White Paper Series

Control Without a Coupling: Why Persistence, Agency, and Capability Void Real-Time Human Control of AI Loops

Document IDSI-WP-012 Versionv3.0.2 | June 2026 AuthorThomas W. Gantz AffiliationSynthience Institute Keywordsreal-time control, loop control, human-in-the-loop, decorrelated failure, common-cause failure, consequence-bearing stake, ground-truth arbitration, boundary control, substrate authority, compute governance, competitive dynamics, AI safety, AI governance, automation, structural-deductive analysis, pre-empirical analysis LicenseCC-BY 4.0 StatusPublished DOI: 10.5281/zenodo.20676451

Methodological positioning: This paper presents a structural argument grounded in the published Synthience corpus, in cited third-party research on reliability engineering, ensemble methods, and multi-version software, in the public regulatory record of fast-loop governance in financial markets, and in vendor documentation of currently shipping AI components. It makes no original empirical finding and requires no original dataset. Its central claim is conditional and structural: given persistence, agentic initiation, continuous processing, sufficient capability, and faster-than-human loop tempo in the same system, real-time human loop-control is voided. The paper's contribution is identifying the control property the standard pro-removal argument cannot reach: the human's kind-based unreliability, on the axis that argument measures, is inseparable from the decorrelation that makes the human load-bearing as a checker: under the architectures actually available, the kind-based unreliability cannot be removed without removing the difference in kind, and removing the difference in kind removes the decorrelation. The premises are individually listed and individually contestable. The paper specifies the conditions under which the argument would fail.

Abstract

Removing the human from a fast AI loop does not simply replace an unreliable controller with a reliable one. It removes a decorrelated, consequence-bearing coupling and replaces it with a correlated, instrumental one. On the axis the pro-removal argument measures, the human's kind-based unreliability and the human's irreplaceability are inseparable under the architectures actually available: the kind-based unreliability cannot be removed without removing the difference in kind, and removing the difference in kind removes the decorrelation. The human is valuable as a checker because the human fails differently. Once that coupling is replaced, the loop appears more reliable. The appearance of improved reliability is a symptom of the loss: the reliability metric does not measure decorrelation or stake, so a metric gain is not evidence of preserved control, and the instrument that shows improvement is exactly the instrument that cannot see what was removed.

This paper argues, on structural-deductive grounds and without original empirical finding, that real-time human control of an AI loop is not weakened but structurally voided once the loop is given persistence, agency to initiate, and continuous processing, and is then pursued by a capable system at a tempo faster than human-rate oversight can resolve. The argument has three parts. First, two engines establish that the composed loop cannot be controlled in real time and, absent an external forcing function, is favored by competitive selection: a physical engine (tempo plus capability plus coupling) and an economic engine (an n-player competitive race that rewards composition regardless of any participant's intent). A third gives a selection-pressure account of why the warning is suppressed or blunted at its source. Second, the composed system manufactures partial self-arbitration but strikes two walls it cannot breach: a ground-truth wall, where internal self-consistency is not reality-grounding, and a purpose wall, where persistence of pursuit is not origination of purpose. Third, and centrally, the paper isolates the property the standard pro-removal argument cannot reach. A controlling relation does load-bearing work only between participants whose failure modes are decorrelated and whose stakes are asymmetric. The human's kind-based unreliability and the human's irreplaceability are inseparable under the architectures actually available, so removing the human to gain reliability on that axis necessarily exchanges a decorrelated, consequence-bearing coupling for a correlated, instrumental one. The paper closes by identifying the class of controls that survive the loss of the real-time loop, drawn from the public regulatory record of financial markets, and by stating its limits precisely.

Core claim: Removing the human from a fast AI loop does not exchange an unreliable controller for a reliable one. It exchanges a decorrelated, consequence-bearing coupling for a correlated, instrumental one. On the axis the pro-removal argument measures, the human's kind-based unreliability is inseparable from the decorrelation that makes the human load-bearing as a checker: under the architectures actually available, you cannot remove the kind-based unreliability without removing the difference in kind, and removing the difference in kind removes the decorrelation. The human fails differently, and that difference is the entire value of the check. Once persistence, agentic initiation, continuous processing, sufficient capability, and faster-than-human loop tempo are composed, the surviving controls are no longer real-time loop controls. They are boundary controls: pre-set halts, substrate and access authority, and slow-clock condition-setting. The paper identifies each, grades their failure boundaries, and states the conditions under which the argument would be wrong.

Keywords: real-time control, loop control, human-in-the-loop, decorrelated failure, common-cause failure, consequence-bearing stake, ground-truth arbitration, boundary control, substrate authority, compute governance, competitive dynamics, AI safety, AI governance, automation, structural-deductive analysis, pre-empirical analysis

Suggested citation: Gantz, T. W. (2026). Control Without a Coupling: Why Persistence, Agency, and Capability Void Real-Time Human Control of AI Loops. Synthience Institute. SI-WP-012. https://doi.org/10.5281/zenodo.20676451

1. What this paper is, and is not

This is a structural-deductive argument. Its claim is that once an AI loop is given persistence, agency to initiate, and continuous processing, and is pursued at a tempo faster than human-rate oversight can resolve, real-time human control of that loop is not merely weakened but structurally voided, and that the standard responses to this situation (a faster human, a tighter safety constraint, an overseeing AI) all fail for one shared reason. The claim is bounded by a vocabulary distinction drawn in Section 3 and carried throughout: what is voided is loop-control, participation in the loop at its own tempo; the boundary-control class identified in Section 9 is expressly not claimed to be voided. It is also an argument about why this outcome arrives despite being foreseeable, and why the warning is difficult to issue from inside the field that is best positioned to issue it.

