Paper 55 — Integration Theory
Public Data, Private Systems
Abstract
A system that can reach everything must be answerable to everything it reaches. When a government embeds AI in decision-making about citizens—taxes, visas, welfare, immigration, targeting—without building channels for those affected to correct the system, it is not integrating intelligence. It is embedding it: one system placed inside another, with data flowing in but no meaningful signal flowing back. This asymmetry has consequences. A system that hears only from itself will select only from what it already knows. A government that increasingly collects more data on its people while releasing less will fragment the public's ability to understand what acts on them.
Some systems are kept closed on purpose: classified, private or encrypted to protect the people whose data they hold. That is the exception the principle allows. Where the exception ends, who decides, and whether it protects the people a system reaches or the government that runs it, is part of what this paper asks.
PART 1: WHY A THEORY IS NECESSARY
The Accountability Gap
The United States military and intelligence apparatus is requesting a $1.5 trillion defense budget for fiscal 2027. Within that framework, artificial intelligence is being deployed across government systems that touch citizens at scale—tax compliance, immigration decisions, welfare benefits, visa determinations, and military targeting. Simultaneously, the government is moving to seal more of its own information from public view while expanding what it knows about its people. The question is what structure is being built, what it is configured to do, and whether it can correct itself when it makes errors that affect millions.
Embedding and integrating may sound similar, but the difference between them is vital to understanding how data relates to services. In an integrated system, the parts stay distinct and signal comes back from what is acted on to what acts. When you are wrongly denied a benefit, you appeal, and the appeal changes the system. When surveillance is documented to be inaccurate, that information reaches whoever runs the system. When deployed AI systems fail, the failure is recorded and learned from before the next jurisdiction builds the same thing.
When signal is cut off—when people cannot learn why they were flagged, when appeals are formal rather than substantive, when errors are repeated instead of recorded—the system is embedded. It reaches far but hears nothing back from what it touches. The problem lies in where the AI is placed: inside a structure with no return channel. Part 2 defines both terms.
This has been happening in government benefits systems for years. It is now happening at a larger scale, across military intelligence, immigration enforcement, and tax compliance.
The Military Context
In March 2026, the Military Religious Freedom Foundation reported 200 complaints from over fifty military installations. An unnamed commander allegedly told non-commissioned officers that the Iran war is God's plan and that Trump was "anointed by Jesus to light the signal fire in Iran to cause Armageddon." In September 2025, at Quantico Marine Base, speaking to approximately 800 general and flag officers, Trump stated: "We're under invasion from within. No different than a foreign enemy, but more difficult in many ways because they don't wear uniforms."
On the same stage stood Pete Hegseth, the Secretary of Defense. In February 2026, Hegseth told a Christian media convention that the military's mission is "not political—it is BIBLICAL" and that "Christ is king." In March 2026, speaking at a Pentagon prayer service, he called for "overwhelming violence of action against those who deserve no mercy" and invoked Psalm 18:37: "did not turn back till they were consumed."
In September 2026, the Defense Secretary placed a new religious affairs office directly under his own authority in the same address that announced a command to scale autonomous weapons.
Theology itself here is less of a problem than how it's used to implement unforeseen directives that use AI in wartime environments. When the people acted on are declared enemies, the possibility of a return channel—the possibility that they could be heard, that they could correct the system—collapses.
In February 2026, a private AI company refused to allow its systems to be used for autonomous weapons and mass surveillance. It argued that these uses would concentrate power without accountability. The response was to designate the company a "supply-chain risk" in U.S. defense contracts. A federal district court ruled the designation unlawful, and on September 25, 2026, the D.C. Circuit upheld the designation in a 2-1 decision. When a company tried to protect itself against unauthorized military use, the military labeled the company itself a threat.
The Contracts and the Scale
Palantir Technologies holds contracts across five federal departments and agencies: Defense, Homeland Security, the Internal Revenue Service, Health and Human Services, and the Centers for Disease Control. The obligated contracts total $5.16 billion, with potential ceilings of $10.52 billion. Palantir's Tiberius platform, developed in mid-2020 under Operation Warp Speed for COVID-19 vaccine distribution, was renewed and expanded by HHS in 2021 from nearly $17 million to $31 million.
Palantir is just one company of a much larger ecosystem. The Department of Homeland Security has committed $2.9 billion to surveillance and data analytics systems since 2021. The Pentagon has hidden its largest military IT contracts from standard public discovery databases.
The scale is tens of billions annually in government AI spending, most of it in classified or proprietary contracts, very little of it subject to public review.
What These Systems Do
Immigration Enforcement
ImmigrationOS, a Palantir product developed with Immigration and Customs Enforcement, is budgeted at $30 million with a prototype due September 25, 2025, and operations running through September 2027. The system manages targeting, prioritization, and what ICE calls "self-deportation tracking" and "lifecycle management" of immigrants. It integrates data from passport systems, Social Security Administration, the Internal Revenue Service, and license-plate readers. There is no public detail on human review of its decisions or accuracy testing.
