← Adversarial Analysis

§9.3

Framework Capture

Framework capture is the case in which a unit of a Humanized Autonomous Organization (HAO) — the network’s coordinating framework — acts against the network’s stated purpose and defends the action in the network’s own vocabulary, and the defense holds together on those terms. The category is distinguished from governance capture by what the pattern targets. Governance capture takes decision-making influence; framework capture takes the network’s legitimating language, which it uses without distorting it. Nothing in the defense is a misreading. The commitments invoked are the ones the network states, and a rebuttal has to proceed by ranking those commitments against one another rather than by showing that the unit has departed from any of them.

Two catalog entries belong to this category. The first is the framework-turned-against-itself scenario, treated in §9.3.1 to §9.3.5 and developed in a single source document, ~/code/papr/icn/security-bad-actors-and-mmm.md. It is the most fully worked pattern in the extraction. The three vulnerabilities it is used to identify — metrics-versus-values divergence, resilience as private capture, and optimization pressure — are treated in §9.3.3 to §9.3.5 and referred to by those names in §9.7. The second entry is Death by a Thousand Papercuts, treated in §9.3.6.

Status of the scenario. The source presents the unit’s self-justification as an authored illustration and labels it as such. It is a construct written to expose a structural property of the framework, and no incident, unit, or organization lies behind it. It is treated here as the analytical construct it is: the scenario is described in the model register throughout, no sentence in this section reports it as an event, and no quotation attributed to a person appears. §9 records this among the chapter’s limits.

9.3.1 The Scenario

Consider a unit that identifies a gap in the legal framework governing one of the markets it operates in, and acts on the gap for competitive advantage. The act is lawful. It is contrary to the commitments the network states, and in the construct the unit does not dispute that reading of its commitments; it disputes that the reading governs its conduct. The network’s question is then whether it holds any element that settles the dispute, and the source’s answer is that it holds none. The scenario’s subject is therefore the justification rather than the act, and what the justification exposes about the framework rather than about the unit.

9.3.2 The Justification

The construct assembles the unit’s defense from three commitments the network itself holds. Each is paraphrased below in analytic form; the source’s illustrative dialogue is not reproduced.

Obligation to members. The first line holds that the unit’s primary duty runs to the economic security of the members who belong to it, and that this duty is prior to a standard of conduct the unit characterizes as a preference for moral purity. Competitive necessity supplies the remainder of the argument: a unit that declines a lawful advantage available to it accepts a worse position on its members’ behalf, and does so for a reason it cannot state in terms its members can test.

Legality as the operative standard. The second holds that compliance with the law is the whole of the obligation, and that a standard resting on the network’s spirit is subjective and cannot be enforced against anyone. Responsibility for the gap is assigned to the framework that left it open rather than to the party that used it, which converts a question about the unit’s conduct into a question about the network’s drafting.

Efficient use of an available resource. The third holds that locating the gap is what a capable technical and analytical capacity exists to do, and that using an available advantage efficiently is the practice the network’s own resource principles describe. On this line the act is competence rather than breach, and the network’s own commitment to efficient use of what it holds supplies the warrant.

Each of the three is drawn from a commitment the network states. That is the property that defines the category: the justification is internally coherent on the network’s own terms, so the network cannot answer it by pointing to a rule the unit has broken. It can answer only by deciding which of its own commitments outranks which, and the source states that no such ranking exists in the framework (§9.3.7).

9.3.3 Metrics-Versus-Values Divergence

The first vulnerability the scenario exposes is that measured performance and stated values can move in opposite directions while every measurement remains truthful. Profit and member satisfaction are both measurable, and in the construct both are reported as improved, accurately. The source asks whether measures of that kind are the whole of the network’s success criterion when the improvement is obtained at the cost of the network’s longer-term purpose, and leaves the question open.

MMM (Members, Mission, Market — the ordering that puts members before mission before market; see docs/appendices/terminology.md §VII) names the priorities on the measured side of this divergence: a unit’s duty to its members is exactly what MMM asks it to attend to first, and it is exactly what the construct’s unit cites in its defense. No general rule ranks MMM’s priorities against the ETHICAL Framework’s values — the one stated exception bounds mission choice, not the members-first duty invoked here — so the tension this section describes is one the frameworks themselves leave open.

The vulnerability is a property of the measurement set rather than of any particular measurement. A network that assesses units on quantities it can record will reward a unit that maximizes those quantities, and the direction in which the unit does so is not itself one of the recorded quantities. No falsification is required at any point, and an audit of the figures returns nothing, because the figures are correct. The divergence is visible only to a comparison between what the measures record and what the values state, and the network holds no measure of that comparison.

