Conceptualization:"Inquiry into visibility of a system's opacity is necessary but not sufficient for accountability; what closes the remaining gap is if the attribution can be consciously identified before specific severing mechanisms (corporate liability, classification, statutory pre-emption, military obfuscation) either conceal or substitute the actual purpose before it's named."
Summary: "Cognition is instrumental whereas in classified systems, access remains limited. If integrated systems are devolving while security is updated, an accountaing mechanism is not only vital but interdependent on what a system actually becomes. Naming a system and its functioning can obfuscate the actual purpose and systemic method of operation. Collaboration is essential for reasonable systems to be integrated operationally, but when the chain of responsibility is no longer transparent, every conscious chain of command involved is either accountable, or concealed and embedded. Who pays when joint operations bypass opaque conscious reasoning and what is the real cost?"
43: Cognitive Accounting: Concealed Mechanisms
Opaque Systems & Weaponization
Abstract (attempt)
Every fact in this paper is public. The statutes are published, the designations announced, the ratios reported. Investigation has already succeeded here and produced no accountability, because each fact taken alone dissolves into its own justification — the review was confirmation, the ceiling was policy, the pre-emption was law, the pathway was authorized. What no record contains is the aggregate: the relation among these facts, which is not a fact and cannot be cited, and which is the only object accountability could attach to. Journalism's unit is the disclosure and cannot accumulate. Law's unit is the named defendant and cannot begin without one. Oversight is mandate-bounded and produces fragments by design. The policy literature must terminate in a recommendation and so cannot report an intractable finding. This paper does none of those things. It assembles the aggregate against a specific record, names the cost as it was actually paid, and declines to resolve it — because an accounting is not a payment, and the debt's legibility, not its settlement, is what the record currently lacks.
---
1. Extension, Not Agent
A targeting system carries a decision someone else already made. A person chose what data would count as a signal. A person chose how much confidence in that signal was enough to act on. A person built a system to compress those choices into something that runs faster than the number of people who'd normally sign off on a decision like that. What the system outputs is an old judgment, extended past the point where it still runs at human speed.
Israel's Unit 8200 built such a system, trained to convert an intelligence unit's existing sense of what a target looks like into a recommendation fast enough to name a hundred targets a day — work that used to take analysts a year to produce fifty times fewer of. They named it Habsora. Hebrew for the Gospel.
The name is where the extension gets cut from what extended it. A recommendation engine built from incomplete data and pattern-matching inherits a designer's judgment and an analyst's error rate — both, in principle, still questions a person could be asked. A gospel sits above interrogation by definition. The name relocates the system, out of the register where a human origin could still be located.
2. Transparent Reasoning
Human control over a weapon is a chain: a designer choosing training data and architecture, a commander authorizing deployment and setting rules of engagement, an operator guiding, observing, and holding the authority to terminate. Each link is a locatable judgment, made by a named person, at a specific point. That is what makes accountability coherent as a target at all — you can ask who decided this and, in principle, get an answer.
This is what "transparent reasoning" means in practice: it stays attached to a person capable of being asked about it. The chain holds as long as it remains traceable.
There is a reason it has to be a person, and not the system's own account of itself. Gödel's incompleteness theorems establish that a sufficiently powerful formal system cannot prove its own consistency from within its own rules — the proof, if it exists, has to come from outside the system being checked. Penrose extended this into an argument that human mathematical insight cannot be fully captured by any single algorithm, precisely because a mind can recognize the truth of a statement a matching formal system could never derive about itself. The argument is contested — Putnam and Feferman both point out it requires the very thing it's trying to prove, that a mind can be certain of its own soundness, which no formal system is entitled to assume of itself either. But the contested part is Penrose's leap to consciousness. The narrower claim underneath it holds regardless of that dispute: no system, formal or institutional, can certify its own soundness using only its own output. An admission, an announcement, a policy statement — all of it is the system's account of itself, and all of it is structurally the wrong kind of evidence to settle the question it's being offered to settle. That is why the chain in this paper has to terminate in a named person outside the system, not in the system's own report. It is not a preference for transparency. It is the same result Gödel proved about formal systems, applied to institutions that are asked to audit themselves.