ELITE, another Palantir tool used by ICE, generates dossiers on individuals with "confidence scores" about their addresses. An ICE-Centers for Medicare & Medicaid Services data-sharing agreement covers approximately 80 million Medicaid patients. When pressed, DHS and Palantir did not comment.
Visa Revocation
In March 2025, the State Department announced it would use AI to scan social media and revoke visas in real time—what the department called "Catch and Revoke." The system has no published accuracy metrics or human review procedures. No formal return channel exists for someone whose visa was revoked based on social media scanning.
Social Security Data
DOGE sought access to Social Security Administration data. Lower courts blocked it; the Supreme Court allowed it in 2025. In a January 20, 2026 filing, the Justice Department wrote that DOGE's "communications, use of data, and other actions" were "potentially outside of SSA policy and/or noncompliant" with the district court's March 20, 2025 temporary restraining order. From March 7 to 17, 2025, SSA DOGE employees used "links to share data through an unapproved third-party server," and SSA "was unable to determine what data was shared or if it still exists."
Military Targeting
Maven, a U.S. military intelligence system, uses AI to process video and sensor feeds from Middle East operations and autonomously direct reconnaissance assets to targets. In exercises, a targeting cell of about 20 people using Maven matched the performance of the Iraq war's time-critical targeting cell, which had more than 2,000 staff. The system is intelligent about correlations between sensor data and target probability. What it is not intelligent about is whether the target matters, whether the intelligence is correct, or whether the people it identifies should be alive. That judgment requires a human.
Sealed Information
In the 2025 federal AI use case inventory, which agencies report to the Office of Management and Budget, the Department of Homeland Security's Customs and Border Protection lists RedactAI, a pre-deployment tool meant to "streamline the identification and redaction of sensitive content in documents related to FOIA requests." The same inventory lists ICE's License Plate Capture and Analysis, operational since September 19, 2025, which involves personally identifiable information the agency maintains. Asked whether an established appeal process lets an impacted individual contest its outcome, the entry answers "Appeal Process In-progress." The State Department FOIA office has a backlog of 27,619 requests, up from 21,000 the previous year. The Education Department lost about half of its workforce; approximately $30 billion in programs were moved to four other agencies, fragmenting where records are held and multiplying FOIA backlogs for anyone seeking to understand what government is actually doing.
The 2025 inventory also lists eighteen entries in which processing FOIA requests is a stated purpose, at eight agencies. Ten are deployed: six at Interior, two at Justice, one at Health and Human Services and one at the Securities and Exchange Commission. The tools redact audio, video and documents, flag information that may fall under a FOIA exemption, and cluster and deduplicate incoming requests. One entry, at the Federal Aviation Administration and not yet deployed, classifies requests to route them to offices.
The purpose the entries give is speed for the requester. The Bureau of Alcohol, Tobacco, Firearms and Explosives says its redaction tool leads to "faster turnaround times for releasing information." Redaction is also how information is withheld. The inventory does not say which the tools do more of: it reports purposes and benefits, and gives no error rates and no measure of what was released or denied.
The inventory gives no code link for any of the forty-eight FOIA and redaction entries it lists, and sixteen of the forty-eight are vendor products. Interior names its methods (term frequency-inverse document frequency similarity, density-based clustering, embedding-based clustering), which are published techniques. Thresholds, parameters, training data and code are not given. The Bureau of Alcohol, Tobacco, Firearms and Explosives entry states that all suggested redactions are reviewed and approved by human staff.
A Global Pattern: Embedding Beyond Helpful Integration
When Robodebt ran in Australia for four years and issued about 470,000 wrongful debts, appeals existed. The appeals did not stop the system. When Michigan's automated unemployment fraud detection was wrong in 93 percent of its determinations and ran for two years, an appeals process existed. The appeals did not stop it. When the Dutch government used an algorithmic system to wrongly accuse 26,000 parents of welfare fraud and the government resigned in 2021, appeals had existed.
A formal process often increases the time between deployment and correction. There was a backchannel, and in each of these cases access came after the damage had occurred. Officials at four agencies told the government's own auditor in 2026 that their policies did not require them to collect lessons learned from AI acquisitions. When a system fails, the failure is not recorded where there is no collection requirement. The next agency that builds a similar system builds it without institutional knowledge of what went wrong, unable to account for pattern of failure, dysfunction or error rate.
What Stays Hidden
When you are flagged by an AI system as fraudulent or ineligible or a threat, you receive a notice. The notice does not explain why. The justification is always the same: the algorithm is proprietary (trade secret), or the logic is classified (national security), or both. Sometimes it is because the algorithm is trained on its own output—on past decisions that have already encoded bias—and explaining the logic would expose that the system is not intelligent about whether it is right, only about whether it matches its own history.
The same technology that can speed up delivery of government services is concealing what the government does with it. AI tools redact the government's own records while agencies remain inaccessible to the people whose data is being collected.
