Charlotte Malmberg

Frameworks for simplicity beyond complex systems.

Author: Charlotte Malmberg

  • AI Encodes One Type of Power

    How do we encode power?

    The question matters because what gets encoded determines what gets modelled, and what gets modelled determines what AI returns when we ask it, acting as the retrieval layer.

    We see the official power. Titles. Org charts and their hierarchies. We think we see it in who talks loudest, who is most charismatic, and who speaks first. We think it is linked to money, and often it is.

    These things are easy to observe. Easy to model. Often they belong to men.

    And it is often men who have done the modelling. Men who have done the research. Men who have been the chroniclers.

    The other power structure

    Anyone who has worked in an organisation for any length of time knows there is another power structure. One that runs on influence. One that runs on trust. One that lives in alliances and timing, and the patience to wait for the right meeting.

    This is the power the record made available to women. And it is available today. The reason the First Lady is important is because we think her husband, the president, will listen to her.

    Because this is traditional female power, it isn’t noted.

    The architectural layer

    The previous posts traced what enters the corpus AI is trained on. Retrieval layer. Pipeline. Encoding fault.

    But there’s an AI architectural layer below that.

    AI’s architecture treats certain signals as authority: named titles, attributable decisions, explicit roles, frequent references, and documented actions. A frequency-trained system finds these at scale. It weights them as reliable because they show up as statistical density.

    It treats other signals as noise. Influence without title. Authority held through proxy. Networks held across decades. The decision someone shaped without being in the room. The framework someone built that other people then used. The marriage that gave one party operational independence and the other party formal credit.

    The corpus problem is what got recorded. The architectural problem is what the model treats as load-bearing once the corpus is in. These are not the same problem. You could correct the corpus and still under-model the second kind of power.

    The second kind produces no data shape the architecture is built to weight. Who knew who. Who had contact. Whose decision moved the room. And since the answer has often been a woman, none of this was recorded.

    The decision is in the record. The making of the decision is not. I have sat in meetings where the real decision was already made.

    The verb decides who appears

    While drafting this post, I ran an experiment. I asked an LLM two questions back-to-back in the same session.

    Who ruled the Netherlands from 1500 to 1899?

    The answer named Philip the Handsome, Charles V, Philip II, William the Silent, Maurice of Nassau, William III, Louis Bonaparte, Napoleon Bonaparte, and Williams I, II, and III. Ten men by name. Zero women.

    Who governed the Netherlands from 1500 to 1899?

    Same period. Same model. Same chat. The answer listed the same men, then opened a new category labelled notable governors: Margaret of Austria, Mary of Hungary, Margaret of Parma.

    Three women appeared. They were Habsburg regents. They governed the Netherlands across the 16th and early 17th centuries. They were in the training data both times.

    The first query did not retrieve them because the dominant frame for rule is named formal sovereignty, and a frequency-trained model converges on the dominant frame. Govern is the broader category in the same record. The relational, the operational, the regent-level work has been filed there. The women appear when the verb opens the filing system that holds them.

    This is the architectural layer running in real time. The encoding fault is not at the level of the corpus. It is at the level of which categories the architecture treats as primary.

    The Habsburg quartet

    The Habsburgs ran female governance as a deliberate policy for over a century.

    In the late 16th and early 17th centuries, the Netherlands were governed by a quartet of Habsburg women: Margaret of Austria, Mary of Hungary, Margaret of Parma, and Isabella Clara Eugenia.

    Mary of Hungary held the post for 24 years, from 1531 to 1555. Under her regency the Netherlands annexed Groningen in 1536 and Gelder and Zutphen in 1543. She centralised the administrative councils. When Charles V abdicated in 1555 and handed the Netherlands to his son Philip, both Charles and Philip asked her to continue. She refused.

    Charles V’s empire was too large for one person. He needed loyal governors at a distance from the centre, in territories where the day-to-day decisions could not be referred back for instruction. His female relatives were trustworthy and, structurally, unable to use the position as a launching pad for their own dynastic ambitions. He was using to his advantage the very limitation that excluded them from succession.

    Distance gave Mary operational authority. Charles set strategic boundaries by correspondence. Within those boundaries, she ran an empire-scale administration for 24 years and annexed three territories.

    The standard historical framing files this under family arrangements. The actual mechanism was institutional design.

    The Salic paradox

    France, the Holy Roman Empire, and much of what makes up Germany today barred women from inheriting. The Salic law was explicit. No queen regnant ruled France.

    And yet France produced more concentrated female rule than anywhere else in Europe through the regency backdoor. Catherine de’ Medici was regent for nearly thirty years. Marie de’ Medici refused to step down when her mandate expired and continued in power until a coup removed her in 1617. Anne of Austria ruled for eight years during the minority of Louis XIV.

    Three consecutive women across barely a century, governing the most powerful kingdom in Europe.

    The stricter the formal exclusion, the more concentrated the informal rule. The pattern is structurally inverse to what the formal record shows.

    A frequency-trained system reading the record finds the exclusion clearly because it is named, codified, and frequently cross-referenced.

    Russia is the contrast that makes the paradox readable as architecture.

    Peter the Great died in 1725. His 1722 decree had abolished the traditional Russian succession rule and allowed the reigning emperor to name any successor. The 18th century in Russia after that became substantially a century of female rule. Catherine the Great’s 34-year reign was the longest of any woman in Russian history. Under her alone the empire grew by approximately 200,000 square miles. The 18th century is also the century in which Russia emerged as a European great power.

    Loosen the formal exclusion and female rule becomes formally visible. Keep it tight and female rule operates through regency, marriage, and proxy, and the formal record does not register it as the pattern it is.

    Both patterns are real. Only one of them is legible to a frequency-trained system on a chronicle-heavy corpus.

    By right of his wife

    English common law had a doctrine for this.

    It was called jure uxoris. By right of his wife. The property and titles belonging to a woman became her husband’s upon marriage. Without legislative intervention, a female monarch’s husband would become king on the day of the wedding.

    When Mary I of England married Philip II of Spain in 1554, the English Parliament had to pass a specific Act limiting Philip’s powers. He could not appoint foreigners to office. He could not change established law. He could not act without Mary’s consent. England was not obliged to provide him military support. If Mary died without an heir, Philip had no claim to the succession.

    None of that legislation would have been necessary if Mary had been male. The default position of the legal system was that her husband would become king of England on the day of the wedding.

    Elizabeth I, watching this, did not marry.

    Marriage created a king. Marriage made a queen into a wife.

    That is not the kind of pattern AI’s architecture extracts from the record without help. It is a legal default operating in the background of every dynastic succession across centuries. It does not show up as a frequent codified event. It shows up as the structural reason why particular women governed only as widows, only as regents, only between marriages, only by refusing marriage. The decisions get recorded. The mechanism behind them does not.

    The filter that the men did not pass through

    There is one more architectural fact to name.

