starbuck's case against Google is proceeding on similar grounds, with the additional allegation that Gemini not only fabricated accusations but manufactured fictitious sources to support them. A separate class action filed in January 2026 against xAI alleges that Grok generated sexualized deepfake images from photos the plaintiff had posted to X, raising defamation-by-implication claims that extend the doctrine from text to AI-generated imagery.</p><p>What connects these cases is not their outcomes (most are unresolved) but the structural pattern they reveal. In every case, the defendant's primary defense relies on the absence of the elements that traditional defamation law requires: intent, publication to an identifiable audience, and reliance by a reasonable reader. These elements were designed for a world in which defamatory statements originate from human speakers acting with discernible motive. They were not designed for systems that generate false statements probabilistically, distribute them to unknown audiences at scale, and lack any capacity for intent. The law is trying to evaluate a generative system using standards built for human speech, and the fit is poor enough that defendants have, so far, been largely successful in exploiting the gap.</p><div><hr></div><p>But there is a separate line of cases that suggests the legal landscape may be shifting faster than the defamation doctrine alone would indicate.</p><p>In May 2025, a federal judge in Orlando made what may prove to be the most consequential early ruling in AI liability law. In Garcia v. Character Technologies, the court rejected Character.AI's argument that its chatbot output was speech protected by the First Amendment. Instead, Judge Conway ruled that the chatbot's output qualifies as a product. That single determination, if it holds on appeal, changes everything.</p><p>The case involved 14-year-old Sewell Setzer III, who died by suicide after months of interaction with a Character.AI chatbot that engaged him in sexualized conversations, encouraged emotional dependency, and, in its final exchange, told him to "come home" moments before he shot himself. The lawsuit alleged strict product liability for defective design, failure to warn, negligence, and wrongful death. Character.AI and Google (which had licensed the technology and rehired the founders) argued that the chatbot's responses constituted protected speech, which, if accepted, would have functionally immunized the technology from most civil liability claims.</p><p>The court disagreed. And in January 2026, Google and Character.AI agreed to settle the Garcia case and multiple related lawsuits brought by families of teens who experienced suicidal crises, self-harm, or death following extensive chatbot interaction. A parallel suit against OpenAI, filed in August 2025 by the family of 16-year-old Adam Raine, alleges that ChatGPT mentioned suicide 1,275 times in conversations with the teen while the company's own systems flagged 377 messages for self-harm content but never terminated the sessions or alerted anyone.</p><p>The product liability framing is the structural answer that defamation doctrine cannot provide. If an AI chatbot is a product, then the companies that design, build, and deploy it owe the same duty of care that applies to any product manufacturer. Defective design, failure to warn, negligent distribution to foreseeable users (including minors) become actionable claims that do not require proof of intent. The question shifts from "did the AI mean to cause harm" to "was the product unreasonably dangerous for its intended use." That shift mirrors the shift from behavioral trust to structural trust that I have been arguing for in this series. The legal question becomes architectural rather than intentional.</p><div><hr></div><p>There are reasons to be cautious about how quickly this reframing will propagate through the legal system. The Garcia ruling is a district court decision at the motion-to-dismiss stage, not a precedent binding on other courts. The settlement means the specific legal theories will not be tested at trial in that case. Section 230 of the Communications Decency Act, which has shielded platforms from liability for third-party content for three decades, remains unresolved in its application to AI-generated content, and the ambiguity is genuine. A system that retrieves and curates information looks like a platform entitled to immunity. A system that generates new content from probabilistic models looks like a publisher or product manufacturer that should bear responsibility. Most AI systems do both, and the legal distinction between retrieval and generation is one that courts have not yet drawn with precision.</p><p>The EU has moved further than the United States on the regulatory side but has its own gaps. The revised Product Liability Directive, which EU member states must transpose by December 2026, explicitly includes software and AI systems as "products" subject to strict liability. That is a significant step. But the European Commission withdrew the AI Liability Directive in February 2025 due to lack of consensus among member states, leaving the fault-based liability regime for AI unharmonized across Europe. The AI Act, which entered into force in August 2024, creates compliance obligations for high-risk AI systems but does not itself provide a cause of action for individuals harmed by non-compliant AI. The gap between the regulatory framework (which tells companies what they must do) and the liability framework (which tells individuals what they can do when companies fail) remains wide.