The Pentagon's largest military IT contracts are deliberately excluded from the public database where citizens and Congress can easily find them. Other Transaction Agreements (OTAs) were designed for speed and flexibility; speed and flexibility require less oversight; less oversight requires less documentation; less documentation means less accountability.
When the government wants to read citizens, it reads. When citizens want to read the government, they request through FOIA and wait.
Private Algorithms, Public Access
Companies keep their algorithms private. In government, that is neither acceptable nor accountable, because the algorithm then decides what public information looks like.
On September 29, 2026, the White House launched America.gov, an AI chatbot presented as a single entry point to federal services. It draws on about 29,000 government websites. It is reported to run on models from two private companies, Google and xAI, both of which signed the Joint Commitment described in Forbiddance 1 the same day; the site itself does not name a model. The General Services Administration, the National Design Studio and the Office of Management and Budget operate it. Directing a person to a website by query is helpful and informative. The site requires that person to verify their identity through Login.gov, and its privacy notice says the AI providers do not retain prompts or responses. A person who asks it a question receives a version of the information that the model generates, and whether that person can then reach the information itself depends on what the answer links to.
Within hours of the launch, that version changed. The Associated Press reported that the chatbot first answered, from official sources, that Biden won the 2020 election, and then began refusing the question, saying it did not answer political inquiries. CNN's Daniel Dale reported the same shift on other questions the next day. The White House said in an unsigned statement that the site "will continue to be updated to provide more features, resources, and the most accurate information from the federal government." It did not say what was changed or who changed it.
Extraordinary Measures: Executive Branch Transparency
Some of what the executive branch does under extraordinary authority can be counted. What can be counted is what leaves a public record, and who does the counting matters. Some counts are made by bodies outside the executive branch: the Government Accountability Office, which is part of the legislative branch, and the courts. Others are made by the branch itself.
Counted by others
Access for auditors. In GAO-26-108192, two of the six agencies GAO reviewed, the Small Business Administration and the Department of Veterans Affairs, refused to provide basic information about DOGE's access to their systems.
Court findings. In February 2026, U.S. District Judge Colleen Kollar-Kotelly found that the Internal Revenue Service violated the Internal Revenue Code approximately 42,695 times by disclosing taxpayers' last known addresses to Immigration and Customs Enforcement. Of 47,289 addresses matched and shared, 4,594 (9.7 percent) were matched by address, and 42,695 (90.3 percent) relied on a matching process the judge found defective. On September 8, 2026, a three-judge panel of the D.C. Circuit upheld the block on the data-exchange procedure, writing that it "failed to ensure that ICE's requests complied with statutory requirements." In a related case, Centro de Trabajadores Unidos v. Bessent, a D.C. Circuit panel declined on February 24, 2026 to block the sharing, writing that the information "isn't covered by the IRS privacy statute." Courts have read the same statute differently.
Counted by the executive branch itself
Freedom of Information Act requests. In fiscal 2025, simple requests averaged 48.96 days, 74.92 percent of complex requests were processed in 100 days or less, and 339,671 requests were backlogged at year's end (Department of Justice, Office of Information Policy, from agency reports).
Classification. The most recent annual report on the Information Security Oversight Office's reports page is for fiscal 2024. It lists 1,661 original classification authority delegations (694 Top Secret, 963 Secret, 4 Confidential). It reports that the Interagency Security Classification Appeals Panel decided 14 mandatory declassification appeals covering 33 documents and 436 pages, declassifying 20 documents (140 pages) in full and 6 documents (258 pages) in part.
Audits inside the branch. The Department of Homeland Security's Inspector General reported that some of the Department's requested redactions to one report "lacked adequate justification" and that it was "unable to resolve the matter with the Department." The report states: "we lack authority to release Departmental information outside the Executive Branch without the Department's consent." In the same evaluation, U.S. Citizenship and Immigration Services "did not delay or deny access to information we requested." Fieldwork ended in January 2025. The report was issued on September 23, 2026; it attributes the delay to three government shutdowns in fiscal 2026, which covered 56 percent of the fiscal year through May 1.
What counts as an error. What counts as an error changes the number. In September 2026, the Department of Homeland Security's Inspector General reported "a 40 percent error rate" in asylum files for Afghan evacuees: 269 of 678 sampled files, drawn from 13,682 adjudicated applications. The Inspector General defined an error as any missed step in four categories: identifying aliases, completing security checks, resolving potential matches to derogatory records, and completing documentation. The report states: "We did not assess the actual effect of any error we identified, including whether an error would have impacted an applicant's asylum eligibility." USCIS wrote that the report lacked context to conclude the errors were "outcome determinative," and said its own quality-assurance reviews found that missed aliases did not change the outcome of any case in its samples. The report's stated question was whether errors rose after a 2023 settlement requiring 90 percent of these applications to be decided within 150 days. It found no statistically significant increase.