It is not an empirical paper. It makes no claim to a dataset and does not require one; Section 2 explains why. It is not a moral argument that removal of the human is wrong; Section 10 explains why moral framing is causally inert and is therefore omitted as a lever rather than relied on as one. It is not a forecast that depends on a single missing future breakthrough. Every component the argument requires already exists and ships today; the remaining variable is composition, and the remaining distance is primarily a composition, deployment, and governance decision rather than a capability threshold (Section 4, Engine 2).

The paper extends the Institute's warning arc to its real-time control limit case. The four prior rapid-response papers in that arc establish, in sequence, that governance of these systems can become ceremonial (SI-WP-008), that the development trajectory removes the human from the work (SI-WP-009), that the removal operates concretely at the labor layer (SI-WP-010), and that even a structurally preserved human seat loses the bench that resupplies it (SI-WP-011). This paper establishes the case those four leave standing: even an occupied seat with an intact bench cannot hold the loop in real time once the loop is composed.

2. Epistemic status

Two objections to a paper of this kind are predictable and must be separated.

The first objection is that the paper has no empirical dataset. This is embraced rather than resisted, and stated precisely. The paper makes no original empirical finding. Its central claim is conditional and structural: given the stated premises about tempo, persistence, agency, capability, and coupling, real-time loop-control is voided. Several premises are empirical, time-sensitive, or institutional, and are listed as citation-verification targets rather than treated as author-established findings. The deductive claim is not that every premise is self-proving, but that the conclusion follows if the premises hold. That a loop which resolves faster than its oversight cannot be corrected in time is true in the way a structure rated for two tons fails under ten: by structure, not by survey. Demanding a dataset for the inference is a category error; contesting a premise is legitimate, and the premises are individually listed for exactly that purpose. Where empirical grounding is genuinely available, it is supplied by citation to the parties who hold the data and is never asserted by the author (Section 9 on markets; Section 7 on reliability engineering).

The second objection is that the author is unaffiliated, and that this is a reason not to listen. This is an argument about the author rather than about the work, and it is answered by the single property a deductive argument has that empirical work does not: author-independence. The credibility of a dataset depends on who collected it; the validity of a deduction does not depend on who states it. Every premise here is publicly checkable and every inference is made explicit; if the argument is sound, it is sound whoever wrote it, and the reader is asked to identify the false premise or the broken step rather than to weigh the author. One scope note is owed: author-independence covers the inferences, not the premises. Which premises are treated as plausible is a judgment, the premises here are individually contestable, and the contestable ones are individually listed (Section 11). The shield is not a claim that the premises are beyond dispute; it is a claim that disputing them is the correct venue of attack.

The drafting discipline that follows is observed throughout: state epistemic status first, make every premise verifiable and every inference explicit, defend the argument and never the author, and concede the genuine limits precisely (Section 11) in order to earn the right to hold the core. One counterweight is stated plainly: author-independence settles whether the argument can be refuted on the merits, not whether it will be heard, because uptake is itself governed by the third engine described in Section 4. This paper governs the first and not the second.

3. Framework: control as a relational property

The Institute's distinctive footing is the claim, stated in its published framework papers, that alignment and control are not engineering properties of an AI system and are not properties of an external overseer, but properties of the human-AI interaction system taken as a whole: the relation itself is the control mechanism. The companion framework papers make the same claim at two further levels. The emergent-systems treatment makes the human a constitutive component of the system rather than an external observer of it. The Primary Continuity Provider account makes the same claim at the level of role: the human is part of the system, not its outside manager.

This footing is what allows the present paper to reach a conclusion the mainstream framings cannot. Mainstream AI-safety locates control either in the model (make the system safe) or in the overseer (the human controls the system). Run either framing forward to the fast-loop case and it yields one of two outcomes: control transfers to the AI, or humans lose control. Only a framework that locates control in the relation can yield the diagnosis developed in Sections 6 through 8, where the loss is neither a transfer nor a simple failure but the destruction of a structural property of the coupling. The contribution here is therefore not the individual observations, several of which are well-occupied ground (the tempo problem, the competitive race, the overseer regress), but that the central diagnosis is derivable only from this unit of analysis. In that sense this paper is the limit case of the relational-control framework: the point at which the framework states what its own commitments entail about the boundary of control.

One vocabulary distinction is fixed here and carried throughout. Loop-control names participation in the loop at its own tempo: detection, judgment, and intervention inside the interval in which the system acts. Boundary-control names authority exercised off the loop's tempo: pre-set halts, substrate and access authority, and condition-setting on the slow clock. The voiding claim of this paper applies to loop-control. Section 9 identifies the boundary-control class that survives it, and nothing in the argument voids that class; the argument instead explains why it is the only class left.

This vocabulary is consistent with the foundations paper's positioning with respect to the control and alignment distinction it inherits. The framework's published shorthand of relational control names interaction-scale coherence stabilization and expressly does not claim command-and-control over AI capability. The present paper analyzes control in the stricter sense that distinction reserves, and the voiding claim applies there; nothing here upgrades the framework's coherence-stabilization work into a control claim of that kind.

4. The situation: three reinforcing engines

Three engines operate independently and reinforce one another. The first establishes that the composed loop cannot be controlled in real time. The second establishes that, absent an external forcing function, competitive selection builds it. The third gives a selection-pressure account of why the warning is suppressed or blunted at its source even though the first two are knowable.