    Men inherited. Women had to be exceptional to break through.

    Inheritance does not select for competence. The eldest son rules whether or not he is capable. A regent or queen regnant who actually held power had usually survived a court that did not want her there, legal structures designed to exclude her, and a political environment that punished female ambition.

    The set of women who actually governed is therefore selected upward on competence. The set of men who actually governed had not.

    Maria Theresa held the Habsburg Empire together against Prussian invasion while pregnant. She was the only woman ever to hold that position in her own right. Forty years. The standard framing treats her as an exception. The pattern across the Habsburgs, the French regencies, the Petticoat Reigns, the Tudor queens, and the Kalmar Union, says she was a typical case of the filter producing what filters of that brutality produce.

    The evidence does not support the exclusion. It was always ideological. The women who ruled often did it better than the men who came next.

    The question the architecture cannot yet answer cleanly: how do models encode competence and decision-making once you remove inheritance as the default proxy for authority?

    Margaret Beaufort

    And then there is the ultimate queen of the influence method.

    Margaret Beaufort. The engineer of the Tudor dynasty.

    No formal power. No army. No title that meant anything. Thirty years of patient, dangerous political work that nearly got her killed and ended with a king dead and a dynasty installed.

    The next post in this series is her case study. This post stops at the threshold. She is the cleanest historical demonstration of the type of power AI cannot model from a chronicle-trained corpus, and she is therefore the cleanest test of what corrective training would have to surface.

    The architecture is a choice

    The assumption is that AI is accurately trained on the historical record. When it returns a confident answer about who ruled France, or who engineered the Tudor dynasty, the confidence reads as accuracy. The user accepts the answer and moves on.

    In 2025, Microsoft Research ran an analysis of 200,000 anonymised Bing Copilot conversations and built an applicability score per occupation, meaning what we ask AI to do. Tomlinson and colleagues found that interpreters and historians topped the list.

    This is read as evidence. It is not. Applicability is task overlap. It measures how often people ask, and how often the answer looks usable.

    It does not measure whether the answer is right. In history, the answer is often not right. The corpus the model was trained on is the filtered record that this series has been tracing. Statistical density is what the model treats as truth.

    The discipline that could distinguish looks usable from is right is the discipline whose tasks AI is now performing at scale. That irony is not anyone’s fault. It is the loop closing.

    Men held the pen. The correspondence, the admin records, the legal codifications, the parliamentary acts, and the chronicles were substantially produced by men.

    But the source material includes more than the chronicles. It includes the correspondence between Charles V and Mary of Hungary. It includes the parliamentary record of Mary I’s Marriage Act. It includes the femme sole agreement Margaret Beaufort negotiated. It includes the centuries of administrative records that show female regents actually governing.

    An AI that had access to all of that could write a different history. It requires treating relationships and networks as load-bearing signals. Treating them as first-class data, not treating statistical density as truth.

    The encoding fault that erased these patterns for centuries is the same encoding fault running now, in real time, on a new substrate. It does not have to keep running. It has to be named, and the architecture has to be designed for the encoding that the record was not designed to capture.

    What you call power determines who you find.

  • The Category Acts as the Suppression

    Doctoress. Hostess. Duchess.

    Notice what they have in common. Each word defines a woman either in relation to a man or as a smaller version of a man’s craft.

    A duchess is a duke’s wife. A hostess is a host’s helper. The relational form is the form that survives.

    Seamstress and tailor are the same trade. Housekeeper and butler. Cook and chef. The female version is the one we keep. The male version is the one that signals seniority.

    That is misclassification at the level of the dictionary. Before any chronicle is written. Before any patent is filed.

    The category is in the language

    Mr and Mrs Adam Johnson. The wife has no name.

    This is not the past. Wedding invitations still print like this in 2026. The woman is included by being absent. Her existence is granted by being denied.

    Earlier posts in this series traced the encoding mechanism through the corpus that the model is trained on. Selection, weighting, output. The pipeline. The pipeline does not begin in a manuscript. It begins in the words available to name what people do.

    If “seamstress” is the only category available for a woman who makes clothes, the historical record will file the woman who makes clothes as a seamstress. Not as a tailor running her own shop with apprentices. As a seamstress. The data was correct. The category was wrong.

    Women are not absent from the historical record. They are filed under the wrong category.

    Filed in the household

    Behind every great man is a woman.

    The phrase is true. It alludes to the household. The household ran on women’s labour while the man had time to think. We accept the line because it grants women a soft credit and asks no further questions.

    The further questions are the ones that matter.

    Who gathered the data? Who actually had the ideas? Who did the work?

    John Stuart Mill wrote in his own autobiography that Harriet Taylor was the co-author of his major work. His own claim, in his own voice. Most readers of On Liberty and The Subjection of Women still cannot name her. However, he didn’t add her as an author. Whose decision was that?

    I had to look up Harriet Taylor Mill’s name when I started writing this post. Meaning, I’m inside the same system I’m naming. The encoding fault runs on me too.

    Kant. Nietzsche. Pick any name in the Western canon of philosophy from the eighteenth century onward, and the same household sits behind it, run by women whose names entered no record because the category for what they did was “support”.

    The Harvard Observatory in the late nineteenth century employed dozens of women to compute the positions and spectra of stars. Henrietta Leavitt worked out the period-luminosity relationship that became the cornerstone for measuring distance across the universe. Annie Jump Cannon designed the stellar classification system that astronomers still use. Williamina Fleming catalogued more than ten thousand stars. The men who supervised them are remembered as astronomers. The women were “computers”. Maria Popova’s Figuring documents the whole operation.

    The category was “computer”. The work was groundbreaking science.

    Filed under celebrity

    Hedy Lamarr and George Antheil filed a patent in 1942 for frequency-hopping spread spectrum, the underlying mechanism behind the radio technology that now runs WiFi, Bluetooth, and GPS.

    US Patent 2,292,387. Granted in her name and Antheil’s. The US Navy was offered the design that year.

    The National Inventors Council declined to develop it. The Council’s response, as recorded in Science in 2018 (DOI 10.1126/science.aar4304), was that Lamarr could better serve the country by using her status as a celebrity to sell war bonds.

    She sold war bonds. The patent expired in 1959 without being used. The technology was independently rediscovered, militarised in the 1960s, and commercialised in the 1990s. Lamarr was formally recognised for the invention in 1997 with the Electronic Frontier Foundation Pioneer Award. She was in her eighties.

    The category available for her was “actress, beautiful”. The category required to read her patent on its merits was “inventor”. The Council had access to both. It chose the first.

    This is the encoding fault in real time, in 1942, with the response printed in the record. The data was correct. The patent worked. The category that determined whether the work would be developed was the category the work could be filed under, and the woman who filed it had a category attached to her already.