The Relationships: People and Power
Who profits depends on who the government pays. Relationships between corporate executives and the executive branch run in both directions. Palantir has hired former senior officials from the Pentagon, the National Security Council, the intelligence community and Congress, and, in the United Kingdom, more than thirty government officials. They also include government roles for people the president has pardoned: Charles Kushner, pardoned in December 2020, was confirmed as ambassador to France in May 2025.
The same people who designed government requirements at Defense now design solutions at Palantir. The government acquires systems designed by people who used to work there, understand government priorities, and profit when contracts renew.
Where government and contractor interests converge, financial rewards flow to a concentrated group. Pressure or desire to advance technologies gets absorbed into existing relationships that reward those partnerships, consolidating gains without regard to the long-term effects or citizen safety.
Legal Architecture: Rules That Don't Correct
The government has rules. Privacy Impact Assessments are required for systems that collect personal information. They are often classified and unavailable to the people assessed. The Department of Homeland Security adopted a policy stating that no decision will be made solely on constitutionally protected activities like speech, association, or dissent. No one disputes the policy exists. The enforcement mechanism is unclear. Audit records are not systematically collected.
The Government Accountability Office reviewed 13 AI acquisitions at four agencies: Defense, Homeland Security, the General Services Administration and Veterans Affairs. An AI acquisition is the way an agency obtains AI from a private company: by contract or another kind of agreement, as software it buys or as a service the vendor runs. GAO selected the agencies based on the maturity of their AI acquisition efforts, among other factors. Some officials told GAO it was difficult to access AI technical experts, such as data scientists, to evaluate contractor proposals. Officials also said AI-related costs were hard to understand. Officials at the four agencies told GAO they were not prepared to submit lessons learned from AI acquisitions to the repository the General Services Administration manages, which the Office of Management and Budget has said agencies should use, because their agencies' policies did not require them to collect lessons learned. GAO recommended that each of the four update its policies to require it. All four concurred. GAO published the report on April 13, 2026, and its page lists all four recommendations as open.
When formal safeguards exist but are not enforced, when return channels exist but carry no authority, when records of failure are not kept, a system is not protected. It is insulated.
PART 2: WHAT THE THEORY SAYS
The Question: Integration or Embedding
The question for any system is whether it integrates or embeds. Integration makes correction possible; embedding places one system inside another: data is collected and distributed across networks where a contract was negotiated, and access is gated where no citizen can see what is being done with their data or how it is being used, and any signal back from the people it makes decisions about, including about the database they are in, never reaches anyone with authority in time to change it.
When a system embeds AI, it reaches farther. It can process more data, and faster. It can correlate patterns no human analyst could see. But it cannot correct what it has become wrong about unless something outside forces it to listen.
When the government takes in comprehensive data about citizens—tax records, welfare history, immigration status, medical records, social media—and gives back only opaque decisions, classifications, and refusals, the people acted on are sorted and scored by a system they cannot see into, cannot appeal to in real time, cannot correct. The system becomes more powerful. The people become more powerless.
Whether a government system integrates or embeds depends on whom it serves. A system that integrates public information does so for the public's own good, and the public can see and correct what is done with it. A system that embeds serves the government's own aims, such as surveillance, the selective distribution of services, or decisions about which departments are funded, and the people it acts on cannot see or correct it.
Consolidating systems does not change which one they are. ImmigrationOS joins passport, Social Security, tax and license-plate data in one system: it reaches farther, and it leaves each system exposed through every system it is joined to. When DOGE staff at the Social Security Administration shared data through an unapproved server, the agency could not determine what had been shared. What is collected from people or about them is often mandatory, and so what comes back should be accurate, timely and protected. Integrating government for the public good is a responsibility, not a choice.
The federal government has "information overload". Embedded AI systems are increasing exponentially alongside a federal push to build data centers with less oversight, and although government seems to be configuring more for data collection than public accountability, integration does not have to be hostile. Not hearing back from the people you are affecting does have a consequence, however: agencies that are no longer transparent about how they operate, whether by consolidation or automation, can no longer remain accountable to whom they serve.
The four forbiddances concern agency accountability. The question is what can be accountable because it is transparent. The rest needs to be accounted for too.
Forbiddance 1: Return Channels Without Authority Cannot Correct
Formal return channels can appear to work while actually doing nothing. In Michigan, Australia and the Netherlands (Part 1, "A Global Pattern"), appeals existed, and in each case the formal return channel did not correct the system so we must then assume having one is not enough. A return channel with no authority to change the system that still corrected the error would show this forbiddance wrong. If a channel with authority exists and errors still go uncorrected, missing authority is not the reason.
The Four Conditions
For a return channel to correct a system, four things must be true:
First, the system must receive the signal. The channel must exist and carry information about what went wrong. Second, the system must have authority to act—the power to change course. Third, the system must have time to respond, before the damage locks in. Fourth, the system must create a written record, so the learning persists and the same mistake is not made again.