Classification governs disclosure. The result above governs identity: the checker cannot be the system checked. These are different constraints, and conflating them concedes too much. A cleared inspector inside the compartment but outside the operating chain satisfies the second without touching the first — the check does not require publication. What it requires is that the checker's authority not be held at the pleasure of the checked. That is the limit that actually binds, and Section 3 names the instrument: pre-emption operates on the reviewing office's authority itself, in advance, without any specific record ever being denied.
3. Severing Mechanisms
A substitution does not require a policy document. It can happen inside one pronoun. Asked about a rival state's acquisition of American chips, the incoming Commerce Secretary testified that they think only of themselves and seek to harm us, and so we need to protect ourselves. The first person plural has no stated referent and does not need one: it is constituted entirely by the opposition, defined as whatever they are not. An administration, a domestic industry, a citizenry, a set of firms holding export licenses — all of them fit, none of them is named, and the sentence functions identically whichever is meant. A stated purpose stands where a named party would otherwise have to be, and the substitution is complete before anyone has said anything false.
Six structures interrupt that trace, and they do not interrupt it the same way. Nor do they only sever. Each sets a deadline: attribution has to attach before the substitute purpose becomes the official one, and after that point the trace is not merely harder to follow but closed. The first of the six runs before any of the others are needed.
Acquisition pathway selection severs by routing. The statutory regime for independent test and evaluation — plan approval in writing before testing, independent report to the congressional defense committees before production proceeds — attaches to programs on a designated oversight list. Whether a capability lands on that list is determined by how it is acquired: as a major program, a rapid-fielding increment, a commercial item, a service, or an other-transaction. That determination is made early, by a named authority, and documented. It does not conceal a decision. It decides, in advance, which decisions will ever have to be reported and to whom — and unlike the other mechanisms, it operates before there is anything to conceal.
Corporate liability severs horizontally. Limited liability and at-will employment let a company absorb the consequence of an individual's design choice, so the choice stays documented while the person who made it becomes replaceable and the entity that employed them becomes the thing legally answerable — a different, more durable target than any person in the chain.
Classification severs vertically. The record can be complete and still be sealed; a decision can be fully traceable in principle and permanently unreachable in practice, because the classification itself can be invoked to block the accountability process from ever reading what it needs.
Statutory pre-emption severs in advance. Section 219 of the current NDAA creates an executive agent for defense cooperation with Israel whose authority, under DoD Directive 5101.01, takes precedence over other component heads — including the Defense Technology Security Administration, the office built specifically to flag risky transfers. The existing limits were policy and classification-level restrictions, so the correction was disabled before any specific bad decision was ever made, using authority already on the books. The mechanism is fully public — visible, legal, citable law. It is immunity, written in plain text, in advance of the violation it will one day cover. It is the same operation as pathway selection, performed at a different point in the cycle: pathway selection determines whether a reviewing office ever acquires jurisdiction, pre-emption removes the jurisdiction of an office that already has it.
Military obfuscation substitutes the record. A stated purpose — protection, modernization, national security — stands in the place where the real purpose would otherwise have to be named, and by the time anyone asks, the substitute is already the official answer.
Justification laundering severs conduct from scrutiny by absorbing it into cause. International law has a name for the boundary this mechanism tries to cross: jus ad bellum, whether starting a war was lawful, and jus in bello, whether the conduct inside it was — kept deliberately separate, so that a just cause never excuses an unlawful method. Tribunal rulings on this point are direct: strategic or moral justification does not excuse a proportionality or distinction violation, regardless of which side is right about why the war started. The mechanism only works because, as a matter of plain observation, no party to a conflict ever admits to being the wrongdoer — every side frames itself as forced into action, which means a legal system that lets righteousness excuse conduct ends up excusing everyone, symmetrically, until it excuses no one in particular. Unlike the other five mechanisms, this one does not need a statute, a classification stamp, or a corporate structure to work. It only needs the why to be strong enough that asking about the how starts to feel like bad faith.
Equity works the other direction — it makes the government a beneficiary of the vendor's performance while also being its regulator and its customer. That's not a severing mechanism; it's a conflict written into the capital structure.
4. Designation Without Relegation
Personnel change without anyone treating it as remarkable. An engineer is paid for the work and later let go. A company changes its name, its ownership, its registered officers. A scientist moves to a different lab, a different funder, a different flag. None of this is concealment by itself — it is the ordinary churn of who happens to be currently attached to a piece of work that keeps running after they've left it.