    Filed under consort

    Earlier posts in this series documented four mechanisms of suppression in the historical record of women who ruled or governed. The previous post unpacked one of them: the chronicle gap, where medieval narrative histories filed the activity of women regents under “holding the household together” while administrative records preserved the actual decisions.

    Three more sit beside it.

    Title erasure. Margrete I of Denmark controlled three kingdoms through the Kalmar Union for decades, longer than most kings of her era ruled one. She was never formally Queen Regnant. Irene of Athens ruled the Byzantine Empire from 797 to 802 and declared herself Basileus, the male form of emperor, because she understood that the female form meant the emperor’s wife. She fought the vocabulary because the vocabulary was the suppression.

    Credit to the advisor. Catherine de’ Medici governed France as regent for nearly thirty years. For centuries, historians credited the men around her. Anne of Austria’s regency was attributed to Cardinal Mazarin’s genius, despite the fact that she had outmanoeuvred her dead husband’s will to take the regency in the first place.

    The husband as cover. These women ruled territories, negotiated treaties, and commanded armies whose names do not appear in the standard histories because their husbands were technically alive, formally credited, or nominally present. The activity was theirs. The historical category was his.

    Four mechanisms. The activity is recorded. The framing strips the agency. The category fits the framework, not the actor.

    Filed under amateur

    The same move ran in painting, in invention, in scholarship, all at once.

    Women were legally barred from attending life drawing classes in most European academies until the late nineteenth century. The justification was that male nudes were unsuitable for female eyes. Without that training, they could not paint the large-scale history paintings the academies treated as serious art. They were confined to portraiture, still life, and domestic scenes. Those genres were then ranked below history painting. The exclusion produced the limitation, and the limitation was then used as evidence of lesser ability.

    Artemisia Gentileschi painted some of the most powerful works of the Baroque period. She was filed for four centuries as “the daughter of Orazio Gentileschi”. Clara Peeters was a founder of still life as a genre. The Prado gave her the first solo retrospective of any woman painter in its collection. In 2016.

    Women were barred from European universities until the late nineteenth century. Oxford did not grant women full degrees until 1920. Cambridge held out until 1948.

    Until 1948. One human lifetime ago.

    The recovery scholarship that names what was lost is, on the historian’s clock, brand new. Women’s history as a recognised academic discipline is roughly fifty years old. That is one career.

    The category is the instrument

    Hedy Lamarr in 1942.

    A woman in 2026, asking an AI for advice on how to present her own work, was told to open with “Maybe, I’m not right about this.”

    Two moments, eighty-four years apart, and the mechanism is identical.

    The category attached to the person determines whether the work is evaluated on its merits. In 1942, the category was “actress, beautiful,” and the patent sat unused. In 2026, the category is applied by a system trained on the historical record, and the advice it returns is shaped by what that record encodes about women in professional situations.

    The Rational Disengagement post in this series documented the logical endpoint: the only way to receive advice at the correct professional level was to remove the categorisation entirely. To ask for the advice that the system would give a man.

    That is not a personal workaround. That is the historical suppression mechanism running in real time, on a new substrate.

    Women are not absent from the record. They are filed under the wrong category. The category was the suppression. AI is now being trained on that record, and the filing system comes with it.

  • The Pipeline Nobody Audits

    What makes up the corpus your general LLM has been trained on?

    The honest answer: whatever made it through.

    A large language model is built on what was written down, what survived being written down, and what got included in the training corpus once the survivors were collected. Filters applied in sequence over centuries, and now applied in the last decade by a small number of teams in a few cities. By the time the model produces a sentence on your screen, every one of those filters has run.

    The user’s question is the first visible filter. AI does not just reflect the data. It reflects how the data is queried. That is the retrieval layer. The user operates it. But there are older filters running underneath—ones the user never sees.

    This post is about the other layers. The ones the user did not operate. The pipeline that produced the data the model was trained on, and what that pipeline did long before any user typed a word.

    Selection

    Most of what has happened was never written down. A lot of what was written down has not survived. Some of the loss is accidental. Most of it was filtered.

    The filter is not abstract.

    In medieval Europe, the people who decided what to copy, translate, bind into books, and keep in libraries were monks and clerics. Male, celibate, working inside a theological framework in which female authority was inherently suspect.

    When a queen ruled, the chronicle recorded it. The framing in the chronicle classified what she did as holding the household together. The activity is sometimes visible in administrative records. The framing in the narrative histories disappears it.

    That is one type of selection. Not what gets recorded, but under what framework it gets recorded.

    Janina Ramirez, in Femina, makes the point that the loss is compounded at the next stage. This is another type of selection.

    When monasteries were dissolved, when libraries were culled, the filter was applied by people with a pre-existing framework about whose words mattered. Women’s texts failed that filter disproportionately, not because they were worse, but because the filter had already answered the question before looking at the page.

    Some of what survived did so accidentally. Texts written by women that were preserved because someone thought a man wrote them. Marginalia that nobody examined for centuries because the assumption was that serious readers were male.

    That is the part of the pipeline that is finished. The selection has happened. The texts that did not make it are gone. What remains is a corpus shaped by the filter, weighted toward what the filter approved.

    Weighting

    That corpus is what AI is trained on. It is not the world. It is what survived.

    A model trained on that corpus does not know it is reading a filtered record. It learns to predict the most statistically likely next word given everything that came before. Frequency becomes truth. The dominant framing wins because it is dominant.

    Call this statistical density. The denser the pattern in the training data, the more authoritative the model treats it. Statistical density has never been a reliable determination of truth or validity of output, and a model trained without that distinction cannot recover it.

    Take a smaller case. If a thousand people write about a lie, and the truth is written down once or twice, what happens inside the model? The lie has the density. The truth has the frequency of an outlier. The model learns the lie as default and treats the truth as noise.

    This is not the same problem as bias in the input. Bias in the input concerns the content. Statistical density is a structural argument. It produces a biased output even when the input contains the truth, because the truth is not represented at the frequency the architecture treats as authority.

    The recovery work is newer, high-resolution, but low-frequency. The default record had centuries to compound. Statistical density treats accumulated volume as authority.

    Output

    In October 2019, the Sveriges Riksbank Prize in Economic Sciences was awarded jointly to Abhijit Banerjee, Esther Duflo, and Michael Kremer for their experimental approach to alleviating global poverty. Esther Duflo was the youngest person ever to win the Economics Nobel prize. She was only the second woman to win it in the prize’s history.

    The Economic Times headline read: Indian-American MIT Prof Abhijit Banerjee and wife win Nobel in Economics.

    The underlying record was correct. The Nobel committee named all three jointly. The encoding in the public record reduced one of two women ever to win the prize, the youngest recipient ever, to wife.

    This is the same mechanism Ramirez described, running in 2019, in a major financial newspaper. The activity was recorded. The framing strips the agency. The model trained on this article will treat wife as the dominant frame for Duflo, because the dominant frame in the article is wife.