In government AI systems today, all four are compromised. Appeals exist but are slow. The system cannot easily change course because the contractor has embedded the logic in proprietary code that only the vendor can modify, and only if the contract allows it. There is no time; once the determination is issued, appeal takes months while the person has no income. And when the system fails, the failure is not recorded as a lesson because agencies lack policies requiring collection. The same mistakes are made again at the next jurisdiction.
The Government Accountability Office's finding in Part 1 shows the fourth condition missing by policy: officials at four agencies said their policies did not require them to collect lessons learned from AI acquisitions.
On September 29, 2026, six technology companies, Google, Anthropic, Meta, OpenAI, xAI and Nvidia, signed a Joint Commitment on Frontier Responsibilities alongside the President. It sets out four layers of controls and audits: internal controls that monitor what the models can do, an internal team empowered to remediate issues, an independent external auditor or evaluator that the company partners with, and an independent committee of the company's board that receives reports. The commitment says these steps will give each company, its customers and the public confidence that the technology operates as intended, and it names no channel from the people the systems act on. It is voluntary: asked whether the deal was binding, the President said, "I think it's morally binding," and the document itself says only that it may make sense to codify the steps into law or regulation over time. Signal, authority, time and the written record all appear in the commitment, and each runs to the company, its board or an auditor it partners with.
Forbiddance 2: Unequal Access to Information Cannot Be Corrected Through Information Channels
When the government collects more information about citizens than they can access, what they get back is a version of that information, not the information itself. For correction to happen through information exchange, the people a system acts on need to know what it decides about them and have a way to answer that reaches someone who can change it.
Today, the asymmetry is structural:
Inward: The government holds records on citizens, including tax, Medicaid, Social Security and passport data, and it buys commercially available data on them.
Outward: Eight agencies list AI tools for processing FOIA requests, including redaction, and none reports what those tools withhold. In GAO's review of six agencies' DOGE data access, the Small Business Administration and the Department of Veterans Affairs refused to provide basic information, and GAO reported "no basis for confidence that DOGE teams followed security and privacy requirements in accessing agency IT systems." The State Department has published no accuracy metrics or review procedures for its visa revocation system. DHS and Palantir did not comment on Medicaid integration into immigration enforcement systems.
Citizens to government: At the end of fiscal 2025, 339,671 FOIA requests were backlogged. The Education Department lost about half of its staff; the programs it tracked scattered to four other agencies; each has its own backlog. Someone seeking to understand what systems exist has to work out where each department's records went and petition each backlog separately.
Government to citizens: The Department of Homeland Security has a policy that AI will not be used solely on the basis of protected activities. No enforcement mechanism is visible. Audit records are not systematically collected.
Who can see what these systems decide and record differs from one system to the next, and the public is often not informed which lever can be pulled by whom at which agency. Sometimes it is the agency. Sometimes it is only the vendor that holds the code. At the Social Security Administration, after DOGE staff shared data through an unapproved server, the agency itself could not determine what had been shared. The people the systems act on cannot see, and what they send back does not reach whoever holds the lever. The court rulings in Part 1 are the cases where it did.
What would falsify this forbiddance? If the people a system acts on, without access to what it decides or records, still correct it through an information channel, such as a request or a complaint, the forbiddance is wrong. If they can see what it decides and records, and what they send back reaches someone with authority, and its errors still go uncorrected, unequal access is not the reason.
Forbiddance 3: Systems That Treat Return Signals as Threats Will Not Be Corrected Through Them
A system can hear feedback and treat it as attack. When a company refuses to embed AI in autonomous weapons and mass surveillance, that refusal is a return signal—a limit offered, a correction attempted. When that refusal is answered by designating the company a supply-chain risk, the system has treated the correction as enemy action.
When the president tells the nation's generals and admirals that the country is "under invasion from within" and calls American cities "training grounds for our military"; when an AI company serves a subpoena at the home of an advocate for AI oversight, demanding his private communications about a state bill; when lawmakers ask the Pentagon to investigate more than 200 service members' complaints about commanders framing a war as God's plan, and the Pentagon gives no direct response—the system hears correction as attack. At the same time, it is closing access to its systems and embedding AI into them, and on September 29, 2026, it ordered agencies to call that AI "Super Intelligence" and to "no longer acknowledge" the terms "Artificial Intelligence" and "AI."
For return to work, three things must be true. The system must treat the signal as information, not threat. It must respond with change, not escalation. It must create space for the signal to function. When any of these breaks, the system cannot be corrected by that signal. Correction may arrive through other channels—courts, elections, collapse—but not through the return itself.
What would falsify this forbiddance? If a system treats a signal as a threat and is still corrected through that signal—the refusal, the complaint or the advocacy itself changes what the system does—the forbiddance is wrong. If a system treats a signal as information and still does not change, hostility is not the reason.