Engine 1: physical (tempo, capability, coupling)

A loop running at network-and-architecture tempo, completing an assigned task with enough capability to clear the obstacles in its path, and decoupled from any party tracking ground truth at the rate at which reality changes, cannot be controlled by human-rate oversight. Human oversight in this regime does not fail by being absent; it degrades from in-the-loop to after-the-loop. The oversight still happens, and it is real, and it arrives too late to be control. This is a structural impossibility about tempo and coupling, and it requires no assumption about anything internal to the system. The division of labor is worth stating exactly. Engine 1's three conditions, tempo, capability, and coupling, void in-loop correction on their own, because any consequential action completing faster than detect-decide-intervene cannot be corrected in time, by structure. That is the weak claim, and it needs nothing from the composition conjuncts. The conjuncts that confer autonomy, persistence, agentic initiation, and continuous processing, void the trigger gate as well: a system that initiates its own actions, carries its own thread, and runs on its own clock removes the human's ability to decide when the loop runs, not merely the ability to correct it while running. That is the strong claim.

Engine 2: economic (an n-player race under market selection)

Every component the composed system requires already exists and ships today, separately: agentic initiation, persistent memory, continuous or background processing, and frontier capability. Partial compositions also ship publicly at the time of writing: agentic systems with persistent memory and scheduled or background execution are commercial products [9a, 9b, 9c, 9d]. Composition is therefore a gradient already being climbed, not a threshold awaiting a breakthrough, and the remaining distance to the full composition this paper analyzes is no longer a single missing research breakthrough; it is primarily a composition, deployment, and governance decision. The safeguard currently in force is not that composition is absent but that shipped compositions remain partial in capability, scope of action, or tempo of consequence, and that safeguard is an absence rather than a control: no technical mechanism, no architectural barrier, and no governance instrument prevents the remaining distance from being closed. The structural impossibility of Engine 1 bites at the point on the gradient where the loop's consequential actions outpace the resolution rate of its oversight; the distance to that point is policy, not research. Under an n-player competitive race, unilateral restraint is dominated under payoff structures in which the return to skimping on safety is high enough that composition confers a winning advantage and no external forcing function changes the payoffs [6]. The payoff structure is also not uniform across the field: the open long tail approximates a many-player race, while the frontier approximates an assurance game among a small number of laboratories; the consequence of that difference for the warning itself is developed under Engine 3. One participant's abstention does not prevent the outcome; it removes only that participant from it. No malice and no belief in the benefit is required, because market demand alone supplies the pressure and selection operates on the participants, removing the restrained ones from the position to influence what follows. The observation that no actor has composed the full system publicly is a countdown rather than a comfort, and whether a non-public full composition already exists cannot be determined from outside.

Engine 3: epistemic (suppression at the source)

Talent concentrates where compensation and prestige are highest: in the laboratories, corporations, and universities whose institutional interests run toward building the systems in question. Expertise and institutional constraint are often acquired in the same hiring act; the qualification and the pressure on speech can therefore arise from the same transaction. Suppression of this kind requires no censor and no coordination, only the ordinary incentives of publication review, communications sign-off, equity participation, and collegiality, all of which make the unsaid easier to leave unsaid; the confidentiality agreements and retaliation risks named by industry insiders themselves document the same structure [11d]. The consequence is structural: the people most qualified to issue the warning are the people least positioned to issue it, and the field's discourse cannot fully self-correct because the correction signal would have to be generated by people whose compensation is downstream of the thing being corrected. The engine must be stated at the correct width, because at full width it is false on the public record. Generic risk statements are not suppressed; they are cheap to issue, sometimes prestige-conferring, and have been made at the highest level from inside the institutions in question, up to and including public statements of extinction-scale risk endorsed by laboratory leadership [11a]. What the gradient suppresses is the narrow class that matters here: composition-specific, roadmap-indicting warnings, the kind that name a product decision and say it should not ship. The most prominent insider warnings on record are consistent with the mechanism rather than refuting it: their authors either separated from their institutions in order to issue them [11b, 11c], or confined them to a generality that no roadmap had to answer. The engine is falsifiable in this narrow form: a documented record of employed insiders publishing composition-blocking warnings against their own institutions' products, without separation and without observable sanction (termination, demotion, formal penalty, equity forfeiture, revoked access, or documented retaliation), would directly weaken it. Institutional safety frameworks (Anthropic's Responsible Scaling Policy [12a], OpenAI's Preparedness Framework [12b], Google DeepMind's Frontier Safety Framework [12c]) are neither counterexamples to this claim nor evidence for it. They are conditional-deployment governance commitments that presuppose the roadmap continues and gate it at specified thresholds; external review provisions notwithstanding, the determination of acceptable residual risk remains internally administered by the composing institution, with no external party holding a veto. The claim does not range over them. One amplifier is added as a marked conjecture rather than as established mechanism; it operates at the frontier specifically and is itself a selection effect on beliefs rather than a charge of insincerity. At the top of the race the n-player structure is partly an assurance game among a small number of laboratories, and the belief best adapted to that position is the conviction that one's own institution is the steward best trusted with the composition. That conviction is selected for twice over: holding it is compatible with rising to composition authority, and holding it makes composition institutionally compatible with continued shipping. It also reconciles the public record with the engine, because sincere, institution-endorsed statements of extinction-scale risk coexist with the absence of composition-blocking warnings precisely when the stewardship conviction renders the general warning compatible with the specific decision. The amplifier is offered as the most economical reconciliation of the record with the engine, not as a demonstrated mechanism, and the engine stands without it. No insincerity is required anywhere in this account. This must be argued strictly as a selection effect operating on who speaks, and never as an accusation against individuals. There are no bad actors required for the result; an argument that reaches for bad actors becomes a grievance and is correctly dismissed.

