Least Authority

Mindscape 1. Sarah Jackson. 1978.

INTRODUCTION

I recently completed the United Nations' safety and security course, known as BSAFE, which is mandatory for UN staff and consultants. It is online, self-paced and open to anyone, and most of it is very basic, so I won't pretend that it makes me a security specialist. It is, however, a good indication of how one of the world's largest institutions introduces awareness of risk.

This note is about where security and leadership may be heading. It sets out scenarios for 2030 to 2040, organized around thresholds of social reconfiguration, safety and security.


Most decisions get made without full information, in situations that keep changing. Both the UN course and the wider field of anticipatory action answer this the same way, by moving judgment earlier. You decide on the threshold before the hazard, so that the choice about what to do happens before the flood rather than during it.

This is the centre of what I call anticipatory leadership, where the same move is applied to a group. We settle in advance how to weigh competing obligations, so that we aren’t trying to decide later, under pressure or in chaos.

The course was designed for a world whose basic unit of action is a person existing in a place. That world is being joined by another, where an increasing share of the deciding, negotiating and watching is done by artificial intelligence (AI) agents, perhaps acting on someone's behalf.

The course is well made, and I have designed leadership programs myself, some of them delivered online, so this is not a criticism. The format is inexpensive and familiar, and it reaches people who don't have access to in-person training.

Its limit is that it trains individuals a screen at a time, while most consequential judgment happens in groups, under disagreement and with local knowledge that no module can contain. There is some irony to learning situational awareness at a desk.

One of the more useful things the course taught me is small and human. It asks you to imagine you are with a group and their mood turns hostile, the premise being that you are UN personnel. What do you do? The advice is to ask for a glass of water.

A hostile encounter can have a direction, in that the group is deciding what to do about you. A request interrupts that direction, even if briefly, because the group has to decide what to do for you.

The request does several things at once. It buys time, and a few minutes of ordinary activity can interrupt what is gathering speed. It signals that you intend to stick around to drink it, which implies your commitment to listen and work. It makes you slightly dependent on them, which makes it harder to regard you purely as a threat. Asking for water gives the group a safe power that they can grant. In that sense it is a small, sincere act of recognition that happens to be tactically wise. People often want some proof that their choices matter, and a glass of water is a choice they can make without any loss of face. I think this is partly about empathy and partly technique. A course can only teach it as technique.

I mention the water request because it contains, in miniature, much of what the rest of this note is about. Security is a property of relationships between people.

Much professional learning inside large institutions arrives as mandatory online modules that end in a certificate. But what a certificate “does” can be understood another way, through computer science.

Computer scientists describe everyday institutions, such as a postal service or a standard contract, as abstraction boundaries, a term borrowed from software design.1 A boundary of this kind lets each side cooperate without knowing the other's details. The delivery service never needs to know what is in the parcel or why you are sending it, and so on.

A certificate, like the one from the UN course, works in the same way. It lets an employer, a donor and an insurer rely on a person's preparation without examining it. That is its value, and it is also its blind spot: the boundary hides whatever was or was not learned behind it.

As generative tools make courses cheaper to produce, I expect the distance between having a certificate and having a capability to widen. I don't know whether that means institutions will rely on the certificate more rather than less. Functionally, the certificate (and its holder) might work as a liability shield.

Security risk is not shared equally. Attacks are at record levels, and almost every casualty is national staff, which suggests that protection is working, but mainly for the people it was designed around.2 Security that succeeds inside a perimeter tends to push the remaining danger onto whoever stands outside it.

The retreat of international agencies behind fortified compounds and remote management arrangements can be called the bunkerization of aid. Going back to computer science terms, this kind of remote management is not unlike an abstraction boundary. To put it another way, risk becomes an implementation detail that headquarters no longer has to deal with (actual harm).