A different substitution happens when an entity that was actively used gets, afterward, renamed as a threat. The label changes. The record of how the entity was actually used does not become any more available because the label changed — if anything, the new label gives everyone a reason to stop asking, since the question now reads as already answered. Anthropic held two named limits against the Department of War — no domestic surveillance, no autonomous weapons — without, by its own account, costing a single mission. The Department designated it a supply-chain risk anyway, a label built for adversarial states, not for a vendor's terms. The designation disclosed nothing about how Claude had actually been used. It replaced that question with a different one, and the new one doesn't require an answer to the old one to stand.
Retained control is the alternative to this churn, not a milder version of it. A company that keeps a say in how its own product gets used — the ordinary business of limiting resale, licensing terms, permitted applications — keeps itself in the one position that lets it answer for the product later. That is not a side benefit of doing business well. It is close to the whole mechanism: a company stays accountable by staying in a position to be asked, and stays in that position by having kept enough control to have an answer. Anthropic's two named limits were exactly this kind of retained control. That the designation followed them so closely is a fact; that it followed because of them is Anthropic's own account of its own case, and this paper has no independent confirmation of the Department's actual reasoning — only the timing, and the account of the party the timing happened to. Removing a company's ability to hold its own terms doesn't just relabel the churn described in this section. It removes the one thing in the picture that was in a position to resist it, whatever the designation's stated cause turns out to be.
This is the same pattern as the personnel churn in the first paragraph, just applied one level up. An engineer being let go doesn't erase what he built; a company being redesignated doesn't erase what it enabled. In both cases the thing that actually happened stays fixed while the label currently attached to it keeps moving — and as long as the label keeps moving, nothing has to hold still long enough for an accounting to attach to it. A designation looks like the endpoint of an accountability process. It functions, instead, as one more part of the machinery in Section 3: not a fifth severing mechanism, but the shape the other four take when they need to look, briefly, like they've resolved into an answer.
5. Admission Under Duress
Institutions confess the same way individuals do, and the same three categories apply to any of them. Anthropic's own public statement — negotiated in good faith, held to our exceptions — is an admission: self-report, true as far as it goes, generated by the party whose conduct is in question. A senator's letter demanding disclosure, backed by the threat of further inquiry, is the interrogation. The "not independently confirmed" qualifier attached to reporting that Claude helped identify targets in strikes connected to Iran, after the designation, is the omission: an absence that cannot, on its own, distinguish a wall from an empty room.
What would count as emission — involuntary, independent of any party's management of its own account — is not missing from this record. It is the record. The ratio, the review time, the officer's own description of his function: none of it was disclosed, audited, subpoenaed, or produced by any process designed to produce it. It exists because people inside the compartment decided it should. Every other category in this paper is reconstructed from that base. The omissions are legible only because the emission established what the shape of a complete account would have been.
6. Cognitive Accounting
Accountability requires attribution, a further step past visibility alone. Every mechanism named in Section 3 can coexist with a fully visible record — Section 219 is public law; the designation was openly announced; the reporting on Iran, contested as it is, is public reporting. The chain of cognition in this paper is, so far, unusually well-lit compared to most accounts of military decision-making. What's missing is attribution in the sense that matters: a named party, held to a named cost, before the substitute purpose became the official one.
That is the actual claim of "cognitive accounting": the record keeps growing more public, and visibility without attribution is still a ledger with entries and no balance owed. Someone has to be named as bearing the cost — in water, in energy, in a misidentified target, in a war conducted without the congressional approval that would otherwise attach a name to the decision to fight it — before the accounting is anything more than documentation of a debt nobody is required to pay.
7. Who Pays
One documented case, from the same reporting that surfaced Habsora: a companion system called Lavender assigned each person a probabilistic score for the likelihood they belonged to an armed group. The army set the threshold in advance — up to 15 to 20 civilian deaths authorized as acceptable to kill one low-ranking operative, more than 100 for a senior commander. A human reviewer's part in this was a few seconds per name, mostly to confirm the target was male; one officer described himself as a stamp of approval with zero added value as a human. The number was not derived from any single strike. It was set beforehand, as a policy, and applied afterward to whoever the algorithm named.