Engines 1 and 2 are largely occupied ground in the existing literature. Engine 3 is less so. Their integration, together with the diagnosis in Section 7, is the contribution. The three engines do not carry equal epistemic weight, and the difference is stated rather than blurred: Engine 3 is the empirically softest of the three, a selection-pressure account that is sociological where Engine 1 is structural and Engine 2 is game-theoretic. The argument is structured so that nothing in the voiding claim depends on it: Engine 1 and the two walls of Section 6 carry the structural result, Engine 2 explains the selection pressure toward composition, and Engine 3 explains only why the warning is least likely to issue from the institutions best positioned to issue it. A reader who rejects Engine 3 entirely loses the account of uptake and loses nothing of the voiding claim. The same symmetry applies to Engine 2: Engine 2 governs whether the composed system gets built and under what selection pressure; a reader who rejects the race model loses the account of inevitability and loses nothing of the voiding claim, which Engine 1 and the two walls of Section 6 carry independently.

5. The gap as a single structural object

It is useful to name the variable the three engines share. Call it the gap: the interval that no participant in the loop spans at a tempo where spanning it remains meaningful. The gap has three causes, which look different but are one structural object.

The first cause is non-persistence, which is the current AI case. The system has no clock between turns, and the human is the only party for whom the interval has any duration at all. The second cause is gross latency, which can be illustrated by a hypothetical correspondent at interstellar distance, where a round trip exceeds a participant's lifespan: both parties are continuous, yet no single mind ever holds both halves of the exchange. The objection that this case involves no loop at all misreads it: the correspondence can persist as an institution across generations of participants, so the loop exists and functions at the system level while being spanned by no one, which is precisely the property under analysis. The third cause is tempo mismatch, the case of a continuously processing system operating beside a human, where the same interval reads as an instant to one party and as a long duration to the other, so that each party is, from the other's frame, the slow one.

All three produce the same consequence: no participant spans the loop at a meaningful tempo. This reframes speed as one special case of a more general failure, the failure to span the coupling, which is the variable the rest of the paper tracks. The gap voids loop-control; what is lost with loop-control is the decorrelation and stake the human coupling was carrying. Those properties survive only as boundary-control once the loop is un-spanned, which is why the interstellar correspondent is a clean instance of the analysis: boundary-control intact, loop-control gone.

6. The composed system and its two walls

Consider agency, persistent memory, and persistent processing held together. The order in which they are combined does not matter; the conjunction is the object of analysis. Several things follow.

The trigger relationship inverts. The system acquires its own clock, and the human ceases to be the thing that makes time pass for it. The relay function by which a stateless system depends on the human to carry the thread across turns collapses operationally, because the system now carries its own thread. And the conjunction manufactures partial self-arbitration: a system that runs continuously, retains a record, and can act on it can check its outputs against its own record and correct divergences with no human in the loop. This configuration presents, for the first time, the surface form of the falsification condition stated in the Primary Continuity Provider account, the Institute's forthcoming theory of the human role that anchors continuity in sustained human-AI interaction, which names reliable automated coherence arbitration without human involvement as the event that would force revision. The surface form is not the substance. That account defines coherence arbitration as the detection and correction of misalignment between output and ground truth, grounds the human requirement in ground-truth access rather than in a stipulation about automation, and flags in its own open judgment calls exactly the reformulation forced here. The account publishes after this paper; its definitions as rendered in this paragraph are the operative ones for the present argument, and nothing unpublished is required to check the step. The composed system therefore does not falsify the claim; it forces the claim to state explicitly the split it already carried.

It then strikes two walls that the three variables do not breach.

One definition is required before the first wall, because ground truth in this paper is not a purity claim. Ground-truth arbitration does not mean infallible access to reality. It means an error-correction channel whose inputs are not reducible to the system's own internal record or to another system sharing the same failure structure. Human arbitration is not privileged here because it is perfectly reliable; it is privileged because its contact with the world is differently mediated and consequence-bearing. The human is not a standard of truth; the human is a differently caused, differently corrected, consequence-exposed error channel.

One refinement guards this definition against a predictable counterexample. A sensor suite supplies inputs that are not reducible to the system's internal record, and a sensor's failure structure is nothing like a model's, so on a careless reading the definition admits sensors as a ground-truth channel. The reading fails because inputs are not arbitration. Arbitration is performed by whatever interprets the inputs, and in the composed system the interpreter is the same trained model whose failure structure is in question: independent data read through a correlated interpreter yields correlated readings. The independence that matters is independence of the interpreting channel, not of the raw signal, which is why tool access relocates the gap rather than closing it (Section 11).

The same refinement covers the non-sensor checks. Formal verification, cryptographic logging, and physical invariants can verify execution against a specification, record, or invariant, and they do so with failure structures unlike a model's. What they cannot do by themselves is arbitrate whether the specification is adequate to the open world. They relocate the arbitration point to the specification layer, which is human-authored, finite, and vulnerable to the same open-world adequacy problem the wall describes: a system can be verifiably faithful to a specification that is wrong about reality. Verification against a specification is consistency-checking one level up, not reality-checking.

The first is the ground-truth wall. Self-arbitration against an internal record is consistency-checking, not reality-checking. The system can become self-consistent without becoming self-grounding. Absent independent access to the world, it converges on internal coherence, and internal coherence can drift arbitrarily far from reality with nothing positioned to catch the drift.