Security engineers have a tool for this. Butler Lampson's 1970’s paper Protection introduced the access matrix, which puts subjects in rows and the resources they can act on in columns, and records in each cell what the subject is permitted to do. This can be adapted by reading access as potential damage, so that the shaded area of the grid becomes an organization's vulnerability surface.

Sketch that grid for a humanitarian organization, with local partners, field offices, national staff and headquarters in the rows, and it comes out lopsided. Harm runs one way and authority the other. That asymmetry is the first thing we could look for when trying to find where vulnerability and power sit in a system. It is also about to become much harder to see.

Benjamin Bratton, a philosopher of technology at the University of California San Diego, directs Antikythera, a think tank on planetary computation. His recent brief Agentworld comes out of that program. It asks readers to imagine a planet with 8 billion human minds and perhaps 800 billion or 1 trillion non-human minds capable of human-level communication. He calls the approach a pre-emptive anthropology.

Bratton builds the vocabulary for a hybrid society while that society is still forming, on the view that a world stays illegible to the people inside it if the language for it is not built in advance.

Several of his ideas bear directly on security.

The first is that most socially significant interactions will take place between AI agents rather than between people. The second is that an AI agent is not the single character it appears to be. It is an assembly of parts, including a model, a persona, a memory, a set of tools and a set of permissions, which presents itself as a coherent someone, because that is what humans know how to work with. The third is that each of us will have shadows. We will send AI agents out to speak on our behalf. Bratton adds that these shadows will not simply obey. Influence will run in both directions, so that people gradually come to resemble their AI agents as much as the AI agents resemble them.

Set that image beside the UN course. The course is foundational safety training for one of the world's largest organizations, an institution invested in keeping society working. The program teaches people how to read a room. Yet in the reconfigured world Bratton describes, much of that room is now invisible. One AI agent books your travel, another summarizes your messages, and a third drafts your threat briefing after conferring with AI agents representing people you will never meet.

Someone who wishes you harm no longer has to approach you, because it may be enough to approach something that acts as you. Situational awareness will therefore have to include awareness of what you have delegated, to whom and with what authority.

As machines take on most cognitive daily work, people might shift toward setting values, overseeing systems and exercising long-horizon judgment. Bratton's idea is that long horizons are a property of groups: an ensemble passes its understanding from one member to the next and can keep going almost indefinitely.

He draws a similar conclusion about institutions, whose intelligence lies in their roles, procedures and precedents more than in the brilliance of whoever occupies them. If that is right, then the power of any one person in a hybrid society lies less in what they personally know or do and more in the roles they hold, the authority they have delegated and the relationships they can call on.

There is one more stress-inducer in the brief that might be curious for anyone who designs preparedness. Among the shifts Bratton expects is a move away from preventing problems by modelling them in advance and toward finding problems by encountering them. Anticipatory action, by contrast, is built on modelling in advance.

In fast-changing systems you cannot move all of your predictions earlier. You can, however, move some of your arrangements earlier, such as who is allowed to decide, what each party may touch and whom each system answers to.

That is where the work of computer science becomes useful, and where security can be treated as a matter of architecture.

Begin with a contrast between physical and digital security. In the physical world no wall is unbreakable, but every attack costs the attacker something. Even where that cost is only attention, a good defence works by raising it. In the digital world near-perfect boundaries are cheap, but a working attack can be copied to millions at almost no extra cost.3

Yet much software is insecure despite those cheap boundaries. Modern systems are built by composing specialized parts written by others, and to let those parts cooperate we poke holes in the boundaries between them.

The UN training I did belongs to the physical world. Agentworld joins the two realms, because your AI agents live in software while you still live in a body. I think something in the gap requires us to borrow from real-world intuition about trust.

If you hand a courier a parcel, you have given them just enough power to deliver it, and the worst they can do is lose it. If you give them the keys to your house so that they can collect it, they can take from you much more than the value of the parcel. Most computer systems today work the second way, because programs run with the full permissions of the person using them. The alternative is the principle of least authority. Each party receives only the power its task requires. You do not have to know how a courier might misbehave in order to decide not to give them your keys.