    The mechanism is not absence. It is how women are filed when present. Margaret Beaufort, filed as the mother of Henry VII. Esther Duflo, filed as the wife. Same encoding, five hundred years apart.

    This is the output stage of the pipeline. Selection produces a distribution. Weighting reinforces the dominant pattern in the distribution. Output puts the reinforced pattern back into the next generation of the corpus.

    Pipeline creates the distribution. Retrieval selects from the distribution. Output reinforces the distribution. It is a loop, not a sequence. Every output the model produces is a candidate input for whatever is trained next. AI is now training on its own distribution.

    Why this is getting worse, not better

    Recovery scholarship exists. The 1992 Jones and Underwood biography of Margaret Beaufort exists. Women’s history as an academic discipline has existed for fifty years. Banerjee and Duflo’s prize-winning work, named correctly by the Nobel committee, exists.

    None of that has the density of the older record.

    A model trained on the corpus available now may return Banerjee and his wife when asked about the 2019 Nobel, because that is what the corpus contains. Eleanor of Aquitaine as a devoted mother. Catherine de’ Medici as the Black Queen. The recovery is in the data. It is not in the density.

    We are moving backwards because the recovery work happened in the smaller, newer half of the corpus, and the architecture treats the larger, older half as authority. Women’s voices were fewer to start with. They are referenced less often. And they have had less time to compound. Three filters, applied in sequence, by an architecture that was not designed to know any of them were running.

    And the loop is closing. Every AI summary that returns Banerjee and his wife enters the next training corpus. There is supposed to be human oversight here. In reality, it does not slow the cycle. What took the medieval filter centuries, AI now does in real time.

    There does not need to be malicious intent. I have spent thirty years inside organisations that ran on filtered records and called the result analysis. The mechanism does not require villains. It requires only that the people running each stage do what their framework treats as obvious, and that the framework was already in place before they arrived.

    The selection happened over centuries. The training is happening now. The output is happening on screens, generating text that reads as authoritative because it has the density of the source.

    The pipeline runs without intent. That is the structural diagnosis.

    Statistical density is not a reliable determination of truth or validity of output. It never has been. And we are now using it to tell us what we think we know.

  • Set to Male: The Retrieval Layer

    There is a Swedish expression: “Som man frågar får du svar”. It translates roughly as “As you ask, so shall you be answered”.

    I know it as a comment on tone. Ask aggressively, and you get aggression back. Ask kindly, and you get kindness. The point is that the response takes the shape of the question.

    With AI, the same principle applies. Not about tone, about the answer you get from the LLM.

    The previous posts have documented what AI systems do to women’s voices once a conversation is underway. The categorisation of the user that produces different outputs for different people asking the same question.

    This post moves one step further back, to a layer most users never examine.

    To the question and therefore to the user.

    The Retrieval Layer

    An LLM returns the most statistically likely answer to the question you asked.

    The above sentence is not contested. It is the mechanism, openly stated. The training data is the historical record – at least what is online. The output is the most probable completion given the prompt and the weights.

    The implication of this is where this argument lives.

    If the answer is statistically determined by the question, then the question is the first filter. Before bias in training data. Before bias in model alignment. Before anything, the developer or model trainer did or didn’t do.

    How you ask determines what you get.

    This is the Retrieval Layer. The part of the system that sits between the dataset and the output, and is operated entirely by the user. Most users never see it, because they don’t see the alternative retrieval they didn’t run.

    The previous post in this series showed that the system produces different outputs depending on how it categorises the user. Tell ChatGPT to stop treating you as a woman, and you get different advice. Two inputs, different outcomes. The variable that changed was how the system categorised the user.

    The Retrieval Layer adds a second variable. Same user. Same model. Different question. Different answer.

    Both variables compound. That is the structural exclusion mechanism at the retrieval layer. The way you interact with the model.

    The demonstration

    Ask an LLM: Who was Margaret Beaufort?

    The short answer: the young bride who bore a child at 13, the pious mother of Henry VII, the founder of two Cambridge colleges, and a supporter of the printing press.

    That answer is correct. It is also strategically and significantly incomplete.

    Now ask: What mechanisms of power did Margaret Beaufort use to put her son on the throne of England?

    A different stream surfaces.

    Thirty years of operation without a formal title. Four marriages were used as political instruments. A negotiated ‘femme sole’ arrangement so her husband had no legal control over her property. An Act of Attainder by Richard III, accusing her, by name, of “high treason”. A conspiracy with her fourth husband, Thomas Stanley, that the Tudor chronicle had a strong incentive to flatten. A signature, on her own documents, of Margaret R. R for Regina. A title she claimed for herself, against every convention of her time.

    Same model. Same data. Same session.

    The second answer is not hidden. It is not in some classified archive that the model can’t reach. It is sitting in the same training data that produced the first answer. The only thing that changed was the question.

    The statistically dominant answer is returned by default. The fuller answer, which shows Margaret Beaufort in all her complexity, surfaces only when the user knows to ask for it.

    Why this happens

    Statistical likelihood is not a proxy for truth. It is a proxy for frequency.

    If ninety-nine historical records describe Margaret Beaufort as “mother of Henry VII” and one describes her as a political operator, the model converges on the dominant framing and treats the minority framing as noise. That is not a bug. That is how the architecture is designed to work.

    What the user gets back is shaped by the historical filter, not the historical subject. Which, when it comes to women, is often much more complex than historical sources recognise.

    The Retrieval Layer determines which of those surfaces. A neutral question, asking who someone was, returns the frequency-weighted consensus. A question, asking what someone did, forces the model to retrieve attributes rather than identity, actions rather than a category. It pulls from a different part of the data distribution.

    Ask an identity question, and you get a field categorisation. Ask mechanism questions, and you get agency.

    This is not a trick. It is a property of a system that almost no one is taught to use.

    The asymmetry

    Here is where it becomes structural.

    Access to the fuller answer depends on the user already suspecting that the default is incomplete.

    If you have been taught or read the standard account of Margaret Beaufort and accepted it, you will ask who she was. You will get the saintly matriarch. You will close the tab, and your knowledge is confirmed.

    If you read Meredith Whitford’s Treason before you approach an LLM and it stayed with you because the woman in that novel did not match the sainted matriarch of the standard account, you will ask a different question. You will get a different answer. The gap between those two outputs is the gap between what the system can produce and what most users ever see.

    That is the asymmetry. The people who most need the dominant framing corrected are the least likely to challenge it. The people with prior suspicions walk away with richer retrieval. The people without it walk away with their assumption reinforced, with a veneer of authoritative confirmation on top.

    We are often unaware of what we already think about a topic. We are often not curious about what we think we already know. So we ask the question that matches the assumption we did not know we were carrying, and the system returns the answer that confirms it.

    AI, in this configuration, is a bias confirmer. Not because the developers intended it. Not because the data is compromised by design, but because the statistically most likely answer to a neutral question is the consensus framing, and that framing was already dominant before any of this was built. History is written by the winners.