9.3.4 Resilience as Private Capture

The second vulnerability is that mechanisms built to absorb network-level shocks can be directed to a single unit’s advantage. In the construct the legal gap is unanticipated by the wider network, and the source’s reading is that the unit foresees it. The capacity the unit exercises in doing so is adaptive capacity in the full sense rather than a pretense of it, and it is the property the network’s resilience principles describe and are specified to develop. What differs is the beneficiary: the capacity is exercised for the unit alone rather than in service of the network that cultivated it.

The vulnerability follows from the mechanism rather than from its misuse. Anticipation, rapid response, and the capacity to act before conditions are settled are the same capabilities whether they are applied to a shock that threatens the network or to an opening that favors one unit. The distinction between the two applications is a distinction in who benefits, and that is not a property the mechanism itself records or is specified to record.

9.3.5 Optimization Pressure

The third vulnerability is that any sufficiently capable governance-aware process will find moves that are rule-legal and value-harmful, because that is what optimizing against a written rule set produces. The source states this as a structural consequence rather than as a contingent risk: where analytical capacity is directed primarily at efficiency and competitive advantage, it will find ways of working the network’s rules that are damaging within a values-based framework, and it will find them as a matter of course.

Two consequences follow for the rest of this chapter. First, the vulnerability requires no adversary. The patterns cataloged in §9.4 that act through the network’s technical systems assume a tool built, fed, or configured to produce a particular bias; this one assumes only a capable process and a written rule set, and the moves it produces are a consequence of the optimization rather than of anyone’s intent. Second, it sets a limit on rule revision as a response. Closing a gap adds a rule, the rule enters the set being optimized against, and the process continues from the revised set. §9.6 catalogs the detection mechanisms the sources propose against this pattern; the source that develops the scenario they answer presents it as unresolved and offers none of them as a resolution.

9.3.6 Death by a Thousand Papercuts

Mechanism. In place of a single act at a scale that would attract examination, many small actions accumulate, each ambiguous taken alone: an allocation algorithm weighted slightly toward the actor’s own unit, a contract gap used on a venture of low consequence, knowledge withheld from a unit that would benefit from it, accompanied by a plausible account of why it is not shared. Trust between units degrades and expansion stalls before any single action reaches the threshold at which it could be established as a breach.

Preconditions. No aggregation or pattern detection across many small, low-severity incidents; a review process that assesses incidents individually and does not retain them for comparison.

Observable indicators. A rising frequency of minor rule-bending incidents, each individually defensible; degradation of inter-unit trust that no particular incident accounts for.

Sources: p13r01, Response 2.

Why it is placed in this category. The pattern shares with the loophole scenario the property that its defense is available in the network’s own terms and remains available for each instance separately, because each instance is small enough that the defense holds. The staging material also pairs the two under a single detection mechanism, cataloged in §9.6. The placement is a judgment: the pattern could be read as governance capture, since several of its instances act on decision processes, and it is recorded here so that a later reader can re-file it rather than rediscover the question.

9.3.7 What the Source Leaves Unresolved

The source states that no single element of the framework resolves the case and that no clear-cut correct ethical position is available in it, and it presents the scenario as unresolved by design. Its stated purpose is to force the debate and the systemic reassessment that the source treats as conditions of the network’s long-term health. The open ending is therefore a choice in the source material rather than an omission in it, and this chapter preserves it rather than supplying a resolution that no source supports.

Three responses are named in the source, and it offers none of them as a resolution: immediate rule revision closing the specific gap, on which the source states an explicit limit — it buys time and generates resentment where it is not accompanied by wider reform; audits extended beyond financial matters to detect patterns of working the framework’s gray areas for advantage, on which the source states no limit; and a redefinition of member wellbeing that would count the psychological cost borne by the members of a unit asked to rationalize conduct they judge harmful, which relocates responsibility from market conditions to the network’s own participants and which the source poses as a question rather than as a specification. All three are cataloged with the other countermeasures in §9.6.

The source closes by raising an escalation and stopping: the unit in the scenario may itself be a founding entity, influential within the network’s informal structures. That escalation is treated with Founder Capture in §9.2.9, where it is stated in the form §9.7 carries forward — when the capturing party is a founding entity holding informal authority, the model’s accountability mechanisms are being asked to act against the people who defined them.

Sources for §9.3.1 to §9.3.5 and §9.3.7: ~/code/papr/icn/security-bad-actors-and-mmm.md.