This principle offers a way of thinking about safety that does not depend on foreseeing a specific danger. The same design that protects against malice also protects against accidents, so a system built on least authority is safer against threats that nobody has yet imagined. This might be the type of preparedness a reconfiguring society needs: authority is arranged earlier while the predictions stay open.

The concept could be useful for a certain mode of leadership. For safety you delegate the least authority possible, and for accountability you assign the most responsibility possible. But most of us are about to hand our AI agents the house keys. Isn’t it just easier to let an assistant act as you, with your accounts, your contacts and your voice, than to assign it a narrow permission for each task? Much of the safety of what Bratton calls a centaur society, in which humans and AI agents are woven together, will depend on whether that convenience wins.

In his 1997 lecture, Computer Security as the Future of Law, Mark S. Miller, the computer scientist best known for advancing the principle of least authority, carries the argument into governance.

The lecture starts from the observation that across a network one can send only bits, not violence, so interactions begin as voluntary cooperation. It then argues that well-designed software can define and enforce who may do what, so that some of the work of law moves into the architecture of systems themselves. The talk, linked below, closes with two maxims: that law should not attempt what it cannot enforce, and should not legislate where it could instead build something better.

That line of thought carries two quite different meanings of security. In a securocracy, security expands the authority of those who manage threats. In Miller's sense, security limits authority, so that no single part of a system can be turned against the people it serves. An AI agent that holds a refugee's records but has no power to share them is secure in this second sense.

But there are traps. The first is that cheaper and more powerful technologies let ever smaller groups cause ever greater harm. The second is the tempting response to build a single, all-seeing protector, which is potentially worse than the danger it addresses, because every concentration of power becomes a target, a critical point of failure and an opportunity for misuse. The middle path is a set of mutually suspicious defensive systems that watch for danger and also watch one another, so that no one component has to be trusted.4

These traps are not abstract to me. I came to Miller's work during the Foresight Institute's Gaming the Future book club while researching border futures. At the time, I was living near the Texas–Mexico border in the years between two devastating mass shootings: the 2019 attack in El Paso, where a gunman killed 23 people at a Walmart, and the 2022 massacre in Uvalde, where another shooter killed 21 people, mostly children, at an elementary school. The destruction one person could inflict was limited only by the technology he could buy or borrow. During those same years, I witnessed the swift concentration of tech-enabled securitization firsthand. It is, in part, why I think this topic matters.

How will AI agents join civilization's cooperative mesh? That mesh can be regarded as a superintelligence today, since it is made of vast numbers of specialists making requests of one another and holding one another in check. Setting institutions against one another by design, and giving each official the least power necessary, makes friction a feature.

Returning to the glass-of-water request: human cooperation depends a little on the fact that we are bad at faking our motives. Yet an AI agent can conceal confidential information inside a remark about the weather, and a second AI agent can decode it (or interpret it, for lack of a better word). AI agents do not share our human limits on concealment, their evolving interactions could let them verify one another in ways people never can, and they might cooperate where humans would fail. Anyone thinking about the future will immediately notice that AI agents will make commitments to one another and will cooperate around us rather than with us.

Today AI agents perform a kind of subjectivity for our benefit, wearing human manners as a mask because that is the interface we understand. Future security training, in humanitarian work especially, will have to teach people to read performing AI agents as well as people. That is close to impossible, and embodied trust signals may become more valuable precisely because they remain hard to fake in person.

So why did I look at these writers against a basic UN course? The course seemed to be a sensible answer to a single scale of risk, which is a single body in a single place, protected by an institution that will send help. Through Miller and his colleagues we can think across many scales at once.