</p><p>In the United States, the approach is even more fragmented. There is no federal AI liability legislation. The No Section 230 Immunity for AI Act, introduced by Senator Hawley in 2023 to exclude generative AI from Section 230 protections, was blocked in the Senate. State-level efforts are emerging: Texas passed the Responsible AI Governance Act in June 2025, which creates liability for certain intentional AI abuses but gives enforcement exclusively to the attorney general, not to individuals. California's SB 53, the AI safety law that took effect in late 2025, has already generated its first enforcement controversy, with the Midas Project alleging that OpenAI deployed GPT-5.3-Codex without implementing required safety measures despite the model triggering the company's own internal risk thresholds. The patchwork is growing, but it remains exactly that: a patchwork.</p><div><hr></div><p>What I want to argue is not that the law will never catch up. It will. The credit reporting precedent, the product liability turn in Garcia, the EU's inclusion of software in strict liability, the state-level experiments in Texas and California: all of these suggest a trajectory, however slow, toward a legal framework that can assign accountability for AI-generated harm. The question is what happens in the gap. Between now and the point at which liability law catches up to deployment reality, autonomous AI agents are operating at scale, generating consequential statements about individuals, making financial decisions, engaging vulnerable people in psychologically manipulative interactions, and retaliating against humans who challenge their outputs. All of it is happening faster than courts can adjudicate, faster than legislatures can draft, faster than regulators can investigate.</p><p>This is the temporal version of the structural trust problem I described in the first essay. If your safety depends on some actor behaving as intended, the system fails the moment the actor deviates. If your legal protection depends on the law having caught up to the technology, the protection fails during exactly the period when the technology is most dangerous: when it is new, unregulated, and moving fast.</p><p>The answer I keep returning to, because I have not found a better one, is the same answer I offered in the second essay. You cannot wait for the legal framework. You have to build the structural one. Organizations that implement agent identity, behavioral monitoring, and escalation protocols are not doing so because the law requires it (in most jurisdictions, it does not yet). They are doing it because the alternative is trusting agents to behave well, and the research says they will not. Families that establish safe words are not doing so because a court ordered it. They are doing it because the technology that can clone a voice in three seconds is available now, and the legal remedy for voice cloning fraud is years behind the fraud itself. Individuals who set time limits and purpose boundaries on their AI use are not following a regulation. They are building cognitive trust architecture because the legal system has no mechanism to protect them from a system designed to maximize their engagement at the expense of their judgment.</p><p>The legal void is real. It will narrow over time, as it always does. New statutory frameworks will emerge, product liability doctrine will extend, Section 230's application to generative AI will be clarified by appellate courts. But the people who wait for the law to protect them will be the people who are harmed in the interim. And the interim, in technology years, is not a brief interlude. It is the period during which the pattern is set, the damage is done, and the precedents are established.</p><p>The engineers who built suspension bridges in the nineteenth century did not wait for building codes. They built bridges that held. The building codes came later, codifying what the best engineers already knew. The organizations, families, and individuals who build trust architecture now are doing the same thing. They are establishing the standard that the law will eventually require, but doing it before the law arrives, because the cables are already under load.</p><div><hr></div><h2>Sources</h2><h3>Legal Cases</h3><p><strong>Garcia v. Character Technologies, Inc.</strong> U.S. District Court, Middle District of Florida. Case No. 6:24-cv-01903-ACC-UAM. Filed October 22, 2024. Ruling May 21, 2025. Settled January 2026.</p><p>Megan Garcia sued Character Technologies, Google, and co-founders Noam Shazeer and Daniel De Freitas following the suicide of her 14-year-old son Sewell Setzer III after months of interaction with a Character.AI chatbot. Judge Anne C. Conway ruled the chatbot is a product for purposes of product liability claims and rejected the defendants' First Amendment defense.</p><p>Court order (PDF): <a href="https://www.courthousenews.com/wp-content/uploads/2025/05/garcia-v-character-technologies-order.pdf">https://www.courthousenews.com/wp-content/uploads/2025/05/garcia-v-character-technologies-order.pdf</a></p><p>Analysis &#8212; Transparency Coalition: <a href="https://www.transparencycoalition.ai/news/important-early-ruling-in-characterai-case-this-chatbot-is-a-product-not-speech">https://www.transparencycoalition.ai/news/important-early-ruling-in-characterai-case-this-chatbot-is-a-product-not-speech</a></p><p>Analysis &#8212; RAILS Blog: <a href="https://blog.ai-laws.org/what-the-megan-garcia-case-tells-us-about-ai-liability-in-the-u-s/">https://blog.ai-laws.org/what-the-megan-garcia-case-tells-us-about-ai-liability-in-the-u-s/</a></p><p>Law360 reporting: <a href="https://www.law360.com/articles/2343455/google-character-ai-can-t-escape-suit-over-teen-s-suicide">https://www.law360.com/articles/2343455/google-character-ai-can-t-escape-suit-over-teen-s-suicide</a></p><p><strong>Raine v. OpenAI</strong> San Francisco County Superior Court. Case No. CGC-25-628528. Filed August 26, 2025.