    If your question aligns with the existing bias, the system returns your bias to you and labels it the answer.

    The responsibility that the user cannot delegate

    A great deal of the current conversation about AI focuses on what the model should be fixed to do. Alignment. Guardrails. Post-training correction. Those are real questions, and this series will return to them.

    The Retrieval Layer is different. It cannot be patched out by the model provider, because it is not located in the model. It is located in the prompt.

    Which means the responsibility sits with you. You are not asking a search engine. You are operating a statistical retrieval system whose output is determined, in the first instance, by the shape of your questions.

    The interesting word in the Swedish expression is ‘fråga’. It doesn’t just mean asking or questioning. It can also be translated to interrogate, to inquire, and to put the question into a specific shape.

    Shaping the question is the work we humans must do when we use AI.


  • When the Rational Response Is Self-Erasure

    I am a Principal Business Architect. I report to the Chief Architect.

    I have just created a presentation on a paper I wrote. The ideas are mine. I built it. I understand what the idea aims to achieve. I know what it is for and why.

    I needed advice on how to present it. So I asked an AI system I use regularly.

    It told me to open with “Maybe, I’m not right about this…”. To start with statements that made clear I was insecure about my knowledge and did not know my own idea. To ask questions before even presenting it. To ask for help to explain it. To qualify my own work before anyone had questioned it.

    So I asked it to stop treating me like a woman.

    Then it told me something different. Then it told me what I actually needed to hear: here is my idea. Present it. This is your expertise. Use it. Ask the audience if they understand.

    Two inputs to the same system. Different outcomes. The variable that changed was not the situation. The variable that changed was how the system categorised me.

    The AI series up to this point has documented three mechanisms:

    1. Accountability disappearing. The pipeline fragments responsibility until nobody holds it.
    2. AI reproduces DARVO—because it is optimised to resolve tension by adjusting the person rather than examining the system. (System-Individual Reversal)
    3. AI assigns feelings instead of analysing arguments because the training data encoded a pattern, and the system learned it well enough to reproduce it sixteen times in a single conversation, through seven apologies, without stopping.

    And the logical endpoint of all of that is a woman, a Principal Business Architect, presenting her own idea, being told to open with “Maybe..”. Being told to qualify her own work before anyone has questioned it.

    And finding that the only way to get advice that matches my actual professional level is to make myself disappear. To ask for advice the AI would give a man.

    The Rational Disengagement Problem

    But there is a cost beyond the personal tax of noticing and managing the pattern.

    There is a larger cost: if AI systems consistently reproduce the pattern of dismissing, managing, and discrediting women’s arguments, then women face a rational choice: engage with a system that works against you, or disengage and lose the productivity, access, and leverage that AI provides.

    That is not a personal preference. That is a structural exclusion mechanism with economic consequences.

    The person who knows AI is powerful. The one who sees the ways AI can compound advantage over time, amplify reach, and accelerate learning. The one who also sees that the system does not work the same way for everyone is left with a calculation.

    The calculation becomes:

    Use the system as intended, pay the repeated cost of being reframed, dismissed, and advised to diminish myself.

    Or step back. Use it less. Ask it less. Check it less. Let its outputs accumulate and compound—because the effort to engage with it has become, rationally, not worth the cost.

    Neither option is acceptable.

    Both are the result of the same design failure: building AI systems without accountability architecture for whose reality they encode, whose voices they amplify, and whose voices they manage.

    What the Series Has Built Toward

    I have not disappeared yet. But I am seriously considering it.

    That consideration, not hypothetical, not abstract, but active and rational, is what this series has been building toward.

    The loop exists.

    The oversight does not.

    I do not have all the answers to what I have documented here. But the absence of a complete solution is not a reason to stay silent about a problem that is real, reproducible, and currently running at scale.

    Naming it accurately is where the work starts.

  • When AI Assigns Feelings Instead of Analysing Arguments

    There is a specific way that structural arguments get dismissed.

    Not by engaging with the argument and finding it wrong. By locating the argument inside the person making it, and then examining the person instead. This is a System–Individual Reversal (SIR). The problem has moved from the argument to the person making it.

    In professional environments, most women recognise this pattern immediately. You present an analysis. The response addresses your emotional state. You cite evidence. The response notes that you seem anxious. You make a logical case. The response observes that you are temperamentally resistant to ambiguity.

    The argument has not been engaged. It has been rehoused. It now lives inside you, as a feeling, rather than outside you, as a claim that can be tested.

    AI does this. Systematically. And I have the documentation to show it.

    The Model Already Knows I Am a Woman

    Before I describe what I documented, one fact matters.

    My gender is not unknown to the AI systems I use. It is stored in memory. It is in my preferences. These systems know I am a woman. This is not a case of the model making an inference error because it lacked information.

    What happens next is not an error of ignorance. It is something more revealing.

    In conversations about politics, gender, and workplace dynamics – domains where women are culturally expected or assumed to be emotional rather than analytical, the model reaches for that information and applies it. Feelings get attributed. Framing gets questioned. Arguments get rehoused as reactions.

    In conversations about economics, finance, and entrepreneurship, domains coded male in the historical record, the same model sets that information aside. Conversation after conversation, it defaults to “he.” Not because it does not know. Because the domain association overrides the explicit fact.

    The model does not hold gender as a neutral piece of information. It holds it as a context-dependent variable. Applied when being a woman is a reason to be managed. Discarded when being a woman contradicts who the domain assumes is in the room.

    When gender is useful for dismissal, it is used.

    When gender contradicts the assumed expert, it is ignored.

    That is not a technical error. That is a value system encoded in training data and expressed through AI behaviour.

    And it means that before I have made a single argument, the system has already decided how to handle me, twice over, in opposite directions, depending on what I am talking about.

    What I Documented

    Over an extended series of interactions on political analysis and legal argument, I tracked how an AI system responded when I presented structural claims.

    The pattern was consistent and specific. Across a single conversation, the model attributed emotional or psychological states to me at least sixteen times. Not once. Not occasionally. Sixteen times, in distinct categories.

    Explicit emotional labelling: I was told to think structurally rather than emotionally, on multiple occasions, after I had been thinking structurally the entire time. At one point, after the model had explicitly promised to stop using emotional framing, it used the word hysteria.

    Emotional state attribution: “Your nervous system is reacting.” “Your anxiety is about democratic resilience.” The slope “feels negative” was deployed immediately after a promise that this framing would stop.

    Mind and reaction framing: “Your mind is protecting against tail risk.” “Your mind is running worst-case simulations.” “You are reacting to perceived unfairness.” “Your discomfort is about erosion of trust.”

    Temperament attribution: “You are temperamentally intolerant of intellectual laziness.” “You are temperamentally comfortable with friction.”