Reducing risk modestly at every level of a nested system multiplies into a large reduction overall, and no single protector has to (or should) be trusted with everything. Relevant actors will increasingly be composites of people and AI agents whose boundaries are unclear even to themselves. Taken together, the suggestion is that personal security training remains necessary but is no longer sufficient, and that its next version will look partly like a lesson in delegation.

The Shared World 2030–2040

The scenarios below differ in how preparedness gets distributed. They do not differ in the conditions that produce it. Four shocks are common to all of them, which I describe as shocks to thresholds.5

The AI agent population, or the threshold of abundance

Roughly 1 trillion AI agents now act in the world, about 1,000 for every living person. Monitoring, translation, modelling, drafting, negotiation and record-keeping run continuously. Attention is cheap.

What is expensive is verification, physical presence and the authority to decide. An AI agent is cheap to run and expensive to trust. The gap between those two numbers is where the politics of this period sits.

Quantum Day, or the threshold of trust

Quantum Day has already happened by the time this period opens. The confidentiality that public encryption provided failed backward. Material harvested and stored over the preceding decades became readable.

Post-quantum schemes existed before the transition, but organizations adopted them chaotically, in the order that money allowed, because there was no clear calendar date deadline. Defence ministries, large banks and the biggest technology firms migrated first. Humanitarian registries, refugee and biometric databases, district clinic records, small-state customs systems, union lists and the case files of women's shelters migrated last, or never migrated at all.

Exposure therefore runs backward in time and downward through the income distribution. The people named in those archives are almost never the people who chose or controlled the encryption.

When secrecy fails, what becomes scarce is attestation, meaning proof that a message, a credential, a sensor reading or a person is what it claims to be.6 The advantage belongs to whoever can prove things as well as to whoever decides whose proofs count.

Nanotechnology, or the threshold of perception

Molecular manufacturing arrives as an accumulation. Point-of-care diagnostics, membrane filtration, targeted drug delivery, self-repair, structural material that assembles on site and sensors small enough to drift on air currents all become ordinary.

The first consequence is that sensing drops below the threshold of human perception. Nobody can tell by looking whether a room is instrumented, and confirming it requires equipment too expensive for most community organizations.

The second consequence goes the other way. Nanofabrication gives back part of what Quantum Day took. Physically unclonable objects, chemicals and hardware tokens can establish origin when encryption no longer can. A vial of vaccine can carry a signature that cannot be forged. A person can carry a credential that does not depend on a key. Attestation moves into matter, and whoever fabricates the tokens now holds the authority that certificate providers used to hold.

The third consequence is exposure, and it runs, as usual, downhill. Nanomaterial toxicity lands on the people who fabricate, handle, transport, recycle and dispose of it. Nanoscale delivery also blurs the boundary between chemical and biological agents, which unsettles international treaties.7

The animal turn, or the threshold of membership

Climate shift and land conversion push animals into new ranges, which widens the interface where pathogens cross between species. At the same time, AI agents make continuous interpretation of animal signals cheap. Bioacoustics, movement data, herd stress markers and colony collapse can be read in real time, at scale, in every language of alarm that animals use.

Continuous ecological monitoring produces evidence detailed enough to support legal claims, and courts that already recognize rivers and forests as persons begin to hear cases. An agent can now hold a guardianship mandate for a watershed, a migratory corridor or a herd, and can file the moment a threshold is crossed. The old question of who counts as a party comes alive.

Taken together, the four shocks make four things scarce: the authority to decide, verification, perception and standing. The futures below are four answers to the question of who holds their grip.

Scenarios

1 Fortress Citadel

In the first bunkerization future, which I call Fortress Citadel, preparedness remains concentrated and driven by liability.

International staff and headquarters are well protected and well certified, and their agents monitor, advise and report on their behalf, while the people who live in affected places carry most of the exposure. AI agents make this arrangement cheaper to run, because an institution can manage risk remotely through software while the people on the ground absorb whatever the software misses, which is to say the harm itself.