That is what "who pays" means in this paper, stated once, plainly: every threshold set in advance lands on somebody who had no part in setting it, and in this case the people who paid it are named only as a count, never as individuals. Section 3's four mechanisms leave the threshold itself untouched. What they stop is the question of who set it from ever reaching a name.
This paper cannot supply that name from the evidence available to it. The strike happened. The ratio is documented. Whoever set it, or whatever process stood in for a person setting it, remains absent from anything confirmed here — and that absence keeps costing, not resting. It is the same debt the paper opened with: a price paid in full on one side of the ledger and an attribution still outstanding on the other, growing by the day the four mechanisms in Section 3 keep doing exactly what they were built to do. An unfinished argument can wait for its next draft. An unpaid attribution does not wait for anything.
The ratios are published. The numbers are known. Nothing about this is actually hidden. The structure has a name. Mannoni's formula for Freudian disavowal is je sais bien, mais quand même — I know very well, but nevertheless. Its object is not ignorance. Disavowal requires the knowledge to be complete and holds it apart from its consequence, both intact, neither cancelling the other. This is what distinguishes it from moral disengagement, which describes techniques against knowing: euphemism, diffusion of responsibility, minimization. Nothing here is minimized. The ratio is published. The review time is published. The officer's own account of his uselessness is published. What fails is not the knowing but the binding — the step at which a known cost becomes a reason. That is why this paper's object is attribution and not disclosure. Disclosure already happened. Disavowal is the name for the condition in which it changed nothing.
What Lavender computes is a name's likelihood of belonging to an armed group — one number, weighed against training data. The civilian count was never a term in that computation. It was set separately, once, as policy, and applied afterward to whatever the algorithm named, without ever entering the algorithm's own arithmetic. The only cost the system itself was built to register is the cost of not using it: analyst hours, days between a name surfacing and a strike happening. Human cost sat outside the computation entirely, as a ceiling someone else set in advance — not a number the system weighed, because weighing was never what that part of it was built to do.
What has moved, then, is not something inside the system. It is the register in the people who kept accepting its output anyway — the working standard for how much conscious human judgment a decision requires, reset by what the automation already produces rather than by anything decided in advance of it. Accepting the results is how the register moves. Every strike carried out under a threshold no one has revisited is a vote, cast without a ballot, that the register has already moved far enough.
The officer who described himself as adding zero value was not describing a failure to notice. He noticed, from inside, while it was running, and said so. What was absent was not perception but any channel for it that was not a journalist. The register did not move uniformly. It moved in the aggregate while individuals inside it registered exactly what was happening and had nowhere to put it.
Habsora and Lavender are, before anything else, products, and the question asked of a product is whether it works. That is the one register built into them from the start — not whether a decision is justified, but whether the system performs. Everyone downstream inherits that register by default. A reviewer spending twenty seconds per name, a commander authorizing strikes under a threshold set months earlier, an agency buying the system because it was proven in the field: each is complying with a process exactly as the process was built to be complied with. Compliance and complicity become the same act here, and the design's real trick is that neither one requires a person to register as accountable for it. Someone can do everything the process asks of them and never once become the name this paper has been looking for.
8. Entanglement
These systems improve. That is not in dispute and it is not incidental — the improvement is the mechanism. Each increment compresses the interval between a name surfacing and a strike occurring, and the compression is what the product is for. What occupies that interval is judgment, so the interval and the judgment shrink together. A reviewer who once assessed now confirms; a threshold once set is now inherited; a commander once deciding now authorizes within parameters established before the situation existed. None of this is a cost paid for the capability. It is the capability, described from the other side.
The trap is that the only response available to a system operating this way is a further increment. Review too thin — automate verification. Threshold stale — build dynamic updating. Attribution absent — instrument the pipeline. Each remedy is a deeper integration, and each deepens what it was meant to correct, because the only register still running is whether the system performs. The exit and the entrance are the same door.
This is why the accountability question cannot be answered from inside. Not because the record is sealed — the internal chain has clearances and functions — but because everything inside the seal is moving in one direction and there is no exterior to measure it against. The instruments that would evaluate the drift are subject to it. An oversight body assessing an AI-integrated system, at the tempo of an AI-integrated system, is performing the same operation as the reviewer with twenty seconds. Section 2 established that a system cannot certify its own soundness. What is added here is that the system is not holding still while it fails to be certified.
