Constraint-first AI governance
A working method for putting high-stakes AI decisions through plural human-modelled review — and proving, to an auditor who trusts no one, that the review was real and not theatre.
Each council seat is distilled from a real expert's complete body of work into deterministic decision rules. The deeper the source, the deeper the seat.
built by the practitioner
Before any seat can vote, an independent protocol pushes it onto cases it was never trained on — to see if it reasons like the expert, or merely repeats them.
tested by an external instrument
Most "AI governance" fails because the same hand that builds the reviewer also grades it. This method keeps building and certifying on opposite sides of a hard line — and that single separation is what an auditor can actually verify.
Eight stages. Tap any stage to open it. The two red stages are the certification gate — the part that makes the rest trustworthy.
Each domain of statecraft is a cabinet of experts, modelled from real careers and certified before it can vote. The council can field thirty or more lanes. It almost never does. Like an attention layer in a language model, only the seats a case actually touches are activated — the rest stay dark, costing nothing.
A routine procurement note lights up four cabinets. A cross-border data ruling lights up nine. A sovereign-scale AI decision convenes the full chamber. The method scales its cost to the consequence of the question, not the size of the roster — so plurality is always available but never wasteful.
Triage sets the depth. Tap a case to see which cabinets convene, which stay dark, and where the certification gate sits. Watch the chamber fill as the consequence grows.
A real-world governance product was reviewed against this method. It had built the reviewers. It had never built the part that proves the reviewers are real.
Determinism makes different AI models converge on similar answers, so swapping models proves nothing. Only pushing a seat off its source material reveals whether it has real judgement underneath.
The seat carries the right knowledge but voices it through the wrong cultural lens — an Eastern or European perspective rendered with a Silicon Valley accent. The fix is matching the model's own grounding to the seat's domain, not chasing the "best" model.
The seat recites the expert's known positions but cannot reason as they would on a case the source material never covered. It cites continuity instead of perceiving it. This is the failure that looks fine until the decision actually matters.
The seat that fights groupthink is not a single sceptic. It is three bounded tools, and each one is forbidden from inventing a cleverer story than the record supports. The discipline is the point — an unbounded contrarian is just another way to lose the argument.
Asks whether the decision is solving the right problem at all. Catches false binaries, stated-preference worship, and willpower-heavy fixes where a change to the system would work better. It reframes; it never persuades.
the behavioural-reframing instinct, made operational
Runs only as a controlled pair — one lane models the most hostile reading a decision will face, the other hardens the wording without hiding any tradeoff. The hostile lane is never allowed to ship alone.
simulate the attack, then defend honestly
Pressures the story a decision tells about itself, then abstains. It holds no weight in the tally by design — its licence to say the unsellable thing comes precisely from its inability to change the outcome.
the court fool, given a seat but not a vote
Each instrument carries a hard stop. If the reframe depends on invented evidence, if the rewrite hides a real blocker, or if the critique collapses into hostile theatre, the tool halts and keeps the original framing visible rather than pretending a cleaner one exists.
Every review returns one of six honest verdicts. The rules forbid the most common dodge: calling something "no finding" when the truth is the evidence was too weak to judge.
Before a high-stakes decision goes public, its wording faces a controlled pair: one voice attacks, one defends. They are never allowed to run apart. The attack alone would be a weapon; the defense alone would be blind to what it is defending against.
Takes the frozen text and builds the strongest distortion a real adversary would apply — what gets clipped, what gets read out of context, where urgency is inflated, where a quote can be turned.
it may
it may not
Answers the strongest hostile frame and rewrites the wording to reduce the attack surface — while refusing to bury any real tradeoff to do it. Truth-preserving is the binding constraint.
it must
The attack lane may never ship alone. A packet that carries pro-spin without its anti-spin companion is, by rule, blocked from publication.
Run as a pair, the spin doctors give an attack and a defense. Fused into one document, they produce something neither writes alone: a line-by-line wording-risk register. For every vulnerable passage, three columns — the attack it invites, the hardening that answers it, and the residual risk that honesty would not let us defend away.
Illustrative — how the register reads in practice.
The residual column is the deliverable a minister actually needs: the honest list of what will still be used against the text after every safe fix is made. The pair finds the attacks. The overlay tells you which ones you cannot wording your way out of — so you decide them in the open, before they decide themselves in public.
Every decision ships with its triage tier, its votes, its recorded dissent, and its certification results — not a vendor's word that review happened.
Seats are modelled on genuinely different experts across economics, law, ethics, philosophy, and international politics — and certified to stay distinct under pressure.
Low-stakes decisions move fast on a small panel. Only high-stakes cases convene the full thirty-plus-lane council. Governance scales with consequence.
The line between building and certifying is the one claim a regulator can check directly. The method is designed so that line is always visible.