Skip to main content
  1. Articles/

The law of authority under acceleration

·6 mins

Why Token Jail is a symptom of an unfinished operating model #

“Token Jail” is being described as vendor lock-in driven by model dependency and rising token costs.

It is not primarily a commercial problem. It is not an API abstraction problem. It is a structural operating model issue.

The core claim is simple:

Under accelerating execution, implicit authority converts directly into structural dependency.


The law #

As execution accelerates, any authority that is not explicitly bounded, contractually defined, and continuously evidenced will compound into systemic dependency.

Acceleration does not create fragility. It removes the buffers that previously masked it.

At human speed, organisations tolerated ambiguity. Authority could be inherited rather than granted. Contracts could be implied rather than enforced. Governance could be retrospective rather than embedded. Evidence could be reconstructed rather than produced.

Machine speed removes those tolerances.

What was survivable becomes binding.


Reframing the problem #

Token Jail is typically framed as model lock-in, API entanglement, escalating token spend, and limited portability. The proposed solutions follow the diagnosis: multi-model routing, gateway abstraction, cost optimisation, runtime guardrails.

These are necessary. They are insufficient.

Token Jail emerges when an organisation cannot safely substitute a model because it cannot isolate execution scope, reproduce behaviour deterministically, prove compliance independent of provider, or generate intrinsic evidence for its decisions.

In this condition, switching providers becomes an audit event. Cost optimisation increases risk. Governance becomes reactive. Dependency hardens.

This is governance captivity, not vendor captivity.

The dependency lives in the Code Value Stream.


Control planes and authority architecture #

A control plane can route between models, enforce runtime policy, monitor token consumption, and apply guardrails. It operates at the API boundary. It improves surface-level optionality.

Authority architecture determines where execution rights are granted, how work transitions between stages, how promotion is earned, how evidence is generated, and how substitution risk is evaluated. It operates at the value stream layer.

If authority remains ambient inside the value stream, model abstraction is cosmetic. Optionality is theoretical. Risk is displaced, not reduced.

True optionality requires authority abstraction, not just model abstraction.


The structural requirements #

To remain governable under acceleration, the Code Value Stream must exhibit three properties.

Bounded execution #

AI systems must operate within explicit scopes: defined inputs and outputs, single-purpose execution units, revocable authority, no inherited standing privilege.

Autonomy scales only when authority narrows.

Without bounded execution, an organisation cannot isolate what a model did from what the surrounding system allowed it to do. Substitution becomes unsafe because the execution surface is undefined.

Deterministic promotion #

Exploration and production must be deliberately separated. Promotion from one to the other requires enforceable contracts: schema-constrained outputs, policy-as-code validation, explicit acceptance criteria, machine-enforced gates.

If promotion depends on interpretive human review, acceleration will outpace governance.

Schema conformance and policy conformance are necessary for safe promotion. They are not sufficient. AI-generated outputs are inherently non-deterministic. The same model given the same inputs may produce structurally valid but semantically different outputs across runs. When the question shifts from “does this output conform?” to “is this output equivalent to what another model would produce?”, the promotion contract must handle output variance, not just output structure.

Substitution safety is ultimately a statistical property, not a deterministic one. The promotion contract needs to declare acceptable variance bounds, not merely structural pass/fail criteria.

How should promotion contracts specify and evaluate semantic equivalence under output variance? This is the hardest unsolved problem in making model substitution safe. No framework resolves it today, including the work behind this article. Naming that honestly matters more than pretending completeness.

Intrinsic evidence #

Defensibility must be generated as a property of execution. Each stage transition should emit context, identity, data classification, policy evaluation result, and validation outcome.

If evidence must be reconstructed, substitution is unsafe. If substitution is unsafe, economic leverage is constrained. If economic leverage is constrained, dependency hardens.

This chain is not hypothetical. It is the mechanism by which implicit authority becomes structural dependency.

These three properties are easier to name than to adopt. “Making authority explicit” reads as a single design move. It is not. It spans at least four distinct concerns that must be coordinated: execution scope, governance classification, promotion logic, and evidence generation. These are separate design problems with separate adoption curves. Organisations will adopt them unevenly. Any strategy that assumes all four are resolved simultaneously will stall on the first dependency it encounters.


The economic consequence #

Token cost is rarely the primary issue. The structural constraint is that optimisation becomes unsafe.

When behavioural equivalence cannot be demonstrated under policy, the cheapest model may be the riskiest. Migration increases audit burden. Governance overhead scales non-linearly. Commercial negotiation loses leverage.

Organisations remain with incumbent providers not by preference, but by structural necessity.

Dependency is the shadow of implicit authority.


Regulated environments #

In regulated enterprises, the threshold for safe substitution is higher. Actions must be traceable. Decisions must be explainable. Data access must be bounded. Policy enforcement must be demonstrable.

Where governance remains external to execution, reviews become bottlenecks, controls become manual, assurance becomes retrospective, and change absorption weakens.

AI does not introduce these weaknesses. It exposes them.

This is why regulated organisations often experience Token Jail earliest and most acutely. The structural gap between implicit authority and explicit governance is wider, and the consequences of that gap are more severe.


The diagnostic #

If the dependency is structural, the diagnostic has to be structural too.

Can a model be substituted without triggering a manual risk assessment? If not, the dependency is on the absence of explicit execution scope.

Can a promotion decision be replayed and arrive at the same outcome? If not, the gate is interpretive.

Does every stage transition emit its own evidence, or is compliance reconstructed after the fact?

Are cost and governance discussed in the same conversation?

These are starting points. Observable symptoms, useful for initial assessment but insufficient for continuous monitoring. A mature diagnostic requires machine-checkable tests: conditions that can be instrumented inside the value stream itself, not inferred from organisational conversation. That bridge from symptom-level indicators to instrumentable structural tests is not yet fully specified. It is an active area of work.


The inversion #

Token Jail is not a model problem. It is a maturity signal.

It signals that acceleration has exceeded the explicitness of the authority model. Under acceleration, implicit contracts become risk, ambient privilege becomes exposure, retrospective governance becomes delay, and human pacing ceases to stabilise the system.

Acceleration punishes implicit systems.


The leadership question #

The question is not: “How do we avoid vendor lock-in?”

It is: “Where does authority still live informally inside our value stream?”

CIO responsibility shifts from tool selection to system design. The priority becomes designing explicit value streams, separating exploration from industrialisation, embedding governance into flow, ensuring authority is bounded and revocable, and making evidence intrinsic to execution.

Under these conditions, models become components. Costs become variables. Optionality becomes real. Regulation becomes defensible.

Without them, acceleration amplifies dependency.

Agents execute. Value streams decide whether that execution compounds leverage or compounds dependency.

Acceleration is inevitable. Implicit authority is not.