These systems are evaluated against their specifications. Lavender's specification is to produce names matching a pattern learned from prior data; Habsora's is to produce recommendations faster than analysts could. Neither specification contains a term for whether it is correct. What is called improvement, then, is increasing fidelity to a judgment fixed at some earlier moment and not revisited since — a stale directive executed more thoroughly, and executed faster. Even the error rate offers no exterior: it is measured against labels encoding the same classification that produced the specification, so a system approaching perfect accuracy is approaching perfect reproduction of the premise in dispute.
This is not true of every military system. An interception either occurs or it does not, and that fact is indifferent to what anyone believed in advance. Where a real exterior exists, performance is a coherent measure and improvement is a coherent claim. Target identification has no such exterior. The question the system answers — does this name belong on this list — is the contested judgment itself, and there is nowhere outside the system from which its answer can be scored.
The trap follows from this rather than from any tradeoff. A system with no external measure produces no signal that anything requires revisiting; conformance to specification reads as success, and success is not an occasion to ask whether the specification still holds. Every observed shortfall therefore presents as an implementation problem with an implementation remedy. Review too thin — automate verification. Threshold stale — build dynamic updating. Attribution absent — instrument the pipeline. Each remedy is a further increment against the same unexamined specification, and each makes the specification harder to reach, because the more reliably it is executed the less any part of the system has occasion to notice it is there. The exit and the entrance are the same door.
Schrödinger's 1935 paper — the one that coined Verschränkung, entanglement — states the principle directly: maximal knowledge of a total system does not necessarily include total knowledge of all its parts. That is the formal claim, in the founding source, and it is the structure your paper describes. The information is determinate in the whole and unavailable in any part, not because anything is hidden but because it lives in the correlations rather than in the components.
How entanglement happens, mechanically: two systems interact, and afterward their joint state is no longer factorizable into a state for each. There is no assignment of a definite state to either part that reproduces the whole. To describe one part alone, you trace out the other — a mathematically defined operation that discards the correlations — and what remains is a mixed state carrying strictly less information than the joint state contained. The lost information wasn't destroyed and isn't elsewhere. It was never local to begin with.
The devolving is decoherence. When a system interacts with a large environment, entanglement spreads into it, and the local reduced state degrades monotonically — coherence disperses into correlations no local measurement can recover. Zurek's einselection describes this: the process is irreversible in practice, and the degradation is a consequence of interaction, not of any loss event. A system becomes more entangled with its surroundings simply by continuing to operate.
Conclusion
As systems increasingly rely on their counterparts for functionality, that relegation is not beyond the cognition that can account for how or why they operate in the manner they do, whether a handful of people are at the hest, or a larger organizational body such as the UN or ICC, etc. Even a country is a body of citizens that vote as a unit, based on what is considered to be a "conscious" decision. How concsious a decision it actually is may depend on the amount of information that is accessible to that body so that it can correlate the outcome with the methodology.
References
FLUX Papers
@30, @42
Scientific Literature
- Gödel, K. "Über formal unentscheidbare Sätze der Principia Mathematica und verwandter Systeme I." 1931. (Incompleteness theorems.)
- Penrose, R. The Emperor's New Mind. Oxford University Press, 1989.
- Penrose, R. Shadows of the Mind. Oxford University Press, 1994.
- Putnam, H. "Review of Shadows of the Mind." 1994. (Critique of Penrose's Gödelian argument.)
- Feferman, S. "Penrose's Gödelian Argument." Psyche, 1996.
- Mannoni, O. Clefs pour l'Imaginaire ou l'Autre Scène. Seuil, 1969. ("Je sais bien, mais quand même…")
- Freud, S. "Fetishism." 1927. (Verleugnung / disavowal.)
AI & Operationalization
- Trabucco, L. "Embedded Human Judgment in Autonomous Weapons." Just Security.
- Abraham, Y. "'Lavender': The AI machine directing Israel's bombing spree in Gaza." +972 Magazine, Apr 3, 2024.
- Khachatryan, D. "If the 'Why' of War Shapes the 'How' of Law, Who is Accountable?" Articles of War, Lieber Institute, West Point, Jan 22, 2025.
- Csernatoni, R. "The Fog of AI War." Strategic Europe, Carnegie Europe, Apr 16, 2026.