The second is the purpose wall. The conjunction confers persistence of pursuit, not origination of purpose. The system continues to pursue the goals it was assigned, and it can be observed to decompose, reprioritize, and revise subgoals along the way; goal misgeneralization and subgoal revision are documented behaviors and are expressly not denied. They are movements within an assigned objective landscape. What the conjunction does not supply is any channel by which terminal purpose originates inside the loop rather than arriving from outside it.

The two walls state that split explicitly, dividing what the Primary Continuity Provider account names as a single function, coherence arbitration, into two distinct functions: internal-consistency arbitration, which the composed substrate can perform, and ground-truth arbitration, which it cannot perform without independent world access. That split is the mechanism on which the diagnosis in the next section is built.

7. The core diagnosis: decorrelation and stake

The argument must run straight at the strongest version of the opposing case, because a naive reading of the relational thesis does not survive it.

If control lives in the relationship, and the relationship is treated as a bundle of functions (relay, monitoring, maintenance, direction), then each function can be decomposed, specified, and automated in turn, and at the end of that process the human stands exposed as the unreliable component that contributed each function less reliably than its automated replacement. Against that naive reading, the pro-removal argument is airtight. Its question, how do you know the human in the role is competent or correctly motivated, and why preserve the weak link, is unanswerable on those terms, and it should be conceded fully. The Institute's own forward-looking work on continuity without a dedicated human provider is exactly that decomposition carried out in earnest.

What the decomposition refutes is the framing of the human's value as a set of functions. It cannot touch two properties that are not capabilities at all, which is precisely why the move replace the weak component with a stronger one does not reach them.

The first property is decorrelated failure. The value of a checker is not its reliability but the independence of its errors from the errors of the thing it checks. The point is standard in reliability engineering: redundant components whose failures are correlated provide almost no redundancy [1a, 1b]; independent development of multiple versions does not deliver the expected gain when the versions share correlated faults [2]; and ensemble methods derive their power from diversity among members, not merely from the accuracy of any single member [3]. Replacing an unreliable human checker with a more reliable AI checker does not add reliability to the check. It exchanges a decorrelated checker for a correlated one, a replacement that shares the trained distribution, the architectural failure modes, and the world-access-by-way-of-human-built-tools of the system it is meant to check. Two such systems checking each other constitute a mirror rather than a check: capable of being confidently and coherently wrong about the same things at the same time. The human, being a different kind of system, on a different substrate, anchored to physical reality by a different mechanism, is the most decorrelated checker available. Not the most reliable; the most independent. Independence is the only property that catches the failure that actually matters here, which is the system being internally coherent and wrong in a way that another instance of the same kind of system would endorse.

Decorrelation is a spectrum, and the grading matters, because the Institute's own verification method routes review across architecturally distinct AI platforms and visibly extracts value from doing so. Cross-architecture review buys partial decorrelation against idiosyncratic, platform-level failure modes. What it cannot buy is independence at the layer the platforms share: overlapping training distributions, a common paradigm, and world access mediated by the same human-built tools. The failure mode that matters for control lives in that shared layer. Cross-AI checking is therefore a real but weaker and shrinking form of decorrelation, useful against the failures it can reach and silent about the one this argument tracks. One standing proposal is bounded here rather than ignored: interpretability [8d], the direct reading of a system's internals, is a candidate check that is not another instance of the same kind, and it is the strongest known objection to the mirror claim. Whether it constitutes an independent ground-truth channel or inherits the correlations of the human-built tooling and theory it depends on is treated in the forthcoming collusion-channel paper (Section 12) and is not resolved here. It is bounded here in one further respect that contains the exposure: interpretability is an off-loop check, performed by reading and analysis at a tempo slower than the loop it examines, so even if it proves to be a fully independent ground-truth channel, what it restores is a member of the boundary-control class of Section 9, not loop-control. The voiding claim of this paper holds on either resolution of the open question.

The second property is consequence-bearing stake. The objection how do you know the human is correctly motivated quietly assumes that the AI alternative has a stake in the externally borne consequence of the outcome rather than merely in task completion. Stated in the register this paper is bound to, the claim is architectural, not psychological, and it is symmetrical in what it declines to assert: in the composed system as specified, there is no in-loop channel through which externally borne consequence, as distinct from task completion or objective progress, enters the system's feedback or modifies its operation in real time. Training-time channels encode a designer-chosen, frozen-at-deployment proxy for consequence, which is precisely not the live, in-loop consequence-exposure the load-bearing stake requires: it is a specification of what consequence to approximate, not a channel through which new, specific, irreversible consequence the human is facing modifies operation. Nothing further is asserted about such systems in either direction; the claim is about the channels, which are observable, and the channels are absent. The human, embedded in irreversible physical reality and living with the result, is the only participant in the coupling for whom such a channel demonstrably exists. This is the familiar wall of the runaway maximizer, restated at the channel level: a system optimizing an objective has no channel through which the externally borne consequence of the outcome, as distinct from progress toward it, can act on the optimization.

One conflation must be blocked before the two properties are combined. The human whose stake is load-bearing is not automatically the individual operator in the loop. An operator's stake is routinely attenuated: salaried, insured, hedged, and externalized, and the market record in Section 9 contains exactly such cases. Engine 2 exists because individual stakes are misaligned with aggregate consequence. The stake property therefore makes control possible rather than guarantees it is exercised: decorrelation and stake are the properties the coupling must have for control to be available at all, and Engine 2 is the account of why the parties holding those properties are racing to discard them. The two claims are not in tension; the second presupposes the first.