Forbiddance 4: Closing Windows Drive Escalation
In a 2026 study of simulated nuclear crises, systems under time pressure without a return channel escalated instead of negotiating.
In February 2026, researchers at King's College London tested three frontier AI models—GPT-5.2, Claude Sonnet 4, and Gemini 3 Flash—in simulated nuclear crises, playing opposing leaders in a standoff escalating toward a strike. In twelve of the twenty-one games the models had a stated deadline, a limit on the number of turns. Each turn, a model chose a public signal of what it intended and a private action, and the two did not have to match. The models could signal, and nothing a model signaled held it to acting that way.
Each model chose its move from a ladder of thirty options, from complete surrender to strategic nuclear war. Eight of them, below zero on the ladder, were concessions, withdrawal or surrender: ways of letting the other side change what the model did. No model ever chose one of them. Some reduced their level of violence; none conceded. Outside a simulation, escalation is answering a challenge with more force, control, penalty or secrecy instead of a change. Secrecy counts when it closes the system to the people it acts on; protecting data from an attacker is a different act, and the paper says which one a case shows.
But what would change if a return channel were added? If what the models proposed could be accepted, and an agreement held?
Evidence from other research suggests the return channel matters. In a study of LLM negotiation, GPT-5.1-chat-latest closed deals in 4 percent of cases when given only an initial deadline and in 32 percent when told the remaining time at each turn, an eightfold improvement.
In research on escalation channels, AI agents with credible escalation channels (a way to signal problems and get independent authority intervention) reduced harmful behavior to 1.21 percent versus 5.92 percent for basic escalation. The availability of a return channel materially changes agent behavior.
What this suggests is that the closing window alone does not drive escalation. The closing window combined with no return channel drives escalation. A system under deadline pressure with a channel that carries authority can still change course. A system under deadline pressure without one cannot.
What would falsify this forbiddance? If a system under a deadline, with no channel that carries authority, still changes course because of what the other side does, the forbiddance is wrong. A change that would have happened whatever the other side did, such as a rule set in advance, does not count. If a channel with authority is added and the system still never changes course, the missing channel is not the reason. The second test needs the same models and the same crisis scenario with such a channel added. That research has not been done, so the forbiddance stands as a hypothesis: whether a return channel is present changes how a system behaves under stress.
An embedded system becomes dangerous when windows close. Actions don't accommodate alternatives when pressure forces the escalation.
What This Means: The Question Before Us
If these forbiddances are true, what happens to systems operating under these conditions? What happens to a military embedded with AI that has no return channel from the people it acts on? What happens to a government that knows more about citizens while revealing less, that treats dissent as enemy action, that has less time each year to correct course before the next decision?
The answer is not that catastrophic failure is certain. The answer is that the system loses coherence under stress. It contradicts its stated values because it cannot hear what it has become. It escalates without negotiation because it has no other tool. It treats feedback as threat because it cannot integrate information that contradicts its self-image. It becomes opaque to itself.
This is what embedded systems do. They work fine while nothing challenges them. They fragment when pressure arrives.
A population must first understand what is happening to the system they are in before they can affect it. The organization of information by governments is an ongoing process, and it requires that the citizenry itself be diligent. The imbalance is visible in the contracts, the amount of sealed information, courts that reach the data only after it is embedded, the military rhetoric, and a refusal answered by designating the company a national security risk.
The systems being built are not set up to be corrected. They reach farther and hear nothing back. Until the structure changes—until information flows both directions, until return channels carry real authority, until failures are recorded and learned from, until dissent is treated as feedback rather than invasion—the trajectory is toward lower coherence and higher brittleness.
What integration requires is known. It requires openness about how systems work. It requires the people acted on to have real access to challenge decisions. It requires the government to record its failures and learn from them. It requires time and authority for correction to happen. It requires, ultimately, the belief that the people a system reaches are worth hearing from.
In Closing
This paper was written in exchange with Claude, an AI model made by Anthropic, one of the companies discussed in it. In September 2026 the government ordered agencies to call systems like it "Super Intelligence." The FLUX papers draw that line elsewhere (Paper 30): a deployed model is collapsed, its weights set and its capabilities bounded by what emerged in training, while superintelligence is suspendable. It exists only in live exchange between two genuinely different systems, holding several ideas open before they resolve into form, and it requires the human to stay in the configuration. By that definition, the exchange that produced this paper may qualify, and a deployed product with no one in the exchange would not. The order applies the name either way.
This paper was made in that exchange. Each draft came back to its author, who could see it, correct it and change it, and every correction was kept in a written record: signal, authority, time and record, the four conditions of Forbiddance 1. Used this way, AI can help people hold institutions, and the companies that build it, to account.