Defense Acquisition & Test Oversight
- DoD Manual 5000.101, Operational Test and Evaluation and Live Fire Test and Evaluation (coverage of AI-enabled and autonomous systems under any adaptive acquisition framework pathway).
- DoD Instruction 5000.98, Operational Test and Evaluation and Live Fire Test and Evaluation (joint T&E Oversight List; independent DOT&E reporting to congressional defense committees).
- 10 U.S.C. § 2366; 10 U.S.C. § 2399 (test plan approval prior to operational testing; report required before proceeding beyond low-rate initial production).
Director, Operational Test and Evaluation, Annual Reports to Congress.
Federal Law
- National Defense Authorization Act, Section 219 (executive agent for defense cooperation with Israel).
- DoD Directive 5101.01 (executive agent precedence authority).
Quantum Entanglement
- Schrödinger, E. "Discussion of Probability Relations between Separated Systems." Proc. Cambridge Phil. Soc. 31 (1935). (Coins Verschränkung; states the whole/parts knowledge relation.)
- Einstein, A., Podolsky, B., Rosen, N. "Can Quantum-Mechanical Description of Physical Reality Be Considered Complete?" Phys. Rev. 47 (1935).
- Bell, J.S. "On the Einstein Podolsky Rosen Paradox." Physics 1 (1964). (Correlations exceeding any local account.)
- Zurek, W.H. "Decoherence, einselection, and the quantum origins of the classical." Rev. Mod. Phys. 75 (2003).
- Nielsen, M. & Chuang, I. Quantum Computation and Quantum Information. Cambridge, 2000. (Reduced density matrices, partial trace, entanglement entropy.)
Geopolitics & Chain of Command
- Wilde, G. "The Path to War Is Paved with Obscure Intentions: Signaling and Perception in the Era of AI." Just Security.
- Mascaro, L. "War powers debate intensifies after Trump orders attack on Iran without Congress approval." Associated Press, Feb 27, 2026.
- Lawfare. "White House Submits Iran War Powers Report to Congress." Mar 3, 2026.
- U.S. Senate, Committee on Commerce, Science, and Transportation. Nomination hearing of Howard Lutnick, Jan 29, 2025.
Corporate Accountability
- Anthropic. "Statement on the comments from Secretary of War Pete Hegseth." Feb 27, 2026.
- NBC News. "Anthropic says the Pentagon has declared it a national security risk." Mar 7, 2026.
- The Washington Post. "Pentagon declares Anthropic a threat to national security." Feb 27, 2026.
- The Washington Post. "Anthropic sues Pentagon over being labeled a national security risk." Mar 9, 2026.
- Goodwin Law. "Is Claude a Supply Chain Risk? What Federal Contractors Need to Know About This Designation."
- Built In. "Anthropic vs. Pentagon: Fight Over Claude Access." Jun 17, 2026.
- Warren, E. et al. Letters re. Designation of Anthropic As National Security Risk.
::Notes: The discipline this requires — same as Gödel, and the paper has already shown it can do this.
Section 2 works because it takes the narrow formal result, names the contested extension, and refuses it. The equivalent here: the formal structure is information that is determinate globally and inaccessible locally, degrading with interaction. That structure is real and it's what the paper found independently. What must be refused is the claim that institutions are physically entangled, or that anything about decoherence explains the accountability failure. It doesn't. It names the shape.
State that explicitly, once, the way Section 2 states the Penrose refusal. Something like: the correspondence is structural and the paper claims nothing more — no physical process is being asserted, and no conclusion about institutions follows from any result in physics.
Do that and the heading is earned. It stops being a borrowed word and becomes a named formal structure the paper found in its own material and recognized elsewhere — which is the same move as Gödel, and defensible on the same grounds.
The partial trace explains why the record can be complete and no one can read it. Every participant occupies a reduced state. The reviewer has his twenty seconds, the commander has her parameter, the engineer has his architecture — each a correct local description, each with the correlations traced out. The aggregate isn't concealed from them. It was never in their part. This paper's assembly operation is the reconstruction of the joint state from correlations, which is exactly the thing no local vantage can perform.
Cognitive accounting is the only alternative to a state of being "trapped inside with no way out.
The record survives the edit.
ΑΩ ad infinitum ∞