Skip to main content
  1. Articles/

Learned, then ratified

·7 mins

A learned system can tell you, in precise detail, what your software did.

It cannot tell you who is answerable for what that behaviour now obliges you to do.

Both sentences are true at the same time. The distance between them is where the current argument about AI-native platforms actually lives, and most of that argument is being had on the wrong side of the gap.


The substrate is right #

The case for building on decisions rather than rows is correct. Reasoning runs better over named entities, explicit relationships, and recorded decisions than over flat tables and late-bound joins. A graph of what was decided beats a warehouse of what was stored. Capture the decision at the moment it is made, with the constraints that bound it and the action that followed, and you get something a machine can reason over instead of a log it has to reconstruct.

None of that is in dispute here. It is close to settled, and it is worth conceding without hedging, because the concession is what makes the rest legible.

It is so nearly settled that it will be built whether or not anyone governs it. That is the part worth pausing on. Inevitability is not vindication. The more capable the substrate, the more consequential the thing it quietly accumulates.


What a record cannot do #

From a passive decision-trace on the left, where undeclared reliance and silent dependency let unsigned obligations accumulate into a learned ontology, to a governed decision on the right, which is signed, weighs its rejected alternatives, can be reversed and retired, and escalates downstream review as loud incompleteness.

A decision-trace is a record. A record replays. It does not reverse.

A governed decision is a different object. It carries the choices that were rejected, not only the one that was taken, because a choice with no rejected alternatives is an implication, not a decision. It carries the obligations it created and the obligations that bound it. Retire it, and the obligations it spawned retire with it, and the downstream decisions that leaned on those obligations reopen for review. The record lets you see what happened. The governed decision lets you undo it and know what else has to move.

There is a limit, and it should be stated rather than hidden. Reliance forms without being declared. With enough consumers, every observable behaviour becomes something someone depends on, and that dependency hardens into an obligation the producer is held to but never authored. A revert can retire what was written down. It cannot retire what was quietly relied upon and never recorded. So the honest posture is not a clean reversal. It is a loud one: retire what is declared, and flag the region where undeclared reliance may live as a blocking state, until a person looks. Silent incompleteness is the failure. Loud incompleteness is a control.


An obligation no one signed #

This is the mechanism the learned-ontology story treats as a feature and should treat as a hazard.

“Let the structure be learned from behaviour” means: let obligations accumulate from what the system is observed to do. Run it long enough and the graph fills with rules no one wrote. Each one binds. None of them was authored. The system has manufactured a backlog of obligations that no human ever signed, and it presents that backlog as an ontology.

The danger is not that the record is wrong. The danger is that it is high-fidelity. A precise, queryable, authoritative-looking account of obligations that no one owns manufactures false consent. Downstream teams, and increasingly downstream agents, read the graph as if it had been ratified, because it looks exactly like a graph that was. Informal contracts everyone distrusts are safer than this, because distrust is itself a working control. False trust removes it.

This is also how the learned substrate will actually be adopted. Capture ships in a sprint. Ratification is organisational work that no one budgets. So the common case is not the governed system. It is capture without ratification: a system that fails authoritative rather than safe.


The one act that is not learned #

Everything that touches behaviour is inductive. The classifier that decides what a behaviour resembles is inductive. The precedent that says two cases are the same is inductive. There is no point pretending the machine can be argued out of induction.

There is exactly one act that is not inductive. A named person signing that they own an obligation, against the evidence in front of them, and will answer for it being wrong. No amount of learning produces that, because induction has no name to put on the line.

This is not a new control to be invented. It is already required. A regulated institution cannot let a decision resolve to “the system decided.” Individual accountability that maps to a natural person is the foundation of the senior-manager regimes. Non-delegable management responsibility for the operational systems is written into the resilience rules. Human oversight that can intervene, override, and stop is written into the high-risk provisions of the AI Act. The obligation to have a signature already exists. The only design freedom left is when it attaches.

Attach it at promotion, and the learned structure becomes a proposal awaiting a decision. Never attach it, and the graph is a source of authority no one granted. The learning is the cheap part, and the industry has found it. The signature is the part that is already the law.


Where the signature has to reach #

There is a harder version of this, and it is the one that separates a slogan from a design.

Signing that an obligation exists is a wholesale act. It happens once. But the traffic does not run at the wholesale layer. Every event that flows afterward asks a retail question: is this a case the signed obligation already covers, or is it new? That question is answered by a classifier, at volume, and no one signs each answer. A classifier that wrongly says “already covered” admits a novel case in silence, under a signature that was never given for it.

Moving the signature to promotion and stopping there leaves the busiest boundary in the system still learned and still unsigned.

The answer is not to sign every event. That would refund the scale the graph was built to buy. The answer is to sign the boundary itself: to make the classifier’s decision threshold an owned, dated, expiring artefact, whose rate of silent error is a number a named person accepted as their risk. Sign the standard by which a million events are judged, not each of the million. Where that lease is live, admission may proceed. Where it has lapsed or was never granted, the boundary cannot admit. It can only escalate.

And it must be said plainly what this buys. A signature over an inductive boundary does not make it safe. It makes its failures owned. The silent error does not disappear. It becomes a bounded, dated, measured liability with a name against it, watched against the envelope that name accepted, tripping a review when it drifts. That is the most any signature can do to an inductive process, and for a regime that asks who is accountable rather than for a proof of zero risk, it is exactly the right amount.


The trade that does not vanish #

None of this is free, and a piece that pretended otherwise would be the same false-consent move it is warning against.

Ownership at real volume is real work. The signed boundary turns a hidden trade into an explicit one: a tighter error rate escalates more and admits less, a looser one admits more and owns a larger risk. That dial does not disappear. It becomes a human decision recorded in a signature, rather than a property of the substrate that no one chose. At sufficient scale the unratified backlog keeps growing, and the governed surface stays smaller than the captured one. The honest instrument is not a promise that this ends. It is a gauge that keeps it visible.

There is a failure mode here worth naming. Govern hard enough and the useful graph and the governed graph drift apart, and people quietly work from the ungoverned one. The defence is not more governance. It is measuring the served fraction and watching it, so the drift is seen before it hardens.


The competition was never about who scans tables faster, and it is not about whose ontology is more learned. Both of those are conceded. A learned graph is a good account of what a system did.

The question underneath it is older and smaller and harder. When observed behaviour becomes a binding obligation, who signed for the moment it began to bind. A system that cannot answer has not built a reasoning substrate. It has built a faster way to accumulate obligations no one owns.

Learned is the easy half. Ratified is the half that was always going to be the work.