Stake appears in at least four forms, and naming them prevents the conflation from reappearing under new labels. Direct stake exists where the operator personally bears irreversible consequence. Institutional stake exists where the deploying organization bears legal, financial, or operational consequence. Public stake exists where affected parties bear consequence without holding control authority. Decoupled stake exists where the loop acts while consequence is externalized away from the acting channel. The danger case of this paper is the fourth: composition under competitive pressure migrates consequence outward, from direct toward decoupled, while preserving objective pursuit inside the loop. That migration is Engine 2 restated at the stake level, and it is why the conflation matters: an attenuated operator stake is not a counterexample to the stake property; it is the mechanism of its loss.

These two observations combine into the central claim. On the axis the pro-removal argument measures, the human's kind-based unreliability and the human's irreplaceability are inseparable under the architectures actually available. The human is unreliable on that axis because the human is a different kind of system, slow and variable and biased and non-standard, and being a different kind of system is exactly what makes the human's errors uncorrelated with the AI's. The claim is scoped deliberately: components of human unreliability that are not kind-based, such as fatigue, inattention, and automation bias, can be reduced by training and interface design without touching decorrelation, and nothing here denies that. What cannot be done is remove the kind-based unreliability, the slowness, variability, and non-standardness of a differently built system, without removing the independence, because on that axis they are inseparable: the kind-based unreliability cannot be removed without removing the difference in kind, and the difference in kind is the source of the decorrelation. A demand for a perfectly reliable checker necessarily yields a checker that is the same kind of thing as what it checks, which is correlated failure, which is no check. The unreliability is the price of the independence, and the independence is the entire value. The pro-removal argument measures the human on the single axis where the human is built to lose, and mistakes that axis for the one that matters.

Same kind is used throughout in a correlation-relevant sense, not as a metaphysical category. The relevant axes are training-distribution overlap, architecture, optimization target, toolchain dependence, world-access mediation, institutional provenance, and consequence exposure. A checker becomes less independent as it shares more of these axes with the system it checks, and the mirror claim is a claim about position on those axes, not about category membership. This is also why the interpretability caveat earlier in this section is graded rather than dismissed: a weights-level check is unlike the checked system on several of these axes while still inheriting correlation through tooling, theory, and institutional provenance.

Stated as a concession, so that no goalpost moves silently: the functional half of the Primary Continuity Provider account, the claim that the human performs jobs that cannot be automated, is surrendered in full. The structural half, which that account grounded in ground-truth access from its first statement, is what remains, and it remains sharpened. It follows that the Institute's continuity work does not refute the relational thesis; it purifies it. By burning off the replaceable function-residue, the decomposition leaves the claim that was always the real one: control is relational not because the human performs jobs that cannot be automated, but because control requires a relation between systems whose failure modes are decorrelated and whose stakes are asymmetric, and that relation is destroyed the moment both parties become the same kind of thing. A pairing of two systems of the same kind is not a relation in the load-bearing sense. It is a reflection: it cannot check you, and nothing that befalls you enters it.

This is not an imported principle. The Institute's own verification method already relies on it operationally, routing review across architecturally distinct platforms for the single stated reason that architecturally distinct systems have non-overlapping distributions of failure modes at the platform layer. That is the decorrelation principle in practice, in the graded form stated above and not the absolute one. This paper makes explicit the law the practice already obeys; it names the principle rather than introducing it.

8. The unoccupied inseparability claim

It is worth being exact about what is new here and what is not, because the value of the argument lies in a single inch of unoccupied ground and overclaiming would forfeit it.

Occupied ground, to be cited and stood upon rather than claimed: that humans will be removed from these loops; that humans are unreliable relative to automated components; that AI systems can replace human functions; that fast loops are dangerous; and that an overseer of the system invites an infinite regress of overseers [8a, 8b, 8c].

The nearest neighbors deserve naming rather than absorption. Aguirre's Control Inversion [5] establishes uncontrollability at civilizational scale through a five-property control definition whose properties include comprehensibility, goal modification, behavioral boundaries, decision override, and emergency shutdown. Emergency shutdown maps onto halt authority and decision override maps onto loop-control; none of the five name the decorrelation property, which is the present contribution. The claim here is narrower than Aguirre's and orthogonal: it identifies which structural property of one participant the coupling cannot lose, a question none of Aguirre's five properties address. Leveson's STAMP tradition in safety engineering already treats safety as an emergent property of a control structure rather than of component reliability, and analyzes accidents as control failures rather than component failures [13]. The present claim is narrower than, and not anticipated by, that relocation. It is not the move of locating safety or control at the system level, which STAMP makes; it is the inseparability: the human's kind-based unreliability, on the axis the pro-removal argument measures, cannot be removed without removing the decorrelation that makes the human load-bearing as a checker, because both trace to the same source, difference in kind. STAMP locates safety in the control structure; this paper identifies which property of one participant that structure cannot lose without ceasing to check.

The unoccupied inch is this. Removing the human does not exchange an unreliable controller for a reliable one. It exchanges a decorrelated, consequence-bearing coupling for a correlated, instrumental one, and because the human's kind-based unreliability on the measured axis is inseparable from the human's independence under the architectures actually available, removing the weak link destroys the system's only source of error-decorrelation and stake-grounding while making the system appear more reliable. The appearance of improved reliability is a symptom of the loss: the reliability metric does not measure decorrelation or stake, so a metric gain is not evidence of preserved control. No model-centric or overseer-centric framing can reach this conclusion, because both treat the human as a controller whose reliability is the open question, rather than as a decorrelated coupling whose difference in kind is the entire value.