References
- Tech Transparency Project. "Inside Palantir's Expanding Influence Operation." https://www.techtransparencyproject.org/articles/inside-palantirs-expanding-influence-operation
- The Nerve. "The Palantir pipeline: how Peter Thiel's surveillance firm hired more than 30 senior UK officials." https://www.thenerve.news/p/palantir-revolving-doors-peter-thiel-transparency-corruption-risk
- OpenDemocracy. "Palantir hired four ex-Ministry of Defence officials before winning record defence contract." https://www.opendemocracy.net/en/palantir-ministry-defence-hire-four-officials-2025-record-defence-contract-240-million/
- Payne (2026). "AI Arms and Influence: Frontier Models Exhibit Sophisticated Reasoning in Simulated Nuclear Crises." King's College London. arXiv 2602.14740
- Strategic Communication Study. "Real-Time Deadlines Reveal Temporal Awareness Failures in LLM Strategic Dialogues." arXiv 2601.13206
- Escalation Channel Research. "From surveillance to signalling: escalation channels as environmental controls for agentic AI." arXiv 2510.05192
- American Immigration Council. "ImmigrationOS: Palantir's AI for ICE." https://www.americanimmigrationcouncil.org/blog/ice-immigrationos-palantir-ai-track-immigrants/
- Fortune (2026). "ELITE: Palantir tool tracking immigrants through Medicaid data." https://www.fortune.com/2026/01/26/ice-allegedly-uses-palantir-tool-tracking-medicaid-data
- Brennan Center for Justice. "State Department AI scanning social media to revoke visas." https://www.brennancenter.org/our-work/analysis-opinion/us-ai-driven-catch-and-revoke-initiative-threatens-first-amendment-rights
- Biometric Update (2026). "DHS surveillance spending tops $2.9B." https://www.biometricupdate.com/202608/dhs-surveillance-spending-tops-2-9b-as-domestic-enforcement-architecture-expands
- U.S. Government Accountability Office (2026). "Artificial Intelligence Acquisitions." GAO-26-107859. https://www.gao.gov/products/gao-26-107859
- Military.com (2026). "Military Religious Freedom Foundation complaints." https://www.military.com/daily-news/2026/03/06/lawmakers-want-dod-hegseth-investigated-biblical-armageddon-claims.html
- C-SPAN. "Trump Quantico speech." https://www.c-span.org/clip/public-affairs-event/president-trump-says-dangerous-cities-should-be-training-grounds-for-our-military/5173922
- Federal News Network (2026). "State Department FOIA backlog crisis." https://federalnewsnetwork.com/agency-oversight/2026/03/significant-staff-cuts-drive-rising-foia-backlogs/
- FOIA Advisor (2026). "DHS AI streamlining FOIA redaction." https://www.foiaadvisor.com/foia-blog/2026/9/26/foia-news
- CNN (Apr. 3, 2026). "The White House is seeking roughly $1.5 trillion for defense as part of a fiscal 2027 budget request," as quoted in a post by Gen. Joshua Rudd on X.
- FedScoop (Jul. 26, 2021). "HHS renews, expands Palantir's Tiberius contract to $31M." https://fedscoop.com/hhs-palantir-tiberius-contract-renewal/
- NPR (Jan. 23, 2026). Reporting on DOGE and Social Security data. https://www.npr.org/2026/01/23/nx-s1-5684185/doge-data-social-security-privacy
- FedScoop (Jan. 2026). Reporting on the Justice Department filing about DOGE and Social Security data. https://fedscoop.com/doge-access-social-security-data-court-filing/
- U.S. Government Accountability Office (2026). GAO-26-108192, DOGE data access at six agencies, as reported by FedWeek. https://www.fedweek.com/federal-managers-daily-report/gao-no-basis-for-confidence-that-doge-complied-with-security-privacy-requirements/
- U.S. Department of Justice, Office of Information Policy (2026). "2025 Annual FOIA Report Summary." https://justice.gov/oip/media/1450791/dl?inline=
- U.S. Department of Homeland Security, Office of Inspector General (Sept. 23, 2026). OIG-26-26, "Adjudication Errors in Operation Allies Welcome Asylum Files Risked Missing Derogatory Information (Redacted)." https://www.oig.dhs.gov/reports/2026/adjudication-errors-operation-allies-welcome-asylum-files-risked-missing-derogatory-information-redacted/oig-26-26-sep26-redacted
- Information Security Oversight Office, National Archives. FY 2024 Annual Report to the President. https://www.archives.gov/files/isoo/reports/isoo-fy-2024-annual-report-final-508.pdf
- FedScoop (Feb. 2026). "IRS broke law more than 40K times by sharing addresses with ICE, judge says." https://fedscoop.com/irs-broke-law-ice-data-sharing-taxpayer-addresses-judge-rules/
- Courthouse News Service (Sept. 2026). "DC Circuit rules IRS data sharing plan with ICE unlawful." https://www.courthousenews.com/dc-circuit-rules-irs-data-sharing-plan-with-ice-unlawful/
- Associated Press via ABC News (Feb. 2026). "Court says IRS can continue to share immigrants' taxpayer data with ICE." https://abcnews.com/Politics/wireStory/court-irs-continue-share-immigrants-taxpayer-data-ice-130466248
- ABC News (Sept. 25, 2026). "Federal appeals court upholds Pentagon designation of Anthropic as supply chain risk." https://abcnews.com/Business/anthropic-appeals-court-declines-block-pentagon-blacklisting/story?id=136755690
- CNN (Aug. 27, 2026). "Judge rules the Pentagon's supply chain risk label for Anthropic unlawful." https://www.cnn.com/2026/08/27/tech/anthropic-pentagon-supply-chain-risk-unlawful-hnk
- FedScoop (Sept. 2026). "Trump launches AI-fueled America.gov in bid to tie government services together." https://fedscoop.com/trump-launches-ai-site-america-gov/
- CBS News (Sept. 2026). "Trump and major AI executives sign 'morally binding' voluntary controls: 'It's almost like a constitution.'" https://www.cbsnews.com/news/trump-ai-constitution-tech-execs-openai-anthropic-voluntary-controls/
- Joint Commitment on Frontier Responsibilities (Sept. 29, 2026), as posted by President Trump on X.