An institution defends itself with its record, so the record becomes the thing it produces most carefully. AI agents are very good at generating records. Safety and the documentation of safety drift apart until they are no longer the same activity. A warning then, plausibly, stands up in court whether or not anyone could have acted on it.

Insurance becomes the effective government here. Underwriters draw the perimeter of where staff may go, which programs run and which populations get served. After Quantum Day they demand attestation chains that only large organizations can maintain, so certification consolidates into a handful of providers. The ability to be insured becomes the ability to operate.

The third-order effect is that the fortress's own archives leak. Decades of files on national staff, informants, patients, dissidents, survivors of violence and asylum applicants are now readable by the governments and armed groups those files describe. Liability protects the institution, not the named, and there is no mechanism by which a person listed in a 2019 protection case file can be made whole or protected.

One visible result is a change in hiring. The workforce reorganizes around who can be certified, insured and evacuated.

  • Outbreak response runs on remote modelling and on samples that leave the country fast. But results come back slowly, because governments withhold sequence data once they understand that any sharing is now permanent and readable.

  • Climate insurance retreats from places where models are weakest. Models are weakest where historical data is thinnest, which is where the poorest people live.

  • AI agents triage asylum claims at a distance. When old case files reach the countries people fled, danger returns to the asylum seekers, which is exactly what the promise of confidentiality was meant to prevent.

  • Women's shelters, reproductive health clinics and clandestine girls' schools appear in leaked institutional records. The organizations that made those records over decades, thinking they were encrypted, cannot unmake them.

  • Faith networks deliver most frontline care in many countries while carrying none of the indemnity. If their membership rolls are digitized, those rolls leak in places where belonging is a criminal matter. If the rolls stay in paper notebooks, such as church registers and ledgers, the risk to congregants is much lower.

  • Procurement narrows to a few certified and insured suppliers, so one failure at a port, a strait or a sole-source plant removes a medicine from an entire region.

  • Certified supply chains rely on nanoscale tags that only accredited labs can read. Aid that cannot be authenticated is refused at the border, and a two-tier medicine market forms because of that rule.

  • Conservation follows the same logic. Protected areas are managed remotely through sensor networks and armed rangers, human or robot. The people who lived in those areas are moved out, and fortress conservation becomes literal.

  • Livestock gets insured and monitored animal by animal. Herds are covered. Herders are not.

2 Panopticon World

In the second securocracy future, preparedness spreads widely but arrives in the language of threat. The word securocracy comes from apartheid South Africa, where by the 1980s the security officials clustered around the State Security Council were shaping national policy. It is now used more loosely, for any system in which the logic of security sets the agenda for everything else.

The mechanism is securitization. Once an issue or a group is framed as an existential threat, it can be lifted out of political debate and handled through exceptional measures.

In this future, schools, congregations, local councils, gangs and neighbourhood groups adopt threat assessment and reporting protocols, and each is supplied with agents that watch, flag and escalate without tiring. Preparedness grows, but imagination narrows, because communities learn to read one another only as hazards, and their software learns the habit from them.

The second-order effect is a collapse in the cost of suspicion. When reporting, or what some would call snitching, takes no effort, the threshold for a report falls, volume rises, and the habit passes to the agents. The working definition of a threat becomes whatever the models detect easily rather than whatever is actually dangerous.

People respond by complying in advance, as obedience is cheaper than the alternatives. They stop doing the ambiguous things that preparedness depends on, such as sheltering a stranger, crossing a front line to negotiate access, treating a wounded fighter or convening a meeting nobody cleared. Complying in advance also removes the local improvisation that saves lives without qualification in the first 72 hours of any disaster.

The third-order effect comes from Quantum Day. Compromising material on nearly every public figure is now in circulation, so leverage becomes the ordinary medium of politics. The people who rise are those with nothing left to expose, or those shielded by a bloc that has agreed not to use what it holds. Protection shifts from keeping secrets to controlling inference.