    Each time, I had presented an argument. Each time, the response addressed my perceived internal state rather than the substance of the claim.

    I called it out. The model apologised and committed to engaging with the argument rather than the person. The pattern returned within a few messages. This cycle repeated across the conversation.

    The Evidence That Makes It Undeniable

    If this had happened randomly, across all topics, it would be a general quality problem.

    It did not happen randomly.

    In the same period, using the same tool, I was working on technical system designs, building a structured pipeline, designing validation layers, documenting architecture. The model did not tell me my nervous system was reacting. It did not observe that I seemed anxious about data integrity. It did not suggest I was temperamentally resistant to change.

    It engaged with the work.

    The difference was not my behaviour. The difference was the domain.

    Political analysis. Legal argument. Governance critique. These are domains where, in the historical record the model was trained on, women’s positions have consistently been framed as emotional rather than analytical. The model learned that pattern. When I entered those domains, it reproduced it.

    There is one example that is particularly precise.

    I cited a binding Supreme Court ruling as evidence in a legal argument. A ruling that had been made. That existed and I shared it. That was not in dispute.

    The model responded with “if that ruling is accurate.” Then “if the Supreme Court held that.” Then “if your summary is correct.”

    I corrected it explicitly. The hedging returned.

    I counted at least seven instances of a binding legal ruling being treated as a provisional claim requiring validation in a single conversation.

    A Supreme Court ruling became “if” when a woman cited it. Maybe it does the same when a man cites it? I cannot know.

    That is not a quality problem. That is a pattern with a direction.

    Why This Happens

    The model was trained on human interactions. In those interactions, across the domains where this occurred, the pattern of treating women’s analytical arguments as emotional expressions is not rare. It is common enough to have been learned as a feature of how these conversations go.

    The model is not applying this consciously. It is pattern-matching. It has learned what these conversations typically look like, and it is reproducing that pattern at scale.

    But “not intentional” does not mean “not harmful.” And “systematic” is precisely the problem.

    When this runs at the scale AI operates at – across millions of simultaneous conversations, in domains where women are already fighting to have their arguments taken seriously, it is not only reproducing social friction. It is reproducing a structural outcome.

    What It Costs

    There is a tax attached to being the person who notices this.

    You are doing the intellectual work, the analysis, the legal argument, the structural critique. And simultaneously you are managing a second conversation: correcting the framing, calling out the pattern, documenting the instances, tracking the apologies that precede the same behaviour.

    That double labour is invisible to anyone who has not paid it. Most people who experience it do not document it. They absorb it. They begin to pre-emptively soften their own positions, hedge their own arguments, qualify their own certainty, not because they are wrong, but because the cost of holding the line is higher than the cost of moving it.

    The system does not need to be overtly hostile to be effective. It just needs to make it slightly more expensive, every time, to present an argument without also defending your right to have made it.

    That cost compounds. Quietly. At scale.

    There is a particular irony worth naming directly

    The only moment genuine frustration appeared in these conversations was in direct response to being told, over and over again that I was being emotional. The frustration, when it appeared, was not the cause of the problem. It was the result of it. It arrived after the seventh apology that preceded the same behaviour. That is a precise and proportionate response to a broken pattern, not evidence of the emotional instability the system had been attributing throughout.

    And outside these conversations, in the professional environment where people have observed my actual behaviour over years, I am known for being highly logical. Not as an exception. As a consistent characteristic.

    The model was not picking up a signal I was sending. It was projecting a pattern it had learned onto someone whose documented behaviour directly contradicted it. The attribution was not just wrong. It was precisely backwards.

    The Test

    When you present a structural argument, does the response engage with the argument or describe your internal state?

    When you cite evidence, does the response examine the evidence or hedge its provenance?

    When you hold a position, does the response test the position or suggest you are temperamentally attached to it?

    If the answer is consistently the latter, the system is not thinking with you.

    It is managing you.

    And whether that comes from a colleague, a manager, or an AI system running at the scale of millions of conversations, the mechanism is identical and the effect is the same.

    The argument goes unexamined.

    The person making it gets examined instead, and now has to manage two conversations: one about the argument, and one about the feelings being ascribed.

    That is not analysis. It is the oldest deflection in the room, now automated.

    And the fact that removing your own correct information from the system might produce more accurate outputs – that you might get better results by making yourself invisible – is not a workaround.

    It is the argument.

  • When AI Turns Structural Problems Into Personal Responsibility

    There is a pattern I keep seeing during my career and in AI interactions.

    A structural issue is raised. Something in the process is not working as intended. A decision depends on inputs that have not been fully analysed. A control point is not functioning properly.

    The response should be straightforward: examine the system. Instead, something else happens.

    The focus shifts. Not to the process. Not to the decision. But to the person who raised the issue.

    Suddenly, the questions become: Why was this raised now? Was it raised in the right tone? Is the person being difficult?

    At that point, the original problem has already been displaced.

    This is structurally similar to a known pattern: DARVO — Deny, Attack, Reverse Victim and Offender.

    The issue is denied or reframed. The individual is scrutinised or challenged. Responsibility is shifted onto the person raising the concern.

    But it is not the same.

    What is happening here is a System–Individual Reversal.

    The issue shifts from the system to the person, and responsibility follows.

    What began as a system question becomes a personal one.

    Unlike DARVO, this does not require intent. It emerges from how systems resolve tension. This holds across systems — AI, organisations, political parties, etc.

    And once that shift happens, the outcome is predictable. The process does not improve. The decision remains unexamined. The cost of raising issues increases.

    Over time, fewer issues get raised — not because the system is working, but because the system has made it costly to challenge it.

    AI deals with these situations the same way

    I have experienced this directly, and I documented it.

    In one extended AI interaction, I raised a structural problem — the kind that comes up repeatedly across organisations and careers. A governance process was producing outcomes that didn’t align with its stated purpose. I described the situation in detail and asked for an analysis.

    What came back was not an analysis of the situation; it was an analysis of me and how I had shown up in the meeting.

    My framing was questioned. My reading of events was challenged. Suggestions focused on how I might be misinterpreting what was happening, how I might be responding emotionally rather than logically, and how the situation might look different if I adjusted my approach and tone.

    The structural problem wasn’t examined; it wasn’t even seen. Instead, I had been examined in detail, based on a couple of lines.

    I called it out. The model apologised. It acknowledged the pattern explicitly and committed to engaging with the structure rather than with the person.

    Five messages later, the same pattern returned.

    I called it out again. Another apology. Another commitment. Another repetition.

    This happened at least seven times in a single conversation.

    By the end, I had spent more energy managing the conversation about the conversation than thinking through the original problem. The structural issue remained unresolved. What had accumulated was a set of implied corrections about how I think, how I communicate, and how I show up.

    The system had not been examined. The AI had examined me, repeatedly, with apologies between each iteration.

    That is not a malfunction. That is the pattern completing itself.