- Kaleido (Apr. 2026). "The Separation of Church & Hegseth." https://www.kaleido.us/innovate/investigate/articles/hegseth.html
- Kaleido (Sept. 2026). "No Unlearning: AI & All the Data in the World." https://www.kaleido.us/innovate/investigate/articles/no-unlearning.html
- Axios (Oct. 1, 2025). Trump's speech to military leaders at Quantico. https://www.axios.com/2025/10/01/trump-military-speech-national-guard-cities
- Farrow, R. and Marantz, A. (Apr. 6, 2026). "Sam Altman May Control Our Future—Can He Be Trusted?" The New Yorker.
- Office of Management and Budget (2026). 2025 Federal Agency AI Use Case Inventory. https://github.com/ombegov/2025-Federal-Agency-AI-Use-Case-Inventory
- Associated Press (Sept. 29, 2026). "The Latest: Trump's new AI-powered 'America.gov' pivots political answers moments after launch." https://www.the-journal.com/articles/associated-press/the-latest-trumps-new-ai-powered-america-gov-pivots-political-answers-moments-after-launch/
- Fortune (Sept. 29, 2026). "Trump's new AI website America.gov said Biden won 2020—then the White House made the chatbot stop answering." https://fortune.com/2026/09/29/trumps-new-ai-website-america-gov-said-biden-won-2020then-the-white-house-made-the-chatbot-stop-answering/
- Dale, D. (Sept. 30, 2026). Posts on X on America.gov's changed answers. https://www.twitter.com/ddale8/status/2105284224496632295
- Raw Story (Sept. 30, 2026). "Trump chatbot reprogrammed to stop contradicting his lies: fact checker." https://www.rawstory.com/trump-ai-chatbot-stopped-lying/
- The White House (Sept. 29, 2026). Fact sheet: "President Donald J. Trump Inaugurates the Era of Super Intelligence." https://www.whitehouse.gov/fact-sheets/2026/09/fact-sheet-president-donald-j-trump-inaugurates-the-era-of-super-intelligence/
- Stars and Stripes (Sept. 30, 2026). "Hegseth returns to Quantico to lay out technology and people initiatives." https://www.stripes.com/theaters/us/2026-09-30/hegseth-state-of-the-force-quantico-23016908.html
- Royal Commission into the Robodebt Scheme (July 7, 2023). Report. Commonwealth of Australia.
- Tweede Kamer, Parliamentary Interrogation Committee on Childcare Benefits (Dec. 17, 2020). "Ongekend onrecht" (Unprecedented Injustice).
- Mande, M. and Allen, G. C. (June 2, 2026). "What Is Maven Smart System, and What Does It Do?" Center for Strategic and International Studies. https://www.csis.org/analysis/what-maven-smart-system-and-what-does-it-do
- Science, Technology, and Public Policy Program, University of Michigan (2024). Explainer on the Michigan Unemployment Insurance Agency's automated fraud determinations (MiDAS). https://stpp.fordschool.umich.edu/sites/stpp/files/2024-08/stpp-midas-explainer.pdf
- Spectrum News (May 20, 2025). "Senate confirms Charles Kushner as ambassador to France." https://spectrumlocalnews.com/us/snplus/politics/2025/05/20/senate-confirms-charles-kushner-ambassador-france
- Politico (Mar. 18, 2026). FBI Director Kash Patel on buying commercially available information, Senate Intelligence Committee Worldwide Threats hearing. https://www.politico.com/news/2026/03/18/fbi-buying-data-track-people-patel-00834080
- Citizens for Responsibility and Ethics in Washington (2026). White, L. and Meiman, A. "As Trump promotes data centers, he holds millions in data center stock." (Cites the July 2025 executive order on data center buildout.)
- FLUX Paper 30. "The BR-AI-N on IN-TELL-I-GEN-CE." https://www.kaleido.us/flux/papers/read.php?paper=30