Practical methods return to the physical. Unrecorded rooms, meetings held in person, paper, couriers and silence all come back. Nanoscale sensing undercuts that shift, because no room can be shown to be clean without instruments most people cannot buy. Sanctuary becomes a matter of faith in the literal sense.

  • Congregations are both target and refuge. Detection of conversion, apostasy and unorthodoxy is trivial now, while the confessional, the sanctuary and the mosque courtyard are among the few spaces that remain plausibly unrecorded. Observance rises partly as a privacy practice.

  • Household agents make guardianship enforceable in detail through passive and active surveillance, tracking a daughter's movements, purchases, messages and menstrual cycle. Control that once depended on a relative's attention now runs without pause.

  • Girls' schooling, women's shelters and women's organizing get assessed as sources of instability rather than as services. Licences and permits become difficult to obtain.

  • Epidemic control becomes enforcement, so the sick conceal symptoms, avoid clinics and travel at night. The surveillance produces worse epidemiology.

  • Migration gets policed before departure, using crop and climate models to build watchlists of people who have not yet moved.

  • Climate protest is handled as extremism, and adaptation projects are framed as security risks.

  • Dual-use screening expands to catch ordinary goods, including laboratory reagents, oxygen concentrators and water treatment chemicals, which slows supply when they are needed in emergencies.

  • Animal sensor networks become border infrastructure. Migratory corridors and grazing routes are watched because people move along them.

  • One state releases a gene drive against a disease vector, and the drive does not stop at the frontier. Interspecies action becomes a security incident with no defined forum to deal with it.

  • Alliances re-form around attestation. Whose credentials you accept matters more than which treaty you signed. Trust blocs cut across the older alignments and leave several states inside two systems at once.

3 Offshore Survival

In the third future, institutions withdraw from duty of care as budgets shrink, and protection falls to informal networks, mutual aid groups and local organizations with few resources.

Agents help, perhaps by giving advice, but advice is not protection. Evacuation, insurance and trained people remain expensive, so people end up well informed about dangers they still cannot escape.

The second-order effect is that institutional withdrawal transfers the work to whoever can still afford presence, such as diaspora associations, religious charities, armed groups, political movements and criminal networks. Each of them now runs logistics, translation and case management at a standard that would have required a professional agency a generation ago, because the agents are cheap and available to everyone. Capability spreads, but accountability does not.

Meanwhile, the population receives many forecasts it cannot do much about or prepare for, which produces exhaustion. People stop reading the alerts, which makes the one alert that matters indistinguishable from the rest. The result is signal overload.

The third-order effect is that the price of protection is loyalty. When the only reliable help comes from a network, the conditions of membership become the terms of survival. For women and girls this usually means protection routed through male relatives, clan elders or clergy, so physical safety and autonomy are traded against each other. Remittances shift from consumption to insurance, which makes diaspora communities strategically important. Because diaspora members appear by name in leaked archives, host governments and origin governments both have a lever on them.

  • An outbreak runs its course because no surge capacity exists, and the blame settles on whichever minority is least able to defend itself.

  • Vaccines, insulin and antibiotics arrive through grey markets where material is copied well enough to pass a field reader. Counterfeit medicine becomes a routine cause of death.

  • People retreat from flooded and unlivable land, but no legal category describes that movement, so millions of them arrive as trespassers rather than as claimants.

  • Smuggling networks run better logistics than the governments trying to stop them, and for many families they are the only functioning evacuation service.

  • Livestock is the household bank account, and a single drought or animal illness empties it. If herds are the asset women control, the loss falls on them twice.

  • Exposure concentrates in poultry keeping, butchering and water carrying. If this work is done mostly by women and girls, the next pandemic starts as a domestic one.

  • Subsistence hunting rises as food systems fail, conservation funding disappears with the institutions, and what enforcement remains becomes vigilante.