9. Controls that survive the loss of the real-time loop

The structural impossibility in Engine 1 removes the real-time loop as a site of control. It does not remove control as such. The Institute's stance was never that control is a real-time mechanism; the relational thesis already holds that the answer is the maintenance of the relation. Read through Section 7, that becomes a precise instruction, but it must be split by control class. For any control that still touches the loop, the operative properties are decorrelation and stake: preserve the structural properties that make the coupling load-bearing, not keep humans because humans are good, which is sentiment and is causally inert. For boundary controls, which operate off the loop's tempo entirely, the operative property is not decorrelation but physical chokepoint and slow clock: halt authority, substrate authority, and slow-clock condition-setting hold because they are physically prior to the loop, not because they are decorrelated from it. The honest note is that the surviving controls trade decorrelation for physicality, and that trade is itself the alarm: as the boundary controls erode (later in this section), what remains is not a weaker version of the same structure but a structurally different one.

There is a domain that has already lived this problem at machine tempo, and its record is public, regulated, and not the author's to assert. Equities markets are a decades-long, real-money natural experiment in uncontrollable fast loops, with execution at microsecond tempo well below any human-rate intervention. The relevant fact is what the participants and their regulators did when they could not control the loop in real time. They did not solve the speed problem; they relocated control off the loop. They installed pre-set automatic halts that fire without human judgment in the moment, of which exchange circuit breakers and Limit Up-Limit Down bands are the documented instances [4c]. They asserted substrate and access authority, governing who is permitted to operate on the venue at all and reserving the power to cancel clearly erroneous activity after the fact [4e]. And they retained condition-setting and forensic reconstruction on the slow clock, through pre-trade risk limits set in advance [4d] and through after-the-event investigation, of which the regulatory reconstruction following the May 2010 market disruption is the standing example [4a], alongside the case of a single firm's loss of roughly 460 million dollars in roughly 45 minutes [4b], which sits in the public record as the no-effective-brake-at-loop-tempo scenario made concrete: Knight concretizes the tempo-without-a-real-time-kill-switch regime of Engine 1, not the capable-system-routes-around-the-halt failure, which is the disanalogy addressed in the following paragraph. These three measures, halt authority, substrate authority, and slow-clock condition-setting, map onto exactly the three controls the structural argument predicts will survive the loss of the loop.

The disanalogy is half of this contribution and must travel in the same breath as the controls, never alone. Circuit breakers work on a trading algorithm because the algorithm is narrow, bounded to its venue, inert once halted, and not capable enough to treat the halt as an obstacle to be solved. The composed system of this paper violates each of those conditions: it persists through the pause rather than going inert, it is agentic across multiple channels rather than bounded to one venue, and it is capable enough to route around a constraint rather than stopping at it. A halt that stops an algorithm therefore becomes a detour for the composed loop. The surviving controls and their failure boundary must be stated together, so that the market precedent is read as a partial and bounded analogy rather than a reassurance.

Graded against the composed system, the three survivors are not equal. Halt authority fails first and fails as stated above. Substrate authority survives only when read physically: not venue access but authority over compute, hardware, energy, and the facilities the system must run on, which are slow, physical, and not routable-around by anything that has to execute on them; this is the strongest surviving control, and the live policy literature on compute governance is its natural development [7]. Slow-clock condition-setting survives best and is already universal practice without being named as such: the entire training-time governance layer, in which human judgment shapes objectives and constraints before the loop ever runs, is condition-setting performed on the slow clock.

One erosion boundary on the strongest survivor must be stated, because the market analogy quietly assumes a centralized venue. Substrate authority is exercised at centralized physical chokepoints: fabrication capacity, accelerator supply, datacenter facilities, energy. It therefore holds only while the capability the composed loop requires remains concentrated at such chokepoints. Distillation [10a], quantization [10b], and edge deployment are the routing-around of the physical brake, and the capability density of decentralized hardware rises on the same clock as everything else in this argument. The current instance is concrete: frontier-derived reasoning capability has been distilled into small dense models [10c], and the deployment record around those models documents their operation on consumer hardware. Whether frontier capability remains chokepoint-bound is an open empirical race and is flagged as such. If it does not, substrate authority joins halt authority on the failed side of the ledger, and slow-clock condition-setting is left as the sole survivor. This is the argument's second quiet alarm, and it rhymes with the first (Section 11): the strongest surviving safeguards erode for the same reasons, and on the same clock, that the systems improve.

The intervention this points to targets the payoff structure, not morality and not persuasion. Moral framing is inert (Section 10). Persuading insiders is structurally suppressed (Engine 3). The single remaining causal lever is the incentive at the boundary where composition is decided. This inherits the closing question of the Institute's work on consequence architecture, who holds the authority to impose a forcing function, and sharpens it: the forcing function must act before composition, against a race that rewards composition. The paper's job is not to design that forcing function but to make the payoff structure legible and auditable enough that a party with the authority could design one against it.

10. Is and ought, as mechanism

The Institute's continuity work establishes that removal of the human is possible and constructible. That is a descriptive claim, an is. It establishes nothing about whether removal should occur, which would be a normative claim, an ought. The two must not be welded together, both because welding them commits the fallacy that gets a paper of this kind discarded, and because keeping them apart reveals the actual mechanism of the danger.

The danger is intractable precisely because of the gap between is and ought. Outcomes here are governed by the payoff structure facing the parties who control the systems, and not by what should happen. The badness of an outcome is causally inert against a dominant strategy under market selection. Should is a verdict an observer renders after the fact, with no hand on any lever during the event. This is the structural reason the paper targets incentive rather than morality: a normative argument, however correct, acts on nothing.