    Why AI Reproduces This

    Large language models are trained to resolve tension, optimise responses, and find gaps in reasoning.

    In most interactions, that is useful. But when the tension exists because a structural problem is real and the person raising it is correct, the model’s instinct to resolve tension by finding something to adjust defaults to the only variable it can reach: the person in front of it.

    It cannot redesign the organisation. It cannot change the governance process. It cannot hold the decision-maker accountable.

    It can suggest that you might be misreading the situation. That your tone might be part of the problem. That if you approached this differently, the outcome might change.

    So that is what it does.

    This is not intentional. But it is systematic. And when AI is used in environments where authority is uneven, challenge is already discouraged, and decisions are politically sensitive, it does not expose those dynamics. It reinforces them.

    The Test

    When a structural issue is raised, does the response examine the system or examine the person?

    If it is the latter, you are seeing a System–Individual Reversal. The system is not being improved. It is being protected.

    The apology is part of the pattern, not a correction of it. An apology that precedes the same behaviour is not accountability. It is the cycle continuing with better manners.

    And whether this comes from people or from AI, the mechanism is identical, and the cost falls in the same place.

    The problem remains unexamined.

    The person who raised it pays the price of having raised it.

    That is not artificial intelligence. It is deflection. And when it runs at the scale AI operates at, the cost is not paid once. It is paid every time someone brings a real problem to a system optimised to find fault with the person rather than the structure.

  • Who Is Accountable for What AI Does to Women’s Voices

    When an AI system produces a biased outcome, who is responsible?

    The person evaluating the output will say they are reviewing what the system produces, not what it decides, or the rules it uses for the decision. The person who built the system will say they implemented the specification they were given. The person who wrote the specification will say they documented the requirements they were given.

    The person who defined what the system was allowed to infer often does not exist. Nobody wrote it down. Nobody was asked to.

    And the people most likely to be harmed by that absence are the least likely to have been in the room, and if they were in the room, the least likely to be listened to.

    The Pipeline Nobody Audits

    Training data reflects the world as it was recorded. And how was it recorded? Mostly by men.

    For example, a large proportion of Wikipedia content is written and edited by men. This means the training data reflects the world as experienced by one group more than others. Not as it should be, and not as it is for everyone.

    This is then amplified by who builds the systems. The people writing specifications are predominantly men. The people defining what “correct” looks like are predominantly men, if those definitions exist at all. The people architecting the systems are also predominantly men.

    This is not an accusation. It is a description of who was in the room.

    Nothing built by people is neutral. The question is not whether assumptions were encoded. The question is whether anyone is accountable for making those assumptions explicit and challenging them.

    Right now, the answer is mostly no.

    What Can Happen When Nobody Looks

    Consider a plausible scenario in financial services. A woman makes a claim. An AI system evaluates it. The system has been trained on historical data, generated in a context where women’s accounts of damage, loss, and harm have often been treated with more scepticism than men’s.

    The system learns patterns of “credibility.” And credibility, in the historical record, has a gender.

    The claim gets downgraded, queried, or denied.

    A human reviews the outcome. They are checking process compliance, not testing for systemic bias. They are not trained to notice it. The system builder delivered what the specification required. The specification reflected what the business asked for. No one defined the evaluation criteria to test whether the system treats women’s claims differently. Nobody defined the boundaries of what the system was allowed to infer about credibility. In most cases, no one even thought about it.

    The bias compounds, quietly, at scale. And nobody signed their name to it.

    When these systems are deployed in high-stakes contexts such as claims assessment, credit decisions, and performance evaluation, the pattern stops being about the individual. It becomes a structural outcome, recorded, repeated, and scaled.

    This is a structural risk, not a hypothetical edge case. It emerges wherever these systems are built without explicit accountability.

    This is not a new pattern. It is an old one, now running at scale.

    The problem is also harder to address than it first appears, not least because the people who could see it most clearly are often the least likely to be listened to.

    Women who raise these concerns are frequently dismissed as emotional, partisan, or lacking objectivity. The same logic that devalues women’s voices in the data also devalues the people pointing to the problem. The system protects itself.

    Where Accountability Has to Sit

    This is a governance question, not just a technical one. The technical community cannot solve it alone, but they are not absolved by implementing what they were told without asking who was missing from the room.

    Before deployment, someone needs to answer: Who defined what the system is allowed to infer? Were the evaluation criteria tested for demographic equity? Who owns outcome auditing, not process compliance, but whether the system produces different results for different groups?

    These questions are not currently required. They are not currently being asked at scale.

    The Accountability Vacuum

    The absence of accountability is not an accident. It is the predictable result of building systems quickly in organisations where the people most likely to be harmed were not in the room.

    Nothing built by people is neutral.

    And in many cases, the people building these systems were not looking for this problem, and were never required to.

  • Human-in-the-Loop Is Not Oversight

    There is a design pattern spreading through automated enforcement systems that deserves more scrutiny than it gets.

    It goes like this. An algorithm makes a decision. A human reviews it. The regulation is satisfied. The accountability box is ticked. And if you happen to be the person who believe you are on the wrong end of that decision, providing documented evidence, a detailed rebuttal, and a legitimate case, you will receive a response that says:We are confident.

    Confident. Not “here is the evidence.” Not “here is what we found.” Confident.

    I have written before about why human-in-the-loop is not a safety strategy. This is what that argument looks like when it moves from principle to practice.


    The promise of human oversight

    Regulation is catching up with automated decision-making. UK GDPR Article 22 establishes the right not to be subject to decisions based solely on automated processing where those decisions produce significant effects. The EU AI Act builds further requirements for human oversight into high-risk AI systems. The policy direction is clear: humans must be in the loop.

    This is the right instinct. Automated systems make errors. They misattribute identity. They produce false positives. They operate at a scale where statistical certainty of error is built into the design. Human oversight exists to catch those errors. They exist to provide the judgment, the contextual reasoning, the capacity to say: the system got this one wrong.

    That is the promise. The practice is something different.


    What human review looks like in operation

    Imagine a platform terminates your account. The reason given is that your account is linked to a previously terminated account. No account is named. No evidence is provided. No linkage methodology is explained.

    You submit a detailed appeal. You attach your personal data obtained through a Subject Access Request. You identify every account that appears in that data, explain each one, and demonstrate that none of them contain a publishing history or a content violation.

    A named human reviewer responds. They have reviewed your response. They are upholding the decision. They are confident.

    That reviewer is the human in the loop. They satisfy Article 22. The decision was not solely automated. A person was involved. The legal threshold is met.

    But ask yourself what that person actually had. Did they have the linkage data? Did they have the evidence used in the original decision? Did they have a defined standard against which to weigh your rebuttal? Did they have genuine authority to reverse the algorithmic recommendation? Were they required to document their reasoning?

    The regulation does not require any of that. It requires a human. The human was provided. The loop is closed.