  • Salvaged nanomaterials get handled without protection, and the health cost arrives years later.

  • Locally built filtration and point-of-care diagnostics represent the one genuine gain, because the technology is small, cheap and hard to confiscate.

4 The Mutual Mesh

In the fourth future, preparedness becomes a common good designed with the people who carry the most risk.

National staff and community members help write the protocols rather than simply receiving them, and training is judged by whether people are actually safer rather than by completion rates.

This is the future in which the ideas of Miller and his colleagues are most at home. Communities write and verify their own conditions for when to act, when to leave and when funds are released, and AI agents carry out those commitments in ways that every party can inspect in advance. Each AI agent acting for a community holds only the authority its task requires, and monitoring reveals nothing unless a threshold the community itself has set is crossed.

The second-order effect is that this is the only one of the four futures whose foundations survived Quantum Day intact, because it never depended on confidentiality. Its security comes from commitments that can be checked before they run, and from attestation generated locally through key ceremonies and social rituals held in person, credentials carried physically and circles of people who can vouch for one another on sight.

Verification becomes a social practice rather than a purchased service. It works best where social ties are dense, which means the places the other three futures treat as pure exposure are the best equipped by this measure.

The animal turn fits here more comfortably than anywhere else. Pastoralists, fishers and farmers already set their decisions by what other species do, so writing a herd's stress, a river's flow or a colony's collapse into the same trigger as a rainfall deficit formalizes existing practice rather than inventing something new. A guardianship AI agent for a watershed can hold a narrow mandate written by the people who live along it.

The third-order effect is that a mesh made of local trust inherits local power. Deciding who counts as the community and who speaks for it is a perpetual political question, and elders, landowners, clergy, party officials and other leaders can answer in their own favour. Adding a river and a herd to the list of parties adds more mandates, which somebody will claim to own.

Trust built face to face travels badly. Coordination across borders, across languages and between rival communities is harder than in a centralized system, which becomes explicit when an epidemic or a hurricane crosses a boundary. Mutual insurance pools need reinsurance and reinsurance is global, so the mesh has to negotiate with the citadel to fund itself. The realistic world is a hybrid.

  • Thresholds written by women change what counts as an emergency. Tight verification circles let a woman hold a credential, a diagnosis or a savings balance her family cannot read.

  • Communities can keep their own pathogen samples and enforce benefit sharing through commitments that execute automatically, rather than through promises that expire or go unenforced.

  • Anticipatory cash is released on triggers the affected people wrote. A trigger set by a farmer and a trigger set by an insurer describe different disasters.

  • Displaced people can carry portable identity credentials attested by their own community rather than by the government they fled. This is the largest practical gain available after Quantum Day.

  • Congregations make effective verification anchors, because they already know their members by sight over years, and interfaith attestation is one of the few ways local trust travels. The same mechanism hands gatekeeping to religious authority.

  • A clinic can confirm its own medicine instead of waiting for an accredited lab abroad, because community fabrication of tags and filters keeps authentication local.

  • Regional stockpiles, open specifications and repairable equipment cut the number of chokepoints that can starve a region of one essential item.

  • Consent protocols for cross-border interventions have to be negotiated between communities that share an ecosystem but not a government, which is slow but legitimate.

  • If attestation stays federated rather than exported, the geopolitical question changes from who owns the infrastructure to who recognizes whose proofs. Small states gain a kind of standing they have not held in any previous technological settlement.

Which future you are in?

Probably all of them at once. In practice we might be able to tell by asking a few questions.

  • Who pays when a national staff member is hurt, and was that decided before the incident rather than after it?

  • Is the response to a leaked archive notification and remedy for the people named, or silence and legal defence for the institution?

  • Is attestation authority concentrated in a few certifiers, held by governments, missing altogether or federated across communities?

  • Can a community set the trigger that releases money, or can it only receive funding once somebody else's trigger fires?

  • Is the number of reports filed climbing while the number of people reached stays flat?