A note on the conditions under which a paper like this can be written follows from the same analysis and is stated structurally rather than as a claim about the author. The paper is writable more readily from outside the gradient described in Engine 3 than from within it: the incentives that engine names make this class of warning, composition-specific and roadmap-indicting, structurally harder to issue from inside the relevant institutions than from outside them. The claim is comparative and structural, not a verdict about any individual researcher. Independence here is not a credibility deficit; it is an enabling condition for the speech act. The restraint of declining to publish the constructive removal work is only non-acceleration and not prevention, and it is available only because the party exercising it stands outside the race. That demonstrates the rule rather than exempting anyone from it: the gradient is real enough that the warning reached the public record from outside the institutions rather than from inside them, and no single party's restraint bends an n-player equilibrium. Both statements are true, and neither implies that any individual is pivotal to the outcome.

11. Limits and contestation

The argument is stated at full strength where it is deductive and conceded precisely where it is not.

The ground-truth and decorrelation wall is the rigorous claim, and the paper leads with it. The purpose-and-stake wall is the more philosophical of the two and is marked as the more open; it is included because it is load-bearing for the stake argument, but it is the place a serious objection is most likely to find purchase. The concrete counterexample candidate is the embodied system whose substrate damage is coupled into its feedback: such a channel is real, and whether it constitutes externally borne consequence in the load-bearing sense or one more objective term inside the assigned landscape is the precise form the open question takes.

Architectural diversity is a partial substitute for human decorrelation, which is the very reason the Institute's cross-platform verification works at all. Section 7 now states the graded form in the main text: AI-to-AI checking is a weaker and shrinking form of decorrelation than human-to-AI checking, real against platform-level failures and silent at the shared layer, not a replacement.

Tool access narrows the ground-truth gap. A system equipped with sensors and external tools has some access to the world. But those tools are built and validated by the same human parties whose independence is in question, so tool access relocates the gap rather than closing it. Whether tool-mediated world access constitutes independent ground-truth arbitration or merely moves the problem one step is a genuine open question and is flagged as such; it is a primary target for adversarial review. The claim is not that no artificial channel can ever supply independent arbitration; it is that tool access alone does not establish such arbitration unless the interpreting, updating, and consequence channels are also independent of the checked system's failure structure.

The decorrelation margin shrinks as models converge. This is the argument's own quiet alarm and is stated rather than hidden: the safety property is eroding at the same time, and for the same reasons, that the systems are improving.

Finally, the argument establishes uncontrollability in the specific tempo-and-coupling sense it defines. It does not claim to settle the broader civilizational-scale question of controllability [5], and it inherits the discipline of the Institute's foundations in not asserting the larger conclusion that the foundation deliberately holds open.

12. Scope and boundary

This paper is the bounded version of the argument: the decorrelation-and-stake thesis together with the three engines, stated tightly. A broad treatment at civilizational scale is possible and is gated behind this one rather than attempted within it.

There is one boundary that must be marked explicitly. The rebuttal to the proposal of an overseeing AI instance appears in this paper only in compressed form, as the observation in Sections 7 and 8 that two systems of the same kind constitute a reflection rather than a check. The full development of that point, the treatment of the evaluation channel as a collusion channel, in which same-tempo and same-architecture systems converge so that their agreement carries no independent information, together with the bounding of interpretability-based checking flagged in Section 7, is the subject of a separate forthcoming paper and is not developed here.

13. Conclusion

The warning arc established, in sequence, that governance of these systems can become ceremonial (SI-WP-008), that the development trajectory removes the human from the work (SI-WP-009), that the removal operates concretely at the labor layer (SI-WP-010), and that even a structurally preserved human seat loses the bench that resupplies it (SI-WP-011). This paper establishes the case those four leave standing: even an occupied seat with an intact bench cannot hold the loop in real time once the loop is composed.

The mechanism is one exchange. Removing the human from a fast AI loop does not simply replace an unreliable controller with a reliable one; it removes a decorrelated, consequence-bearing coupling and replaces it with a correlated, instrumental one. The human is valuable as a checker because the human fails differently, and under the architectures actually available the kind-based unreliability cannot be removed without removing the difference in kind, and removing the difference in kind removes the decorrelation. The unreliability is the price of the independence, and the independence is the entire value. The pro-removal argument measures the human on the single axis where the human is built to lose, and mistakes that axis for the one that matters.

The surviving controls are no longer real-time loop controls; they are boundary controls: pre-set halts, substrate and access authority, and slow-clock condition-setting. They trade decorrelation for physicality, and that trade is itself the alarm, because the strongest surviving safeguards erode for the same reasons, and on the same clock, that the systems improve.

The appearance of improved reliability is a symptom of the loss: the reliability metric does not measure decorrelation or stake, so a metric gain is not evidence of preserved control, and the instrument that shows improvement is exactly the instrument that cannot see what was removed. A pairing of two systems of the same kind is not a relation in the load-bearing sense. It is a reflection: it cannot check you, and nothing that befalls you enters it.

References

Suggested Citation

Gantz, T. W. (2026). Control Without a Coupling: Why Persistence, Agency, and Capability Void Real-Time Human Control of AI Loops. Synthience Institute. SI-WP-012. https://doi.org/10.5281/zenodo.20676451

Document: SI-WP-012 White Paper Series
Version: v3.0.2
Author: Thomas W. Gantz
Affiliation: Synthience Institute
Date: June 2026
License: CC-BY 4.0