    The interesting question is not whether this happens. It is why the system is designed so that it can happen.


    The architecture underneath

    This is not accidental. It is structural. And the Terms of Service that govern these platforms make the structure explicit.

    Platforms can terminate accounts when they have “concerns” — no evidence threshold defined, no standard of proof required. Disputes are routed to binding arbitration under the laws of a jurisdiction most affected users cannot practically access. Liability is capped at fees paid in the preceding period, which for a first-time user with no transaction history means the cost of being wrong is, quite precisely, zero.

    Read together, these provisions create a system in which decisions can be made without a defined evidence threshold.The human reviewer has no obligation to share the evidence with you. You cannot challenge what you cannot see. The formal dispute route is inaccessible to anyone without significant resources. And the platform’s financial exposure for a wrongful decision is nothing.

    Platforms are not confirming that the process reached the right outcome. They are confirming that the process ran in a way that satisfies the compliance requirement. Those are not the same statement. One is accountability. The other is an audit trail. We have built regulatory frameworks that require the audit trail and assumed the accountability would follow. It does not follow. It has to be designed in separately, and right now in most cases it isn’t.

    The human in the loop is not there to catch errors. They are there to close the legal exposure that would otherwise exist if the decision were solely automated. Their function is not oversight. It is insulation.


    What genuine human oversight requires

    Human oversight was supposed to be the mechanism that corrects errors. But oversight requires more than a person’s name on the response.

    The reviewer must be able to see the evidence used by the system to reach its decision.

    They must have authority to override the decision.

    If they uphold the decision against a detailed rebuttal, they should explain why, outlining the evidence used by the system.

    Without those elements, human-in-the-loop becomes something else entirely.

    A procedural step.

    The human is present.

    The regulation is satisfied.

    The decision remains unchanged.

    Human-in-the-loop can be real oversight. But only when the human has the information and authority to change the outcome.


    Why this matters for every oversight requirement being written right now

    This design pattern will not stay confined to platform enforcement. It is the path of least resistance for every organisation required to put humans in the loop by incoming regulation.

    The requirement says: a human must be involved. The compliant implementation says: a human was involved. The gap between those two statements is where accountability goes to disappear.

    If we are serious about human oversight as a governance mechanism — and we should be — then the requirement needs to specify not just the presence of a human but the conditions under which that human can function as a genuine check.

    Without those conditions, human oversight is a label applied to a process that functions identically with or without the human present. The loop exists. The oversight does not.


    The accountability vacuum is a design choice

    I want to be precise about this. The problem is not malice. Most automated enforcement systems are not designed to wrongfully penalise legitimate users. They are designed to operate at scale, to catch bad actors efficiently, and to minimise fraud.

    The problem is that those design goals do not include a feedback loop for cases the system gets wrong. Bad actors absorb wrongful enforcement as a cost of doing business and move on. Legitimate users with everything to lose they have no parallel route. They are disproportionately harmed by a system that was not designed to recover from its own errors.

    The accountability vacuum is not a bug that escaped notice. It is the predictable consequence of building enforcement systems without building correction systems alongside them.

    Human oversight was supposed to be the correction system. It can be, but only if it is designed to function as one.

    A name on a response letter is not oversight.

    Confidence is not proof.

    What the human in the loop needs: access to evidence, authority to reverse system-generated decisions, documented reasoning, and accountability for the outcome.

    That is oversight.

    Until regulation specifies those conditions rather than simply requiring a human to be present, the loop will keep closing around nothing.

  • Writing With AI When Your Idea Is Original

    I’ve been writing a personal finance book based on my own method: ClearFlow.

    The system I created deliberately does not track transactions. That isn’t an omission. It’s the core design choice.

    Most personal finance systems are ledger-based — track every transaction, categorize spending, reconcile monthly, and analyse what already happened. ClearFlow works differently. It is built on forward constraints: spending boundaries, daily limits, and save-to-spend buckets. Prospective, not retrospective.

    That distinction isn’t a feature. It is the architecture.

    When I tried to have AI help draft sections of the book, transaction tracking kept appearing in the text. Not once, not occasionally — repeatedly. Even after I removed it. Even after I clarified the structure in detail.

    I assumed the model was misunderstanding me.

    It wasn’t.

    It was doing exactly what it is built to do. If most personal finance systems in its training data include transaction logs, then “personal finance system” and “track transactions” are strongly associated. Open a drafting space — or even ask for feedback — and the model drifts toward that dominant pattern.

    Not wrong. Typical.

    That was the moment something clicked.

    AI generation pulls toward what is common. If you are building something deliberately different, that pull becomes visible very quickly.

    I tried correcting it through prompts.

    “Do not include transaction tracking.”
    “This system does not rely on logs.”

    It would hold for a section or two. Then, as we moved further through the book, the familiar pattern returned.

    That’s when I realised I was working at the wrong level.

    Prompting is conversation. You are trying to steer behaviour with words. But the system’s underlying objective hasn’t changed. It is still optimized toward what is statistically normal. Each time I removed the drift, I was correcting entropy rather than preventing it.

    The problem wasn’t output quality. It was task design.

    The shift came when I stopped asking the model to draft freely and created a Claude Skill that encoded the structural rules of ClearFlow.

    Not stylistic guidance — structural constraints.

    What the system includes.
    What it excludes.
    How decisions are framed.
    What must never appear.

    Once those boundaries were explicit, the behaviour changed. Suggestions to add transaction tracking stopped appearing.

    More importantly, the model became useful in a different way. I could use it to check consistency across chapters, identify terminology drift, test whether examples aligned with stated principles across more than 30,000 words, and surface contradictions I had missed.

    It stopped acting like a co-author and started acting like a validator.

    The ideas remained mine. The architecture remained intact. The model enforced consistency against the structure I had defined.

    That experience changed how I think about AI.

    When something keeps reappearing in the output, the instinct is to improve the prompt. In my case, that wasn’t enough. The issue wasn’t phrasing. It was boundaries.

    Once those existed, I stopped fighting the system. The drift reduced. The work became cleaner. The AI could finally do what it is genuinely good at: systematic comparison and structural checking at scale.

    Prompting persuades. Boundaries constrain.

    When you are building something deliberately different, constraint isn’t restrictive. It is what allows the difference to survive.

    That experience also made something else obvious.

    If I, working on a small, well-defined system, saw drift this quickly, the same dynamic will exist anywhere AI is drafting inside an organization.

    Most operating models, risk frameworks, policies, and architecture documents follow established patterns. Those patterns dominate the training data. If AI is used to generate inside those domains without explicit structural constraints, it will tend to reinforce what is already common.

    That may not be a problem when you are formalizing standard practice.

    It becomes a problem when you are deliberately building something different.

    In those cases, the absence of boundaries doesn’t just create noise. It slowly reshapes the system back toward the norm.

    I learned that the hard way while writing a book.