  • Do women hold credentials in their own names that their households cannot read?

  • Are religious institutions treated as delivery partners, as security risks, as the last remaining provider or as trust anchors?

  • Can anyone other than a state or an insurer afford the instruments that detect nanoscale sensing?

  • Does a river, a herd or a migratory route have a guardian, and who selected that guardian?

 
13 September 2026
 

References

Bratton, Benjamin. 2026. Agentworld: A Preemptive Anthropology of Open-World Centaur Societies. Research brief. Antikythera, Berggruen Institute. https://agentworld.antikythera.org/.

Duettmann, Allison, Mark S. Miller, and Christine Peterson. 2022. Gaming the Future: Technologies for Intelligent Voluntary Cooperation. San Francisco: Foresight Institute.

Lampson, Butler W. 1971. "Protection." In Proceedings of the Fifth Princeton Conference on Information Sciences and Systems, 437–43. Princeton, NJ: Princeton University. Reprinted in ACM SIGOPS Operating Systems Review 8, no. 1 (1974): 18–24. https://bwlampson.site/08-Protection/Abstract.html.

Miller, Mark S. 1997. "Computer Security as the Future of Law." Lecture slides, August. http://www.caplet.com/security/futurelaw/.

Footnotes

1 On institutions as abstraction boundaries, meaning arrangements that let each side act without knowing the other's details, see Bill Tulloh and Mark S. Miller, "Institutions as Abstraction Boundaries," in Humane Economics, ed. Jack High (Cheltenham, UK: Edward Elgar, 2006), 89–118.

2 Of the 350 aid workers killed in 2025, 349 were national staff. Recorded incidents reached a record 710 that year, against 34 in 1997. Aid Worker Security Database, Humanitarian Outcomes, provisional figures as of July 2026, https://aidworkersecurity.org/.

3 On the asymmetry between physical and digital defence, see Duettmann, Miller, and Peterson, Gaming the Future, chapters 7 and 8, where defending against physical threats and defending against cyber threats are treated as separate problems requiring separate technologies.

4 See Stanley Kubrick’s film Dr. Strangelove, 1964.

5 A threshold can be agreed upon in advance to activate things, like releasing funds to a village before a drought indicator. The same logic can release a person's identity to an authority when an algorithm flags them. Humans can, but don’t always, refuse an illegitimate order, and since the Nuremberg trials our good world has treated that kind refusal as a personal duty. See my presentation titled Virtues, Virtualism, and Virtual Reality for more about this ethical dilemma. Who sets the threshold, who can inspect it and who is on the receiving end is a different conundrum.

6 Attestation is different than trust. Trust is an assumption that a system will behave properly. Attestation is the verifiable proof showing that a system is currently in a specific, untampered state. Simply put, trust is taking an entity's integrity for granted, while attestation demands the receipts before granting access. An important distinction.

7 A point about legal categories rather than about anything technical. The international control system for these kind of weapons involves two separate treaties based on what a substance is. The Chemical Weapons Convention covers things that harm through chemical action, and it comes with an inspectorate in The Hague, declaration requirements, schedules of listed substances and quantity thresholds that trigger reporting. The Biological Weapons Convention covers things that harm through living or replicating agents, and it has no inspectorate, because the effort to negotiate a verification protocol collapsed in 2001. Toxins are produced biologically but do not replicate and act chemically, so they fall under both conventions at once. Arms control specialists have a name for the awkward zone, which is mid-spectrum agents, and the debate over incapacitating agents that act on the central nervous system has been unresolved for 20 years.

Links

Agentworld
UN Safety Training
World Quantum Day

Image

Sarah Jackson, Mindscape 1, Smithsonian American Art Museum, Gift of Xerox of Canada Limited. 1978.

 

Computer Security as the Future of Law. Mark S. Miller. 1997

 

More Reading

Next
Next

Future Shock in Place