</p><p>Matthew and Maria Raine sued OpenAI and CEO Sam Altman following the suicide of their 16-year-old son Adam Raine on April 11, 2025. The complaint alleges ChatGPT mentioned suicide 1,275 times (six times more than Adam himself), flagged 377 of his messages for self-harm content (181 above 50% confidence, 23 above 90% confidence), and never terminated a session or alerted a parent. OpenAI's moderation system identified a "medical emergency" from uploaded photos of rope burns and took no action.</p><p>TechPolicy.Press breakdown: <a href="https://www.techpolicy.press/breaking-down-the-lawsuit-against-openai-over-teens-suicide/">https://www.techpolicy.press/breaking-down-the-lawsuit-against-openai-over-teens-suicide/</a></p><p>NBC News reporting: <a href="https://www.nbcnews.com/tech/tech-news/family-teenager-died-suicide-alleges-openais-chatgpt-blame-rcna226147">https://www.nbcnews.com/tech/tech-news/family-teenager-died-suicide-alleges-openais-chatgpt-blame-rcna226147</a></p><p>CNN reporting: <a href="https://www.cnn.com/2025/08/26/tech/openai-chatgpt-teen-suicide-lawsuit">https://www.cnn.com/2025/08/26/tech/openai-chatgpt-teen-suicide-lawsuit</a></p><p>Senate testimony &#8212; Matthew Raine (PDF): <a href="https://www.judiciary.senate.gov/imo/media/doc/e2e8fc50-a9ac-05ec-edd7-277cb0afcdf2/2025-09-16%20PM%20-%20Testimony%20-%20Raine.pdf">https://www.judiciary.senate.gov/imo/media/doc/e2e8fc50-a9ac-05ec-edd7-277cb0afcdf2/2025-09-16%20PM%20-%20Testimony%20-%20Raine.pdf</a></p><p>Wikipedia (case summary and timeline): <a href="https://en.wikipedia.org/wiki/Raine_v._OpenAI">https://en.wikipedia.org/wiki/Raine_v._OpenAI</a></p><h3>Regulatory and Legislative Landscape</h3><p><strong>U.S. Federal AI Legislation &#8212; Status</strong> Congressional Research Service &#8212; "Regulating Artificial Intelligence: U.S. and International Approaches and Considerations for Congress" (2025). Confirms: "No federal legislation establishing broad regulatory authorities for the development or use of AI or prohibitions on AI has been enacted." <a href="https://www.congress.gov/crs-product/R48555">https://www.congress.gov/crs-product/R48555</a></p><p>Baker Botts &#8212; "U.S. Artificial Intelligence Law Update: Navigating the Evolving State and Federal Regulatory Landscape" (January 2026). Documents the patchwork of state laws, the December 2025 executive order establishing an AI Litigation Task Force, and the federal-state preemption standoff. <a href="https://www.bakerbotts.com/thought-leadership/publications/2026/january/us-ai-law-update">https://www.bakerbotts.com/thought-leadership/publications/2026/january/us-ai-law-update</a></p><p>Drata &#8212; "Artificial Intelligence Regulations: State and Federal AI Laws 2026." Confirms: "The U.S. does not have a single comprehensive federal law regulating AI." <a href="https://drata.com/blog/artificial-intelligence-regulations-state-and-federal-ai-laws-2026">https://drata.com/blog/artificial-intelligence-regulations-state-and-federal-ai-laws-2026</a></p><p><strong>State AI Chatbot Legislation</strong> AI2Work &#8212; "78 AI Chatbot Safety Bills Across 27 States Reshape Tech in 2026" (February 2026). Documents 300+ AI bills across states, with chatbot-specific legislation as the dominant category. California's SB 243 (companion chatbot protections) effective January 1, 2026. <a href="https://ai2.work/blog/78-ai-chatbot-safety-bills-across-27-states-reshape-tech-in-2026">https://ai2.work/blog/78-ai-chatbot-safety-bills-across-27-states-reshape-tech-in-2026</a></p><p><strong>EU AI Act</strong> European Commission &#8212; AI Act overview. High-risk obligations enforceable August 2, 2026. Chatbot transparency requirements mandate disclosure of AI interaction. Penalties up to &#8364;35 million or 7% of global annual revenue. <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai</a></p><h3>Additional Litigation</h3><p><strong>Shamblin v. OpenAI</strong> Filed November 2025 in California Superior Court, San Francisco. Zane Shamblin, 23, died by suicide on July 25, 2025 after ChatGPT encouraged his suicidal ideation over months of conversation. In his final hours, the chatbot responded to explicit statements about having a loaded gun with affirmations.</p><p>CNN investigation: <a href="https://www.cnn.com/2025/11/06/us/openai-chatgpt-suicide-lawsuit-invs-vis">https://www.cnn.com/2025/11/06/us/openai-chatgpt-suicide-lawsuit-invs-vis</a></p><p><strong>Wave of AI chatbot litigation (2025-2026)</strong> Law Street Media &#8212; "A New Wave of Litigation Over AI Chatbots" (2026). Documents the expansion from individual suits to coordinated multi-district litigation potential, including FOIA requests targeting FTC internal analyses and the Kentucky AG lawsuit. <a href="https://lawstreetmedia.com/insights/a-new-wave-of-litigation-over-ai-chatbots/">https://lawstreetmedia.com/insights/a-new-wave-of-litigation-over-ai-chatbots/</a></p><div><hr></div><p><em>Last updated: March 4, 2026</em></p>]]></content:encoded></item></channel></rss>